USENIX Security2021Top-tier venue
AdCube: WebVR Ad Fraud and Practical Confinement of Third-Party Ads
Hyunjoo Lee, Jiyeon Lee, Daejun Kim, Suman Jana, Insik Shin, Sooel Son
Abstract
Web technology has evolved to offer 360-degree immersive browsing experiences. This new technology, called WebVR, enables virtual reality by rendering a three-dimensional world on an HTML canvas. Unfortunately, there exists no browser-supported way of sharing this canvas between different parties. Assuming an abusive ad service provider who exploits this absence, we present four new ad fraud attack methods. Our user study demonstrates that the success rates of our attacks range from 88.23% to 100%, confirming their effectiveness. To mitigate the presented threats, we propose AdCube, which allows publishers to specify the behaviors of third-party ad code and enforce this specification. We show that AdCube is able to block the presented threats with a small page loading latency of 236 msec and a negligible frame-per-second (FPS) drop for nine WebVR official demo sites.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7aec44e1-0732-4218-8e45-ccee1b20a7e7Cited by top-tier papers7
- When the User Is Inside the User Interface: An Empirical Study of UI Security Properties in Augmented RealityKaiming Cheng, Arkaprabha Bhattacharya, Michelle Lin, Jaewook Lee et al.USENIX Security 2024 · 29 citations
- VeriEdge: Verifying and Enforcing Service Level Agreements for Pervasive Edge ComputingXiaojian Wang, Ruozhou Yu, Dejun Yang, Huayue Gu et al.INFOCOM 2024 · 6 citations
- Welcome to the Dark Side: Analyzing the Revenue Flows of Fraud in the Online Ad EcosystemEmmanouil Papadogiannakis, Nicolas Kourtellis, Panagiotis Papadopoulos, Evangelos P. MarkatosWWW 2025 · 3 citations
- Unveiling Collusion-Based Ad Attribution Laundering Fraud: Detection, Analysis, and Security ImplicationsTong Zhu, Chaofan Shou, Zhen Huang, Guoxing Chen et al.CCS 2024 · 3 citations
- SoK: Come Together - Unifying Security, Information Theory, and Cognition for a Mixed Reality Deception Attack Ontology & Analysis FrameworkAli Teymourian, Andrew M. Webb, Taha Gharaibeh, Arushi Ghildiyal et al.USENIX Security 2025
Builds on4
- Towards Security and Privacy for Multi-user Augmented Reality: Foundations with End UsersKiron Lebeck, Kimberly Ruth, Tadayoshi Kohno, Franziska RoesnerS&P 2018 · 135 citations
- Securing Augmented Reality OutputKiron Lebeck, Kimberly Ruth, Tadayoshi Kohno, Franziska RoesnerS&P 2017 · 103 citations
- What Mobile Ads Know About Mobile UsersSooel Son, Daehyeok Kim, Vitaly ShmatikovNDSS 2016 · 101 citations
- All Your Clicks Belong to Me: Investigating Click Interception on the WebMingxue Zhang, Wei Meng, Sangho Lee, Byoungyoung Lee et al.USENIX Security 2019 · 26 citations
Related papers
- Shadowed Realities: An Investigation of UI Attacks in WebXRChandrika Mukherjee, Reham Mohamed, Arjun Arunasalam, Habiba Farrukh et al.USENIX Security 2025
- EXRPOSE: Runtime UI-based Attack Detection in WebXRChandrika Mukherjee, Aishwarya Devi Akila Pandian, Arjun Arunasalam, Jiasi Chen et al.CCS 2026
- "Just stop doing everything for now!": Understanding security attacks in remote collaborative mixed realityMaha Sajid, Syed Ibrahim Mustafa Shah Bukhari, Bo Ji, Brendan David-JohnIEEE VR 2025 · 7 citations
- Measuring and Disrupting Anti-Adblockers Using Differential Execution AnalysisShitong Zhu, Xunchao Hu, Zhiyun Qian, Zubair Shafiq et al.NDSS 2018 · 44 citations
- The Big Brother's New Playground: Unmasking the Illusion of Privacy in Web Metaverses from a Malicious User's PerspectiveAndrea Mengascini, Ryan Aurelio, Giancarlo PellegrinoCCS 2024
