DOI: 10.1145/3831661 ISSN: 2474-9567

SafeSpeaker: Voice Obfuscation for Resource-Constrained IoT Devices

Cameron Haire, Yasha Iravantchi, Kang G. Shin, Alanson P. Sample

Embodied voice assistants offer an intuitive and powerful interaction modality, but they also pose significant privacy-leakage risks when uploading raw voice recordings to the cloud for processing. These voice recordings contain a wealth of private information beyond just spoken content, such as acoustic features that can be used to identify and track users. Existing privacy-protection approaches either rely on encryption and cloud-side processing (leaving raw audio exposed in transit and storage) or use voice obfuscation algorithms whose compute and memory demands exceed what microcontroller-class IoT devices can sustain in real time. As a result, the most resource-constrained microphone-enabled devices, which are also among the most numerous, lack any practical voice privacy protection. We present SafeSpeaker , a lightweight voice obfuscation framework that closes this gap by running entirely on the edge device that captures the audio, breaking the link between user identity and speech before any recording leaves the device. SafeSpeaker uses a time-domain, formant-approximate transformation that avoids the frequency-domain transforms used by prior DSP-based approaches, processing audio nearly 2× faster while matching the identity-obfuscation performance (equal error rate) of state-of-the-art resource-aware methods. We demonstrate the practicality of this design with a real-time prototype on a $3 Arm Cortex-M4 microcontroller that sits between a microphone and an off-the-shelf smart speaker while maintaining the usability to understand and respond to voice commands. By making voice obfuscation feasible at this hardware tier, SafeSpeaker extends on-device voice privacy protections to a substantially larger class of microphone-enabled smart devices.