Red-teaming voice agents: audio as the attack surface, multi-turn pressure, and closing the loop
Summary
A deep dive into red-teaming voice agents, highlighting audio as an attack surface, the need for multi-turn testing, and practical baseline methodologies (1,200 calls) for pre-launch safety.
Similar Articles
Building voice AI agents that take turns like humans — the gotchas nobody warns you about
This article shares hard-won lessons from building real-time voice AI agents, highlighting the importance of proper turn-taking, VAD handling, billing awareness, and avoiding echo loops.
8 months running a voice agent in production: what broke, what fixed it, and the system prompt I use
A practitioner shares 8 months of experience running a voice agent for a law firm, detailing challenges like latency, turn-taking, and post-call workflows, and provides a working system prompt.
Expanding on how Voice Engine works and our safety research
OpenAI details the development history and safety approach for Voice Engine, from internal testing in 2022 through various limited deployments including ChatGPT Voice Mode and TTS API, emphasizing careful rollout with professional voice actors and ongoing collaboration with policymakers to address synthetic voice risks.
Navigating the challenges and opportunities of synthetic voices
OpenAI discusses the challenges and opportunities of its Voice Engine technology, emphasizing safety measures, usage policies, and the need for societal resilience against synthetic voice risks. The company is previewing but not widely releasing the technology, while advocating for voice authentication reforms and public education on AI capabilities.
EVA-Bench: A New End-to-end Framework for Evaluating Voice Agents
EVA-Bench introduces a comprehensive end-to-end framework for evaluating voice agents, simulating realistic multi-turn conversations and measuring performance across voice-specific failure modes with novel accuracy (EVA-A) and experience (EVA-X) metrics. The benchmark includes 213 scenarios across enterprise domains and a perturbation suite for accent and noise robustness, revealing substantial gaps in current systems.