Skip to main content
  1. Home
  2. Emerging Tech
  3. Mobile
  4. News

Forget Face ID, VoiceGesture reads your lips with sonar to unlock your phone

Add as a preferred source on Google

Voice-recognition technology is getting better and better, but if you’re using it for security applications such as spoken passwords, it is not infallible. A team of researchers at Florida State University in Tallahassee may have a solution for spoofing attacks on voice biometrics, however — and it involves sonar.

Called VoiceGesture, the system developed by the team reappropriates your smartphone as a Doppler radar, transmitting a high-frequency sound from the device’s speaker and then listening to the reflections on the microphone when a person says their passcode. Compared to some of the weaknesses involved in regular voice biometric systems, such as the risk of someone impersonating your voice or using a recorded sample, it’s far more effective.

Recommended Videos

“Our system evaluation involves 21 users with thousands of passphrases and three types of smartphones: Samsung Note 5, Note 3, and Galaxy S5,” Jie Yang, an assistant professor in the Department of Computer Science, told Digital Trends. “Experimental results show that VoiceGesture achieves over 99 percent spoofing attack detection accuracy at around one percent equal error rate (EER).”

Florida State isn’t the only research institute currently investigating ways to make voice biometrics more secure. Recently, we covered a research project from the University of Michigan, which utilizes an accelerometer-based wearable accessory — currently a necklace, earbuds, or glasses attachment — to measure the unique skin vibrations in a person’s face, throat, or chest when they talk.

But what makes VoiceGesture stand out is the fact that it requires no additional hardware in order to work. Yang says that it can be integrated with existing smartphone operating systems and mobile apps for more secure device login, without having to change the physical devices themselves. He told us that the team has already approached Google, who are reviewing the proposed technique. “We also plan to reach out to other smartphone manufacturers like Samsung and Huawei,” Yang said. Should it prove as secure as the team claims, let us hope this turns up on a next-generation smartphone in the near future.

A paper describing the work, titled “Hearing Your Voice is Not Enough: An Articulatory Gesture Based Liveness Detection for Voice Authentication,” is available to read here.

Luke Dormehl
I'm a UK-based tech writer covering Cool Tech at Digital Trends. I've also written for Fast Company, Wired, the Guardian…
Chinese startup claims its brain implant takes just 10 minutes to place, no skull surgery required
StairMed Technology's vein-based BCI could beat Neuralink's roughly two-hour surgery on speed, but the device still hasn't undergone human trials.
Art, Plate, Crystal

Brain implants, like the ones made by Elon Musk's Neuralink, typically involve open-skull surgery. But a Chinese startup says it can skip that step entirely, threading its device into the brain through a vein in a procedure that reportedly takes as little as ten minutes. According to the South China Morning Post, Shanghai-based StairMed Technology is one of several companies pursuing this approach, as the country pushes to expand its homegrown brain-computer interface (BCI) industry.

Faster than Neuralink, on paper

Read more
This bizarre email flaw is leaking corporate secrets to anyone who buys the right domain
Security researchers discovered companies are accidentally sending sensitive emails to domains that outsiders can register.
Maill app icon notifications

You don't always need to hack into a company's systems to get its secrets. Sometimes, the company will simply email them to you. A new report by WIRED's Matt Burgess has uncovered a bizarre email security problem in which companies are inadvertently sending sensitive information to domains that can be registered and controlled by outsiders. Security researchers Cory Solovevich and Mike Sheward discovered that seemingly harmless addresses such as noreply and deleteduser can become unexpected gateways to corporate information when the domains behind them aren't properly controlled.

The "hack" is buying the right domain

Read more
I found 3 ChatGPT features that turned out to be way more useful than I expected
ChatGPT on iPhone

I use ChatGPT pretty much every day, but somewhere along the way, I’ve also developed a habit of poking around and looking for features I haven’t tried yet. Some discoveries are genuinely useful, while others are the kind I’ll probably remember once every six months.

Every once in a while, though, I stumble across something that actually changes how I use ChatGPT. That happened recently with three features I’d somehow been overlooking. I’ve started using all three regularly now, and if you spend a lot of time in ChatGPT too, I think you’re missing out by not giving them a shot.

Read more