From Perception to Protection: A Developer-Centered Study of Security and Privacy Threats in Extended Reality (XR)

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Cai, Kunlin, Zhang, Jinghuai, Li, Ying, Wang, Zhiyuan, Chen, Xun, Li, Tianshi, Tian, Yuan
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914027341348864
author Cai, Kunlin
Zhang, Jinghuai
Li, Ying
Wang, Zhiyuan
Chen, Xun
Li, Tianshi
Tian, Yuan
author_facet Cai, Kunlin
Zhang, Jinghuai
Li, Ying
Wang, Zhiyuan
Chen, Xun
Li, Tianshi
Tian, Yuan
contents The immersive nature of XR introduces a fundamentally different set of security and privacy (S&P) challenges due to the unprecedented user interactions and data collection that traditional paradigms struggle to mitigate. As the primary architects of XR applications, developers play a critical role in addressing novel threats. However, to effectively support developers, we must first understand how they perceive and respond to different threats. Despite the growing importance of this issue, there is a lack of in-depth, threat-aware studies that examine XR S&P from the developers' perspective. To fill this gap, we interviewed 23 professional XR developers with a focus on emerging threats in XR. Our study addresses two research questions aiming to uncover existing problems in XR development and identify actionable paths forward. By examining developers' perceptions of S&P threats, we found that: (1) XR development decisions (e.g., rich sensor data collection, user-generated content interfaces) are closely tied to and can amplify S&P threats, yet developers are often unaware of these risks, resulting in cognitive biases in threat perception; and (2) limitations in existing mitigation methods, combined with insufficient strategic, technical, and communication support, undermine developers' motivation, awareness, and ability to effectively address these threats. Based on these findings, we propose actionable and stakeholder-aware recommendations to improve XR S&P throughout the XR development process. This work represents the first effort to undertake a threat-aware, developer-centered study in the XR domain -- an area where the immersive, data-rich nature of the XR technology introduces distinctive challenges.
format Preprint
id arxiv_https___arxiv_org_abs_2509_06368
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle From Perception to Protection: A Developer-Centered Study of Security and Privacy Threats in Extended Reality (XR)
Cai, Kunlin
Zhang, Jinghuai
Li, Ying
Wang, Zhiyuan
Chen, Xun
Li, Tianshi
Tian, Yuan
Cryptography and Security
Human-Computer Interaction
The immersive nature of XR introduces a fundamentally different set of security and privacy (S&P) challenges due to the unprecedented user interactions and data collection that traditional paradigms struggle to mitigate. As the primary architects of XR applications, developers play a critical role in addressing novel threats. However, to effectively support developers, we must first understand how they perceive and respond to different threats. Despite the growing importance of this issue, there is a lack of in-depth, threat-aware studies that examine XR S&P from the developers' perspective. To fill this gap, we interviewed 23 professional XR developers with a focus on emerging threats in XR. Our study addresses two research questions aiming to uncover existing problems in XR development and identify actionable paths forward. By examining developers' perceptions of S&P threats, we found that: (1) XR development decisions (e.g., rich sensor data collection, user-generated content interfaces) are closely tied to and can amplify S&P threats, yet developers are often unaware of these risks, resulting in cognitive biases in threat perception; and (2) limitations in existing mitigation methods, combined with insufficient strategic, technical, and communication support, undermine developers' motivation, awareness, and ability to effectively address these threats. Based on these findings, we propose actionable and stakeholder-aware recommendations to improve XR S&P throughout the XR development process. This work represents the first effort to undertake a threat-aware, developer-centered study in the XR domain -- an area where the immersive, data-rich nature of the XR technology introduces distinctive challenges.
title From Perception to Protection: A Developer-Centered Study of Security and Privacy Threats in Extended Reality (XR)
topic Cryptography and Security
Human-Computer Interaction
url https://arxiv.org/abs/2509.06368