USENIX Security2023Top-tier venue
Exploring User Reactions and Mental Models Towards Perceptual Manipulation Attacks in Mixed Reality
Kaiming Cheng, Jeffery F. Tian, Tadayoshi Kohno, Franziska Roesner
Abstract
Perceptual Manipulation Attacks (PMA) involve manipulating users' multi-sensory (e.g., visual, auditory, haptic) perceptions of the world through Mixed Reality (MR) content, in order to influence users' judgments and following actions. For example, a MR driving application that is expected to show safety-critical output might also (maliciously or unintentionally) overlay the wrong signal on a traffic sign, misleading the user into slamming on the brake. While current MR technology is sufficient to create such attacks, little research has been done to understand how users perceive, react to, and defend against such potential manipulations. To provide a foundation for understanding and addressing PMA in MR, we conducted an in-person study with 21 participants. We developed three PMA in which we focused on attacking three different perceptions: visual, auditory, and situational awareness. Our study first investigates how user reactions are affected by evaluating their performance on "microbenchmark" tasks under benchmark and different attack conditions. We observe both primary and secondary impacts from attacks, later impacting participants' performance even under non-attack conditions. We follow up with interviews, surfacing a range of user reactions and interpretations of PMA. Through qualitative data analysis of our observations and interviews, we identify various defensive strategies participants developed, and we observe how these strategies sometimes backfire. We derive recommendations for future investigation and defensive directions based on our findings.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext be42bc13-6c50-43c7-96fd-337dd09d205dCited by top-tier papers14
- Memory Manipulations in Extended RealityElise Bonnail, Wen-Jie Tseng, Mark McGill, Eric Lecolinet et al.CHI 2023 · 49 citations
- When the User Is Inside the User Interface: An Empirical Study of UI Security Properties in Augmented RealityKaiming Cheng, Arkaprabha Bhattacharya, Michelle Lin, Jaewook Lee et al.USENIX Security 2024 · 29 citations
- Was it Real or Virtual? Confirming the Occurrence and Explaining Causes of Memory Source Confusion between Reality and Virtual RealityElise Bonnail, Julian Frommel, Eric Lecolinet, Samuel Huron et al.CHI 2024 · 14 citations
- ViDDAR: Vision Language Model-Based Task-Detrimental Content Detection for Augmented RealityYanming Xiu, Tim Scargill, Maria GorlatovaIEEE VR 2025 · 14 citations
- Remote Keylogging Attacks in Multi-user VR ApplicationsZihao Su, Kunlin Cai, Reuben Beeler, Lukas Dresel et al.USENIX Security 2024 · 13 citations
Builds on7
- Towards Security and Privacy for Multi-user Augmented Reality: Foundations with End UsersKiron Lebeck, Kimberly Ruth, Tadayoshi Kohno, Franziska RoesnerS&P 2018 · 135 citations
- The Dark Side of Perceptual Manipulations in Virtual RealityWen-Jie Tseng, Elise Bonnail, Mark McGill, Mohamed Khamis et al.CHI 2022 · 118 citations
- Securing Augmented Reality OutputKiron Lebeck, Kimberly Ruth, Tadayoshi Kohno, Franziska RoesnerS&P 2017 · 103 citations
- Secure Multi-User Content Sharing for Augmented Reality ApplicationsKimberly Ruth, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2019 · 63 citations
- Altering Perceived Softness of Real Rigid Objects by Restricting Fingerpad DeformationYujie Tao, Shan-Yuan Teng, Pedro LopesUIST 2021 · 49 citations
Related papers
- Liar, Liar, Headset on Fire: Understanding the Effects of Deception Attacks on Decision-Making in a Mixed Reality GameAli Teymourian, Taha Gharaibeh, Ibrahim Baggili, Andrew M. WebbCHI 2026
- What and When to Explain?: On-road Evaluation of Explanations in Highly Automated VehiclesGwangbin Kim, Dohyeon Yeo, Taewoo Jo, Daniela Rus et al.UbiComp 2023 · 34 citations
- "Just stop doing everything for now!": Understanding security attacks in remote collaborative mixed realityMaha Sajid, Syed Ibrahim Mustafa Shah Bukhari, Bo Ji, Brendan David-JohnIEEE VR 2025 · 7 citations
- Relay and Betray: Exploiting Client-Side Authority in Multi-User Mixed RealityMutahar Ali, Habiba FarrukhUSENIX Security 2026
- SwitchAR: Perceptual Manipulations in Augmented RealityJonas Wombacher, Zhipeng Li, Jan GugenheimerUIST 2025 · 1 citation
