AVP-Inspect: Coordinated Cyber-Physical Testing for Privacy Analysis of COTS Apple Vision Pro Applications
Yichang Xiong, Vamsi Shankar Simhadri, Yue Xiao, Xiaokuan Zhang
Abstract
XR devices introduce substantial privacy concerns due to their comprehensive data collection capabilities that surpass traditional computing platforms. While existing works have demonstrated privacy concerns on Android-based XR devices such as Meta Quest series by performing network traffic analysis, little attention has been paid to the Apple Vision Pro (AVP) devices, mainly due to the closed nature and the technical challenges associated with AVP devices. In this work, we make a bold attempt to detect privacy violations of AVP applications from network traffic through automatic testing on AVP devices. Our key insight is that effective AVP application testing requires coordinated control of both cyber (software) and physical (hardware) components, which we term Coordinated Cyber-Physical Testing.
Building on this insight, we design and implement AVP-Inspect, an automatic dynamic analysis framework for AVP applications, overcoming significant challenges enforced by the closed-source nature of AVP ecosystem. AVP-Inspect consists of three components: an automatic device controller by building customized hardware devices, a 3D UI explorer by designing a new exploration engine, and a privacy violation detector by constructing a unified privacy taxonomy for AVP. We first evaluated AVP-Inspect on a manually constructed ground truth dataset, then performed a large-scale analysis on 324 AVP applications downloaded from the App Store, with each app tested for 20 minutes. We found that 188 (58.0%) of apps exhibit at least one violation, and more than 60% of the network traffic flows are not properly disclosed.
• Security and privacy → Software security engineering; Mobile and wireless security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f2427769-1db4-4c91-bcf4-adc78ea4b3f5Builds on45
- PolicyLint: Investigating Internal Privacy Policy Contradictions on Google PlayBenjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker et al.USENIX Security 2019 · 185 citations
- Understanding User Identification in Virtual Reality Through Behavioral Biometrics and the Effect of Body NormalizationJonathan Liebers, Mark Abdelaziz, Lukas Mecke, Alia Saad et al.CHI 2021 · 94 citations
- SoK: Authentication in Augmented and Virtual RealitySophie Stephenson, Bijeeta Pal, Stephen Fan, Earlence Fernandes et al.S&P 2022 · 76 citations
- Using Siamese Neural Networks to Perform Cross-System Behavioral Authentication in Virtual RealityRobert Miller, Natasha Kholgade Banerjee, Sean BanerjeeIEEE VR 2021 · 71 citations
- VR-Spy: A Side-Channel Attack on Virtual Key-Logging in VR HeadsetsAbdullah Al Arafat, Zhishan Guo, Amro AwadIEEE VR 2021 · 70 citations
Related papers
- An Empirical Study on Oculus Virtual Reality Applications: Security and Privacy PerspectivesHanyang Guo, Hong-Ning Dai, Xiapu Luo, Zibin Zheng et al.ICSE 2024 · 17 citations
- Virtual Reality, Real Problems: A Longitudinal Security Analysis of VR FirmwareVamsi Shankar Simhadri, Yichang Xiong, Habiba Farrukh, Xiaokuan ZhangCCS 2025
- AUTOVR: Automated UI Exploration for Detecting Sensitive Data Flow Exposures in Virtual Reality AppsJohn Y. Kim, Chaoshun Zuo, Yanjie Zhao, Zhiqiang LinUSENIX Security 2025
- WhisperTest: A Voice-Control-based Library for iOS UI AutomationZahra Moti, Tom Janssen-Groesbeek, Steven Monteiro, Andrea Continella et al.CCS 2025
- VPVet: Vetting Privacy Policies of Virtual Reality AppsYuxia Zhan, Yan Meng, Lu Zhou, Yichang Xiong et al.CCS 2024 · 2 citations
