CHOP: Breaking Anonymity in XR through a Novel and Cost-effective Chain of Privacy Attacks and Differential Privacy-Based Defenses
Ripan Kumar Kundu, Brendan David-John, Khaza Anuarul Hoque
摘要
The convergence of artificial intelligence (AI) and extended reality (XR) technologies (AIXR) promises innovative applications across many domains. However, the sensitive nature of data (e.g., eye-tracking) used in these systems also raises significant privacy concerns, as adversaries can exploit this data and these models to infer personal information. Prior research has primarily examined membership inference attacks (MIA) to leak privacy at the model-level and re-identification attacks (RDA) at the dataset-level, separately as individual attacks. While these attacks are relevant to the XR domain, launching these attacks as individual attacks is not practical and incurs more attack cost. To address this gap, we present the first comprehensive study of chain of privacy (CHOP) attacks against AIXR applications. We demonstrate how adversaries can launch such attacks with a high success rate, in a cost-effective way, by sequentially combining MIA and Attribute inference attacks (AIA) to re-identify XR users without access to raw XR data, training distributions, or model parameters. We evaluate our proposed method in realistic AIXR settings by adopting deep learning (DL)-based cybersickness detection as a representative AIXR application. Specifically, we train two state-of-the-art DL models on two open-source datasets: Simulation 2021 and VRWalking, and a new XR cybersickness dataset constructed from 34 participants via a user study. Our findings reveal that the proposed CHOP attacks pose severe risks to DL-based cybersickness detection, achieving re-identification rates of up to 94% and 97% on the open-source and the developed cross-linked datasets, respectively, underscoring the feasibility and severity of cross-dataset privacy violations. Furthermore, cost analysis reveals that the proposed CHOP attack is ≈ 2× more cost-effective than traditional individual attacks for re-identifying XR users. Finally, we propose two ε-differential privacy (DP)-enabled privacy-preserving mechanisms: Differentially Private Stochastic Gradient Descent (DPSGD) and Private Aggregation of Teacher Ensembles (PATE) to mitigate CHOP attacks. Our results show that the proposed defense reduces the re-identification rate by up to 88% and 79% while maintaining high model utility, with classification accuracies of up to 94% and 92% for the same datasets using Transformer models.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Obscuring the 'Who,' Preserving the 'What': Targeted Eye-tracking Feature Obfuscation in Virtual Reality for Privacy-Utility BalanceNasim Ahmed, Md Mahedi Hassan, Md Mushfique Hossain, Nazmus Shakib Shadin 等IEEE VR 2026
- Toward Multimodal Privacy in XR: Design and Evaluation of Composite Privatization Methods for Gaze and Body Tracking DataAzim Ibragimov, Ethan Wilson, Kevin R. B. Butler, Eakta JainIEEE VR 2026 · 被引用 1 次
- LiteVR: Interpretable and Lightweight Cybersickness Detection using Explainable AIRipan Kumar Kundu, Rifatul Islam, John Quarles, Khaza Anuarul HoqueIEEE VR 2023 · 被引用 34 次
- Privacy-preserving datasets of eye-tracking samples with applications in XRBrendan David-John, Kevin R. B. Butler, Eakta JainIEEE VR 2023 · 被引用 35 次
- PRECYSE: Predicting Cybersickness using Transformer for Multimodal Time-Series Sensor DataDayoung Jeong, Kyungsik HanUbiComp 2024 · 被引用 35 次
