The Big Brother's New Playground: Unmasking the Illusion of Privacy in Web Metaverses from a Malicious User's Perspective DOI Creative Commons
Andrea Mengascini,

Ryan Aurelio,

Giancarlo Pellegrino

и другие.

Опубликована: Дек. 2, 2024

Metaverses are virtual worlds where users can engage in social exchanges, collaborate, or play games. Their clients now JavaScript programs that run inside modern web browsers. They implement functionalities typical of multiplayer video games, like 3D and physics engines, requiring them to maintain complex data structures objects the browser's memory. Unfortunately, these be accessed manipulated by malicious users, allowing learn about events beyond ones rendered on screen hijack metaverse spy other users.In this paper, we propose one first comprehensive security assessments for platforms. We begin with a survey selection three platforms introduce software-centric threat modeling approach designed identify security-relevant entities. Then, global object snapshot diffing technique in-memory correlated attribute design 10 attacks, which eight successfully executed against at least metaverses, enabling user perform audio/video surveillance continuous position tracking - mention few who could exacerbate current threats posed stalkers online abusers. Finally, discuss implications our attacks should become business tool possible solutions.

Язык: Английский

SoK: Data Privacy in Virtual Reality DOI Creative Commons
Gonzalo Munilla Garrido, Vivek Nair, Dawn Song

и другие.

Proceedings on Privacy Enhancing Technologies, Год журнала: 2023, Номер 2024(1), С. 21 - 40

Опубликована: Окт. 22, 2023

The adoption of virtual reality (VR) technologies has rapidly gained momentum in recent years as companies around the world begin to position so-called ''metaverse'' next major medium for accessing and interacting with internet. While consumers have become accustomed a degree data harvesting on web, real-time nature sharing metaverse indicates that privacy concerns are likely be even more prevalent new ''Web 3.0.'' Research into VR demonstrated plethora sensitive personal information is observable by various would-be adversaries from just few minutes telemetry data. On other hand, we yet see parallels many privacy-preserving tools aimed at mitigating threats conventional platforms. This paper aims systematize knowledge landscape countermeasures proposing comprehensive taxonomy attributes, protections, based study 74 collected publications. We complement our qualitative discussion statistical analysis risk associated sources inherent consideration known attacks defenses. By focusing highlighting clear outstanding opportunities, hope motivate guide further research this increasingly important field.

Язык: Английский

Процитировано

14

New Technology Deployment and Corporate Responsibilities in the Metaverse DOI Creative Commons
Martín Wynn, Peter Jones

Knowledge, Год журнала: 2023, Номер 3(4), С. 543 - 556

Опубликована: Сен. 27, 2023

The term “metaverse” came to the fore in 2021 when Facebook rebranded its corporate identity Meta and signalled intention invest at least USD 10 billion developing concepts related products that year. However, there is still little consensus defining what constitutes metaverse, although a widespread, though not universal, agreement it will bring wide range of benefits across society. More specifically, advent continuing evolution metaverse has strategic operational implications for, impacts on, industry business large. Adopting an inductive, interpretivist approach, this exploratory research article presents case examples guidance on responsible development provided by two IT services companies. This identifies major risks responsibilities associated with assesses how companies might address these responsibilities. Very been published area, attempts make small contribution filling gap literature. finds are largely line those currently digital responsibility, concludes impact extent regulatory change depend nature materialises forthcoming decade.

Язык: Английский

Процитировано

13

Digital Healthcare in the Metaverse: Insights into Privacy and Security DOI
Mehdi Letafati, Safa Otoum

IEEE Consumer Electronics Magazine, Год журнала: 2023, Номер 13(3), С. 80 - 89

Опубликована: Ноя. 20, 2023

In this article, metaverse healthcare systems are studied from the privacy and security perspectives. We address data communication for metaverse, threats of employing machine learning artificial intelligence (ML/AI) algorithms healthcare. addition, human-centric social interactions in is studied. Our goal to present new visions approaches, including physical layer security, semantic communications, differential privacy, adversarial learning. These approaches have shown promising results field communications networking, as well computer science domain, showcasing a huge potential be employed systems. As case study, we propose distributed systems, where each virtual clinic perturbs its medical model vector safeguard against malicious clients honest-but-curious servers. Through our experiments on Breast Cancer Wisconsin Dataset, highlight privacy-utility tradeoff different adjustable levels privacy.

Язык: Английский

Процитировано

12

Deep Motion Masking for Secure, Usable, and Scalable Real-Time Anonymization of Ecological Virtual Reality Motion Data DOI
Vivek Nair, Wenbo Guo, James F. O’Brien

и другие.

2022 IEEE Conference on Virtual Reality and 3D User Interfaces Abstracts and Workshops (VRW), Год журнала: 2024, Номер unknown, С. 493 - 500

Опубликована: Март 16, 2024

Virtual reality (VR) and "metaverse" systems have recently seen a resurgence in interest investment as major technology companies continue to enter the space. However, recent studies demonstrated that motion tracking "telemetry" data used by nearly all VR applications is uniquely identifiable fingerprint scan, raising significant privacy concerns surrounding metaverse technologies. In this paper, we propose new "deep masking" approach scalably facilitates real-time anonymization of telemetry data. Through large-scale user study $(N=182)$ , demonstrate our method significantly more usable private than existing anonymity systems.

Язык: Английский

Процитировано

4

Metaverse & Human Digital Twin: Digital Identity, Biometrics, and Privacy in the Future Virtual Worlds DOI Creative Commons
Pietro Ruiu, Michele Nitti, Virginia Pilloni

и другие.

Multimodal Technologies and Interaction, Год журнала: 2024, Номер 8(6), С. 48 - 48

Опубликована: Июнь 5, 2024

Driven by technological advances in various fields (AI, 5G, VR, IoT, etc.) together with the emergence of digital twins technologies (HDT, HAL, BIM, etc.), Metaverse has attracted growing attention from scientific and industrial communities. This interest is due to its potential impact on people lives different sectors such as education or medicine. Specific solutions can also increase inclusiveness disabilities that are an impediment a fulfilled life. However, security privacy concerns remain main obstacles development. Particularly, data involved be comprehensive enough granularity build highly detailed copy real world, including Human Digital Twin person. Existing countermeasures largely ineffective lack adaptability specific needs applications. Furthermore, virtual worlds large-scale varied terms hardware implementation, communication interfaces, software, which poses huge interoperability difficulties. paper aims analyse risks opportunities associated adopting replicas humans (HDTs) within challenges related managing identities this context. By examining current landscape, we identify several open currently limit adoption HDTs Metaverse. Additionally, explores range promising methodologies assess their suitability Finally, two example scenarios presented Medical Education fields.

Язык: Английский

Процитировано

4

Exploring the use of AI avatars by marriage and family therapists practitioners as a therapeutic intervention DOI Open Access

Alex D. Colvin,

C. Benjamin

Family Relations, Год журнала: 2025, Номер unknown

Опубликована: Янв. 28, 2025

Abstract Objective This article provides an overview of artificial intelligence (AI) avatar technology and its potential use as a therapeutic intervention by licensed marriage family therapists (MFTs) within the system context. Background With growth therapy, it is essential to equip future practitioners with tools for effective service delivery. As virtual environments evolve, MFTs must be prepared engage clients all ages interested in these technologies. Method The authors present conceptual paper on AI technology, exploring applications therapy examining diffusion innovation theory assess adoption. Results avatars offer many benefits, including increasing accessibility affordability; enhanced communication settings; augmenting treatment possibilities individuals families; safe, anonymous environment that encourages client expression. also helps alleviate therapist burnout. Conclusion Although should not replace human interactions, can enhance delivery MFT practices, helping profession stay relevant this digital age improving accessibility. Implications Integrating create new training opportunities practitioners. Professional associations develop guidelines optimize practice revolution advances.

Язык: Английский

Процитировано

0

Exploring the Uncoordinated Privacy Protections of Eye Tracking and VR Motion Data for Unauthorized User Identification DOI
Samantha Aziz, Oleg V. Komogortsev

Опубликована: Март 8, 2025

Язык: Английский

Процитировано

0

Movement- and Traffic-based User Identification in Commercial Virtual Reality Applications: Threats and Opportunities DOI
Sara Baldoni,

Salim Benhamadi,

Federico Chiariotti

и другие.

Опубликована: Март 8, 2025

Язык: Английский

Процитировано

0

Cyber Security and Privacy Issues in Extended Reality Healthcare Applications: Scoping Review (Preprint) DOI Creative Commons
Kaitlyn Lake, Andrea Mc Kittrick, Mathilde R. Desselle

и другие.

JMIR XR and spatial computing., Год журнала: 2024, Номер 1, С. e59409 - e59409

Опубликована: Сен. 1, 2024

Abstract Background Virtual reality (VR) is a type of extended (XR) technology that seeing increasing adoption in health care. There robust evidence articulating how consumer-grade VR presents significant cybersecurity and privacy risks due to the often ubiquitous wide range data collection user monitoring, as well unique impact attacks immersive nature technology. However, little known about these translate use systems care settings. Objective The objective this scoping review identify potential associated with clinical XR systems, focus on VR, mitigations for them. Methods followed PRISMA-ScR (Preferred Reporting Items Systematic reviews Meta-Analyses extension Scoping Reviews), publications were reviewed using Covidence software. Google Scholar database was searched predefined search terms. inclusion criteria articles restricted relevant primary studies published from 2017 2024. Furthermore, reviews, abstracts, viewpoints, opinion pieces, low-quality excluded. Additionally, publication statistics, topic, technology, cyber threats, risk mitigation extracted. These synthesized analyzed STRIDE (spoofing, tampering, repudiation, information disclosure, denial service, elevation privilege) framework, enterprise management National Institute Standards Technology Cybersecurity Framework, developing threat taxonomies. Results returned 482 matched criteria. After title abstract screening, 53 extracted full-text review, which 29 included analysis. Of these, majority last 4 years had VR. greatest identified components disclosure by tampering when mapped against framework. strategies provide confidentiality integrity can potentially address threats. Only 3 papers mention context none threats or have been studied setting. Conclusions This where personal health-related may be inferred usage data, breaching confidentiality, most posited systems. manipulation highlighted, could safety launched compromised system. Many but must first assessed their effectiveness suitability services. services should consider governance each individual application based threshold perceived benefits. Finally, it also important note limited quality scope Scholar.

Язык: Английский

Процитировано

3

Truth in Motion: The Unprecedented Risks and Opportunities of Extended Reality Motion Data DOI Creative Commons
Vivek Nair, Louis Rosenberg, James F. O’Brien

и другие.

IEEE Security & Privacy, Год журнала: 2023, Номер 22(1), С. 24 - 32

Опубликована: Ноя. 16, 2023

Motion tracking "telemetry" data lies at the core of nearly all modern extended reality (XR) and metaverse experiences. While generally presumed innocuous, recent studies have demonstrated that motion actually has potential to profile deanonymize XR users, posing a significant threat security privacy in metaverse.

Язык: Английский

Процитировано

5