Have you confirmed that the add-on doesn't simply trigger if a website uses the WebAudio API? All fingerprinting techniques also have legitimate applications. If they could be reliably distinguished from non-malicious uses, browsers would have blocked them long ago.