USENIX Security2026Top-tier venue
Motion in the Clear: Reconstructing VR User Behavior from Network Traffic
JiHo Lee, JinYi Yoon, Taejoong Chung, Brendan David-John, Bo Ji
Abstract
Virtual Reality (VR) applications stream high-rate head and hand motion to support real-time multi-user interaction. This motion telemetry is privacy sensitive, enabling behavioral inference such as user identification and virtual typing inference. We show that VR motion can be reconstructed from passively observed network traffic alone, even when the adversary has no application access, device compromise, or message-format knowledge. From an ecosystem measurement of 75 popular VR applications, we find that multiplayer uplink traffic is dominated by sustained, high-frequency UDP and that payload encryption is uncommon. Despite application-specific serialization and unknown encodings, motion updates retain a smooth temporal structure that remains visible in plaintext UDP payload bytes.
Leveraging this property, we present PACMO, a passive, encoding-agnostic attack that uses controlled input patterns to automatically localize motion-related packet fields and reconstruct head and hand trajectories in a black-box manner. The reconstructed motion enables high-impact downstream attacks, achieving up to 96.2% user identification accuracy and 69.4% virtual typing inference accuracy. Our results expose a systemic network-layer privacy risk in immersive systems and motivate treating motion synchronization traffic as sensitive by default.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on19
- Understanding User Identification in Virtual Reality Through Behavioral Biometrics and the Effect of Body NormalizationJonathan Liebers, Mark Abdelaziz, Lukas Mecke, Alia Saad et al.CHI 2021 · 94 citations
- VR-Spy: A Side-Channel Attack on Virtual Key-Logging in VR HeadsetsAbdullah Al Arafat, Zhishan Guo, Amro AwadIEEE VR 2021 · 70 citations
- A Keylogging Inference Attack on Air-Tapping Keyboards in Virtual EnvironmentsÜlkü Meteriz-Yildiran, Necip Fazil Yildiran, Amro Awad, David MohaisenIEEE VR 2022 · 40 citations
- Can Virtual Reality Protect Users from Keystroke Inference Attacks?Zhuolin Yang, Zain Sarwar, Iris Hwang, Ronik Bhaskar et al.USENIX Security 2024 · 26 citations
- Understanding Parents' Perceptions and Practices Toward Children's Security and Privacy in Virtual RealityJiaxun Cao, Abhinaya S. B., Anupam Das, Pardis Emami NaeiniS&P 2024 · 19 citations
Related papers
- Going through the motions: AR/VR keylogging from user head motionsCarter Slocum, Yicheng Zhang, Nael B. Abu-Ghazaleh, Jiasi ChenUSENIX Security 2023
- Remote Keylogging Attacks in Multi-user VR ApplicationsZihao Su, Kunlin Cai, Reuben Beeler, Lukas Dresel et al.USENIX Security 2024 · 13 citations
- Movement- and Traffic-based User Identification in Commercial Virtual Reality Applications: Threats and OpportunitiesSara Baldoni, Salim Benhamadi, Federico Chiariotti, Michele Zorzi et al.IEEE VR 2025 · 2 citations
- When VR Meets BCI: (Un)Observable Brainwave-Aware Privacy Reconstruction in the Metaverse via Unrestricted Inbuilt Motion SensorsTao Ni, Zehua Sun, Qingchuan Zhao, Wei-Bin Lee et al.S&P 2026
- Unique Identification of 50, 000+ Virtual Reality Users from Head & Hand Motion DataVivek Nair, Wenbo Guo, Justus Mattern, Rui Wang et al.USENIX Security 2023
