Inception Attacks: Immersive Hijacking in Virtual Reality Systems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yang, Zhuolin, Li, Cathy Yuanchen, Bhalla, Arman, Zhao, Ben Y., Zheng, Haitao
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909309662658560
author Yang, Zhuolin
Li, Cathy Yuanchen
Bhalla, Arman
Zhao, Ben Y.
Zheng, Haitao
author_facet Yang, Zhuolin
Li, Cathy Yuanchen
Bhalla, Arman
Zhao, Ben Y.
Zheng, Haitao
contents Today's virtual reality (VR) systems provide immersive interactions that seamlessly connect users with online services and one another. However, these immersive interfaces also introduce new vulnerabilities, making it easier for users to fall prey to new attacks. In this work, we introduce the immersive hijacking attack, where a remote attacker takes control of a user's interaction with their VR system, by trapping them inside a malicious app that masquerades as the full VR interface. Once trapped, all of the user's interactions with apps, services and other users can be recorded and modified without their knowledge. This not only allows traditional privacy attacks but also introduces new interaction attacks, where two VR users encounter vastly different immersive experiences during their interaction. We present our implementation of the immersive hijacking attack on Meta Quest headsets and conduct IRB-approved user studies that validate its efficacy and stealthiness. Finally, we examine effectiveness and tradeoffs of various potential defenses, and propose a multifaceted defense pipeline.
format Preprint
id arxiv_https___arxiv_org_abs_2403_05721
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Inception Attacks: Immersive Hijacking in Virtual Reality Systems
Yang, Zhuolin
Li, Cathy Yuanchen
Bhalla, Arman
Zhao, Ben Y.
Zheng, Haitao
Cryptography and Security
Today's virtual reality (VR) systems provide immersive interactions that seamlessly connect users with online services and one another. However, these immersive interfaces also introduce new vulnerabilities, making it easier for users to fall prey to new attacks. In this work, we introduce the immersive hijacking attack, where a remote attacker takes control of a user's interaction with their VR system, by trapping them inside a malicious app that masquerades as the full VR interface. Once trapped, all of the user's interactions with apps, services and other users can be recorded and modified without their knowledge. This not only allows traditional privacy attacks but also introduces new interaction attacks, where two VR users encounter vastly different immersive experiences during their interaction. We present our implementation of the immersive hijacking attack on Meta Quest headsets and conduct IRB-approved user studies that validate its efficacy and stealthiness. Finally, we examine effectiveness and tradeoffs of various potential defenses, and propose a multifaceted defense pipeline.
title Inception Attacks: Immersive Hijacking in Virtual Reality Systems
topic Cryptography and Security
url https://arxiv.org/abs/2403.05721