USENIX Security2023Top-tier venue
LocIn: Inferring Semantic Location from Spatial Maps in Mixed Reality
Habiba Farrukh, Reham Mohamed, Aniket Nare, Antonio Bianchi, Z. Berkay Celik
Abstract
Mixed reality (MR) devices capture 3D spatial maps of users' surroundings to integrate virtual content into their physical environment. Existing permission models implemented in popular MR platforms allow all MR apps to access these 3D spatial maps without explicit permission. Unmonitored access of MR apps to these 3D spatial maps poses serious privacy threats to users as these maps capture detailed geometric and semantic characteristics of users' environments. In this paper, we present LOCIN, a new location inference attack that exploits these detailed characteristics embedded in 3D spatial maps to infer a user's indoor location type. LOCIN develops a multi-task approach to train an end-to-end encoderdecoder network that extracts a spatial feature representation for capturing contextual patterns of the user's environment. LOCIN leverages this representation to detect 3D objects and surfaces and integrates them into a classification network with a novel unified optimization function to predict the user's indoor location. We demonstrate LOCIN attack on spatial maps collected from three popular MR devices. We show that LOCIN infers a user's location type with an average 84.1% accuracy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3bf04788-60d5-4684-8d06-aac72f71a3a9Cited by top-tier papers3
- mmSpyVR: Exploiting mmWave Radar for Penetrating Obstacles to Uncover Privacy Vulnerability of Virtual RealityLuoyu Mei, Ruofeng Liu, Zhimeng Yin, Qingchuan Zhao et al.UbiComp 2025 · 13 citations
- Speak Up, I'm Listening: Extracting Speech from Zero-Permission VR SensorsDerin Cayir, Reham Mohamed Aburas, Riccardo Lazzeretti, Marco Angelini et al.NDSS 2025
- From Perception to Protection: A Developer-Centered Study of Security and Privacy Threats in Extended Reality (XR)Kunlin Cai, Jinghuai Zhang, Ying Li, Zhiyuan Wang et al.NDSS 2026
Builds on10
- Deep Hough Voting for 3D Object Detection in Point CloudsCharles R. Qi, Or Litany, Kaiming He, Leonidas J. GuibasICCV 2019 · 1,467 citations
- 3D Instance Segmentation via Multi-Task Metric LearningJean Lahoud, Bernard Ghanem, Martin R. Oswald, Marc PollefeysICCV 2019 · 189 citations
- Face-Mic: inferring live speech and speaker identity via subtle facial dynamics captured by AR/VR motion sensorsCong Shi, Xiangyu Xu, Tianfang Zhang, Payton Walker et al.MobiCom 2021 · 89 citations
- VR-Spy: A Side-Channel Attack on Virtual Key-Logging in VR HeadsetsAbdullah Al Arafat, Zhishan Guo, Amro AwadIEEE VR 2021 · 70 citations
- A Keylogging Inference Attack on Air-Tapping Keyboards in Virtual EnvironmentsÜlkü Meteriz-Yildiran, Necip Fazil Yildiran, Amro Awad, David MohaisenIEEE VR 2022 · 40 citations
Related papers
- Unravelling Spatial Privacy Risks of Mobile Mixed Reality DataJaybie A. de Guzman, Aruna Seneviratne, Kanchana ThilakarathnaUbiComp 2021 · 22 citations
- HoloLogger: Keystroke Inference on Mixed Reality Head Mounted DisplaysShiqing Luo, Xinyu Hu, Zhisheng YanIEEE VR 2022 · 30 citations
- Relay and Betray: Exploiting Client-Side Authority in Multi-User Mixed RealityMutahar Ali, Habiba FarrukhUSENIX Security 2026
- "Just stop doing everything for now!": Understanding security attacks in remote collaborative mixed realityMaha Sajid, Syed Ibrahim Mustafa Shah Bukhari, Bo Ji, Brendan David-JohnIEEE VR 2025 · 7 citations
- Privacy-Preserving Representations are not Enough: Recovering Scene Content from Camera PosesKunal Chelani, Torsten Sattler, Fredrik Kahl, Zuzana KukelovaCVPR 2023
