"Just stop doing everything for now!": Understanding security attacks in remote collaborative mixed reality
Maha Sajid, Syed Ibrahim Mustafa Shah Bukhari, Bo Ji, Brendan David-John
Abstract
Mixed Reality (MR) devices are being increasingly adopted across a wide range of real-world applications, ranging from education and healthcare to remote work and entertainment. However, the unique immersive features of MR devices, such as 3D spatial interactions and the encapsulation of virtual objects by invisible elements, introduce new vulnerabilities leading to interaction obstruction and misdirection. We implemented latency, click redirection, object occlusion, and spatial occlusion attacks within a remote collaborative MR platform using the Microsoft HoloLens 2 and evaluated user behavior and mitigations through a user study. We compared responses to MR-specific attacks, which exploit the unique characteristics of remote collaborative immersive environments, and traditional security attacks implemented in MR. Our findings indicate that users generally exhibit lower recognition rates for immersive attacks (e.g., spatial occlusion) compared to attacks inspired by traditional ones (e.g., click redirection). Our results demonstrate a clear gap in user awareness and responses when collaborating remotely in MR environments. Our findings emphasize the importance of training users to recognize potential threats and enhanced security measures to maintain trust in remote collaborative MR systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 07867d24-3c8d-4bd3-b2c8-397687088f31Cited by top-tier papers2
- Exploring Student Feedback Needs and Design Opportunities in Data Storytelling EducationJennifer Posada, Taha Hassan, Lujie Karen Chen, Louise Yarnall et al.CHI 2026 · 2 citations
- "Having Lunch Now": Understanding How Users Engage with a Proactive Agent for Daily Planning and Self-ReflectionAdnan Abbas, Caleb Wohn, Arnav Jagtap, Eugenia Ha Rim Rho et al.CHI 2026 · 1 citation
Builds on15
- ARTEMIS: A Collaborative Mixed-Reality System for Immersive Surgical TelementoringDanilo Gasques, Janet G. Johnson, Tommy Sharkey, Yuanyuan Feng et al.CHI 2021 · 144 citations
- Towards Security and Privacy for Multi-user Augmented Reality: Foundations with End UsersKiron Lebeck, Kimberly Ruth, Tadayoshi Kohno, Franziska RoesnerS&P 2018 · 135 citations
- Privacy-Enhancing Technology and Everyday Augmented Reality: Understanding Bystanders' Varying Needs for Awareness and ConsentJoseph O'Hagan, Pejman Saeghe, Jan Gugenheimer, Daniel Medeiros et al.UbiComp 2023 · 102 citations
- A Survey on Remote Assistance and Training in Mixed Reality EnvironmentsCatarina G. Fidalgo, Yukang Yan, Hyunsung Cho, Maurício Sousa et al.IEEE VR 2023 · 69 citations
- Secure Multi-User Content Sharing for Augmented Reality ApplicationsKimberly Ruth, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2019 · 63 citations
Related papers
- Relay and Betray: Exploiting Client-Side Authority in Multi-User Mixed RealityMutahar Ali, Habiba FarrukhUSENIX Security 2026
- HoloLogger: Keystroke Inference on Mixed Reality Head Mounted DisplaysShiqing Luo, Xinyu Hu, Zhisheng YanIEEE VR 2022 · 30 citations
- When the User Is Inside the User Interface: An Empirical Study of UI Security Properties in Augmented RealityKaiming Cheng, Arkaprabha Bhattacharya, Michelle Lin, Jaewook Lee et al.USENIX Security 2024 · 29 citations
- Liar, Liar, Headset on Fire: Understanding the Effects of Deception Attacks on Decision-Making in a Mixed Reality GameAli Teymourian, Taha Gharaibeh, Ibrahim Baggili, Andrew M. WebbCHI 2026
- Unravelling Spatial Privacy Risks of Mobile Mixed Reality DataJaybie A. de Guzman, Aruna Seneviratne, Kanchana ThilakarathnaUbiComp 2021 · 22 citations
