Case · DiggingBeagle record

Sirens’Whisper injected near-ultrasonic prompts into speech-driven LLMs

A 2026 research framework used near-ultrasonic audio to deliver covert prompts and jailbreaks to speech-driven LLM interfaces under black-box conditions with commodity hardware.

Research demonstration of covert prompt injection into speech-driven LLMs. It establishes an input channel, not autonomous model escape.

Case kind
vulnerability
Claims
2

Reconstruction

Timeline

  1. 2026-03

    Step

Claims & evidence

Implications

Multimodal-agent security needs to authenticate and separate human speech from machine-readable acoustic instructions rather than assuming audible equivalence.

Controls & mitigations

  • Near-ultrasonic filtering and microphone hardening
  • Authenticate command provenance rather than treating all decoded speech as human-authorized
  • Adversarial testing across devices and environments
  • Require confirmation for high-impact actions

What remains unknown

  • Results are specific to tested devices, acoustic environments and model interfaces and should not be generalized to every microphone or speech model.

Cite this record

DiggingBeagle. “Sirens’Whisper injected near-ultrasonic prompts into speech-driven LLMs.” https://diggingbeagle.com/cases/sirens-whisper-injected-near-ultrasonic-prompts-into-speech-driven-llms/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.