AVP-Inspect: Coordinated Cyber-Physical Testing for Privacy Analysis of COTS Apple Vision Pro Applications
Yichang Xiong, Vamsi Shankar Simhadri, Yue Xiao, Xiaokuan Zhang
摘要
XR devices introduce substantial privacy concerns due to their comprehensive data collection capabilities that surpass traditional computing platforms. While existing works have demonstrated privacy concerns on Android-based XR devices such as Meta Quest series by performing network traffic analysis, little attention has been paid to the Apple Vision Pro (AVP) devices, mainly due to the closed nature and the technical challenges associated with AVP devices. In this work, we make a bold attempt to detect privacy violations of AVP applications from network traffic through automatic testing on AVP devices. Our key insight is that effective AVP application testing requires coordinated control of both cyber (software) and physical (hardware) components, which we term Coordinated Cyber-Physical Testing.
Building on this insight, we design and implement AVP-Inspect, an automatic dynamic analysis framework for AVP applications, overcoming significant challenges enforced by the closed-source nature of AVP ecosystem. AVP-Inspect consists of three components: an automatic device controller by building customized hardware devices, a 3D UI explorer by designing a new exploration engine, and a privacy violation detector by constructing a unified privacy taxonomy for AVP. We first evaluated AVP-Inspect on a manually constructed ground truth dataset, then performed a large-scale analysis on 324 AVP applications downloaded from the App Store, with each app tested for 20 minutes. We found that 188 (58.0%) of apps exhibit at least one violation, and more than 60% of the network traffic flows are not properly disclosed.
• Security and privacy → Software security engineering; Mobile and wireless security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper45
- PolicyLint: Investigating Internal Privacy Policy Contradictions on Google PlayBenjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker 等USENIX Security 2019 · 被引用 185 次
- Understanding User Identification in Virtual Reality Through Behavioral Biometrics and the Effect of Body NormalizationJonathan Liebers, Mark Abdelaziz, Lukas Mecke, Alia Saad 等CHI 2021 · 被引用 94 次
- SoK: Authentication in Augmented and Virtual RealitySophie Stephenson, Bijeeta Pal, Stephen Fan, Earlence Fernandes 等S&P 2022 · 被引用 76 次
- Using Siamese Neural Networks to Perform Cross-System Behavioral Authentication in Virtual RealityRobert Miller, Natasha Kholgade Banerjee, Sean BanerjeeIEEE VR 2021 · 被引用 71 次
- VR-Spy: A Side-Channel Attack on Virtual Key-Logging in VR HeadsetsAbdullah Al Arafat, Zhishan Guo, Amro AwadIEEE VR 2021 · 被引用 70 次
相关 Paper
- An Empirical Study on Oculus Virtual Reality Applications: Security and Privacy PerspectivesHanyang Guo, Hong-Ning Dai, Xiapu Luo, Zibin Zheng 等ICSE 2024 · 被引用 17 次
- Virtual Reality, Real Problems: A Longitudinal Security Analysis of VR FirmwareVamsi Shankar Simhadri, Yichang Xiong, Habiba Farrukh, Xiaokuan ZhangCCS 2025
- AUTOVR: Automated UI Exploration for Detecting Sensitive Data Flow Exposures in Virtual Reality AppsJohn Y. Kim, Chaoshun Zuo, Yanjie Zhao, Zhiqiang LinUSENIX Security 2025
- WhisperTest: A Voice-Control-based Library for iOS UI AutomationZahra Moti, Tom Janssen-Groesbeek, Steven Monteiro, Andrea Continella 等CCS 2025
- VPVet: Vetting Privacy Policies of Virtual Reality AppsYuxia Zhan, Yan Meng, Lu Zhou, Yichang Xiong 等CCS 2024 · 被引用 2 次
