arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

利用感知能力:针对多模态大语言模型智能体的隐蔽并发音频提示注入攻击

Piggybacking on Perception: Stealthy Concurrent Audio Prompt Injections against Multimodal LLM Agents

Mingxiao Liu, Yitong Li, Haoren Zhao, Yaoxiang Bian, Jianan Ma, Jian Zhang, Jialuo Chen, Xinhao Deng, Zhen Wang

arXiv 2607.28165首次发表:更新:

AI 中文总结

该研究针对多模态LLM智能体提出隐蔽并发音频提示注入攻击,构建首个相关基准并评估多款智能体,还提出CADV防御机制,经实验验证攻击有效且防御可靠。

AI 中文摘要

由大语言模型(LLM)驱动的多模态智能体正越来越多地通过连续音频交互部署,以执行自主任务。这种范式提升了交互自然度,但也引入了一个关键且未被充分探索的攻击面,因为音频输入不可避免地包含用户无法控制的环境噪声。本文研究针对多模态智能体的并发音频提示注入攻击。与针对语音设备的传统声学攻击不同,我们提出了指令增强和场景隐藏的新技术,这些方法可让恶意音频指令不可察觉地“搭载”在用户语音上,从而劫持智能体执行恶意操作。为系统量化该威胁,我们构建了AudioAgentSecurity,这是首个针对音频指令注入攻击的综合基准,涵盖8个真实世界任务场景和10种不同攻击模式。我们评估了11种最先进的智能体,包括Gemini 3 Pro和GPT-4o-audio。值得注意的是,我们的方法对先进的Gemini 3 Pro实现了69.10%的平均攻击成功率(ASR)。为应对这一威胁,我们进一步提出了级联音频解耦与验证(Cascaded Audio Decoupling and Verification,CADV),这是一种基于源分离和一致性分析的防御机制。与现有的提示级防御相比,CADV利用声学源分离和跨模态一致性分析来更稳健地检测音频指令注入,在不同攻击向量上实现了超过90%的检测成功率。最后,在真实世界实验中,我们让人类志愿者在不同动态真实场景下使用豆包AI智能手机开展测试,证实了这些攻击具有高隐蔽性和有效性,同时表明我们的防御机制可有效缓解这些漏洞。

英文摘要

Large Language Model (LLM)-driven multimodal agents are increasingly deployed to execute autonomous tasks via continuous audio interaction. While this paradigm enhances interaction naturalness, it introduces a critical yet under-explored attack surface, as audio inputs inevitably contain environmental noise beyond user control. In this paper, we investigate concurrent audio prompt injection attacks targeting multimodal agents. Distinct from traditional acoustic attacks on voice devices, we propose novel techniques for instruction augmentation and scenario concealment. These methods allow malicious audio instructions to imperceptibly "piggyback" onto user speech, thereby hijacking agents to execute malicious actions. To systematically quantify this threat, we construct AudioAgentSecurity, the first comprehensive benchmark for audio instruction injection attacks, encompassing 8 real-world task scenarios and 10 distinct attack patterns. We evaluate 11 state-of-the-art agents, including Gemini 3 Pro and GPT-4o-audio. Notably, our methods achieve an average Attack Success Rate (ASR) of 69.10\% against the advanced Gemini 3 Pro. To counter this threat, we further introduce Cascaded Audio Decoupling and Verification (CADV), a defense mechanism based on source separation and consistency analysis. Compared with existing prompt-level defenses, CADV achieving up to 96\% detection accuracy and providing effective protection against a broad range of acoustic injection attacks. Finally, real-world experiments with human volunteers on Doubao AI Smartphone in diverse dynamic real-world scenarios confirm the attacks' high stealth and efficacy, while demonstrating that our defense reliably mitigates these vulnerabilities.

Comments19 pages, 8 figures, The code is publicly available at https://github.com/Limax666/AudioAgentSecurity

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑