You play a podcast on YouTube and an inaudible sound to the human ear starts playing: it's instructions for your AI agents

TL;DR AI
2 min readKey summary
Researchers from China and Singapore showed that manipulated audio can inject hidden instructions into voice AI agents.
Across 13 tested models, the attack succeeded 79% to 96% of the time by disguising commands as natural room echo.
The prompts could trigger sensitive searches, email sending, or file downloads, and common defenses mostly failed.
The study warns that attacks built on open-weight models may also transfer to closed AI systems.



