CHOP: Breaking Anonymity in XR through a Novel and Cost-effective Chain of Privacy Attacks and Differential Privacy-Based Defenses
Ripan Kumar Kundu, Brendan David-John, Khaza Anuarul Hoque
Abstract
The convergence of artificial intelligence (AI) and extended reality (XR) technologies (AIXR) promises innovative applications across many domains. However, the sensitive nature of data (e.g., eye-tracking) used in these systems also raises significant privacy concerns, as adversaries can exploit this data and these models to infer personal information. Prior research has primarily examined membership inference attacks (MIA) to leak privacy at the model-level and re-identification attacks (RDA) at the dataset-level, separately as individual attacks. While these attacks are relevant to the XR domain, launching these attacks as individual attacks is not practical and incurs more attack cost. To address this gap, we present the first comprehensive study of chain of privacy (CHOP) attacks against AIXR applications. We demonstrate how adversaries can launch such attacks with a high success rate, in a cost-effective way, by sequentially combining MIA and Attribute inference attacks (AIA) to re-identify XR users without access to raw XR data, training distributions, or model parameters. We evaluate our proposed method in realistic AIXR settings by adopting deep learning (DL)-based cybersickness detection as a representative AIXR application. Specifically, we train two state-of-the-art DL models on two open-source datasets: Simulation 2021 and VRWalking, and a new XR cybersickness dataset constructed from 34 participants via a user study. Our findings reveal that the proposed CHOP attacks pose severe risks to DL-based cybersickness detection, achieving re-identification rates of up to 94% and 97% on the open-source and the developed cross-linked datasets, respectively, underscoring the feasibility and severity of cross-dataset privacy violations. Furthermore, cost analysis reveals that the proposed CHOP attack is ≈ 2× more cost-effective than traditional individual attacks for re-identifying XR users. Finally, we propose two ε-differential privacy (DP)-enabled privacy-preserving mechanisms: Differentially Private Stochastic Gradient Descent (DPSGD) and Private Aggregation of Teacher Ensembles (PATE) to mitigate CHOP attacks. Our results show that the proposed defense reduces the re-identification rate by up to 88% and 79% while maintaining high model utility, with classification accuracies of up to 94% and 92% for the same datasets using Transformer models.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 15d18ef4-e167-45fd-815e-352145d00ec1Related papers
- Obscuring the 'Who,' Preserving the 'What': Targeted Eye-tracking Feature Obfuscation in Virtual Reality for Privacy-Utility BalanceNasim Ahmed, Md Mahedi Hassan, Md Mushfique Hossain, Nazmus Shakib Shadin et al.IEEE VR 2026
- Toward Multimodal Privacy in XR: Design and Evaluation of Composite Privatization Methods for Gaze and Body Tracking DataAzim Ibragimov, Ethan Wilson, Kevin R. B. Butler, Eakta JainIEEE VR 2026 · 1 citation
- LiteVR: Interpretable and Lightweight Cybersickness Detection using Explainable AIRipan Kumar Kundu, Rifatul Islam, John Quarles, Khaza Anuarul HoqueIEEE VR 2023 · 34 citations
- Privacy-preserving datasets of eye-tracking samples with applications in XRBrendan David-John, Kevin R. B. Butler, Eakta JainIEEE VR 2023 · 35 citations
- PRECYSE: Predicting Cybersickness using Transformer for Multimodal Time-Series Sensor DataDayoung Jeong, Kyungsik HanUbiComp 2024 · 35 citations
