Pith. sign in

REVIEW 3 major objections 5 minor 105 references

SoK: Come Together -- Unifying Security, Information Theory, and Cognition for a Mixed Reality Deception Attack Ontology & Analysis Framework

T0 review · 3 major / 5 minor · reviewed 2026-08-07 · deepseek-v4-flash

Pith's one-line read Mixed-reality deception attacks can be systematically analyzed through a framework that unifies security, information theory, and cognition.

desk verdict A useful qualitative ontology for MR deception attacks, but the information-theoretic 'formalization' is overstated and needs correction before the framework is used as a basis for empirical work. read the letter →

arxiv 2502.09763 v1 pith:FHCAI7EM submitted 2025-02-13 cs.CR cs.HC

classification cs.CRcs.HC
keywords mixedrealitydeceptionattacksontologyinformationtheorychannelcapacitycognitiondecision-makingsystematizationofknowledge
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This SoK paper argues that deception attacks on mixed reality (MR) users — attacks that overlay fake objects, hide real ones, or manipulate tracking — can be analyzed in one coherent framework instead of case-by-case. The authors build an ontology of such attacks from the Borden-Kopp deception model, then attach two formal models: an information-theoretic model that treats the MR headset as a transmitter and the user's senses as a receiver, and a decision-making model that maps attacks onto perception, attention, and memory. The resulting MR Deception Analysis Framework (DAF) lets researchers assess how an attack degrades information channels and which cognitive processes it disrupts. If the framework holds, it gives security researchers a shared language for describing MR deception, a way to compare attacks, and a scaffold for designing experiments.

What carries the argument

The load-bearing machinery is the Borden-Kopp deception taxonomy, which sorts attacks into channel attacks (overt degradation, covert degradation, denial) and processing attacks (corruption, subversion). Carrying the formal analysis are Shannon's channel capacity theorem — $C = W \log_2(1 + S/(N_A + N_E))$ — which treats the MR headset as transmitter and human senses as receiver, and Vitanyi's similarity metric $M(X,Y) = 1 - D(X,Y)$ based on normalized information distance, which measures how well a deceptive message mimics a legitimate one. The cognitive side is carried by a decision-making model with seven components (sensory inputs, attention, perception, memory, decision-making, execution, responses) whose perception stages and attention types DAF uses as assessment axes. These components together let DAF rate each attack's effect on bandwidth, signal, noise, mimicry, perception, attention, and memory.

What would settle it

A controlled experiment measuring the predicted relationships would settle it: for a set of MR deception attacks, measure channel-capacity proxies such as task performance, reaction time, and perceptual accuracy, alongside cognitive disruption measured by eye movements and subjective confusion. If an attack rated 'low' on DAF's information model produces severe behavioral disruption, or a 'high' attack produces none, the framework's quantitative mapping fails. More specifically, if covert degradation attacks that reduce signal $S$ do not reduce users' ability to detect altered objects at the rate Shannon's signal-to-noise ratio predicts, the model's application to perception is not predictive.

Watch

Extended reading notes

Core claim

On the paper's own terms, the central discovery is that MR deception attacks are not an unstructured grab-bag but fall into four Borden-Kopp strategies — degradation, denial, corruption, and subversion — and that the effects of those strategies can be expressed through two quantitative lenses. First, Shannon's channel capacity $C = W \log_2(1 + S/(N_A + N_E))$ models how attacks reduce what a headset can communicate to a user: denial cuts bandwidth $W$, overt degradation adds attacker noise $N_A$, covert degradation lowers signal $S$. Second, Vitanyi's normalized information distance $D(X,Y)$ and its complement $M = 1 - D$ quantify how closely an attacker's deceptive message mimics the legitimate system message, with corruption lowering $M$ and subversion requiring $M$ to stay near 1 to avoid detection. These two models plug into a decision-making model of perception (selection, organization, interpretation), attention (selective, divided, sustained, executive), and memory, yielding DAF as a table-based assessment tool. The paper claims this is the first unified framework connecting MR security, information theory, and cognition for deception analysis.

Load-bearing premise

The load-bearing premise is that human perception and cognition can be modeled as an information channel with bandwidth, signal, and noise, so Shannon's channel capacity and Vitanyi's similarity metric meaningfully describe how deception attacks affect a user; if the human mind does not behave like such a channel, the formal models are only metaphors.

Editorial extensions

If this is right

  • Channel attacks and processing attacks can be cataloged in one ontology, so any new technical attack can be mapped onto the deception categories (Table 2).
  • DAF yields qualitative low/medium/high ratings of how each attack affects perception stages and attention types, enabling comparisons such as identifying which attacks pose the highest threat.
  • The interpretation stage of perception is the primary target of deception attacks, because false beliefs are formed through interpretation of perceived stimuli.
  • Most current technical attacks enable channel attacks rather than processing attacks, pointing future research toward technical attacks that manipulate cognition.
  • DAF is intended as a generalizable tool that can be extended to other human-computer interaction contexts, not just MR headsets.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the Shannon/Vitanyi mapping is taken literally, DAF's ratings could be operationalized as measurable quantities; but if human perception does not behave like a fixed-bandwidth channel, the quantitative veneer becomes heuristic and DAF would still work as a qualitative checklist.
  • A natural testable extension would be to pair DAF ratings with eye-tracking or reaction-time measures during controlled MR deception trials, checking whether attacks rated 'high' on attention disruption actually produce the largest attentional capture.
  • The framework's treatment of subversion as requiring repeated exposure suggests a temporal dimension — trust erosion over time — that a static information-theoretic distance cannot capture; modeling deception as a sequence of messages could sharpen the framework.
  • DAF could be applied to non-MR deceptive interfaces such as smartphones or web pages, since the same perception, attention, and memory structure applies.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. This SoK paper proposes an ontology and analysis framework for deception attacks in Mixed Reality (MR). It reviews 80 articles spanning MR security, information theory, and cognition; organizes attacks using the Borden-Kopp model into channel attacks (overt/covert degradation, denial) and processing attacks (corruption, subversion); maps technical attacks to ontology categories in Table 2; presents an information-theoretic model in Section 6 using Shannon channel capacity (Eq. 1) and a normalized difference/similarity metric (Eqs. 2-3); presents a decision-making model in Section 7; and integrates these into the MR Deception Analysis Framework (DAF) in Table 3. The paper claims five key findings and identifies five research gaps.

Significance. If the framework were fully realized, it would fill a genuine gap: no existing work unifies MR security with cognition for deception analysis, and a shared vocabulary for describing MR deception attacks is needed. The literature review is broad, the ontology is a useful organizational device, and the authors are candid in Section 9 about the lack of empirical validation and in RG5 about the need for empirical findings. The paper also provides a reproducible artifact: the analyzed article list is released on Zenodo. However, the central claim that the information-theoretic and decision-making models 'mathematically formalize' attack effects is currently overstated. The equations in Section 6 are used qualitatively, and Eq. (2) misstates the definition of K from the cited source. The contribution is therefore better characterized as a qualitative/analogical framework than as a derived mathematical model. With appropriate reframing and correction, this would be a valuable SoK; in its current form, the main claim needs revision.

major comments (3)
  1. [§6.1, Eq. (1)] Equation (1) is presented as a formal model of MR deception effects, but none of W, S, N_A, and N_E is operationally defined for a human perceptual channel, and no procedure is given for measuring or estimating these quantities from an MR system or an attack. The statements that denial reduces W, degradation raises N, and so on are qualitative monotonicity claims, not a derivation of attack impact. This is confirmed by Table 3, where the information-theoretic columns are checkmarks and the Low/Medium/High ratings are expert judgments based on the Section 8 rubrics, not outputs of Eq. (1). The abstract's claim that the model 'mathematically formalizes the effects of attacks on information communication' is therefore not supported. I recommend either reframing Section 6 as an analogical/qualitative model or providing an operationalization and a worked example that maps attack parameters to C values.
  2. [§6.3, Eqs. (2)-(3)] The paper states that K in Eq. (2) is 'the editing function applied to X and Y'. In the cited source (Li et al., IEEE Transactions on Information Theory, 50(12), 2004), K denotes Kolmogorov complexity, not an editing function. This is not a notational quibble: the normalized information distance metric's universality and metric properties rely on Kolmogorov complexity, and edit distance does not inherit them. In addition, Kolmogorov complexity is uncomputable, so Eq. (2) cannot be evaluated without specifying a computable approximation (e.g., LZ complexity), which the paper does not provide. The subsequent assertion in Section 6.3 that subversion attacks require M to remain close to 1 is not derived from Eq. (3) and appears to express an attack-design intuition rather than a consequence of the model. These issues undermine the claim that the mimicry model 'formalizes' processing attacks.
  3. [§5 and §8, Table 3] The ontology is constructed from the Borden-Kopp categories (Section 5, first paragraph), so the later findings that channel attacks target selection mechanisms and processing attacks target interpretation (KF 3 and KF 4, Table 3) are partly built into the classification rather than independently discovered. The mapping in Table 2 is also based on expert judgment via mini-Delphi, but no inter-rater reliability or independent coding validation is reported. The paper should either present these as properties of the chosen taxonomy or provide an independent validation step to support them as empirical findings. This would also address the circularity concern that the ontology predetermines several of the key findings.
minor comments (5)
  1. [Table 3] The legend of Table 3 appears to be missing the visual markers for the rating levels ('Low = , Low-Medium = ...') in the text version, making the table difficult to interpret. Please ensure the final PDF renders the markers correctly.
  2. [Figure 1 and §6.3] The model in Eq. (2) is taken from a paper with four authors (Li et al. [60]), yet Figure 1 and Section 6.3 repeatedly call it 'Vitanyi's model'. Please correct the attribution to include all authors or use 'the Li et al. similarity metric'.
  3. [§6.3] The sentence 'Thus, M must remain close to 1 as the user has a greater chance of detecting deceptions through repeated exposure' is logically confusing: high similarity should make detection harder, not easier. Please rephrase to state the intended claim, e.g., subversion attacks aim to keep M close to 1, and detection would require M to drop.
  4. [Section 8] The rubric questions produce Low/Medium/High ratings, but the paper does not describe how the ratings in Table 3 were derived from those questions. Adding a small worked example for one attack would improve reproducibility and help readers apply DAF.
  5. [Boxed findings] Several 'key findings' (notably KF 1 and KF 5) are meta-claims or aspirations rather than findings from the literature review. Consider labeling them as observations, implications, or research opportunities to avoid overclaiming.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the paper is an explicitly literature-grounded taxonomy and expert-analysis framework, and its central claims do not reduce to their own inputs by construction.

full rationale

I walked the claimed derivation chain. The ontology is explicitly built on the Borden-Kopp deception model (Section 5), and the information-theoretic and decision-making models are constructed from Shannon, Vitanyi, and cognitive psychology literature (Sections 6 and 7). DAF (Table 3) is presented as an expert-analysis integration, not as a numerical output of Equations (1)-(3). The paper's key findings, such as KF 3 and KF 4, are summaries of the taxonomy's definitions rather than empirical discoveries, but the paper does not disguise them as derived predictions; it explicitly calls for empirical validation (RG 5 and the Limitations paragraph). The only self-citations sharing an author with this paper ([17], [18], [99]) are to empirical attack papers used as examples, not as load-bearing justification for the framework; they are independent, externally testable results. Two rigor issues are present but are not circularity: Eq. (2) mislabels K as 'the editing function' when the cited source defines K as Kolmogorov complexity, and Eq. (1) is never instantiated with measurable values connecting it to Table 3. These are correctness and operationalization concerns, not cases where the derivation is equivalent to its input by definition.

Assumptions & free parameters 0 free parameters · 5 assumptions · 0 invented entities

The central claim rests on five main premises: the validity of the Borden-Kopp taxonomy for MR, the transfer of Shannon's communication model to human perception, the relevance of Vitanyi's similarity metric to deception mimicry, the acceptance of the information-processing model of cognition, and the reliability of the authors' expert mapping in Table 2. No free parameters or invented physical entities are introduced; the framework is conceptual and qualitative.

assumptions (5)
  • domain assumption The Borden-Kopp taxonomy (Degradation, Denial, Corruption, Subversion) is a valid and complete basis for categorizing MR deception attacks.
    Section 5 derives the ontology directly from Borden-Kopp [11,15,50], assuming this military information-warfare taxonomy transfers to human perceptual manipulation in MR.
  • domain assumption Shannon's channel capacity model applies to human perception of MR output, treating the headset as transmitter and human senses as receiver.
    Section 6 uses Equation 1 to model MR deception attacks, which assumes information flows from MR headset to user in a Shannon-like channel with bandwidth W, signal S, and noise N.
  • domain assumption Vitanyi's normalized information distance is an appropriate measure of how well a deceptive message mimics the true MR system message.
    Section 6 applies Equations 2 and 3 to Corruption and Subversion attacks, assuming the similarity metric captures psycholinguistic or cognitive mimicry, which is not established in the cited literature.
  • domain assumption The information processing model of cognition (sensory input, attention, perception, memory, decision-making) is an accepted description of how a user processes MR sensory stimuli.
    Section 7 builds the decision-making model entirely on this cognitive framework, citing psychology literature as background rather than empirical validation in MR settings.
  • ad hoc to paper The authors' expert judgment accurately maps technical attacks to deception ontology categories in Table 2.
    Table 2 uses a mini-Delphi process, but the specific coding decisions are presented without inter-rater reliability or a transparent decision procedure, making the mapping an unverified expert assumption.

how reviews work

0 comments
Cite this review

Pith. "Pith review of SoK: Come Together -- Unifying Security, Information Theory, and Cognition for a Mixed Reality Deception Attack Ontology & Analysis Framework." pith.science (2026). https://pith.science/paper/FHCAI7EM

@misc{pith2026250209763,
  author       = {Pith},
  title        = {Pith review of: SoK: Come Together -- Unifying Security, Information Theory, and Cognition for a Mixed Reality Deception Attack Ontology & Analysis Framework},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/FHCAI7EM}},
  note         = {Machine review of arXiv:2502.09763}
}
read the original abstract

We present a primary attack ontology and analysis framework for deception attacks in Mixed Reality (MR). This is achieved through multidisciplinary Systematization of Knowledge (SoK), integrating concepts from MR security, information theory, and cognition. While MR grows in popularity, it presents many cybersecurity challenges, particularly concerning deception attacks and their effects on humans. In this paper, we use the Borden-Kopp model of deception to develop a comprehensive ontology of MR deception attacks. Further, we derive two models to assess impact of MR deception attacks on information communication and decision-making. The first, an information-theoretic model, mathematically formalizes the effects of attacks on information communication. The second, a decision-making model, details the effects of attacks on interlaced cognitive processes. Using our ontology and models, we establish the MR Deception Analysis Framework (DAF) to assess the effects of MR deception attacks on information channels, perception, and attention. Our SoK uncovers five key findings for research and practice and identifies five research gaps to guide future work.

Figures

Figures reproduced from arXiv: 2502.09763 by the authors.

Figure 1
Figure 1. Our five-stage methodology beginning with literature review (top). Outcomes of the literature review informed [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. Mind Map of MR Deception Attacks Ontology. Channel attacks on the left. Processing attacks on the right. [PITH_FULL_IMAGE:figures/full_fig_p007_2.png] view at source ↗
Figure 3
Figure 3. MR Deception Information-Theoretic Model. Mes [PITH_FULL_IMAGE:figures/full_fig_p010_3.png] view at source ↗
Figures from the paper (1 more)
Figure 4
Figure 4. Figure 4: MR Deception Decision-Making Model. External stimuli (left) are input to cognitive processes (right). Stimuli are first processed by perception. Selective attention manages perception on relevant stimuli. Organized stimuli are stored in working memory. Interpreted stim…

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

105 extracted references · 74 canonical work pages

  1. [1]

    Redmiles

    Devon Adams, Alseny Bah, Catherine Barwulor, Nureli Musaby, Kadeem Pitkin, and Elissa M. Redmiles. Ethics emerging: the story of privacy and security perceptions in virtual reality. In Fourteenth Symposium on Usable Privacy and Security (SOUPS 2018) , pages 427–442, Baltimore, MD, August 2018. USENIX Association

  2. [2]

    Tan, and Jaime Teevan

    Eytan Adar, Desney S. Tan, and Jaime Teevan. Benevolent decep- tion in human computer interaction. In Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, CHI ’13, page 1863–1872, New York, NY , USA, 2013. Association for Computing Machinery

  3. [3]

    Vr-spy: A side- channel attack on virtual key-logging in vr headsets

    Abdullah Al Arafat, Zhishan Guo, and Amro Awad. Vr-spy: A side- channel attack on virtual key-logging in vr headsets. In 2021 IEEE Virtual Reality and 3D User Interfaces (VR), pages 564–572. IEEE, 2021

  4. [4]

    Tahir Qadri

    Syed Muhammad Ali, Zeeshan Mahmood, and Dr. Tahir Qadri. 3d view: Designing of a deception from distorted view-dependent images and explaining interaction with virtual world. Sir Syed University Research Journal of Engineering & Technology, 7(1):11, Dec. 2018

  5. [5]

    Mixed reality market to reach $456.8 billion, globally, by 2032 at 67.0% cagr: Allied market re- search

    Allied Analytics LLP. Mixed reality market to reach $456.8 billion, globally, by 2032 at 67.0% cagr: Allied market re- search. https://finance.yahoo.com/news/mixed-reality-market-reach- 456-140000614.html, 2024

  6. [6]

    Atkinson and R.M

    R.C. Atkinson and R.M. Shiffrin. Human memory: A proposed system and its control processes. volume 2 of Psychology of Learning and Motivation, pages 89–195. Academic Press, 1968

  7. [7]

    Cyber-physical security for iot networks: a comprehensive review on traditional, blockchain and arti- ficial intelligence based key-security

    Ankit Attkan and Virender Ranga. Cyber-physical security for iot networks: a comprehensive review on traditional, blockchain and arti- ficial intelligence based key-security. Complex & Intelligent Systems, 8(4):3559–3591, 2022

  8. [8]

    Baddeley

    Alan D. Baddeley. Working memory. Science, 255(5044):556–559, 1992

Show all 105 references
  1. [9]

    Baddeley

    Alan D. Baddeley. Working Memory, Thought, and Action. Oxford Psychology Series. OUP Oxford, 2007

  2. [10]

    Baddeley and Graham Hitch

    Alan D. Baddeley and Graham Hitch. Working memory. The psy- chology of learning and motivation: Advances in research and theory, 8:47–89, 1974

  3. [11]

    What is information warfare? Aerospace Power Chronicles, 1999(11):1–1, 1999

    Andrew Borden. What is information warfare? Aerospace Power Chronicles, 1999(11):1–1, 1999

  4. [12]

    Evaluating object manipu- lation interaction techniques in mixed reality: Tangible user interfaces and gesture

    Evren Bozgeyikli and Lal Lila Bozgeyikli. Evaluating object manipu- lation interaction techniques in mixed reality: Tangible user interfaces and gesture. In 2021 IEEE Virtual Reality and 3D User Interfaces (VR), pages 778–787. IEEE, 2021

  5. [13]

    Willing to be fooled: Security and autoamputation in augmented reality

    Bo Brinkman. Willing to be fooled: Security and autoamputation in augmented reality. In 2012 IEEE International Symposium on Mixed and Augmented Reality - Arts, Media, and Humanities (ISMAR-AMH), pages 89–90, 2012

  6. [14]

    Misinfor- mation in virtual reality

    James Brown, Jeremy Bailenson, and Jeffrey Hancock. Misinfor- mation in virtual reality. Journal of Online Trust and Safety , 1(5), 2023

  7. [15]

    Cutting through the tangled web: An information-theoretic perspective on information warfare

    Lachlan Brumley, Carlo Kopp, and Kevin B Korb. Cutting through the tangled web: An information-theoretic perspective on information warfare. Air Power Australia Analyses, 9(2):1, 2012

  8. [16]

    Buller and Judee K

    David B. Buller and Judee K. Burgoon. Interpersonal deception theory. Communication Theory, 6(3):203–242, 1996

  9. [17]

    Immersive virtual reality attacks and the human joystick

    Peter Casey, Ibrahim Baggili, and Ananya Yarramreddy. Immersive virtual reality attacks and the human joystick. IEEE Transactions on Dependable and Secure Computing, 18(2):550–562, 2021

  10. [18]

    Inception: Virtual space in memory space in real space – memory forensics of immersive virtual reality with the htc vive

    Peter Casey, Rebecca Lindsay-Decusati, Ibrahim Baggili, and Frank Breitinger. Inception: Virtual space in memory space in real space – memory forensics of immersive virtual reality with the htc vive. Digital Investigation, 29:S13–S21, 07 2019

  11. [19]

    Prins, S

    Ryszard Cetnarski, Alberto Betella, H. Prins, S. Kouider, and P. Ver- schure. Subliminal response priming in mixed reality: The ecological validity of a classic paradigm of perception. PRESENCE: Teleopera- tors and Virtual Environments, 23:1–17, 2014

  12. [20]

    Stealthy and practical multi-modal attacks on mixed reality tracking

    Yasra Chandio, Noman Bashir, and Fatima M Anwar. Stealthy and practical multi-modal attacks on mixed reality tracking. In 2024 IEEE International Conference on Artificial Intelligence and eXtended and Virtual Reality (AIxVR), pages 11–20. IEEE, 2024

  13. [21]

    When the user is inside the user interface: An empirical study of ui security properties in augmented reality

    Kaiming Cheng, Arkaprabha Bhattacharya, Michelle Lin, Jaewook Lee, Aroosh Kumar, Jeffery F Tian, Tadayoshi Kohno, and Franziska Roesner. When the user is inside the user interface: An empirical study of ui security properties in augmented reality. In USENIX Security Symposium, 2024

  14. [22]

    Exploring user reactions and mental models towards per- ceptual manipulation attacks in mixed reality

    Kaiming Cheng, Jeffery F Tian, Tadayoshi Kohno, and Franziska Roesner. Exploring user reactions and mental models towards per- ceptual manipulation attacks in mixed reality. In USENIX Security, volume 18, 2023

  15. [23]

    Cranford, Cleotilde Gonzalez, Palvi Aggarwal, Milind Tambe, Sarah Cooney, and Christian Lebiere

    Edward A. Cranford, Cleotilde Gonzalez, Palvi Aggarwal, Milind Tambe, Sarah Cooney, and Christian Lebiere. Towards a cognitive theory of cyber deception. Cognitive Science, 45(7):e13013, 2021

  16. [24]

    An experimental application of the delphi method to the use of experts

    Norman Dalkey and Olaf Helmer. An experimental application of the delphi method to the use of experts. Management science, 9(3):458– 467, 1963

  17. [25]

    Deceiving audio design in augmented environments : A systematic review of audio effects in augmented reality

    Esrnée Henrieke Anne de Haas and Lik-Hang Lee. Deceiving audio design in augmented environments : A systematic review of audio effects in augmented reality. In 2022 IEEE International Symposium on Mixed and Augmented Reality Adjunct (ISMAR-Adjunct), pages 36–43, 2022

  18. [26]

    Delphi procedure in core outcome set development: rating scale and consensus criteria determined outcome selection

    Dorien De Meyer, Jan Kottner, Hilde Beele, Jochen Schmitt, Toni Lange, Ann Van Hecke, Sofie Verhaeghe, and Dimitri Beeckman. Delphi procedure in core outcome set development: rating scale and consensus criteria determined outcome selection. Journal of Clinical Epidemiology, 11...

  19. [27]

    Lying in everyday life

    Bella M DePaulo, Deborah A Kashy, Susan E Kirkendol, Melissa M Wyer, and Jennifer A Epstein. Lying in everyday life. Journal of personality and social psychology, 70(5):979, 1996

  20. [28]

    Dionisio, E

    D. Dionisio, E. Granholm, W. Hillix, and W. F. Perrine. Differentia- tion of deception using pupillary responses as an index of cognitive processing. Psychophysiology, 38 2:205–11, 2001

  21. [29]

    Interactions between visual working memory and selective attention

    Paul E Downing. Interactions between visual working memory and selective attention. Psychological science, 11(6):467–473, 2000

  22. [30]

    Dunbar, Matthew L

    Norah E. Dunbar, Matthew L. Jensen, Elena Bessarabova, Judee K. Burgoon, Daniel Rex Bernard, Kylie J. Harrison, Katherine M. Kel- ley, Bradley J. Adame, and Jacqueline M. Eckstein. Empowered by persuasive deception: The effects of power and deception on domi- nance, credibilit...

  23. [31]

    The repertoire of nonverbal behavior: Categories, origins, usage, and coding

    Paul Ekman and Wallace V Friesen. The repertoire of nonverbal behavior: Categories, origins, usage, and coding. semiotica, 1(1):49– 98, 1969

  24. [32]

    Working memory capacity as executive attention

    Randall W Engle. Working memory capacity as executive attention. Current directions in psychological science, 11(1):19–23, 2002

  25. [33]

    Monique Ernst and Martin P. Paulus. Neurobiology of decision mak- ing: A selective review from a neurocognitive and clinical perspective. Biological Psychiatry, 58(8):597–604, 2005

  26. [34]

    {LocIn}: Inferring semantic location from spatial maps in mixed reality

    Habiba Farrukh, Reham Mohamed, Aniket Nare, Antonio Bianchi, and Z Berkay Celik. {LocIn}: Inferring semantic location from spatial maps in mixed reality. In32nd USENIX Security Symposium (USENIX Security 23), pages 877–894, 2023

  27. [35]

    Sok: Data privacy in virtual reality

    Gonzalo Munilla Garrido, Vivek Nair, and Dawn Song. Sok: Data privacy in virtual reality. arXiv preprint arXiv:2301.05940, 2023

  28. [36]

    Gaspar, Redona Methasani, and Maurice E

    Joseph P. Gaspar, Redona Methasani, and Maurice E. Schweitzer. Emotional intelligence and deception: A theoretical model and propo- sitions. Journal of Business Ethics, 177(3):567–584, May 2022

  29. [37]

    Gaspar and Maurice E

    Joseph P. Gaspar and Maurice E. Schweitzer. The emotion deception model: A review of deception in negotiation and the role of emotion in deception. Negotiation and Conflict Management Research, 6(3):160– 179, 2013

  30. [38]

    James J. Gibson. The ecological approach to visual perception: clas- sic edition. Psychology press, 2014

  31. [39]

    Victor A. Gombos. The cognition of deception: The role of executive processes in producing lies. Genetic, Social, and General Psychology Monographs, 132(3):197–214, 2006

  32. [40]

    Misinformation, disinfor- mation, and online propaganda

    Andrew M Guess and Benjamin A Lyons. Misinformation, disinfor- mation, and online propaganda. Social media and democracy: The state of the field, prospects for reform, 10, 2020

  33. [41]

    De Guzman, Kanchana Thilakarathna, and Aruna Senevi- ratne

    Jaybie A. De Guzman, Kanchana Thilakarathna, and Aruna Senevi- ratne. Security and privacy approaches in mixed reality. ACM Com- puting Surveys, 52(6):1–37, oct 2019

  34. [42]

    Cyber secu- rity threats and challenges in collaborative mixed-reality

    Jassim Happa, Mashhuda Glencross, and Anthony Steed. Cyber secu- rity threats and challenges in collaborative mixed-reality. Frontiers in ICT, 6, 2019

  35. [43]

    Divided Attention, pages 1–3

    Walter Herbranson. Divided Attention, pages 1–3. Springer Interna- tional Publishing, Cham, 2017

  36. [44]

    The psychology of deception

    Ray Hyman. The psychology of deception. Annual review of psychol- ogy, 40(1):133–154, 1989

  37. [45]

    The Principles of Psychology, volume 1

    William James. The Principles of Psychology, volume 1. Henry Holt and Company, New York, 1890

  38. [46]

    The psychology of deception

    Joseph Jastrow. The psychology of deception. 1900

  39. [47]

    Cognitive neuro- science of honesty and deception: a signaling framework

    Adrianna C Jenkins, Lusha Zhu, and Ming Hsu. Cognitive neuro- science of honesty and deception: a signaling framework. Current Opinion in Behavioral Sciences, 11:130–137, 2016. Computational modeling

  40. [48]

    Prospect theory: An analysis of decision under risk

    Daniel Kahneman and Amos Tversky. Prospect theory: An analysis of decision under risk. Econometrica, 47(2):263–291, 1979

  41. [49]

    Schweitzer

    Polly Kang and Maurice E. Schweitzer. Emotional deception in negotiation. Organizational Behavior and Human Decision Processes, 173:104193, 2022

  42. [50]

    Information warfare

    Carlo Kopp. Information warfare. part 1. a fundamental paradigm of infowar. Part 1. A fundamental paradigm of infowar, 4, 2000

  43. [51]

    Shannon, hypergames and information warfare

    Carlo Kopp. Shannon, hypergames and information warfare. Journal of Information Warfare, 2(2):108–118, 2003

  44. [52]

    fake news

    Carlo Kopp, Kevin B. Korb, and Bruce I. Mills. Information-theoretic models of deception: Modelling cooperation and diffusion in popula- tions exposed to "fake news". PLOS ONE, 13(11):1–35, 11 2018

  45. [53]

    How to safely augment reality: Challenges and directions

    Kiron Lebeck, Tadayoshi Kohno, and Franziska Roesner. How to safely augment reality: Challenges and directions. In Proceedings of the 17th International Workshop on Mobile Computing Systems and Applications, HotMobile ’16, page 45–50, New York, NY , USA, 2016. Association for ...

  46. [54]

    Securing augmented reality output

    Kiron Lebeck, Kimberly Ruth, Tadayoshi Kohno, and Franziska Roes- ner. Securing augmented reality output. In 2017 IEEE symposium on security and privacy (SP), pages 320–337. IEEE, 2017

  47. [55]

    Dreadful

    David Leblanc. Dreadful. https://blogs.msdn.microsoft.com/ david_leblanc/2007/08/14/dreadful/. Accessed: 2024-08-27

  48. [56]

    Using virtual reality to study food cravings

    Tracey Ledoux, Anthony S Nguyen, Christine Bakos-Block, and Patrick Bordnick. Using virtual reality to study food cravings. Ap- petite, 71:396–402, 2013

  49. [57]

    AdCube: WebVR ad fraud and practical confinement of Third-Party ads

    Hyunjoo Lee, Jiyeon Lee, Daejun Kim, Suman Jana, Insik Shin, and Sooel Son. AdCube: WebVR ad fraud and practical confinement of Third-Party ads. In 30th USENIX Security Symposium (USENIX Security 21), pages 2543–2560. USENIX Association, August 2021

  50. [58]

    Truth-default theory (tdt) a theory of human deception and deception detection

    Timothy R Levine. Truth-default theory (tdt) a theory of human deception and deception detection. Journal of Language and Social Psychology, 33(4):378–392, 2014

  51. [59]

    Timothy R. Levine. Truth-default theory and the psychology of lying and deception detection. Current Opinion in Psychology, 47:101380, 2022

  52. [60]

    Ming Li, Xin Chen, Xin Li, Bin Ma, and P.M.B. Vitanyi. The similarity metric. IEEE Transactions on Information Theory, 50(12):3250–3264, 2004

  53. [61]

    I know what you enter on gear vr

    Zhen Ling, Zupei Li, Chen Chen, Junzhou Luo, Wei Yu, and Xinwen Fu. I know what you enter on gear vr. In 2019 IEEE Conference on Communications and Network Security (CNS), pages 241–249. IEEE, 2019

  54. [62]

    Eavesdropping on controller acoustic emanation for keystroke inference attack in virtual reality

    Shiqing Luo, Anh Nguyen, Hafsa Farooq, Kun Sun, and Zhisheng Yan. Eavesdropping on controller acoustic emanation for keystroke inference attack in virtual reality. In The Network and Distributed System Security Symposium (NDSS), 2024

  55. [63]

    The breakdown of vigilance during prolonged visual search

    Norman H Mackworth. The breakdown of vigilance during prolonged visual search. Quarterly Journal of Experimental Psychology, 1(1):6– 21, 1948

  56. [64]

    Information manipulation theory

    Steven A McCornack. Information manipulation theory. Communica- tions Monographs, 59(1):1–16, 1992

  57. [65]

    No escape from reality: Security and privacy of augmented reality browsers

    Richard McPherson, Suman Jana, and Vitaly Shmatikov. No escape from reality: Security and privacy of augmented reality browsers. In Proceedings of the 24th International Conference on World Wide Web, WWW ’15, page 743–753, Republic and Canton of Geneva, CHE, 2015. Internationa...

  58. [66]

    Behavioural deception and formal models of communication

    Gregory McWhirter. Behavioural deception and formal models of communication. The British Journal for the Philosophy of Science, 67(3):757–780, 2016

  59. [67]

    Common vul- nerability scoring system

    Peter Mell, Karen Scarfone, and Sasha Romanosky. Common vul- nerability scoring system. IEEE Security & Privacy , 4(6):85–89, 2006

  60. [68]

    A taxonomy of mixed reality visual displays

    Paul Milgram and Fumio Kishino. A taxonomy of mixed reality visual displays. IEICE Trans. Information Systems, vol. E77-D, no. 12:1321–1329, 12 1994

  61. [69]

    Mitchell

    Robert W. Mitchell. The psychology of human deception. Social Research, 63(3):819–861, 1996

  62. [70]

    Mitchell

    R.W. Mitchell. Deception: Perspectives on Human and Nonhuman Deceit, chapter A Framework for Discussing Deception. SUNY series in animal behavior. State University of New York Press, 1986

  63. [71]

    Twenty years of load theory—where are we now, and where should we go next? Psychonomic bulletin & review, 23:1316–1340, 2016

    Gillian Murphy, John A Groeger, and Ciara M Greene. Twenty years of load theory—where are we now, and where should we go next? Psychonomic bulletin & review, 23:1316–1340, 2016

  64. [72]

    Exploring the privacy risks of adversarial vr game design

    Vivek Nair, Gonzalo Munilla Garrido, Dawn Song, and James O’Brien. Exploring the privacy risks of adversarial vr game design. In Proc. 24th Privacy Enhancing Tech. Symp, pages 238–256, 2023

  65. [73]

    Would you do it?: Enacting moral dilemmas in virtual reality for understanding ethical decision-making

    Evangelos Niforatos, Adam Palma, Roman Gluszny, Athanasios V our- vopoulos, and Fotis Liarokapis. Would you do it?: Enacting moral dilemmas in virtual reality for understanding ethical decision-making. In Proceedings of the 2020 CHI Conference on Human Factors in Computing Sys...

  66. [74]

    15 years of research on redirected walking in immersive virtual environments

    Niels Christian Nilsson, Tabitha Peck, Gerd Bruder, Eri Hodgson, Stefania Serafin, Mary Whitton, Frank Steinicke, and Evan Suma Rosenberg. 15 years of research on redirected walking in immersive virtual environments. IEEE computer graphics and applications , 38(2):44–56, 2018

  67. [75]

    Detecting framerate-oriented cyber attacks on user experience in virtual reality

    Blessing Odeleye, George Loukas, Ryan Heartfield, and Fotios Spyri- donis. Detecting framerate-oriented cyber attacks on user experience in virtual reality. 2021

  68. [76]

    A mini-delphi approach: An improvement on single round tech- niques

    Shi Qing Pan, Maria Vega, Alan J Vella, Brian H Archer, and GR Par- lett. A mini-delphi approach: An improvement on single round tech- niques. Progress in tourism and hospitality research , 2(1):27–39, 1996

  69. [77]

    Orienting of attention

    Michael I Posner. Orienting of attention. Quarterly journal of experi- mental psychology, 32(1):3–25, 1980

  70. [78]

    The attention system of the human brain

    Michael I Posner and Steven E Petersen. The attention system of the human brain. Annual review of neuroscience, 13(1):25–42, 1990

  71. [79]

    A brief introduction to perception

    OU Qiong. A brief introduction to perception. Studies in literature and language, 15(4):18–28, 2017

  72. [80]

    The Logic of Perception

    Irvin Rock. The Logic of Perception. MIT Press, Cambridge, 1983

  73. [81]

    Security and privacy for augmented reality systems

    Franziska Roesner, Tadayoshi Kohno, and David Molnar. Security and privacy for augmented reality systems. Commun. ACM, 57(4):88–96, apr 2014

  74. [82]

    A review on mixed reality: Current trends, challenges and prospects

    Somaiieh Rokhsaritalemi, Abolghasem Sadeghi-Niaraki, and Soo-Mi Choi. A review on mixed reality: Current trends, challenges and prospects. Applied Sciences, 10:636, 01 2020

  75. [83]

    The contribution of work- ing memory to divided attention

    Valerio Santangelo and Emiliano Macaluso. The contribution of work- ing memory to divided attention. Human Brain Mapping, 34(1):158– 175, 2013

  76. [84]

    Blended agents: Manipulation of physical objects within mixed reality environments and beyond

    Susanne Schmidt, Oscar Javier Ariza Nunez, and Frank Steinicke. Blended agents: Manipulation of physical objects within mixed reality environments and beyond. In Symposium on Spatial User Interaction, pages 1–10, 2019

  77. [85]

    A mathematical theory of communication

    Claude Elwood Shannon. A mathematical theory of communication. The Bell system technical journal, 27(3):379–423, 1948

  78. [86]

    Face-mic: inferring live speech and speaker identity via subtle facial dynamics captured by ar/vr motion sensors

    Cong Shi, Xiangyu Xu, Tianfang Zhang, Payton Walker, Yi Wu, Jian Liu, Nitesh Saxena, Yingying Chen, and Jiadi Yu. Face-mic: inferring live speech and speaker identity via subtle facial dynamics captured by ar/vr motion sensors. In Proceedings of the 27th Annual International C...

  79. [87]

    Information processing models of cognition

    Herbert A Simon. Information processing models of cognition. An- nual review of psychology, 30(1):363–396, 1979

  80. [88]

    Going through the motions: {AR/VR} keylogging from user head motions

    Carter Slocum, Yicheng Zhang, Nael Abu-Ghazaleh, and Jiasi Chen. Going through the motions: {AR/VR} keylogging from user head motions. In 32nd USENIX Security Symposium (USENIX Security 23), pages 159–174, 2023

  81. [89]

    That doesn’t go there: Attacks on shared state in Multi-User augmented reality applications

    Carter Slocum, Yicheng Zhang, Erfan Shayegani, Pedram Zaree, Nael Abu-Ghazaleh, and Jiasi Chen. That doesn’t go there: Attacks on shared state in Multi-User augmented reality applications. In 33rd USENIX Security Symposium (USENIX Security 24) , pages 2761– 2778, Philadelphia,...

  82. [90]

    Skills of divided attention

    Elizabeth Spelke, William Hirst, and Ulric Neisser. Skills of divided attention. Cognition, 4(3):215–230, 1976

  83. [91]

    Sok: Authentication in aug- mented and virtual reality

    Sophie Stephenson, Bijeeta Pal, Stephen Fan, Earlence Fernandes, Yuhang Zhao, and Rahul Chatterjee. Sok: Authentication in aug- mented and virtual reality. In 2022 IEEE Symposium on Security and Privacy (SP), pages 267–284. IEEE, 2022

  84. [92]

    The role of selective atten- tion on academic foundations: A cognitive neuroscience perspective

    Courtney Stevens and Daphne Bavelier. The role of selective atten- tion on academic foundations: A cognitive neuroscience perspective. Developmental cognitive neuroscience, 2:S30–S48, 2012

  85. [93]

    Remote keylogging attacks in multi-user vr applications

    Zihao Su, Kunlin Cai, Reuben Beeler, Lukas Dresel, Allan Garcia, Ilya Grishchenko, Yuan Tian, Christopher Kruegel, and Giovanni Vi- gna. Remote keylogging attacks in multi-user vr applications. arXiv preprint arXiv:2405.14036, 2024

  86. [94]

    Deceit and self-deception

    Robert Trivers. Deceit and self-deception. Mind the gap: Tracing the origins of human universals, pages 373–393, 2010

  87. [95]

    The dark side of perceptual manipulations in virtual reality

    Wen-Jie Tseng, Elise Bonnail, Mark McGill, Mohamed Khamis, Eric Lecolinet, Samuel Huron, and Jan Gugenheimer. The dark side of perceptual manipulations in virtual reality. In CHI Conference on Human Factors in Computing Systems. ACM, apr 2022

  88. [96]

    Injected and deliv- ered: Fabricating implicit control over actuation systems by spoofing inertial sensors

    Yazhou Tu, Zhiqiang Lin, Insup Lee, and Xiali Hei. Injected and deliv- ered: Fabricating implicit control over actuation systems by spoofing inertial sensors. In 27th USENIX security symposium (USENIX Secu- rity 18), pages 1545–1562, 2018

  89. [97]

    Judgment under uncertainty: Heuristics and biases: Biases in judgments reveal some heuristics of thinking under uncertainty

    Amos Tversky and Daniel Kahneman. Judgment under uncertainty: Heuristics and biases: Biases in judgments reveal some heuristics of thinking under uncertainty. science, 185(4157):1124–1131, 1974

  90. [98]

    Working memory capacity and sustained attention: A cognitive-energetic perspective

    Nash Unsworth and Matthew K Robison. Working memory capacity and sustained attention: A cognitive-energetic perspective. Jour- nal of Experimental Psychology: Learning, Memory, and Cognition, 46(1):77, 2020

  91. [99]

    Rise of the metaverse’s immersive virtual reality malware and the man- in-the-room attack & defenses

    Martin V ondráˇcek, Ibrahim Baggili, Peter Casey, and Mehdi Mekni. Rise of the metaverse’s immersive virtual reality malware and the man- in-the-room attack & defenses. Computers & Security, 127:102923, 2023

  92. [100]

    The dark side of augmented reality: Exploring manipulative designs in ar

    Xian Wang, Lik-Hang Lee, Carlos Bermejo Fernandez, and Pan Hui. The dark side of augmented reality: Exploring manipulative designs in ar. International Journal of Human-Computer Interaction, pages 1–16, 2023

  93. [101]

    On the cognitive processes of human perception with emotions, motivations, and attitudes

    Yingxu Wang. On the cognitive processes of human perception with emotions, motivations, and attitudes. International Journal of Cognitive Informatics and Natural Intelligence (IJCINI), 1(4):1–13, 2007

  94. [102]

    Inception attacks: Immersive hijacking in virtual reality systems

    Zhuolin Yang, Cathy Yuanchen Li, Arman Bhalla, Ben Y Zhao, and Haitao Zheng. Inception attacks: Immersive hijacking in virtual reality systems. arXiv preprint arXiv:2403.05721, 2024

  95. [103]

    Foren- sic analysis of immersive virtual reality social applications: a primary account

    Ananya Yarramreddy, Peter Gromkowski, and Ibrahim Baggili. Foren- sic analysis of immersive virtual reality social applications: a primary account. In 2018 IEEE Security and Privacy Workshops (SPW), pages 186–196. IEEE, 2018

  96. [104]

    It’s all in your head (set): Side-channel attacks on AR/VR systems

    Yicheng Zhang, Carter Slocum, Jiasi Chen, and Nael Abu-Ghazaleh. It’s all in your head (set): Side-channel attacks on AR/VR systems. In 32nd USENIX Security Symposium (USENIX Security 23), pages 3979–3996, 2023

  97. [105]

    DePaulo, and Robert Rosenthal

    Miron Zuckerman, Bella M. DePaulo, and Robert Rosenthal. Verbal and nonverbal communication of deception. volume 14 ofAdvances in Experimental Social Psychology, pages 1–59. Academic Press, 1981

Pith tools

Reviewed August 7, 2026 · model on record in the stance chip above.