REVIEW 3 major objections 6 minor 149 references
From Perception to Protection: A Developer-Centered Study of Security and Privacy Threats in Extended Reality (XR)
T0 review · 3 major / 6 minor · reviewed 2026-08-04 · deepseek-v4-flash
Pith's one-line read Professional XR developers recall very few XR-specific security threats and sensitive data types, and unfamiliar attacks are rated as significantly less important and practical.
desk verdict A well-run, novel qualitative study of XR developers with one real statistical weak spot: the pooled awareness-rating tests are confounded by attack category, so the cognitive-bias claim needs within-category analysis. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central apparatus is a threat-aware interview protocol: a curated, categorized set of nine XR-sensitive data types, seven XR-specific attack categories, four data leakage channels, and a slide deck of mitigation strategies, all drawn from top-venue literature. Awareness labels are assigned from participants' statements—whether they mentioned an attack unprompted, had considered it before, or supplied additional examples—and these labels are then compared against Likert ratings of threat importance and practicality. This protocol converts the general question of what developers know into measurable recognition before versus after demonstration, and it supplies the quantitative evidence th
What would settle it
Take a cohort of XR developers, run static and network-flow analysis on the apps they ship to enumerate collected sensitive data and protections, then compare those results with the developers' unprompted recall in a structured interview. If developers who recall few threats nevertheless ship apps with robust protections—or developers who recall many threats ship vulnerable apps—the claim that awareness is the binding constraint would fail. A simpler check: ask a fresh developer sample to free-list XR threats without any curated set; if the average rises well above 0.9 of 7 attack categories,
Extended reading notes
Core claim
The authors report that 23 professional XR developers, interviewed for about 90 minutes each, spontaneously named on average only 0.9 of 7 XR-specific attack categories and 2.1 types of XR-sensitive data from their own apps before a curated threat set was shown to them; after seeing the taxonomy they recognized 4.8 sensitive data types. Awareness shaped perception: attacks developers already knew received a higher median importance rating (7/7 versus 6/7) and higher median practicality rating (7/7 versus 5/7), with Mann-Whitney U tests significant at p < 0.001. The paper interprets this as evidence that awareness gaps and cognitive biases, not just platform defenses, are a primary bottleneck
Load-bearing premise
The study relies on developers' self-reports in a 90-minute interview as a proxy for their actual building and protection behavior, and it assumes the curated threat set broadly represents the threats XR applications really face.
Editorial extensions
If this is right
- Developer awareness and support, not just platform-level defenses, become the central lever for improving XR security and privacy; giving developers a concrete threat vocabulary should translate into more protections in actual apps.
- Threat-aware education and just-in-time tooling embedded in normal development workflows, such as IDE reminders and standardized communication channels, should raise recognition of XR-specific risks and improve the quality of developer-proposed mitigations.
- Existing mitigation strategies will see limited adoption while they sacrifice XR utility, so usable S&P solutions must preserve the immersive functionality that developers and users expect.
- Diffusion of responsibility across developers, platform providers, and users means an effective XR security framework should assign ownership for each threat category and supply practice checklists similar to those used in web or mobile security.
- Because developers are often unaware of existing policies, standards, and mitigation tools, awareness campaigns and clearer communication channels could unlock protections that are already available but underused.
Reading between the lines
- A natural next step is to measure whether awareness translates into practice: audit a sample of published XR apps' actual data collection, storage, and network flows and compare the results with developer self-reports. The paper itself lists vetting developers' real implementations as future work.
- If the awareness-gap account is right, interventions aimed only at users or policymakers will not close XR's security gap; developer-facing tooling, incentives, and ownership assignment are a necessary complement.
- The recruitment pool, which drew from LinkedIn and compensated participants, may skew toward more engaged or security-conscious developers, so the same study on a broader population could find even larger recall gaps.
- Because the demonstrated threat set was curated from recent top-venue literature and the paper acknowledges it did not exhaustively cover every XR threat, the quantitative recall figures are best interpreted as tied to the 2024-2025 threat landscape rather than as timeless baselines.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This manuscript reports a qualitative interview study with 23 professional XR developers. The study is structured around two research questions: how developers perceive emerging security and privacy (S&P) threats in XR, and how they perceive current mitigations and community support. The authors curated a taxonomy of XR-sensitive data types (Table II), XR S&P attacks (Table III), leakage channels (Table V), and mitigation tools (Table IV). Before seeing these materials, participants recalled on average only 2.1 XR-sensitive data types and 0.9 of 7 XR-specific attack categories; after prompting, they recognized 4.8 data types. The paper reports that known attacks were rated significantly more important (median 7 vs 6) and practical (median 7 vs 5) than unknown attacks, and that developers propose better mitigation for known attacks. The qualitative analysis identifies awareness gaps, misconceptions about data sensitivity and local app security, and a diffusion of responsibility, leading to recommendations for XR-specific standards, tools, and communication channels.
Significance. If the findings hold, this is a valuable and timely contribution: it is, to my knowledge, the first developer-centered, threat-aware study of XR S&P. The design has notable strengths: pre-demonstration recall is measured before exposure to the curated threat set; the labeling protocol is documented with inter-rater reliability (Cohen's Kappa 0.812 for attack awareness, 0.920 for mitigation awareness, 0.827 weighted Kappa for mitigation quality); the full interview script and codebook are in appendices; and the participant pool (23 professionals, diverse app categories and platforms) is reasonable for an interview study. The descriptive findings — that unprompted recall of XR-specific threats is low, and that developers are unaware of many existing mitigations — are credible and practically important. However, the statistical evidence for the causal-sounding claim that awareness shapes threat perception is currently undermined by the analysis design, as detailed below.
major comments (3)
- [§V.A (and §VI.A)] The Mann-Whitney U-tests in §V.A pool ratings across all 7 attack categories and all 23 participants (U=4245.5, z=-3.458, p<0.001 for importance; U=5032.5, z=-6.125, p<0.001 for practicality). This treats each participant-attack rating as independent, ignoring within-participant correlation, and — more importantly — attack category is a confounder: social attacks are widely known and rated highly important/practical, while perception and physiology attacks are less known and rated lower. The pooled test cannot distinguish 'familiarity inflates perceived importance' from 'the attacks that are well-known are also the ones developers legitimately rate higher.' Please re-run the comparison within each attack category, or use a mixed-effects model with random intercepts for participant and attack and awareness as a fixed effect, and report per-category effect sizes. The same issue applies to
- [§V.A, §VII] The language 'undermines their perceptions' (Section V.A) and 'awareness gaps ... undermine their perception' (Section VII) asserts a directional psychological effect. The data are cross-sectional and self-reported at one time point: awareness and ratings are measured together, so reverse causality (developers who consider an attack important are more likely to read about it) or a third variable (e.g., prior experience with a particular app genre) is equally plausible. Please rephrase to 'is associated with' and explicitly discuss the direction-of-causality limitation, or provide a design that manipulates awareness (e.g., comparing ratings before and after informing participants).
- [Appendix A / Abstract / Discussion] The central conclusion in the abstract and discussion is that awareness is a 'binding constraint' on XR security and that developer awareness gaps 'shape their judgments.' However, the measurements are entirely self-reported recall and stated perceptions, not observed implementation behavior. Appendix A correctly lists 'vetting developers' actual implementations for potential S&P issues' as future work, but the main text should prominently carry this caveat: low unprompted recall in a 90-minute interview does not establish that deployed XR applications lack protections, nor that developers who verbalize less awareness build less secure apps. The authors should either temper the scope claims or add complementary evidence (e.g., app inspection, platform review data, or a behavioral task).
minor comments (6)
- [§IV.A] The transition from 2.1 to 4.8 sensitive data types is described as 'significantly more,' but no inferential statistic is reported for this within-subject comparison. Please provide the test (e.g., Wilcoxon signed-rank) or replace 'significantly' with a descriptive statement.
- [§III.C] The text says 'inter-rater reliability was not calculated for the coding process' (following McDonald et al.) and then immediately reports Cohen's Kappa and weighted Kappa. This is not contradictory if the Kappas are for the labeled awareness/mitigation-quality variables only, but the juxtaposition is confusing. Please clarify in one sentence that the open-coding reliability was not computed, whereas the later labeling pass used IRR.
- [§IV.B] In the P13 quote, 'sensors available in the excess' appears to be a typo for 'access'; 'V A' should be 'VA.' Please proofread quotes and acronyms.
- [Table I] Participant IDs are inconsistently capitalized: 'p11' in Table I versus 'P11' in the text and other tables. Please standardize.
- [References] Reference [50] is incomplete: 'S. Das, C. Faklaris, J. I. Hong, and L. Dabbish. Now Foundations and Trends, 2023.' Missing title/venue details. Please fix.
- [§V.A] When reporting that '6/23 developers reported being unaware of any XR-specific attacks' and '3.7/7.0 attack categories' were not previously known, please specify whether these figures come from pre-demonstration free recall or from the post-hoc awareness labeling after the demonstration. The distinction matters for interpreting the magnitude of the awareness gap.
Circularity Check
No significant circularity: the study's measurements are anchored to externally published threat taxonomies and pre-demonstration recall, not to the authors' own derivations.
full rationale
This paper is a qualitative, interview-based empirical study rather than a formal derivation, so the main circularity patterns do not apply. The central awareness statistics (Section IV.A: '2.1 types of XR-sensitive data'; Section V.A: 'an average of only 0.9/7.0 XR-specific attack types') are collected before participants are shown the curated threat set, making them genuine recall measures relative to an externally grounded list (Tables II and III are compiled from prior literature, including [26], [55], and [14], not derived from the participants themselves). The Section V.A Mann-Whitney tests compare ratings grouped by awareness labels; although pooling ratings across attack categories may create a statistical confound (category and awareness are correlated), this is a validity concern, not a definitional circularity. No fitted parameter is renamed as a prediction, no uniqueness theorem is imported from the authors' prior work, and no ansatz is smuggled in via citation. Self-citations such as [8] (VR keylogging) and [117] (IDE reminders) are present, but they are not load-bearing for the central claim: [8] is one illustrative attack among seven, and [117] supports a recommendation. Appendix A explicitly lists 'vetting developers' actual implementations' as future work, which is an honest scope limitation rather than a circular step. The paper does not claim to derive XR threat perceptions from its own outputs; it measures them against external benchmarks. Therefore, no circular step can be exhibited, and the appropriate score is 0.
Assumptions & free parameters
assumptions (5)
- domain assumption The curated threat, data, and leakage-channel sets (Tables II-V) are broadly representative of the emerging XR S&P threat landscape.
- domain assumption Self-reported awareness and stated practices during a 90-minute interview proxy for developers' actual development behavior and app S&P posture.
- domain assumption The normative baselines used to label developer beliefs as 'misconceptions' (GDPR, CCPA, and the cited XR research) are the correct standards for XR threat handling.
- domain assumption Thematic saturation was reached at 23 participants, so additional interviews would not change the findings.
- standard math Mann-Whitney U tests are appropriate for comparing ordinal Likert ratings between aware and unaware groups; test assumptions hold.
Cite this review
Pith. "Pith review of From Perception to Protection: A Developer-Centered Study of Security and Privacy Threats in Extended Reality (XR)." pith.science (2026). https://pith.science/paper/UEYVJV3D
@misc{pith2026250906368,
author = {Pith},
title = {Pith review of: From Perception to Protection: A Developer-Centered Study of Security and Privacy Threats in Extended Reality (XR)},
year = {2026},
howpublished = {\url{https://pith.science/paper/UEYVJV3D}},
note = {Machine review of arXiv:2509.06368}
}
read the original abstract
The immersive nature of XR introduces a fundamentally different set of security and privacy (S&P) challenges due to the unprecedented user interactions and data collection that traditional paradigms struggle to mitigate. As the primary architects of XR applications, developers play a critical role in addressing novel threats. However, to effectively support developers, we must first understand how they perceive and respond to different threats. Despite the growing importance of this issue, there is a lack of in-depth, threat-aware studies that examine XR S&P from the developers' perspective. To fill this gap, we interviewed 23 professional XR developers with a focus on emerging threats in XR. Our study addresses two research questions aiming to uncover existing problems in XR development and identify actionable paths forward. By examining developers' perceptions of S&P threats, we found that: (1) XR development decisions (e.g., rich sensor data collection, user-generated content interfaces) are closely tied to and can amplify S&P threats, yet developers are often unaware of these risks, resulting in cognitive biases in threat perception; and (2) limitations in existing mitigation methods, combined with insufficient strategic, technical, and communication support, undermine developers' motivation, awareness, and ability to effectively address these threats. Based on these findings, we propose actionable and stakeholder-aware recommendations to improve XR S&P throughout the XR development process. This work represents the first effort to undertake a threat-aware, developer-centered study in the XR domain -- an area where the immersive, data-rich nature of the XR technology introduces distinctive challenges.
Figures
Reference graph
Works this paper leans on
-
[1]
Extended reality market to hit usd 519.5 bn by 2032,
Y . Shinde, “Extended reality market to hit usd 519.5 bn by 2032,” Jul
-
[2]
Thinking ahead about XR: Privacy and security in an immersive world,
J. Soroushian, “Thinking ahead about XR: Privacy and security in an immersive world,” Bipartisan Policy Center, Jul 2021. [Online]. Available: https://bipartisanpolicy.org/blog/thinking-ahead-about-xr-p rivacy-and-security-in-an-immersive-world
2021
-
[3]
What is extended reality?
D. Weinstein, “What is extended reality?” Dec 2024. [Online]. Available: https://blogs.nvidia.com/blog/what-is-extended-reality/
2024
-
[4]
Communication behavior in embodied virtual reality,
H. J. Smith and M. Neff, “Communication behavior in embodied virtual reality,” in CHI, 2018
2018
-
[5]
The eye in extended reality: A survey on gaze interaction and eye tracking in head-worn extended reality,
A. Plopski, T. Hirzle, N. Norouzi, L. Qian, G. Bruder, and T. Langlotz, “The eye in extended reality: A survey on gaze interaction and eye tracking in head-worn extended reality,” CSUR, 2022
2022
-
[6]
What is mixed reality?
M. Speicher, B. D. Hall, and M. Nebeling, “What is mixed reality?” in CHI, 2019
2019
-
[7]
Can Virtual Reality Protect Users from Keystroke Inference Attacks?
Z. Yang, Z. Sarwar, I. Hwang, R. Bhaskar, B. Y . Zhao, and H. Zheng, “Can virtual reality protect users from keystroke inference attacks?” arXiv preprint arXiv:2310.16191, 2023
work page Pith review arXiv 2023
-
[8]
Remote Keylogging Attacks in Multi-user VR Applications
Z. Su, K. Cai, R. Beeler, L. Dresel, A. Garcia, I. Grishchenko, Y . Tian, C. Kruegel, and G. Vigna, “Remote keylogging attacks in multi-user vr applications,” arXiv preprint arXiv:2405.14036, 2024
work page Pith review arXiv 2024
Show all 149 references
-
[9]
It’s all in your head (set): Side-channel attacks on{AR/VR}systems,
Y . Zhang, C. Slocum, J. Chen, and N. Abu-Ghazaleh, “It’s all in your head (set): Side-channel attacks on{AR/VR}systems,” in USENIX Security, 2023
2023
-
[10]
Exploring user reactions and mental models towards perceptual manipulation attacks in mixed reality,
K. Cheng, J. F. Tian, T. Kohno, and F. Roesner, “Exploring user reactions and mental models towards perceptual manipulation attacks in mixed reality,” in USENIX Security, 2023
2023
-
[11]
Immersive virtual reality attacks and the human joystick,
P. Casey, I. Baggili, and A. Yarramreddy, “Immersive virtual reality attacks and the human joystick,” IEEE Transactions on Dependable and Secure Computing, 2019
2019
-
[12]
The dark side of perceptual manipu- lations in virtual reality,
W.-J. Tseng, E. Bonnail, M. McGill, M. Khamis, E. Lecolinet, S. Huron, and J. Gugenheimer, “The dark side of perceptual manipu- lations in virtual reality,” in CHI, 2022
2022
-
[13]
Face-mic: inferring live speech and speaker identity via subtle facial dynamics captured by ar/vr motion sensors,
C. Shi, X. Xu, T. Zhang, P. Walker, Y . Wu, J. Liu, N. Saxena, Y . Chen, and J. Yu, “Face-mic: inferring live speech and speaker identity via subtle facial dynamics captured by ar/vr motion sensors,” in Mobicom, 2021
2021
-
[14]
Security and privacy in virtual reality: a literature survey,
A. Giaretta, “Security and privacy in virtual reality: a literature survey,” Virtual Reality, 2024
2024
-
[15]
Security and privacy approaches in mixed reality: A literature survey,
J. A. De Guzman, K. Thilakarathna, and A. Seneviratne, “Security and privacy approaches in mixed reality: A literature survey,” CSUR, 2019
2019
-
[16]
Truth in motion: The unprecedented risks and opportunities of extended reality motion data,
V . Nair, L. Rosenberg, J. F. O’Brien, and D. Song, “Truth in motion: The unprecedented risks and opportunities of extended reality motion data,” 2023
2023
-
[17]
Behavioural biometrics in virtual reality: To what extent can we identify a person based solely on how they watch 360-degree videos?
M. Wierzbowski, G. Pochwatko, P. Borkiewicz, D. Cnotkowski, M. Pabi ´s-Orzeszyna, and P. Kobyli ´nski, “Behavioural biometrics in virtual reality: To what extent can we identify a person based solely on how they watch 360-degree videos?” in ISMAR-Adjunct. IEEE, 2022
2022
-
[18]
Unique identification of 50,000+ virtual reality users from head & hand motion data,
V . Nair, W. Guo, J. Mattern, R. Wang, J. F. O’Brien, L. Rosenberg, and D. Song, “Unique identification of 50,000+ virtual reality users from head & hand motion data,” in USENIX Security, 2023
2023
-
[19]
Going through the motions:{AR/VR}keylogging from user head motions,
C. Slocum, Y . Zhang, N. Abu-Ghazaleh, and J. Chen, “Going through the motions:{AR/VR}keylogging from user head motions,” in USENIX Security, 2023
2023
-
[20]
You are not your developer, either: A research agenda for usable security and privacy research beyond end users,
Y . Acar, S. Fahl, and M. L. Mazurek, “You are not your developer, either: A research agenda for usable security and privacy research beyond end users,” SecDev, 2016
2016
-
[21]
Assessing user apprehensions about mixed reality arti- facts and applications: The mixed reality concerns (mrc) questionnaire,
C. Katins, P. W. Wo ´zniak, A. Chen, I. Tumay, L. V . T. Le, J. Uschold, and T. Kosch, “Assessing user apprehensions about mixed reality arti- facts and applications: The mixed reality concerns (mrc) questionnaire,” in CHI, 2024
2024
-
[22]
” what are they gonna do with my data?
A. SB, A. Agrawal, Y . Yao, Y . Zou, and A. Das, “” what are they gonna do with my data?”: Privacy expectations, concerns, and behaviors in virtual reality,” PETS, vol. 2025, 2025
2025
-
[23]
“those things are written by lawyers, and programmers are reading that
S. A. Horstmann, S. Domiks, M. Gutfleisch, M. Tran, Y . Acar, V . Moonsamy, and A. Naiakshina, ““those things are written by lawyers, and programmers are reading that.” mapping the communi- cation gap between software developers and privacy experts,” PETS, 2024
2024
-
[24]
How does usable security (not) end up in software products? results from a qualitative interview study,
M. Gutfleisch, J. H. Klemmer, N. Busch, Y . Acar, M. A. Sasse, and S. Fahl, “How does usable security (not) end up in software products? results from a qualitative interview study,” in IEEE S&P, 2022
2022
-
[25]
Ethics emerging: the story of privacy and security perceptions in virtual reality,
D. Adams, A. Bah, C. Barwulor, N. Musaby, K. Pitkin, and E. M. Red- miles, “Ethics emerging: the story of privacy and security perceptions in virtual reality,” in SOUPS, 2018
2018
-
[26]
Sok: Data privacy in virtual reality,
G. M. Garrido, V . Nair, and D. Song, “Sok: Data privacy in virtual reality,” arXiv preprint arXiv:2301.05940, 2023
2023 arXiv
-
[27]
Going incognito in the metaverse,
V . Nair, G. M. Garrido, and D. Song, “Going incognito in the metaverse,” arXiv preprint arXiv:2208.05604, 2022
2022 arXiv
-
[28]
{LocIn}: Inferring semantic location from spatial maps in mixed reality,
H. Farrukh, R. Mohamed, A. Nare, A. Bianchi, and Z. B. Celik, “{LocIn}: Inferring semantic location from spatial maps in mixed reality,” in USENIX Security, 2023
2023
-
[29]
Unravelling spatial privacy risks of mobile mixed reality data,
J. A. d. Guzman, A. Seneviratne, and K. Thilakarathna, “Unravelling spatial privacy risks of mobile mixed reality data,” IMWUT, 2021
2021
-
[30]
Eavesdropping on controller acoustic emanation for keystroke inference attack in virtual reality,
S. Luo, A. Nguyen, H. Farooq, K. Sun, and Z. Yan, “Eavesdropping on controller acoustic emanation for keystroke inference attack in virtual reality,” in NDSS, 2024
2024
-
[31]
Harass- ment in social virtual reality: Challenges for platform governance,
L. Blackwell, N. Ellison, N. Elliott-Deflo, and R. Schwartz, “Harass- ment in social virtual reality: Challenges for platform governance,” CSCS, 2019
2019
-
[32]
Disturbing the peace: Experiencing and mitigating emerging harassment in social virtual reality,
G. Freeman, S. Zamanifard, D. Maloney, and D. Acena, “Disturbing the peace: Experiencing and mitigating emerging harassment in social virtual reality,” CSCW, 2022
2022
-
[33]
The social engineer: An immersive virtual reality educational game to raise social engineering aware- ness,
P. Jansen and F. Fischbach, “The social engineer: An immersive virtual reality educational game to raise social engineering aware- ness,” in Extended Abstracts of the 2020 Annual Symposium on Computer-Human Interaction in Play, 2020
2020
-
[34]
” creepy towards my avatar body, creepy towards my body
K. Schulenberg, G. Freeman, L. Li, and C. Barwulor, “” creepy towards my avatar body, creepy towards my body”: How women experience and manage harassment risks in social virtual reality,” CSCW, 2023
2023
-
[35]
Understanding safety risks and safety design in social vr environments,
Q. Zheng, S. Xu, L. Wang, Y . Tang, R. C. Salvi, G. Freeman, and Y . Huang, “Understanding safety risks and safety design in social vr environments,” CSCW, 2023
2023
-
[36]
When the user is inside the user interface: An empirical study of ui security properties in augmented reality,
K. Cheng, A. Bhattacharya, M. Lin, J. Lee, A. Kumar, J. F. Tian, T. Kohno, and F. Roesner, “When the user is inside the user interface: An empirical study of ui security properties in augmented reality,” in USENIX Security, 2024
2024
-
[37]
That doesn’t go there: Attacks on shared state in{Multi- User}augmented reality applications,
C. Slocum, Y . Zhang, E. Shayegani, P. Zaree, N. Abu-Ghazaleh, and J. Chen, “That doesn’t go there: Attacks on shared state in{Multi- User}augmented reality applications,” in USENIX Security, 2024
2024
-
[38]
Deepfake in the meta- verse: Security implications for virtual gaming, meetings, and offices,
S. Tariq, A. Abuadbba, and K. Moore, “Deepfake in the meta- verse: Security implications for virtual gaming, meetings, and offices,” 14 in Proceedings of the 2nd Workshop on Security Implications of Deepfakes and Cheapfakes, 2023
2023
-
[39]
Vr-spy: A side-channel attack on virtual key-logging in vr headsets,
A. Al Arafat, Z. Guo, and A. Awad, “Vr-spy: A side-channel attack on virtual key-logging in vr headsets,” in IEEE VR, 2021
2021
-
[40]
{OVRseen}: Auditing network traffic and privacy policies in oculus {VR},
R. Trimananda, H. Le, H. Cui, J. T. Ho, A. Shuba, and A. Markopoulou, “{OVRseen}: Auditing network traffic and privacy policies in oculus {VR},” in USENIX Security, 2022
2022
-
[41]
An empirical study on oculus virtual reality applications: Security and privacy perspectives,
H. Guo, H.-N. Dai, X. Luo, Z. Zheng, G. Xu, and F. He, “An empirical study on oculus virtual reality applications: Security and privacy perspectives,” in ICSE, 2024
2024
-
[42]
Immersive technology standards for privacy, safety, and security,
Cyber XR Coalition, “Immersive technology standards for privacy, safety, and security,” Cyber XR Coalition, Tech. Rep., 2021, accessed July 22, 2025. [Online]. Available: https://cyberxr.org/wp-content/upl oads/2021/05/Immersive\ Technology\ Standards.pdf
2021
-
[43]
The metaverse and standards,
L. Rosenberg, C. Wallace, K. Pearlman, and B. Choudhary, “The metaverse and standards,” 05 2023
2023
-
[44]
Understanding security mistakes developers make: Qual- itative analysis from build it, break it, fix it,
D. V otipka, K. R. Fulton, J. Parker, M. Hou, M. L. Mazurek, and M. Hicks, “Understanding security mistakes developers make: Qual- itative analysis from build it, break it, fix it,” in USENIX Security, 2020
2020
-
[45]
Security in the software development lifecycle,
H. Assal and S. Chiasson, “Security in the software development lifecycle,” in SOUPS, 2018
2018
-
[46]
How developers talk about personal data and what it means for user privacy: A case study of a developer forum on reddit,
T. Li, E. Louie, L. Dabbish, and J. I. Hong, “How developers talk about personal data and what it means for user privacy: A case study of a developer forum on reddit,” CSCW, 2021
2021
-
[47]
Privacy champions in software teams: Understanding their motivations, strategies, and challenges,
M. Tahaei, A. Frik, and K. Vaniea, “Privacy champions in software teams: Understanding their motivations, strategies, and challenges,” in CHI, 2021
2021
-
[48]
Under- standing challenges for developers to create accurate privacy nutrition labels,
T. Li, K. Reiman, Y . Agarwal, L. F. Cranor, and J. I. Hong, “Under- standing challenges for developers to create accurate privacy nutrition labels,” in CHI, 2022
2022
-
[49]
Safety and privacy in immersive extended reality: An analysis and policy recommendations,
E. Hine, I. N. Rezende, H. Roberts, D. Wong, M. Taddeo, and L. Floridi, “Safety and privacy in immersive extended reality: An analysis and policy recommendations,” Digital Society, 2024
2024
-
[50]
S. Das, C. Faklaris, J. I. Hong, and L. A. Dabbish. Now Foundations and Trends, 2023
2023
-
[51]
Enabling developers, protecting users: Investigating harassment and safety in vr,
S. Abhinaya, A. Sabir, and A. Das, “Enabling developers, protecting users: Investigating harassment and safety in vr,” arXiv e-prints, pp. arXiv–2403, 2024
2024
-
[52]
Understanding parents’ perceptions and practices toward children’s security and privacy in virtual reality,
J. Cao, A. Das, P. Emami-Naeini et al., “Understanding parents’ perceptions and practices toward children’s security and privacy in virtual reality,” arXiv preprint arXiv:2403.06172, 2024
2024 arXiv
-
[53]
Implications of xr on privacy, security and behaviour: Insights from experts,
M. Abraham, P. Saeghe, M. Mcgill, and M. Khamis, “Implications of xr on privacy, security and behaviour: Insights from experts,” in Nordic CHI, 2022
2022
-
[54]
Is virtual reality product development different? an empirical study on vr product development practices,
S. A. Karre, N. Mathur, and Y . R. Reddy, “Is virtual reality product development different? an empirical study on vr product development practices,” in ISEC, 2019
2019
-
[55]
Intrinsic cognitive security (ics),
DARPA, “Intrinsic cognitive security (ics),” Oct 2023. [Online]. Available: https://sam.gov/opp/cfaf7a3e51fc4f62ae4120f88d52f418/vie w
2023
-
[56]
Extended privacy for extended reality: XR technology has 99 problems and privacy is several of them,
S. Pahi and C. Schroeder, “Extended privacy for extended reality: XR technology has 99 problems and privacy is several of them,” Notre Dame Journal on Emerging Technologies, apr 2023. [Online]. Available: https://ndlsjet.com/extended-privacy-for-extended-reality-x r-technology...
2023
-
[57]
Privacy leakage via unrestricted motion-position sensors in the age of virtual reality: A study of snooping typed input on virtual keyboards,
Y . Wu, C. Shi, T. Zhang, P. Walker, J. Liu, N. Saxena, and Y . Chen, “Privacy leakage via unrestricted motion-position sensors in the age of virtual reality: A study of snooping typed input on virtual keyboards,” in IEEE Security and Privacy, 2023
2023
-
[58]
Speak up, i’m listening: Extracting speech from zero-permission vr sensors,
D. Cayir, R. Mohamed, R. Lazzeretti, M. Angelini, A. Acar, M. Conti, Z. B. Celik, and S. Uluagac, “Speak up, i’m listening: Extracting speech from zero-permission vr sensors,” in NDSS, 2025
2025
-
[59]
Stealthy and practical multi- modal attacks on mixed reality tracking,
Y . Chandio, N. Bashir, and F. M. Anwar, “Stealthy and practical multi- modal attacks on mixed reality tracking,” in AIxVR. IEEE, 2024
2024
-
[60]
Facereader: Unobtrusively mining vital signs and vital sign embedded sensitive info via ar/vr motion sensors,
T. Zhang, Z. Ye, A. T. Mahdad, M. M. R. R. Akanda, C. Shi, Y . Wang, N. Saxena, and Y . Chen, “Facereader: Unobtrusively mining vital signs and vital sign embedded sensitive info via ar/vr motion sensors,” in ACM CCS, 2023
2023
-
[61]
Bpsniff: Continuously surveilling private blood pressure information in the metaverse via unrestricted inbuilt motion sensors,
Z. Ye, A. T. Mahdad, Y . Wang, C. Shi, Y . Chen, and N. Saxena, “Bpsniff: Continuously surveilling private blood pressure information in the metaverse via unrestricted inbuilt motion sensors,” in IEEE Security and Privacy, 2025
2025
-
[62]
Privacy and security in extended reality: Exploring the risks of external biometric data collection,
N. Noah and S. Das, “Privacy and security in extended reality: Exploring the risks of external biometric data collection,” Available at SSRN 4780358, 2024
2024
-
[63]
Behavr: User identification based on vr sensor data,
I. Jarin, Y . Duan, R. Trimananda, H. Cui, S. Elmalaki, and A. Markopoulou, “Behavr: User identification based on vr sensor data,” arXiv preprint arXiv:2308.07304, 2023
2023 arXiv
-
[64]
Gazeploit: Remote keystroke inference attack by gaze estimation from avatar views in vr/mr devices,
H. Wang, Z. Zhan, H. Shan, S. Dai, M. Panoff, and S. Wang, “Gazeploit: Remote keystroke inference attack by gaze estimation from avatar views in vr/mr devices,” in ACM CCS, 2024
2024
-
[65]
Novel challenges of safety, security and privacy in extended reality,
J. Gugenheimer, W.-J. Tseng, A. H. Mhaidli, J. O. Rixen, M. McGill, M. Nebeling, M. Khamis, F. Schaub, and S. Das, “Novel challenges of safety, security and privacy in extended reality,” in CHI Extended Abstracts, 2022
2022
-
[66]
Hidden reality: Caution, your hand gesture inputs in the immersive virtual world are visible to all!
S. R. K. Gopal, D. Shukla, J. D. Wheelock, and N. Saxena, “Hidden reality: Caution, your hand gesture inputs in the immersive virtual world are visible to all!” in USENIX Security, 2023
2023
-
[67]
In situ with bystanders of augmented reality glasses: Perspectives on recording and privacy- mediating technologies,
T. Denning, Z. Dehlawi, and T. Kohno, “In situ with bystanders of augmented reality glasses: Perspectives on recording and privacy- mediating technologies,” in CHI, 2014
2014
-
[68]
How to safely augment reality: Challenges and directions,
K. Lebeck, T. Kohno, and F. Roesner, “How to safely augment reality: Challenges and directions,” in Proceedings of the 17th International Workshop on Mobile Computing Systems and Applications, 2016
2016
-
[69]
Virtual reality and augmented reality security: A re- connaissance and vulnerability assessment approach,
S. Dastgerdy, “Virtual reality and augmented reality security: A re- connaissance and vulnerability assessment approach,” arXiv preprint arXiv:2407.15984, 2024
2024 arXiv
-
[70]
Secure voice input on augmented reality head- sets,
J. Shang and J. Wu, “Secure voice input on augmented reality head- sets,” IEEE Transactions on Mobile Computing, 2020
2020
-
[71]
Augmenting security and privacy in the virtual realm: An analysis of extended reality devices,
D. Cayir, A. Acar, R. Lazzeretti, M. Angelini, M. Conti, and S. Ulua- gac, “Augmenting security and privacy in the virtual realm: An analysis of extended reality devices,” IEEE Security & Privacy, 2023
2023
-
[72]
Cybersecurity and privacy challenges in extended reality: Threats, solutions, and risk mitigation strategies,
M. El-Hajj, “Cybersecurity and privacy challenges in extended reality: Threats, solutions, and risk mitigation strategies,” in Virtual Worlds. MDPI, 2024
2024
-
[73]
Memory manipulations in extended reality,
E. Bonnail, W.-J. Tseng, M. Mcgill, E. Lecolinet, S. Huron, and J. Gugenheimer, “Memory manipulations in extended reality,” in CHI, 2023
2023
-
[74]
Automated psychological therapy using immersive virtual reality for treatment of fear of heights: a single-blind, parallel-group, randomised controlled trial,
D. Freeman, P. Haselton, J. Freeman, B. Spanlang, S. Kishore, E. Al- bery, M. Denne, P. Brown, M. Slater, and A. Nickless, “Automated psychological therapy using immersive virtual reality for treatment of fear of heights: a single-blind, parallel-group, randomised controlled t...
2018
-
[75]
The coding manual for qualitative researchers,
J. Salda ˜na, “The coding manual for qualitative researchers,” 2021
2021
-
[76]
Reliability and inter- rater reliability in qualitative research: Norms and guidelines for cscw and hci practice,
N. McDonald, S. Schoenebeck, and A. Forte, “Reliability and inter- rater reliability in qualitative research: Norms and guidelines for cscw and hci practice,” CSCW, 2019
2019
-
[77]
Interrater reliability: the kappa statistic,
M. L. McHugh, “Interrater reliability: the kappa statistic,” Biochemia medica, 2012
2012
-
[78]
Gdpr and augmented reality advertising: Ensuring consumer privacy,
GDPR Advisor, “Gdpr and augmented reality advertising: Ensuring consumer privacy,” https://www.gdpr-advisor.com/gdpr-and-augment ed-reality-advertising-ensuring-consumer-privacy/, 2025
2025
-
[79]
Va publications,
U.S. Department of Veterans Affairs, “Va publications,” https://www. va.gov/vapubs/, n.d
-
[80]
Photon: The networking library for unity
E. Games, “Photon: The networking library for unity.” [Online]. Available: https://www.photonengine.com
-
[81]
European xr industry report 2025,
XR4Europe, “European xr industry report 2025,” XR4Europe, Tech. Report, May 2025. [Online]. Available: https://xr4europe.eu/w p-content/uploads/European-XR-Industry-Report-2025.pdf
2025
-
[82]
Something personal from the metaverse: goals, topics, and contextual factors of self-disclosure in commercial social vr,
P. Sykownik, D. Maloney, G. Freeman, and M. Masuch, “Something personal from the metaverse: goals, topics, and contextual factors of self-disclosure in commercial social vr,” in CHI, 2022
2022
-
[83]
Anonymity vs. famil- iarity: Self-disclosure and privacy in social virtual reality,
D. Maloney, S. Zamanifard, and G. Freeman, “Anonymity vs. famil- iarity: Self-disclosure and privacy in social virtual reality,” in VRST, 2020
2020
-
[84]
Regulation (EU) no 2016/679: General data protection regulation (GDPR),
European Parliament and Council of the European Union, “Regulation (EU) no 2016/679: General data protection regulation (GDPR),” Official Journal of the European Union, May 2016. [Online]. Available: https://eur-lex.europa.eu/eli/reg/2016/679/oj
2016
-
[85]
Guidance: Data security and privacy,
Office of the Vice Provost for Research, Lehigh University, “Guidance: Data security and privacy,” Online, 2025. [Online]. Available: https://research.lehigh.edu/policies-guidance-forms/guidanc e-data-security-and-privacy
2025
-
[86]
Research data privacy,
Office of Research Cyberinfrastructure, University of Central Florida, “Research data privacy,” Online, 2025. [Online]. Available: https://rci.research.ucf.edu/resource/research-data-privacy/ 15
2025
-
[87]
Personal and sensitive data,
Staff, Faculty of Archaeology, Leiden University, “Personal and sensitive data,” Online, 2025. [Online]. Available: https://www.staff. universiteitleiden.nl/vr/archaeology/research-data-management-in-arc haeology/personal-and-sensitive-data
2025
-
[88]
Sok: Opportunities for software-hardware-security code- sign for next generation secure computing,
D. Dangwal, M. Cowan, A. Alaghi, V . T. Lee, B. Reagen, and C. Trippel, “Sok: Opportunities for software-hardware-security code- sign for next generation secure computing,” in Proceedings of the 9th International Workshop on Hardware and Architectural Support for Security and ...
2020
-
[89]
Hardware/software cooperative design against power side- channel attacks on iot devices,
M. Yang, T. Ahmed, S. Inagaki, K. Sakiyama, Y . Li, and Y . Hara- Azumi, “Hardware/software cooperative design against power side- channel attacks on iot devices,” IEEE Internet of Things Journal, 2024
2024
-
[90]
Hardware-software co-design for side-channel protected neural net- work inference,
A. Dubey, R. Cammarota, A. Varna, R. Kumar, and A. Aysu, “Hardware-software co-design for side-channel protected neural net- work inference,” in HOST. IEEE, 2023
2023
-
[91]
AR/VR Poses New Content Moderation Challenges That Policymakers Should Address,
D. Castro, “AR/VR Poses New Content Moderation Challenges That Policymakers Should Address,” ITIF, Tech. Rep., Feb. 2022. [Online]. Available: https://itif.org/publications/2022/02/28/arvr-poses-new-con tent-moderation-challenges-policymakers-should-address
2022
-
[92]
A guideline proposal for minimizing cybersickness in vr-based serious games and applica- tions,
T. Porcino, D. Reilly, E. Clua, and D. Trevisan, “A guideline proposal for minimizing cybersickness in vr-based serious games and applica- tions,” in SeGAH. IEEE, 2022
2022
-
[93]
Am i responsible for end-user’s security? a programmer’s perspective,
C. Wijayarathna and N. A. G. Arachchilage, “Am i responsible for end-user’s security? a programmer’s perspective,” arXiv preprint arXiv:1808.01481, 2018
2018 arXiv
-
[94]
Eight lightweight usable security principles for developers,
P. L. Gorski, L. L. Iacono, and M. Smith, “Eight lightweight usable security principles for developers,” IEEE Security & Privacy, 2022
2022
-
[95]
Inclusive security and privacy,
Y . Wang, “Inclusive security and privacy,” IEEE Security & Privacy, 2018
2018
-
[96]
Shostack, Threat modeling: Designing for security
A. Shostack, Threat modeling: Designing for security. John wiley & sons, 2014
2014
-
[97]
Anduril and meta team up to transform xr for the american military,
A. Industries, “Anduril and meta team up to transform xr for the american military,” 2025, accessed: 2025-07-14. [Online]. Available: https://www.anduril.com/article/anduril-and-meta-team-up-to-transfo rm-xr-for-the-american-military/
2025
-
[98]
How augmented reality (ar) is transforming healthcare in 2025: Benefits and applications,
L. Nurture, “How augmented reality (ar) is transforming healthcare in 2025: Benefits and applications,” 2025, accessed: 2025-07-14. [Online]. Available: https://www.letsnurture.com/blog/how-augmented-reality-a r-is-transforming-healthcare-in-2025-benefits-and-applications.html
2025
-
[99]
Ethics in the software development process: from codes of conduct to ethical deliberation,
J. Gogoll, N. Zuber, S. Kacianka, T. Greger, A. Pretschner, and J. Nida- R¨umelin, “Ethics in the software development process: from codes of conduct to ethical deliberation,” Philosophy & Technology, 2021
2021
-
[100]
California consumer privacy act,
California State Legislature, “California consumer privacy act,” 2018. [Online]. Available: https://oag.ca.gov/privacy/ccpa
2018
-
[101]
NSA’s Research Directorate, “Ghidra,” https://ghidra-sre.org/, 2024
2024
-
[102]
Code analysis using .net compiler platform (roslyn) analyzers - visual studio (windows),
Mikadumont, “Code analysis using .net compiler platform (roslyn) analyzers - visual studio (windows),” 2024. [Online]. Available: https://learn.microsoft.com/en-us/visualstudio/code-quality/roslyn-ana lyzers-overview?view=vs-2022
2024
-
[103]
Arya: Operating system support for securely augmenting reality,
K. Lebeck, K. Ruth, T. Kohno, and F. Roesner, “Arya: Operating system support for securely augmenting reality,” IEEE S&P, 2018
2018
-
[104]
Developer category - meta community forums,
“Developer category - meta community forums,” https://communityfor ums.atmeta.com/category/developer, 2025, accessed: 2025-07-17
2025
-
[105]
Xr & spatial computing – nvidia developer forums,
“Xr & spatial computing – nvidia developer forums,” https://forums .developer.nvidia.com/c/omniverse/xr-spatial-computing/707, 2025, accessed: 2025-07-17
2025
-
[106]
Xr community – immersiveunity,
“Xr community – immersiveunity,” https://xrcommunity.immersiveuni ty.com/, 2025
2025
-
[107]
Awe usa 2025: The world’s #1 xr event,
“Awe usa 2025: The world’s #1 xr event,” in Augmented World Expo (AWE), 2025, immersive spatial computing expo, June 2025. [Online]. Available: https://www.awexr.com/usa-2025
2025
-
[108]
IEEE conference on virtual reality and 3d user interfaces,
“IEEE conference on virtual reality and 3d user interfaces,” in IEEE VR, 2025, 32nd annual conference held in Saint-Malo, France. [Online]. Available: https://ieeevr.org/2025/
2025
-
[109]
Building the metaverse responsibly,
Meta Platforms, Inc., “Building the metaverse responsibly,” https://ab out.fb.com/news/2021/09/building-the-metaverse-responsibly/, 2021, accessed: 2025-04-20
2021
-
[110]
The metaverse and standards,
XRSI, “The metaverse and standards,” Jul 2023. [Online]. Available: https://xrsi.org/publication/the-metaverse-and-standards
2023
-
[111]
A tale from the trenches: cognitive biases and software development,
S. Chattopadhyay, N. Nelson, A. Au, N. Morales, C. Sanchez, R. Pan- dita, and A. Sarma, “A tale from the trenches: cognitive biases and software development,” in ICSE, 2020
2020
-
[112]
Magazine
S. Magazine. (2021) The next frontier in cybersecurity: Mitigating normalcy bias. Accessed: 2025-04-16. [Online]. Available: https: //www.securitymagazine.com/articles/96934-the-next-frontier-in-cyber security-mitigating-normalcy-bias
2021
-
[113]
Android security best practices,
Google, “Android security best practices,” https://source.android.com /docs/security/best-practices, 2025, accessed: 2025-04-20
2025
-
[114]
Sp 800-123. guide to general server security,
K. A. Scarfone, W. Jansen, and M. Tracy, “Sp 800-123. guide to general server security,” 2008
2008
-
[115]
Current practices, challenges, and design implications for collaborative ar/vr application development,
V . Krauß, A. Boden, L. Oppermann, and R. Reiners, “Current practices, challenges, and design implications for collaborative ar/vr application development,” in CHI, 2021
2021
-
[116]
XR Association Releases State of the Industry Report,
XR Association, “XR Association Releases State of the Industry Report,” 2023. [Online]. Available: https://xra.org/xr-association-relea ses-state-of-the-industry-report/
2023
-
[117]
Coconut: An ide plugin for developing privacy-friendly apps,
T. Li, Y . Agarwal, and J. I. Hong, “Coconut: An ide plugin for developing privacy-friendly apps,” IMWUT, 2018
2018
-
[118]
Meta community forums,
“Meta community forums,” https://communityforums.atmeta.com/, accessed: 2025-04-20
2025
-
[119]
Bystander intervention in emergen- cies: diffusion of responsibility
J. M. Darley and B. Latan ´e, “Bystander intervention in emergen- cies: diffusion of responsibility.” Journal of personality and social psychology, 1968
1968
-
[120]
Why do developers get password storage wrong? a qualitative usability study,
A. Naiakshina, A. Danilova, C. Tiefenau, M. Herzog, S. Dechand, and M. Smith, “Why do developers get password storage wrong? a qualitative usability study,” in ACM CCS, 2017
2017
-
[121]
Android permissions: User attention, comprehension, and behavior,
A. P. Felt, E. Ha, S. Egelman, A. Haney, E. Chin, and D. Wagner, “Android permissions: User attention, comprehension, and behavior,” in SOUPS, 2012
2012
-
[122]
Security and privacy for augmented reality systems,
F. Roesner, T. Kohno, and D. Molnar, “Security and privacy for augmented reality systems,” Communications of the ACM, 2014
2014
-
[123]
Apple Vision Pro Privacy Overview,
Apple Inc., “Apple Vision Pro Privacy Overview,” February 2024. [Online]. Available: https://www.apple.com/privacy/docs/Apple\ Vis ion\ Pro\ Privacy\ Overview.pdf
2024
-
[124]
Privacy is just no longer a thing in augmented reality?
M. S. Smith, “Privacy is just no longer a thing in augmented reality?” IEEE Spectrum, 2024, accessed: 2025-04-23. [Online]. Available: https://spectrum.ieee.org/apple-vision-pro-privacy
2024
-
[125]
Owasp top ten,
Open Worldwide Application Security Project (OW ASP), “Owasp top ten,” https://owasp.org/www-project-top-ten/, 2021, accessed: 2025- 04-22
2021
-
[126]
User privacy and data flow control for android apps: Systematic literature review,
Z. R. Alkindi, M. Sarrab, and N. Alzeidi, “User privacy and data flow control for android apps: Systematic literature review,”Journal of Cyber Security and Mobility, 2021
2021
-
[127]
Standar- dising a moving target: The development and evolution of iot security standards,
I. Brass, L. Tanczer, M. Carr, M. Elsden, and J. Blackstock, “Standar- dising a moving target: The development and evolution of iot security standards,” in Living in the Internet of Things: Cybersecurity of the IoT. IET, 2018
2018
-
[128]
Extended reality (xr) toward building immersive solu- tions: the key to unlocking industry 4.0,
A. Alhakamy, “Extended reality (xr) toward building immersive solu- tions: the key to unlocking industry 4.0,” ACM Computing Surveys, 2024
2024
-
[129]
A comprehensive quality evaluation of security and privacy advice on the web,
E. M. Redmiles, N. Warford, A. Jayanti, A. Koneru, S. Kross, M. Morales, R. Stevens, and M. L. Mazurek, “A comprehensive quality evaluation of security and privacy advice on the web,” in USENIX Security, 2020
2020
-
[130]
” i need a better description
R. Cummings, G. Kaptchuk, and E. M. Redmiles, “” i need a better description”: An investigation into user expectations for differential privacy,” in ACM CCS, 2021
2021
-
[131]
Immersive notification framework: Adaptive & plausible notifications in virtual reality,
A. Zenner, M. Speicher, S. Klingner, D. Degraen, F. Daiber, and A. Kr ¨uger, “Immersive notification framework: Adaptive & plausible notifications in virtual reality,” in Extended abstracts of CHI, 2018
2018
-
[132]
Challenges of moderating social virtual reality,
N. Sabri, B. Chen, A. Teoh, S. P. Dow, K. Vaccaro, and M. Elsherief, “Challenges of moderating social virtual reality,” in CHI, 2023
2023
-
[133]
Metavradar: Measuring metaverse virtual reality network activity,
M. Lyu, R. D. Tripathi, and V . Sivaraman, “Metavradar: Measuring metaverse virtual reality network activity,” POMACS, 2023
2023
-
[134]
Hand and body privacy notice,
Meta, “Hand and body privacy notice,” 2024. [Online]. Available: https://www.meta.com/help/quest/articles/accounts/privacy-informati on-and-settings/hand-tracking-privacy-notice/
2024
-
[135]
Meta quest virtual reality check (vrc) guidelines,
Meta, “Meta quest virtual reality check (vrc) guidelines,” https://deve loper.oculus.com/resources/publish-quest-req/, 2024
2024
-
[136]
Security and privacy for augmented reality: Our 10-year retrospective,
F. Roesner and T. Kohno, “Security and privacy for augmented reality: Our 10-year retrospective,” in VR4Sec: 1st International Workshop on Security for XR and XR for Security, 2021. 16 APPENDIX A. Limitations and Future Work Since our study involve demonstrations of XR risks, ...
2021
-
[138]
XR Development Background: •Q1: In your opinion, how critical is security within Extended Reality (XR) applications in 1-7 •Q2: In your opinion, how critical is privacy within Extended Reality (XR) applications in 1-7 •Q3: Which stakeholder in the XR community do you think sho...
-
[139]
Appendix: Interview Procedures and Scripts The interview was divided into three main parts, followed by a post-study feedback segment, lasting approximately 90 minutes
Demographic Questions: •Q12: Which of the following best describes you? –18-25 years old –25-35 years old –35-45 years old –45-55 years old –>55 years old •Q13: Do you speak English? –Yes –No •Q14: Level of Education –Less than a high school diploma –High school diploma –Colle...
-
[140]
Questions focused on participants’ recent XR applications and the privacy and security challenges they encountered
Part 1: Background Questions::Participants were asked to describe their background in XR development, including any training they received related to privacy and security. Questions focused on participants’ recent XR applications and the privacy and security challenges they en...
-
[141]
Q2.1Please describe any privacy threats, such as data leakage, you are aware of in XR applications
Part 2: Threats During XR Development:This subsec- tion explores privacy and security threats in XR development, focusing on sensitive data, current policies, and real-world examples of potential risks. Q2.1Please describe any privacy threats, such as data leakage, you are awa...
-
[142]
Significant performance issues/crash (reduce immer- sive experience)
-
[143]
Unexpected application behaviors
-
[144]
Allow attacks (e.g., remote code execution) - Do you usually check specifications for potential secu- rity issues before using the corresponding API? - Have you encountered any difficulties when read- ing/understanding the specifications (e.g., reading OpenXR/MRTK/Oculus speci...
-
[145]
Aimed at compromising user security, privacy, and interaction integrity in digital environments
Security attacks include any forms of digital manipu- lation and interference. Aimed at compromising user security, privacy, and interaction integrity in digital environments
-
[146]
Privacy attacks infer or extract sensitive information from users or their surroundings
-
[147]
Please describe any potential attacks that can affect secu- rity or privacy that you are aware of in XR applications (In the apps you developed/Played before)
Note: The attacks may be not limited to active attack but also the malicious contents added accidentally. Please describe any potential attacks that can affect secu- rity or privacy that you are aware of in XR applications (In the apps you developed/Played before). [Here, we d...
-
[148]
[Here, we demo some privacy and security related best practices and/or mitigations strategies
Part 3: Best Practices and Mitigations:In this subsec- tion, we demonstrate best practices and mitigation strategies for XR security and privacy, assessing their effectiveness and stakeholder responsibilities. [Here, we demo some privacy and security related best practices and...
-
[149]
Part 4: Post-Study Feedback:In this subsection, partic- ipants provide feedback on their impressions of XR security and privacy and share insights gained from the study. Q4.1Other than the discussed examples, what do you foresee as the future challenges or directions for devel...
-
[2024]
Available: https://scoop.market.us/extended-reality-m arket-news/
[Online]. Available: https://scoop.market.us/extended-reality-m arket-news/
Reviewed August 4, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.