UltrasonicWhisper+: Ultrasonic Attacks Generate Phantom Sounds in Your Hearable
Hiroki Watanabe, Tsutomu Terada
Abstract
Modern hearables, such as wireless earbuds with transparency mode, are designed to enhance user awareness by relaying ambient sounds. However, this functionality introduces a new attack surface. We present UltrasonicWhisper+, a novel attack that exploits microphone nonlinearity to inject inaudible ultrasound into hearables, resulting in the demodulation of phantom audible sounds delivered directly to the user. Unlike prior ultrasound-based attacks that target voice assistants, our method deceives users themselves by simulating either internal hearable audio or spatial environmental sounds. We evaluate five commercial hearables and find that demodulated sound quality varies by device, with mean opinion scores (MOS) ranging from 1.26 to 3.27 and short-time objective intelligibility (STOI) ranging from 0.44 to 0.75. Behavioral studies show that participants followed an average of 28.0% of false instructions even after being warned about the attack. Moreover, spatialized ultrasonic sounds achieved 65.5% localization accuracy (±45°), and a false acceptance rate of 28.4% when perceived as ambient sound. These findings demonstrate that users can be reliably deceived via inaudible audio signals, raising serious concerns for safety-critical applications. Our results call for a reexamination of hearable device security and highlight the need for robust countermeasures.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get ebb21ce1-0b40-431c-b9de-c274d8ede9f0Related papers
- Sirens' Whisper: Inaudible Near-Ultrasonic Jailbreaks of Speech-Driven LLMsZijian Ling, Pingyi Hu, Xiuyong Gao, Xiaojing Ma et al.USENIX Security 2026 · 185 citations
- EarArray: Defending against DolphinAttack via Acoustic AttenuationGuoming Zhang, Xiaoyu Ji, Xinfeng Li, Gang Qu et al.NDSS 2021
- InfoMasker: Preventing Eavesdropping Using Phoneme-Based NoisePeng Huang, Yao Wei, Peng Cheng, Zhongjie Ba et al.NDSS 2023
- Inaudible Adversarial Perturbation: Manipulating the Recognition of User Speech in Real TimeXinfeng Li, Chen Yan, Xuancun Lu, Zihan Zeng et al.NDSS 2024
- LaserAdv: Laser Adversarial Attacks on Speech Recognition SystemsGuoming Zhang, Xiaohui Ma, Huiting Zhang, Zhijie Xiang et al.USENIX Security 2024 · 6 citations
