MetaGuardian: Enhancing Voice Assistant Security through Advanced Acoustic Metamaterials
Zhiyuan Ning, Zheng Wang, Zhanyong Tang
Abstract
Voice assistants (VAs) have become integral to daily life, yet their always-on microphones make them attractive targets for attacks that threaten user privacy and safety. We present MetaGuardian, the first system to leverage acoustic metamaterials to defend against three major classes of attacks for VAs - inaudible, adversarial, and laser-based - within a single, portable design. Unlike prior defenses, MetaGuardian can be seamlessly integrated into the enclosures of commercial smart devices, providing strong protection without requiring software modification, hardware redesign, or costly machine learning models. MetaGuardian leverages mutual impedance effects between metamaterial units to extend the protection range to 16–40 kHz, effectively blocking wideband inaudible attacks. It also employs a carefully designed coiled space structure to disrupt adversarial signals while preserving normal VA operations. Its universal design allows flexible adaptation to different devices, striking a balance between portability and protection effectiveness. In controlled evaluations, MetaGuardian achieves a high defense success rate across all attack types, offering a practical and reliable foundation for securing VAs on smart devices.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on15
- DolphinAttack: Inaudible Voice CommandsGuoming Zhang, Chen Yan, Xiaoyu Ji, Tianchen Zhang et al.CCS 2017 · 753 citations
- CommanderSong: A Systematic Approach for Practical Adversarial Voice RecognitionXuejing Yuan, Yuxuan Chen, Yue Zhao, Yunhui Long et al.USENIX Security 2018 · 389 citations
- Robust Detection of Machine-induced Audio Attacks in Intelligent Audio Systems with Microphone ArrayZhuohang Li, Cong Shi, Tianfang Zhang, Yi Xie et al.CCS 2021 · 29 citations
- ALIF: Low-Cost Adversarial Audio Attacks on Black-Box Speech Platforms using Linguistic FeaturesPeng Cheng, Yuwei Wang, Peng Huang, Zhongjie Ba et al.S&P 2024 · 16 citations
- VoShield: Voice Liveness Detection with Sound Field DynamicsQiang Yang, Kaiyan Cui, Yuanqing ZhengINFOCOM 2023 · 13 citations
Related papers
- StickShield: Flexible Acoustic Metamaterial Defense for Securing Microphones Against Voice AttacksZhiyuan Ning, Zhanyong Tang, JiaYi Xing, Rui Hou et al.CCS 2026
- MicGuard: A Comprehensive Detection System against Out-of-band Injection Attacks for Different Level Microphone-based DevicesTiantian Liu, Feng Lin, Zhongjie Ba, Li Lu et al.USENIX Security 2024 · 4 citations
- LaserAdv: Laser Adversarial Attacks on Speech Recognition SystemsGuoming Zhang, Xiaohui Ma, Huiting Zhang, Zhijie Xiang et al.USENIX Security 2024 · 6 citations
- Learning Normality is Enough: A Software-based Mitigation against Inaudible Voice AttacksXinfeng Li, Xiaoyu Ji, Chen Yan, Chaohao Li et al.USENIX Security 2023
- Light Commands: Laser-Based Audio Injection Attacks on Voice-Controllable SystemsTakeshi Sugawara, Benjamin Cyr, Sara Rampazzi, Daniel Genkin et al.USENIX Security 2020
