Banana Navy
Catalog FR
Lab · Threat modeling IA · Fiche détaillée

Session and media tampering (injection, codec, ultrasound)

the attacker alters the session (SIP injection, malformed packets) or the media stream (codec manipulation, inaudible payloads, adversarial perturbations) to divert processing or hide content.

SheetF6
CategoryT-TB7-01 (tampering de l'entrée)
Layers2 · Session Security, 5 · Audio Normalization
Systemvoicebot IA

deterministic session validation (SIP auth, TLS/SRTP, IP allowlist), RTP validation, media normalisation and filtering (resampling, band-pass), artifact detection.

The threat

the attacker alters the session (SIP injection, malformed packets) or the media stream (codec manipulation, inaudible payloads, adversarial perturbations) to divert processing or hide content.

Angle mortWhy classic frameworks miss it

network integrity is covered, but the integrity of the processed media is not: content inaudible to a human remains a real input for transcription, and a manipulated stream can sabotage a model undetected by ear.

MitigationProposed approach

deterministic session validation (SIP auth, TLS/SRTP, IP allowlist), RTP validation, media normalisation and filtering (resampling, band-pass), artifact detection.

The proposed control
no abnormal packet passes without verified processing.

Expected evidence
a manipulated stream is rejected or neutralised before transcription.

SourcesReferences and public research

Recherche publiquePublic research sources: MITRE ATLAS 2026.07 (verified technique mapping), OWASP GenAI (catégories par abus de modèle), and the public risk-voicebot (aivansoul/risk-voicebot) template defining the 20 checkpoints. No client registry data: generic sheet, no rating, no verdict.
couche 2 · Session Securitycouche 5 · Audio Normalization

Explore the 20 security layers

MITRE ATLAS 2026.07 · OWASP GenAI · risk-voicebot