I just sent you a long article which you could not have read in the time it took you to reply. I would suggest you start there and read that article, which outlines several cases where the author was able to create contrived false positives and negatives.
Contrived false positives and negatives could (and should!) always be possible. That doesn't tell us anything about the natural false positive and negative rates, and a lot of people who have actively tried to use voice instruction to get models to consistently fool the detector without iterating against it directly have failed.