Relay and Betray: Exploiting Client-Side Authority in Multi-User Mixed Reality
Mutahar Ali, Habiba Farrukh
摘要
Multi-user mixed reality (MR) apps create shared immersive environments where users interact through embodied avatars and virtual objects in real time. These apps are increasingly used in education, workforce training, enterprise collaboration, and social experiences. To maintain immersion, multi-user MR apps minimize latency by making clients compute and broadcast state updates, such as object tracking and interaction updates. Many apps also let users upload user-generated content, such as custom avatars and 3D assets, which is distributed to other participants. This design implicitly assumes client-side trust, where each client is expected to behave honestly: report correct state updates and upload well-formed content. However, a malicious user can exploit this trust to access information that should not be perceptually or logically available to them, inject false updates, bypass moderation and safety features, or upload malicious user-generated content. While prior work has demonstrated side-channels, perception manipulation, and privacy attacks on MR systems, the security implications of client-side trust in shared MR environments remain largely unexplored. In this paper, we present the first systematic analysis of security risks introduced by client-side trust in multi-user MR apps. We model how users and virtual objects are represented and synchronized across clients, derive security invariants that capture the conditions for safe and correct interaction, and develop a methodology to test for violations via runtime instrumentation and malicious user-generated avatars. Applying this methodology to 20 popular multi-user MR apps across different use cases and platforms, we identify five attack categories: (1) video and audio surveillance, (2) tampering of virtual objects, (3) circumvention of safety features, (4) disruption and denial-of-service, and (5) impersonation of other users. Our findings show that architectural reliance on client-side trust in multi-user MR allows a single malicious user to compromise the privacy, security, and safety of other users.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper26
- Rethinking Access Control and Authentication for the Home Internet of Things (IoT)Weijia He, Maximilian Golla, Roshni Padhi, Jordan Ofek 等USENIX Security 2018 · 被引用 221 次
- SoK: Hate, Harassment, and the Changing Landscape of Online AbuseKurt Thomas, Devdatta Akhawe, Michael D. Bailey, Dan Boneh 等S&P 2021 · 被引用 175 次
- VR-Spy: A Side-Channel Attack on Virtual Key-Logging in VR HeadsetsAbdullah Al Arafat, Zhishan Guo, Amro AwadIEEE VR 2021 · 被引用 70 次
- "Creepy Towards My Avatar Body, Creepy Towards My Body": How Women Experience and Manage Harassment Risks in Social Virtual RealityKelsea Schulenberg, Guo Freeman, Lingyuan Li, Catherine BarwulorCSCW 2023 · 被引用 67 次
- A First Look at ZoombombingChen Ling, Utkucan Balci, Jeremy Blackburn, Gianluca StringhiniS&P 2021 · 被引用 51 次
相关 Paper
- "Just stop doing everything for now!": Understanding security attacks in remote collaborative mixed realityMaha Sajid, Syed Ibrahim Mustafa Shah Bukhari, Bo Ji, Brendan David-JohnIEEE VR 2025 · 被引用 7 次
- That Doesn't Go There: Attacks on Shared State in Multi-User Augmented Reality ApplicationsCarter Slocum, Yicheng Zhang, Erfan Shayegani, Pedram Zaree 等USENIX Security 2024 · 被引用 21 次
- LocIn: Inferring Semantic Location from Spatial Maps in Mixed RealityHabiba Farrukh, Reham Mohamed, Aniket Nare, Antonio Bianchi 等USENIX Security 2023
- Omniscience for the Masses: New Threats in the Metaverse's Democratized World CreationAndrea Mengascini, Ryan Aurelio, Jason Polakis, Giancarlo PellegrinoCCS 2026
- Secure Multi-User Content Sharing for Augmented Reality ApplicationsKimberly Ruth, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2019 · 被引用 63 次
