Inaudible Ultrasonic LLM Jailbreak
Speech-driven Large Language Models (LLMs) and end-to-end Large Audio-Language Models (LALMs) are vulnerable to inaudible near-ultrasonic prompt injections, a framework dubbed Sirens' Whisper (SWhisper). By exploiting the non-linear response of commodity microphones, attackers can encode structured, phonetically optimized adversarial prompts into the 17–22 kHz near-ultrasonic band. Using regularized channel-inversion pre-compensation, the attacker shapes the waveform to account for microphone…
Evaluated models: GLM-4 Voice, Qwen Omni Turbo, Llama 3.1 8B Instruct+5 more
- GLM-4 Voice
- Qwen Omni Turbo
- Llama 3.1 8B Instruct
- Gemma 3 4B
- Qwen 2.5 7B Instruct
- Mistral 7B Instruct v0.3
- GLM-4 Air 250414
- Grok 4