Researches Claim New Way of Hacking into Virtual Assistants Using Ultrasonic Waves

A smartphone microphone can pick up sounds inaudible to human ear.

Advertisement
By Darab Mansoor Ali | Updated: 17 March 2020 17:48 IST
Highlights
  • The research is conducted by Scientists at the Michigan State University
  • Scientists were able to engage assistants in 15 phones
  • This vulnerability was first discovered in 2017

This phenomenon was first discovered in 2017 as the ‘Dolphin Attack’

Voice-based virtual assistants are susceptible to hacking, like most online tools. Researchers at the Michigan State University's College of Engineering now claim to have discovered a new way of hacking into a person's personal device by engaging virtual assistants like Apple's Siri and the Google Assistant through ultrasonic soundwaves. The research paper was presented by scientists from Michigan State University's Department of Science and Engineering at the Network and Distributed System Security Symposium on February 24. The researchers used inaudible ultrasonic vibrations to give commands to the virtual assistants, since a smartphone's microphone can pick up sounds inaudible to the human ear.

The study, named SurfingAttack, was headed by Michigan State University's Assistant Professor in the Department of Computer Science and Engineering, Qiben Yan. Yan told a website called TechXplore that the research team used inaudible vibrations that can be sent through any hard and flat surface (especially tabletops) to activate voice assistants up to 30 feet away.

Advertisement

The researchers placed mobile phones on a hard surface and ran ultrasonic waves from across the surface. The ultrasonic waves engaged the virtual assistant; as a smartphone's microphone was detect inaudible sounds. Hackers could use ultrasonic waves to secretly control the voice assistants on smartphones, which are usually activated using phrases like 'OK Google' or 'Hey Siri' as wake up words. Then, the attacker can give whichever command he/she pleases. This is dangerous since there are a lot of malicious use cases that a hacker can engage in by using this technique. Some examples were placing a malicious call to a friend or family or cancelling meetings, or activating smart home appliances.

To come to the conclusion, the researchers used piezoelectric transducer under a table or charging station which converted electricity into ultrasonic vibrations. The technique worked for 15 out of the total 17 smartphones used by the researchers. They used 17 different phone models to test this technique, out of which it worked on the following: iPhone 5, iPhone 5S, iPhone 6, iPhone X, Google Pixel, Pixel 2, Pixel 3, Xiaomi Mi 5, Xiaomi Mi 8, Xiaomi Mi 8 Lite, Samsung Galaxy S7, Galaxy S9 and the Honor View 8. "This research exposes the insecurity within smartphone voice assistants," a co-author told TechXplore. The researchers also advised people to be wary of public charging stations.

Advertisement

Now, this is not the first time such a vulnerability has surfaced. It was first discovered almost three years ago, in 2017 by researchers at China's Zheijiang University. It was named as the 'Dolphin Attack' at that time, since Dolphins use ultrasound to navigate. In the Dolphin attack also, the attackers used frequencies inaudible by a human ear to engage virtual assistants in smartphones and smart speakers.


Is Redmi Note 9 Pro the new best phone under Rs. 15,000? We discussed how you can pick the best one, on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OPPO K14 5G Overview: Segment's Smoothest and Longest-Performing Smartphone Under ₹25,000
  2. Vivo X300 FE Arrives in India With a 50-Megapixel Zeiss Camera at This Price
  3. Infinix Note 60 Pro Review: Just Another Mid-Ranger?
  4. Samsung Galaxy Watch 9 Visits Company's Site Well Ahead of Anticipated Debut
  5. Adobe Acrobat gets a Productivity Agent, New PDF Spaces Features
  6. Vaazha II: Biopic of a Billion Bros OTT Release Date Revealed Online
  1. Astronomers Discover Trans-Neptunian Object With Atmosphere in Outer Solar System
  2. Samsung's One UI 8.5 Update Finally Rolls Out to Galaxy S25 Series, S24 Series, S25 FE, Z Fold 7 and Z Flip 7
  3. Samsung Galaxy A27 5G Shows Up on Geekbench Again With Slightly Improved Performance Scores
  4. Adobe Unveils New Productivity Agent for Acrobat, Adds New Features to PDF Spaces
  5. Google's May 2026 Update for Pixel Devices Rolls Out With Fixes for Slow Wireless Charging, Screen Freezing Issues
  6. Colombia Seeks to Mine Bitcoin Using Surplus Renewable Energy From Country's Coastline
  7. CloudZ RAT Malware Could Exploit Microsoft Phone Link App to Access Messages and OTPs, Researchers Warn
  8. Vaazha II: Biopic of a Billion Bros OTT Release Date: When and Where to Watch This Malayalam Drama Film Online
  9. Dacoit: A Love Story OTT Release Date: When and Where to Watch Adivi Sesh and Mrunal Thakur Starrer Online?
  10. Sony Xperia 1 VIII Price, Sale Date Reportedly Surface Online via Amazon Listing
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.