Privacy Leakage via Unrestricted Motion-Position Sensors in the Age of Virtual Reality: A Study of Snooping Typed Input on Virtual Keyboards
Yi Wu, Cong Shi, Tianfang Zhang, Payton Walker, Jian Liu, Nitesh Saxena, Yingying Chen
Abstract
Virtual Reality (VR) has gained popularity in numerous fields, including gaming, social interactions, shopping, and education. In this paper, we conduct a comprehensive study to assess the trustworthiness of the embedded sensors on VR, which embed various forms of sensitive data that may put users’ privacy at risk. We find that accessing most on-board sensors (e.g., motion, position, and button sensors) on VR SDKs/APIs, such as OpenVR, Oculus Platform, and WebXR, requires no security permission, exposing a huge attack surface for an adversary to steal the user’s privacy. We validate this vulnerability through developing malware programs and malicious websites and specifically explore to what extent it exposes the user’s information in the context of keystroke snooping. To examine its actual threat in practice, the adversary in the considered attack model doesn’t possess any labeled data from the user nor knowledge about the user’s VR settings. Extensive experiments, involving two mainstream VR systems and four keyboards with different typing mechanisms, demonstrate that our proof-of-concept attack can recognize the user’s virtual typing with over 89.7% accuracy. The attack can recover the user’s passwords with up to 84.9% recognition accuracy if three attempts are allowed and achieve an average of 87.1% word recognition rate for paragraph inference. We hope this study will help the community gain awareness of the vulnerability in the sensor management of current VR systems and provide insights to facilitate the future design of more comprehensive and restricted sensor access control mechanisms.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers19
- When the User Is Inside the User Interface: An Empirical Study of UI Security Properties in Augmented RealityKaiming Cheng, Arkaprabha Bhattacharya, Michelle Lin, Jaewook Lee et al.USENIX Security 2024 · 29 citations
- Penetration Vision through Virtual Reality Headsets: Identifying 360-degree Videos from Head MovementsAnh Nguyen, Xiaokuan Zhang, Zhisheng YanUSENIX Security 2024 · 17 citations
- An Empirical Study on Oculus Virtual Reality Applications: Security and Privacy PerspectivesHanyang Guo, Hong-Ning Dai, Xiapu Luo, Zibin Zheng et al.ICSE 2024 · 17 citations
- FaceReader: Unobtrusively Mining Vital Signs and Vital Sign Embedded Sensitive Info via AR/VR Motion SensorsTianfang Zhang, Zhengkun Ye, Ahmed Tanvir Mahdad, Md Mojibur Rahman Redoy Akanda et al.CCS 2023 · 16 citations
- Remote Keylogging Attacks in Multi-user VR ApplicationsZihao Su, Kunlin Cai, Reuben Beeler, Lukas Dresel et al.USENIX Security 2024 · 13 citations
Builds on7
- Face-Mic: inferring live speech and speaker identity via subtle facial dynamics captured by AR/VR motion sensorsCong Shi, Xiangyu Xu, Tianfang Zhang, Payton Walker et al.MobiCom 2021 · 89 citations
- VR-Spy: A Side-Channel Attack on Virtual Key-Logging in VR HeadsetsAbdullah Al Arafat, Zhishan Guo, Amro AwadIEEE VR 2021 · 70 citations
- No Training Hurdles: Fast Training-Agnostic Attacks to Infer Your TypingSong Fang, Ian D. Markwood, Yao Liu, Shangqing Zhao et al.CCS 2018 · 46 citations
- A Keylogging Inference Attack on Air-Tapping Keyboards in Virtual EnvironmentsÜlkü Meteriz-Yildiran, Necip Fazil Yildiran, Amro Awad, David MohaisenIEEE VR 2022 · 40 citations
- User Authentication via Electrical Muscle StimulationYuxin Chen, Zhuolin Yang, Ruben Abbou, Pedro Lopes et al.CHI 2021 · 35 citations
Related papers
- Can Virtual Reality Protect Users from Keystroke Inference Attacks?Zhuolin Yang, Zain Sarwar, Iris Hwang, Ronik Bhaskar et al.USENIX Security 2024 · 26 citations
- Going through the motions: AR/VR keylogging from user head motionsCarter Slocum, Yicheng Zhang, Nael B. Abu-Ghazaleh, Jiasi ChenUSENIX Security 2023
- When VR Meets BCI: (Un)Observable Brainwave-Aware Privacy Reconstruction in the Metaverse via Unrestricted Inbuilt Motion SensorsTao Ni, Zehua Sun, Qingchuan Zhao, Wei-Bin Lee et al.S&P 2026
- Non-intrusive and Unconstrained Keystroke Inference in VR Platforms via Infrared Side ChannelTao Ni, Yuefeng Du, Qingchuan Zhao, Cong WangNDSS 2025
- Eyes on your Typing: Snooping Finger Motions on Virtual KeyboardsSunwoo Lee, Wonsuk ChoiS&P 2025
