LOGBOOK

HELP

Quiz Entry - updated: 2026.09.18

How can a voice assistant be commanded by a sound its owner cannot hear?

Ultrasonic frequencies above human hearing are used as a carrier, amplitude-modulated by ordinary speech; the microphone's own non-linearity demodulates it back into audible-range signals, so the assistant hears a command that the room does not.

The devices in question — Siri, Alexa, Google Assistant — are designed to be controlled by voice, which means they are permanently listening. The attack (known as DolphinAttack) exploits how the listening hardware works rather than any flaw in the assistant:

  1. A microphone converts sound into an electronic signal via a deformable membrane that vibrates when struck by sound waves.
  2. That vibration is transformed into electronic form. Human hearing tops out around 20 kHz, so anything above that is inaudible to a person — but the membrane still responds to it.
  3. The attacker uses an ultrasonic frequency amplitude-modulated by the frequency of ordinary speech.
  4. The ultrasound acts as a carrier wave for the spoken message, and the microphone's imperfect (non-linear) response recovers the speech as if it had been spoken aloud.

Because the carrier is inaudible, the command can be embedded into music or spoken text and delivered from a speaker, a video, or a passing device without anyone in the room noticing.

The consequences are exactly the consequences of the assistant's legitimate powers: unlocking smart locks, reaching bank accounts, retrieving personal information — anything a voice command can do.

Tip: the general pattern is worth more than the specific attack. A sensor's physical response is part of its attack surface. Software validation cannot help if the transducer itself accepts input the designer assumed was impossible.

Go deeper:

From Quiz: SIOT / IoT Networking and Security | Updated: Sep 18, 2026