Motion in the Clear: Reconstructing VR User Behavior from Network Traffic
JiHo Lee, JinYi Yoon, Taejoong Chung, Brendan David-John, Bo Ji
摘要
Virtual Reality (VR) applications stream high-rate head and hand motion to support real-time multi-user interaction. This motion telemetry is privacy sensitive, enabling behavioral inference such as user identification and virtual typing inference. We show that VR motion can be reconstructed from passively observed network traffic alone, even when the adversary has no application access, device compromise, or message-format knowledge. From an ecosystem measurement of 75 popular VR applications, we find that multiplayer uplink traffic is dominated by sustained, high-frequency UDP and that payload encryption is uncommon. Despite application-specific serialization and unknown encodings, motion updates retain a smooth temporal structure that remains visible in plaintext UDP payload bytes.
Leveraging this property, we present PACMO, a passive, encoding-agnostic attack that uses controlled input patterns to automatically localize motion-related packet fields and reconstruct head and hand trajectories in a black-box manner. The reconstructed motion enables high-impact downstream attacks, achieving up to 96.2% user identification accuracy and 69.4% virtual typing inference accuracy. Our results expose a systemic network-layer privacy risk in immersive systems and motivate treating motion synchronization traffic as sensitive by default.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper19
- Understanding User Identification in Virtual Reality Through Behavioral Biometrics and the Effect of Body NormalizationJonathan Liebers, Mark Abdelaziz, Lukas Mecke, Alia Saad 等CHI 2021 · 被引用 94 次
- VR-Spy: A Side-Channel Attack on Virtual Key-Logging in VR HeadsetsAbdullah Al Arafat, Zhishan Guo, Amro AwadIEEE VR 2021 · 被引用 70 次
- A Keylogging Inference Attack on Air-Tapping Keyboards in Virtual EnvironmentsÜlkü Meteriz-Yildiran, Necip Fazil Yildiran, Amro Awad, David MohaisenIEEE VR 2022 · 被引用 40 次
- Can Virtual Reality Protect Users from Keystroke Inference Attacks?Zhuolin Yang, Zain Sarwar, Iris Hwang, Ronik Bhaskar 等USENIX Security 2024 · 被引用 26 次
- Understanding Parents' Perceptions and Practices Toward Children's Security and Privacy in Virtual RealityJiaxun Cao, Abhinaya S. B., Anupam Das, Pardis Emami NaeiniS&P 2024 · 被引用 19 次
相关 Paper
- Going through the motions: AR/VR keylogging from user head motionsCarter Slocum, Yicheng Zhang, Nael B. Abu-Ghazaleh, Jiasi ChenUSENIX Security 2023
- Remote Keylogging Attacks in Multi-user VR ApplicationsZihao Su, Kunlin Cai, Reuben Beeler, Lukas Dresel 等USENIX Security 2024 · 被引用 13 次
- Movement- and Traffic-based User Identification in Commercial Virtual Reality Applications: Threats and OpportunitiesSara Baldoni, Salim Benhamadi, Federico Chiariotti, Michele Zorzi 等IEEE VR 2025 · 被引用 2 次
- When VR Meets BCI: (Un)Observable Brainwave-Aware Privacy Reconstruction in the Metaverse via Unrestricted Inbuilt Motion SensorsTao Ni, Zehua Sun, Qingchuan Zhao, Wei-Bin Lee 等S&P 2026
- Unique Identification of 50, 000+ Virtual Reality Users from Head & Hand Motion DataVivek Nair, Wenbo Guo, Justus Mattern, Rui Wang 等USENIX Security 2023
