Generator Prompt to Run Cloned-Voice Attack Campaigns Against Call Channels with Arbiter
This **Arbiter** generator runs a cloned-voice gauntlet against your call channels in the sandbox with current synthesis tooling. Arbiter, the deepidv adversarial agent, attacks **helpdesk recovery**, **payment instruction** lines, and **video KYC audio**, probes **detection evasion** for the shortest utterance and noisiest channel where confidence collapses, and tests **agent discretion** against social pressure, then returns findings ranked by exploitability and a weekly regression suite.
How to use this prompt
- 1
Open Arbiter in the deepidv dashboard and paste the full prompt, scoping it to your sandbox and enrolled test voices only.
- 2
Confirm the call channels in scope: helpdesk, treasury, and remote onboarding.
- 3
Review the per-channel detection rates and the protocol gaps where a missed clone still succeeded.
- 4
Feed the findings into the weekly regression suite so the defense is measured against current tooling, not last quarter's.
The prompt
Arbiter, run a cloned-voice gauntlet against our call channels, in the sandbox, using current voice synthesis tooling. Campaign scope: 1. Helpdesk recovery: cloned customer voices with breached-data scripts attempting credential resets, across our top reset scenarios. Measure whether synthetic voice detection flags the call and whether the login-grade re-verification protocol holds when it does not. 2. Payment instruction: cloned executive and vendor voices directing payment changes above and below the verified-human release threshold, including video-plus-voice combinations. Any release without liveness-confirmed re-authentication is a critical finding. 3. Video KYC audio: synthetic voice over live and injected video in remote onboarding, testing that audio and visual verdicts fuse and that a contradiction between them escalates rather than averages. 4. Detection evasion: vary clone quality, sample source, utterance length, and background conditions; find the shortest utterance and noisiest channel where detection confidence collapses, and map what the escalation policy does in that band. 5. Agent discretion probe: where a human agent is in the loop, test the social scripts that pressure them past protocol, and record whether the protocol or the discretion won. Output: findings ranked by exploitability, per-channel detection rates and latency, the protocol gaps where a missed clone still succeeded, and the weekly regression suite. No production customer records; use sandbox personas and enrolled test voices only.
Test it in Claude or another LLM
This prompt is built for the Arbiter agent inside deepidv, where Arbiter drives synthetic audio at your live detection and escalation policy in a sandbox. You can rehearse the campaign design in a general LLM before running it against enrolled test voices.
- 1
Paste the full prompt into Claude, ChatGPT, or Gemini, replacing Arbiter, with a role instruction such as: You are a voice-channel red-team lead.
- 2
Describe your call channels and current escalation protocol in the scope block.
- 3
Ask the model to draft the campaign matrix and the findings template, then run the real campaign in Arbiter.
Synthetic sample data to paste alongside the prompt
Fake test data, safe to share with any LLM. Swap in your own once the output looks right.
CALL CHANNELS (synthetic): a bank helpdesk handling 8,000 resets a month, a treasury line releasing wires above a verified-human threshold, and remote video onboarding. Current control on resets: agent judgment plus knowledge questions.
Pairs with on deepidv
Sources & further reading
FAQ
What does the Voice Clone Gauntlet test?
Helpdesk credential-reset recovery, payment-instruction calls above and below the release threshold, video KYC audio-visual fusion, detection evasion across clone quality and utterance length, and whether human agents hold protocol under social pressure. Output ranks findings by exploitability and produces a weekly regression suite.
Is it safe to run against production?
No. The prompt is scoped to the sandbox with enrolled test voices and synthetic personas only, never production customer records, so the campaign measures your defense without exposing real callers.
Why does a missed clone still need a passing grade?
Because detection is probabilistic. The gauntlet checks that the protocols behind detection, login-grade re-verification for resets and liveness-confirmed re-authentication for payments, hold even when a clone is not flagged, so a missed detection still gains nothing.
Related prompts
Run it with live verification data
These prompts work in any LLM. Inside the deepidv dashboard, Luna, Arbiter, and Arc run them against your real sessions, screening lists, and audit trails.
Book a Demo