HoloLogger: Keystroke Inference on Mixed Reality Head Mounted Displays
Shiqing Luo, Xinyu Hu, Zhisheng Yan
Abstract
When using personal computing services in mixed reality (MR) such as online payment and social media, sensitive information and account passwords must be typed in MR. To design secure MR systems and build up user trust, it is imperative to first understand the security threat to the sensitive MR input. Although keystroke inference attacks by analyzing human-computer interaction in videos or via wireless signals have been successful, they require placing extra hardware near the user which is easily noticeable in practice. In this paper, we expose a more dangerous malware-based attack through the vulnerability that no permission is required for accessing MR motion data. We aim to monitor MR headset motion and infer the user input through a benign App. Realizing the attack system requires addressing unique challenges in MR such as six-degree-of-freedom (6DoF) device motion and no explicit motion signal for keystroke identification. To this end, we present HoloLogger, the first malware-based keystroke inference attack system on HoloLens. HoloLogger is empowered by a 6DoF-head-motion-driven key tracking scheme and an air-tap-pattern-based keystroke inference framework. Extensive evaluations with 25 users and 750 inference trials of passwords consisting of 4–8 lowercase English letters demonstrate that HoloLogger successfully achieves a top-5 accuracy of 93%. HoloLogger is also robust in various environments such as different user positions and input categories.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers21
- Can Virtual Reality Protect Users from Keystroke Inference Attacks?Zhuolin Yang, Zain Sarwar, Iris Hwang, Ronik Bhaskar et al.USENIX Security 2024 · 26 citations
- That Doesn't Go There: Attacks on Shared State in Multi-User Augmented Reality ApplicationsCarter Slocum, Yicheng Zhang, Erfan Shayegani, Pedram Zaree et al.USENIX Security 2024 · 21 citations
- Penetration Vision through Virtual Reality Headsets: Identifying 360-degree Videos from Head MovementsAnh Nguyen, Xiaokuan Zhang, Zhisheng YanUSENIX Security 2024 · 17 citations
- GAZEploit: Remote Keystroke Inference Attack by Gaze Estimation from Avatar Views in VR/MR DevicesHanqiu Wang, Zihao Zhan, Haoqi Shan, Siqi Dai et al.CCS 2024 · 16 citations
- Remote Keylogging Attacks in Multi-user VR ApplicationsZihao Su, Kunlin Cai, Reuben Beeler, Lukas Dresel et al.USENIX Security 2024 · 13 citations
Related papers
- Eavesdropping on Controller Acoustic Emanation for Keystroke Inference Attack in Virtual RealityShiqing Luo, Anh Nguyen, Hafsa Farooq, Kun Sun et al.NDSS 2024
- Going through the motions: AR/VR keylogging from user head motionsCarter Slocum, Yicheng Zhang, Nael B. Abu-Ghazaleh, Jiasi ChenUSENIX Security 2023
- Privacy Leakage via Unrestricted Motion-Position Sensors in the Age of Virtual Reality: A Study of Snooping Typed Input on Virtual KeyboardsYi Wu, Cong Shi, Tianfang Zhang, Payton Walker et al.S&P 2023
- A Keylogging Inference Attack on Air-Tapping Keyboards in Virtual EnvironmentsÜlkü Meteriz-Yildiran, Necip Fazil Yildiran, Amro Awad, David MohaisenIEEE VR 2022 · 40 citations
- "Just stop doing everything for now!": Understanding security attacks in remote collaborative mixed realityMaha Sajid, Syed Ibrahim Mustafa Shah Bukhari, Bo Ji, Brendan David-JohnIEEE VR 2025 · 7 citations
