An Empirical Study on Oculus Virtual Reality Applications: Security and Privacy Perspectives
Hanyang Guo, Hong-Ning Dai, Xiapu Luo, Zibin Zheng, Gengyang Xu, Fengliang He
摘要
Although Virtual Reality (VR) has accelerated its prevalent adoption in emerging metaverse applications, it is not a fundamentally new technology. On one hand, most VR operating systems (OS) are based on off-the-shelf mobile OS (e.g., Android). As a result, VR apps also inherit privacy and security deficiencies from conventional mobile apps. On the other hand, in contrast to conventional mobile apps, VR apps can achieve immersive experience via diverse VR devices, such as head-mounted displays, body sensors, and controllers though achieving this requires the extensive collection of privacy-sensitive human biometrics (e.g., hand-tracking and face-tracking data). Moreover, VR apps have been typically implemented by 3D gaming engines (e.g., Unity), which also contain intrinsic security vulnerabilities. Inappropriate use of these technologies may incur privacy leaks and security vulnerabilities although these issues have not received significant attention compared to the proliferation of diverse VR apps. In this paper, we develop a security and privacy assessment tool, namely the VR-SP detector for VR apps. The VR-SP detector has integrated program static analysis tools and privacy-policy analysis methods. Using the VR-SP detector, we conduct a comprehensive empirical study on 500 popular VR apps. We obtain the original apps from the popular Oculus and SideQuest app stores and extract APK files via the Meta Oculus Quest 2 device. We evaluate security vulnerabilities and privacy data leaks of these VR apps by VR app analysis, taint analysis, and privacy-policy analysis. We find that a number of security vulnerabilities and privacy leaks widely exist in VR apps. Moreover, our results also reveal conflicting representations in the privacy policies of these apps and inconsistencies of the actual data collection with the privacy-policy statements of the apps. Based on these findings, we make suggestions for the future development of VR apps.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Motion in the Clear: Reconstructing VR User Behavior from Network TrafficJiHo Lee, JinYi Yoon, Taejoong Chung, Brendan David-John 等USENIX Security 2026
- Omniscience for the Masses: New Threats in the Metaverse's Democratized World CreationAndrea Mengascini, Ryan Aurelio, Jason Polakis, Giancarlo PellegrinoCCS 2026
- XRFix: Exploring Performance Bug Repair of Extended Reality Applications with Large Language ModelsJingwen Wu, Hanyang Guo, Hong-Ning Dai, Xiapu LuoICSE 2026
- From Perception to Protection: A Developer-Centered Study of Security and Privacy Threats in Extended Reality (XR)Kunlin Cai, Jinghuai Zhang, Ying Li, Zhiyuan Wang 等NDSS 2026
- When VR Meets BCI: (Un)Observable Brainwave-Aware Privacy Reconstruction in the Metaverse via Unrestricted Inbuilt Motion SensorsTao Ni, Zehua Sun, Qingchuan Zhao, Wei-Bin Lee 等S&P 2026
它引用的顶会 Paper10
- 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions SystemJoel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On 等USENIX Security 2019 · 被引用 196 次
- An Empirical Assessment of Global COVID-19 Contact Tracing ApplicationsRuoxi Sun, Wei Wang, Minhui Xue, Gareth Tyson 等ICSE 2021 · 被引用 54 次
- Why Eve and Mallory Still Love Android: Revisiting TLS (In)Security in Android ApplicationsMarten Oltrogge, Nicolas Huaman, Sabrina Amft, Yasemin Acar 等USENIX Security 2021 · 被引用 45 次
- Contact Tracing App Privacy: What Data Is Shared By Europe's GAEN Contact Tracing AppsDouglas J. Leith, Stephen FarrellINFOCOM 2021 · 被引用 42 次
- How Developers Optimize Virtual Reality Applications: A Study of Optimization Commits in Open Source Unity ProjectsFariha Nusrat, Foyzul Hassan, Hao Zhong, Xiaoyin WangICSE 2021 · 被引用 31 次
相关 Paper
- OVRseen: Auditing Network Traffic and Privacy Policies in Oculus VRRahmadi Trimananda, Hieu Le, Hao Cui, Janice Tran Ho 等USENIX Security 2022
- Virtual Reality, Real Problems: A Longitudinal Security Analysis of VR FirmwareVamsi Shankar Simhadri, Yichang Xiong, Habiba Farrukh, Xiaokuan ZhangCCS 2025
- AUTOVR: Automated UI Exploration for Detecting Sensitive Data Flow Exposures in Virtual Reality AppsJohn Y. Kim, Chaoshun Zuo, Yanjie Zhao, Zhiqiang LinUSENIX Security 2025
- Side-channel Inference of User Activities in AR/VR Using GPU ProfilingSeonghun Son, Chandrika Mukherjee, Reham Mohamed Aburas, Berk Gülmezoglu 等NDSS 2026 · 被引用 4 次
- Privacy Leakage via Unrestricted Motion-Position Sensors in the Age of Virtual Reality: A Study of Snooping Typed Input on Virtual KeyboardsYi Wu, Cong Shi, Tianfang Zhang, Payton Walker 等S&P 2023
