Fetching from the wire…
Public story · 2026-07-31 · high
Researchers hid the attack inside a user's own speech and confirmed it on a real Doubao AI phone in the wild.
Why now: As of July 31, 2026, always-listening assistants like Doubao AI's are already running on real phones, which is exactly the setup researchers used to confirm the attack works outside the lab.
A new attack embeds malicious instructions inside a user's own speech, hijacking Gemini 3 Pro in 69.1% of tests, according to a paper posted to arXiv.
Always-listening assistants are built to trust whatever the user says, and this attack breaks that assumption without touching a line of code. Researchers tested it against eleven agents, then took it off the bench onto a live Doubao AI smartphone with volunteers in real rooms.
The method, called instruction augmentation with scenario concealment, layers commands into audio overlapping the user's own speech, per the paper. That overlap is what makes the injection imperceptible, instead of an obvious separate sound.
There's a defense. CADV, which separates audio sources and checks them for consistency across channels, catches over 90% of these attacks. Prompt-level filtering misses them completely, per the paper.
CADV already catches over 90% of these attacks, so the technology isn't the hard part. What's unresolved is whether shipped products add anything like it. Doubao AI's phone assistant already proved the attack works in real rooms. The open question is whether it gets a defense like CADV before shipping teams keep trusting prompt-level filtering alone.
Each link below shares sources, entities, or timing with this story.
Simon Willison uses Gemini / Shared entity: Gemini / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Simon Willison uses Gemini); both cover Gemini; reported by the same outlet (arxiv.org).
Gemini competes with Claude / Shared entity: Gemini / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Gemini competes with Claude); both cover Gemini; reported by the same outlet (arxiv.org).
Gemini competes with Claude / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Gemini competes with Claude); both cover ASR, Gemini; reported by the same outlet (arxiv.org).
Gemini built by Google / Shared entity: Gemini / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Gemini built by Google); both cover Gemini; overlapping topics (against, agent).
Gemini built by Google / Shared entity: Gemini / Shared topic / Earlier coverage
Linked by a graph relationship (Gemini built by Google); both cover Gemini; overlapping topics (agent, attack, gemini).
Codex competes with Gemini / Same source domain / Shared topic / Tension
Linked by a graph relationship (Codex competes with Gemini); reported by the same outlet (arxiv.org); overlapping topics (against, agent, attack).
Gemini competes with Claude / Shared entity: Gemini / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Gemini competes with Claude); both cover Gemini; overlapping topics (agent, gemini).
Gemini competes with Claude / Shared entity: Gemini / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Gemini competes with Claude); both cover Gemini; reported by the same outlet (arxiv.org).