Pith. sign in

REVIEW 2 cited by

Can Virtual Reality Protect Users from Keystroke Inference Attacks?

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2310.16191 v1 pith:THQCAPHN submitted 2023-10-24 cs.CR

classification cs.CR
keywords attackstypedcontentuserusersvirtualattackeravatar
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Virtual Reality (VR) has gained popularity by providing immersive and interactive experiences without geographical limitations. It also provides a sense of personal privacy through physical separation. In this paper, we show that despite assumptions of enhanced privacy, VR is unable to shield its users from side-channel attacks that steal private information. Ironically, this vulnerability arises from VR's greatest strength, its immersive and interactive nature. We demonstrate this by designing and implementing a new set of keystroke inference attacks in shared virtual environments, where an attacker (VR user) can recover the content typed by another VR user by observing their avatar. While the avatar displays noisy telemetry of the user's hand motion, an intelligent attacker can use that data to recognize typed keys and reconstruct typed content, without knowing the keyboard layout or gathering labeled data. We evaluate the proposed attacks using IRB-approved user studies across multiple VR scenarios. For 13 out of 15 tested users, our attacks accurately recognize 86%-98% of typed keys, and the recovered content retains up to 98% of the meaning of the original typed content. We also discuss potential defenses.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. From Perception to Protection: A Developer-Centered Study of Security and Privacy Threats in Extended Reality (XR)

    cs.CR 2025-09 conditional novelty 6.0 of 10

    A 23-developer interview study shows professional XR developers recall few XR-specific threats unprompted, rate unfamiliar attacks lower, and exhibit awareness gaps plus diffusion of responsibility.

  2. Virtual Reality, Real Problems: A Longitudinal Security Analysis of VR Firmware

    cs.CR 2025-08 conditional novelty 6.0 of 10

    A longitudinal study of 300+ Meta Quest and Pico firmware images shows VR devices systematically miss Android-standard kernel, binary, permission, and SELinux protections.

Pith tools