Phipps, Anthony (2022) Modelling and mitigating the threats to audio based computer systems: experimentation into the use of digital and audio steganography for authentication. Doctoral thesis, London Metropolitan University.
Conversational computing is rapidly changing the way we interact with computing devices. Voice assistants have become ubiquitous and are embedded in phones, laptops, cars, smart speakers, and everyday household appliances. The use of speech interfaces has delivered increased convenience and accessibility. Whilst use of voice computing is common for internet search, playing music and home automation, it has had relatively low uptake for activities requiring high confidence from a security perspective. The purpose of this research was to establish what security challenges exist and how these can be addressed.
The current approaches to conversational computing and voice assistants vary depending upon the platform and by the particular application. By far the most common approach is for the interactions to be unauthenticated at time of use, relying on techniques such as physical security, pre-registration, and authenticated devices.
Research has shown that voice computing and speech interfaces are subject to a growing number of attacks. In many scenarios there is no authentication at all for individual interactions. Voice biometrics is an area where some progress has been made however voice biometrics do not perform as well as other biometric authentication methods.
The aim of this research was to critically review the current state of audio-based security technologies from a threat-model based approach, experimentally test what could be done to address the current gaps using audio steganography and propose an approach to incorporating such techniques into a conceptual model. This gave rise to research questions such as what are the threats to be addressed? What factors could be used to address these threats? Is it possible to authenticate users whilst retaining the convenience of an audio channel using techniques such as audio steganography?
A hybrid methodology that combined conceptual modelling and experimental approaches was used to conduct the research.
The threats to audio and speech interfaces are growing in number and many are yet to be addressed. The use of audio steganography has been investigated as a method of transmitting authentication data that preserves the convenience of using audio channel and a model developed that shows how this could be used.
The threat model from this research shows the challenges that any speech-based system face. The conceptual model proposed in this research outlines how these threats may be addressed in the case of using any voice assistant type devices.
Experimentation has shown some promise in the method of using audio steganography as an authentication factor. Future work should focus on how to make the audio authentication method more robust to environmental factors and explore further novel uses of this technique.
![]() |
View Item |
Tools
Tools