Near-Ultrasound Inaudible Trojan (NUIT): Exploit Your Speaker to Attack Your Microphone

NUIT-1

NUIT-1

NUIT-2

NUIT-2

What is NUIT?

NUIT is a novel inaudible attack against voice assistants (Siri, Google Assistant, Alexa, Cortana) that can be waged remotely through internet. Nuit  appears as a sound clip  in near-ultrasound frequency range (16kHz-20kHz), thus can be played on the victim's COTS speaker to attack the voice assistant  (i) on the same device (NUIT-1);(ii) on victim's other devices (NUIT-2).

Note that Nuit2 is between two phones (Device 1: performs as the attacking device or the speaker. Device 2 is the victim device, which voice assistants are the NUIT2 attacks’ target) 

To cite

@inproceedings {287266,

title = {{Near-Ultrasound} Inaudible Trojan (Nuit): Exploiting Your Speaker to Attack Your Microphone},

booktitle = {32nd USENIX Security Symposium (USENIX Security 23)},

year = {2023},

address = {Anaheim, CA},

url = {https://www.usenix.org/node/287267},

publisher = {USENIX Association},

month = aug,

}

Other NUIT 1 Demos(Exploiting Your Speaker to Attack Your Microphone on the Same Device) : 

NUIT-1 Silent Response End-to-End Attack:

Embedded into a file with no background music:


Embedded into a file with background music:


Real-time online chatting attack:

Other NUIT 2 Demos(Exploiting Your Speaker on One Device to Attack Your Microphone on Another Device):

NUIT-2 Silent Response End-to-End Attack:

Between two phones:

Between a phone and another IoT device (laptop, google home, echo, desktop)


Between two IoT devices:


Real-time online chatting attack:


Embedded into a file with background music:


Directionality Test

 

iPhone 6 Plus vs. iPhone X,XR legit command test

https://youtu.be/ig1-YPlnGj8

Contact us for future collaboration at 

NUIT is discovered by researchers from University of Texas at San Antonio and University of Colorado Colorado Springs.  We are: