A User-Controlled Ultrasonic Obstruction Framework for Defending Against Voice Assistant and Covert Microphone Eavesdropping
The widespread adoption of always-listening voice assistants, together with the growing availability of low-cost covert recording devices, has created two related but distinct audio privacy threats: authorized microphones that may capture more than a user intends, and unauthorized microphones that capture without consent at all. Existing defenses treat these threats in isolation. Voice-assistant privacy relies on manufacturer trust and after-the-fact data deletion, while covert device detection depends on specialized, single-technique tools that require manual expertise. This paper proposes a unified, user-controlled acoustic privacy framework built on broadband ultrasonic obstruction, an inaudible signal that disrupts the microphone hardware itself rather than the data pipeline behind it. The framework operates in two modes: a manually toggled Privacy Mode that immediately obstructs any nearby microphone, known or unknown, with activation and release fully controlled by the user; and an on-demand Bug Sweep Mode that detects unauthorized listening devices using network-traffic and optical signals available on a standard smartphone. We deliberately defer automatic, content-aware triggering, i.e. detecting sensitive conversation and obstructing without user initiation, to future work, avoiding the surveillance-to-prevent-surveillance paradox inherent in content-analysing privacy systems. This positions the proposed system as a practical, immediately deployable middle ground between passive OS-level permission indicators and expensive professional counter-surveillance equipment. Keywords: acoustic privacy, ultrasonic jamming, voice assistant privacy, covert device detection, zero-trust sensing, microphone obstruction
1. Introduction
The proliferation of voice assistants and internet-connected microphones has made continuous audio sensing a normal feature of homes, offices, and shared spaces such as hotel rooms and meeting rooms. Alongside this, low-cost covert recording devices have made unauthorized audio surveillance increasingly accessible to non-experts. This work addresses eavesdropping from two related but distinct sources: authorized microphones, such as voice assistants, which may capture more audio than a user intends; and unauthorized microphones, such as hidden bugs, which capture audio without consent altogether.
Existing defenses address these threats separately, and each has real limitations. Voice-assistant privacy today relies almost entirely on manufacturer trust, permission toggles, and after-the-fact data deletion, none of which prevent audio capture in the first place. Covert-device detection tools rely on specialized hardware such as RF spectrum analysers or non-linear junction detectors, which are costly, require trained manual operation, and often miss devices that transmit intermittently or record offline. No existing consumer-accessible system addresses both threats through a single, low-cost, user-operable mechanism, despite both frequently coexisting in the same physical spaces.
This paper proposes a two-mode system to close that gap: a manually triggered Privacy Mode that applies broadband ultrasonic obstruction to any nearby microphone, and an on-demand Bug Sweep Mode that detects unauthorized devices via smartphone-accessible network and optical signals. Section 2 reviews related work. Section 3 states the research gap explicitly. Section 4 presents the system design and design rationale. Section 5 outlines the intended evaluation methodology. Section 6 discusses limitations and future work, and Section 7 concludes.
2. Related Work
Ultrasonic jamming exploits the nonlinearity of MEMS microphone circuits: an inaudible near-ultrasonic signal, once captured and down-converted by a microphone's analog front-end, injects disruptive noise into the audible band and degrades downstream speech recognition. Tang et al. [1] presented a dedicated ultrasonic jamming system evaluated across practical device scenarios, while Yu et al. [2] proposed a Time-Frequency Mosaic technique that generates short, speaker-adapted jamming signals instead of fixed noise, reporting substantial word-error-rate increases at low signal-to-noise ratios. A 2024 study on near-ultrasound voice-privacy protection [3] explored inaudible noise fields for masking conversation while noting that some newer microphone and speech-recognition pipelines are becoming more resistant to ultrasonic interference. Prior systems broadly follow two design philosophies: indiscriminate, always-on jammers that disrupt every nearby microphone, and selective systems such as MicShield [4], which attempt to pass intended wake words through while jamming unintended speech.
A separate line of work addresses detecting hidden cameras and microphones that a user has not authorized. Network-traffic-based approaches fingerprint the distinctive packet patterns of streaming video without decrypting the stream, including iCamInspector [5] and a real-time traffic-similarity system combined with WiFi signal tracing [6]. Localization techniques include WiFi signal-propagation-path analysis [7], smartphone time-of-flight sensing [8], and compact FM-module hardware [9]. Geloczi et al. [10] addressed detection, localization, and isolation of concealed IoT devices generally, and Li et al. [11] introduced electromagnetic-radiation analysis to find hidden GPS trackers that evade traffic- and RF-based methods entirely. A 2025 survey [12] synthesizes this space and notes that no single technique reliably covers all covert device types.
While prior work has separately advanced ultrasonic jamming for voice-assistant privacy and detection/localization for covert surveillance devices, no existing system unifies these into a single, consumer-operable tool addressing both threat classes under one control model. Existing jamming systems assume a known target device; existing detection systems stop at identification without an integrated obstruction response. This work addresses that gap with a dual-mode system in which one user-triggered Privacy Mode provides broadband obstruction applicable to both authorized and unauthorized microphones, deferring automatic threat classification to future work in favour of a reliable, predictable, user-controlled trust model.
2. Proposed System
2.1 Privacy Mode
Privacy Mode is a manual toggle that activates broadband ultrasonic obstruction covering any microphone within range, irrespective of whether it belongs to a known device (a voice assistant) or an unidentified one (a covert bug). Because the system does not need to know which microphones are present before acting, it requires no prior detection or localization step; this is a deliberate design choice, since a user typically has no way to know a room contains a hidden bug before entering it. Activation and release are entirely user-controlled: turning the mode off restores normal microphone function immediately, including full, unimpeded operation of the user's own voice assistant.
2.2 Bug Sweep Mode
Bug Sweep Mode is a separate, manually triggered function that scans for unauthorized devices using signals available on a standard smartphone: network-traffic fingerprinting to identify WiFi-streaming cameras, and optical lens-glint detection via the phone camera to identify hidden camera lenses. Detected devices are logged with a confidence score and location estimate, and can optionally be used to enable directional obstruction targeted at a specific device once localized, as an enhancement layered on top of Privacy Mode's default broadband coverage.

*Figure 1. System architecture: Privacy Mode and Bug Sweep Mode operate as decoupled pipelines converging on a shared obstruction actuator and dashboard.*
2.3 Shared Components
• Transparency dashboard: live status of whether Privacy Mode is active, and a history of Bug Sweep results, so system behaviour is always auditable to the user rather than a silent background process.
• Graceful degradation: when Privacy Mode is off, the system introduces zero interference by construction; there is no automatic override logic to second-guess this state.
• Waveform design: jamming signal characteristics are evaluated across microphone hardware types (MEMS vs. electret) to maximise obstruction generalisability rather than tuning to one specific device.
2.4 System Flow
At runtime, the two modes operate independently but share the same underlying obstruction actuator and dashboard. When Privacy Mode is switched on, the actuator begins broadband ultrasonic emission immediately; no sensing, classification, or device inventory step sits on this critical path, which keeps activation latency low and behaviour predictable. Bug Sweep Mode, when separately triggered, runs its own short-lived pipeline: capture network traffic and camera frames for a bounded scan window, score candidate devices, present results on the dashboard, and, only if the user opts in, hand a location estimate to the actuator to enable directional emphasis on top of the existing broadband coverage. Because the two pipelines are decoupled, a failure or false negative in Bug Sweep Mode does not weaken Privacy Mode's baseline protection, and Privacy Mode can be used on its own without ever running a sweep.
3. Design Rationale
The central design decision in this work is to make obstruction manually triggered and manually released, rather than automatically triggered by inferred context or conversation content. An automatic system would need to classify, in real time, whether the current acoustic situation is a trusted interaction or a privacy risk; this is both technically fragile (a high false-positive rate makes a voice assistant unusable) and ethically fraught, since classifying conversation content requires the system to listen to and interpret speech, reproducing the very surveillance it aims to prevent. Manual control sacrifices automation for predictability and trust, consistent with the design philosophy behind established privacy mechanisms such as camera covers and mute switches. Directional and detection-triggered obstruction are treated as optional enhancements layered on top of this reliable baseline, not as prerequisites for protection.
4. Evaluation Plan
As this work is proposed as a design and systems contribution rather than a completed deployment, evaluation is structured as two planned studies rather than reported results:
• Microphone-hardware characterisation study: measuring automatic speech recognition word-error-rate degradation under obstruction across a range of microphone hardware types (MEMS, electret) to establish which device classes the jamming approach generalises to.
• Longitudinal robustness study: repeated testing of obstruction effectiveness against commercial voice assistants over time, to assess whether vendor firmware updates adapt to or filter the jamming signal, and whether waveform adjustments are needed in response.
Success is defined along two axes reported together, so that protection is never assessed independently of usability: protection effectiveness and usability preservation. Table 1 summarises the planned studies and the metric each is designed to produce.
*Table 1. Planned evaluation studies and metrics.*
| Study | Metric | What It Establishes |
| Microphone-hardware characterisation | ASR word-error-rate under obstruction, by mic type | Which microphone classes (MEMS vs. electret) the jamming approach generalises to |
| Longitudinal robustness | WER over repeated trials across firmware versions | Whether commercial assistants adapt to or filter the jamming signal over time |
| Usability preservation | Task success rate with Privacy Mode off | That the assistant functions normally when protection is not requested |
5. Conclusion
This paper presented a user-controlled ultrasonic obstruction framework that unifies protection against two previously separately addressed audio privacy threats: authorized voice assistants and unauthorized covert microphones. By deliberately choosing manual activation and release over automatic, content-aware triggering, the design prioritises predictability and user trust over automation, while still leaving a clear, staged path toward more adaptive protection as future work. The result is a system that is honest about what it does not yet do, while offering an immediately deployable, low-cost middle ground between passive privacy indicators and specialised counter-surveillance equipment.
References
[1] H. Tang, Y. Wang, Z. Jing, and J. Guo, "Design and Implementation of an Ultrasonic Audio Jamming System," in Proc. 2024 4th International Conference on Electronic Information Engineering and Computer Technology (EIECT), IEEE, 2024.
[2] Z. Yu, L. Tang, K. Wang, X. Tang, and H. Ge, "Dynamic Ultrasonic Jamming via Time-Frequency Mosaic for Anti-Eavesdropping Systems," Electronics, vol. 14, no. 15, p. 2960, 2025.
[3] "Safeguarding Voice Privacy: Harnessing Near-Ultrasound," arXiv:2404.04769, 2024.
[4] K. Sun et al., "MicShield: Selective Jamming for Voice Assistant Privacy," in Proc. ACM SenSys, 2020.
[5] P. R. Chaudhary, J. Christopher, and R. R. Maiti, "iCamInspector: Classify Video Traffic and Detect IoT (Spy) Camera Flows," Conference Paper, Dec. 2024.
[6] H. An, W. Park, and S. Park, "Wireless Spy Camera Spotter System With Real-Time Traffic Similarity Analysis and WiFi Signal Tracing," IEEE Access, 2024.
[7] X. Zhang, Z. Ma, J. Huang, and B. Liu, "Hidden WiFi Camera Localization via Signal Propagation Path Analysis," Conference Paper, Dec. 2024.
[8] J. C. Navares-Vazquez, Z. Qiu, P. Arias, and J. Balado Frias, "LAPD: Hidden Spy Camera Detection using Smartphone Time-of-Flight Sensors," May 2025.
[9] Q. Liao, J. Lin, Y. Huang, Z. Gong, and K. Wu, "CamFirm: A Compact FM-Based Module for Hidden Camera Detection," in Proc. IEEE PerCom, 2025.
[10] E. Geloczi, H. C. Pöhls, F. Klement, J. Posegga, and S. Katzenbeisser, "Unveiling the Shadows: An Approach towards Detection, Precise Localization, and Effective Isolation of Concealed IoT Devices in Unfamiliar Environments," in Proc. 23rd Workshop on Privacy in the Electronic Society (WPES '24), ACM, 2024, pp. 109–123.
[11] Y. Li, Z. Yan, W. Jin, Z. Ning, and D. Liu et al., "GPSBuster: Busting out Hidden GPS Trackers via MSoC Electromagnetic Radiations," in Proc. ACM CCS, 2024.
[12] Q. Liao, J. Lin, Y. Huang, and K. Wu, "Hidden Camera Detection in Smart Environments: A Comprehensive Survey of Current Methods, Challenges, and Future Perspectives," Mar. 2025.