USENIX Security2024Top-tier venue
That Doesn't Go There: Attacks on Shared State in Multi-User Augmented Reality Applications
Carter Slocum, Yicheng Zhang, Erfan Shayegani, Pedram Zaree, Nael B. Abu-Ghazaleh, Jiasi Chen
Abstract
Augmented Reality (AR) is expected to become a pervasive component in enabling shared virtual experiences. In order to facilitate collaboration among multiple users, it is crucial for multi-user AR applications to establish a consensus on the"shared state"of the virtual world and its augmentations, through which they interact within augmented reality spaces. Current methods to create and access shared state collect sensor data from devices (e.g., camera images), process them, and integrate them into the shared state. However, this process introduces new vulnerabilities and opportunities for attacks. Maliciously writing false data to"poison"the shared state is a major concern for the security of the downstream victims that depend on it. Another type of vulnerability arises when reading the shared state; by providing false inputs, an attacker can view hologram augmentations at locations they are not allowed to access. In this work, we demonstrate a series of novel attacks on multiple AR frameworks with shared states, focusing on three publicly-accessible frameworks. We show that these frameworks, while using different underlying implementations, scopes, and mechanisms to read from and write to the shared state, have shared vulnerability to a unified threat model. Our evaluation of these state-of-art AR applications demonstrates reliable attacks both on updating and accessing shared state across the different systems. To defend against such threats, we discuss a number of potential mitigation strategies that can help enhance the security of multi-user AR applications.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f768429c-6e00-4b0e-b699-e75c1d84a6a6Cited by top-tier papers6
- "Just stop doing everything for now!": Understanding security attacks in remote collaborative mixed realityMaha Sajid, Syed Ibrahim Mustafa Shah Bukhari, Bo Ji, Brendan David-JohnIEEE VR 2025 · 7 citations
- SoK: Come Together - Unifying Security, Information Theory, and Cognition for a Mixed Reality Deception Attack Ontology & Analysis FrameworkAli Teymourian, Andrew M. Webb, Taha Gharaibeh, Arushi Ghildiyal et al.USENIX Security 2025
- From Perception to Protection: A Developer-Centered Study of Security and Privacy Threats in Extended Reality (XR)Kunlin Cai, Jinghuai Zhang, Ying Li, Zhiyuan Wang et al.NDSS 2026
- GradEscape: A Gradient-Based Evader Against AI-Generated Text DetectorsWenlong Meng, Shuguo Fan, Chengkun Wei, Min Chen et al.USENIX Security 2025
- Relay and Betray: Exploiting Client-Side Authority in Multi-User Mixed RealityMutahar Ali, Habiba FarrukhUSENIX Security 2026
Builds on15
- Towards Security and Privacy for Multi-user Augmented Reality: Foundations with End UsersKiron Lebeck, Kimberly Ruth, Tadayoshi Kohno, Franziska RoesnerS&P 2018 · 135 citations
- Poltergeist: Acoustic Adversarial Machine Learning against Cameras and Computer VisionXiaoyu Ji, Yushi Cheng, Yuepeng Zhang, Kai Wang et al.S&P 2021 · 99 citations
- Segment and Complete: Defending Object Detectors against Adversarial Patch Attacks with Robust Patch DetectionJiang Liu, Alexander Levine, Chun Pong Lau, Rama Chellappa et al.CVPR 2022 · 99 citations
- Secure Multi-User Content Sharing for Augmented Reality ApplicationsKimberly Ruth, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2019 · 63 citations
- HoloLogger: Keystroke Inference on Mixed Reality Head Mounted DisplaysShiqing Luo, Xinyu Hu, Zhisheng YanIEEE VR 2022 · 30 citations
Related papers
- When the User Is Inside the User Interface: An Empirical Study of UI Security Properties in Augmented RealityKaiming Cheng, Arkaprabha Bhattacharya, Michelle Lin, Jaewook Lee et al.USENIX Security 2024 · 29 citations
- Securing Augmented Reality OutputKiron Lebeck, Kimberly Ruth, Tadayoshi Kohno, Franziska RoesnerS&P 2017 · 103 citations
- SoK: Authentication in Augmented and Virtual RealitySophie Stephenson, Bijeeta Pal, Stephen Fan, Earlence Fernandes et al.S&P 2022 · 76 citations
- PROMAR: Practical Reference Object-based Multi-user Augmented RealityTengpeng Li, Son Nam Nguyen, Xiaoqian Zhang, Teng Wang et al.INFOCOM 2020 · 3 citations
- Erebus: Access Control for Augmented Reality SystemsYoonsang Kim, Sanket Goutam, Amir Rahmati, Arie E. KaufmanUSENIX Security 2023
