Erebus: Access Control for Augmented Reality Systems
Yoonsang Kim, Sanket Goutam, Amir Rahmati, Arie E. Kaufman
摘要
Augmented Reality (AR) is widely considered the next evolution in personal devices, enabling seamless integration of the digital world into our reality. Such integration, however, often requires unfettered access to sensor data, causing significant overprivilege for applications that run on these platforms. Through analysis of 17 AR systems and 45 popular AR applications, we explore existing mechanisms for access control in AR platforms, identify key trends in how AR applications use sensor data, and pinpoint unique threats users face in AR environments. Using these findings, we design and implement Erebus, an access control framework for AR platforms that enables fine-grained control over data used by AR applications. Erebus achieves the principle of least privileged through the creation of a domain-specific language (DSL) for permission control in AR platforms, allowing applications to specify data needed for their functionality. Using this DSL, Erebus further enables users to customize app permissions to apply under specific user conditions. We implement Erebus on Google's AR-Core SDK and port five existing AR applications to demonstrate the capability of Erebus to secure various classes of apps. Performance results using these applications and various microbenchmarks show that Erebus achieves its security goals while being practical, introducing negligible performance overhead to the AR system.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Exploring the Design Space of Privacy-Driven Adaptation Techniques for Future Augmented Reality InterfacesShwetha Rajaram, Macarena Peralta, Janet G. Johnson, Michael NebelingCHI 2025 · 被引用 7 次
- Designing Effective Consent Mechanisms for Spontaneous Interactions in Augmented RealityMaximiliane Windl, Petra Zsofia Laboda, Sven MayerCHI 2025 · 被引用 6 次
- Privacy Equilibrium: Balancing Privacy Needs in Dynamic Multi-User Augmented Reality ScenariosShwetha Rajaram, Jiasi Chen, Michael NebelingUIST 2025 · 被引用 3 次
- Mind the Gap: Mapping Wearer-Bystander Privacy Tensions and Context-Adaptive Pathways for Camera GlassesXueyang Wang, Kewen Peng, Xin Yi, Hewu LiCHI 2026 · 被引用 2 次
- SpeechLess: Micro-utterance with Personalized Spatial Memory-aware Assistant in Everyday Augmented RealityYoonsang Kim, Devshree Jadeja, Divyansh Pradhan, Yalong Yang 等IEEE VR 2026 · 被引用 1 次
它引用的顶会 Paper4
- TrackFormer: Multi-Object Tracking with TransformersTim Meinhardt, Alexander Kirillov, Laura Leal-Taixé, Christoph FeichtenhoferCVPR 2022 · 被引用 927 次
- Video Instance SegmentationLinjie Yang, Yuchen Fan, Ning XuICCV 2019 · 被引用 615 次
- Multiview: Finding Blind Spots in Access-Deny Issues DiagnosisBingyu Shen, Tianyi Shan, Yuanyuan ZhouUSENIX Security 2023
- Track To Detect and Segment: An Online Multi-Object TrackerJialian Wu, Jiale Cao, Liangchen Song, Yu Wang 等CVPR 2021
相关 Paper
- What You Experience is What We Collect: User Experience Based Fine-Grained Permissions for Everyday Augmented RealityMelvin Abraham, Mark McGill, Mohamed KhamisCHI 2024 · 被引用 18 次
- SoK: Authentication in Augmented and Virtual RealitySophie Stephenson, Bijeeta Pal, Stephen Fan, Earlence Fernandes 等S&P 2022 · 被引用 76 次
- When the User Is Inside the User Interface: An Empirical Study of UI Security Properties in Augmented RealityKaiming Cheng, Arkaprabha Bhattacharya, Michelle Lin, Jaewook Lee 等USENIX Security 2024 · 被引用 29 次
- That Doesn't Go There: Attacks on Shared State in Multi-User Augmented Reality ApplicationsCarter Slocum, Yicheng Zhang, Erfan Shayegani, Pedram Zaree 等USENIX Security 2024 · 被引用 21 次
- Bringing Balance to the Force: Dynamic Analysis of the Android Application FrameworkAbdallah Dawoud, Sven BugielNDSS 2021
