The Dark Side of Metaverse: Unmasking the Threats from eXtended Reality (XR) Systems
This talk reveals how the seamless integration of computation, networking, and physical components in XR devices turns every layer of the system into an attack surface that non-intrusively leaks user privacy, ranging from what users type and do to what they perceive in virtual scenes.
Overview
Extended Reality (XR) devices are best understood not as conventional mobile terminals but as full-fledged cyber-physical systems. Following the NSF's characterization of CPS as engineered systems built from and depending upon the seamless integration of computation, networking, and physical components, an XR platform tightly couples a physical sensing layer that continuously measures and illuminates the user's body, a networking layer that sustains immersive rendering through behavior-dependent wireless transmission, and a computation layer that fuses these streams into real-time interactions in virtual scenes. Precisely because this integration is seamless, every layer becomes an attack surface. Physical emanations escape into the ambient environment, network traffic modulates the surrounding radio medium, and inbuilt sensors capture far more of the user than applications require, allowing adversaries to breach privacy non-intrusively without malware installation, physical constraints, or even line-of-sight access.
In this talk, I will unveil the emerging privacy threats in the Metaverse by systematically characterizing the leakage across these cyber-physical layers, and illustrate them through signal modeling, analysis, and reconstruction. Specifically, I will introduce a non-intrusive and unconstrained keystroke inference attack that exploits infrared emanations from the constellation tracking system to recover virtual keyboard inputs (NDSS'25), and a long-range, through-wall eavesdropping attack that leverages the wireless power side channel to uncover multi-level user behaviors, ranging from websites and apps to unseen in-game activities and avatar-based keystrokes, at distances of 5 to 8 meters (CCS'26). Then, I will present our recent study that pushes privacy inference beyond observable behaviors to unobservable brain-level perceptions, reconstructing EEG-correlated representations from unrestricted motion sensors to reveal what a user is perceiving inside the virtual scenes (S&P'26). Finally, I will discuss effective countermeasures and outline future directions toward trustworthy XR platforms.
Presenters
Brief Biography
Ni is an assistant professor of Computer Science in the Computer, Electrical and Mathematical Sciences and Engineering Division at KAUST. His research spans computer systems security, machine learning systems security, embodied AI security, and low-power mobile computing.
Before joining KAUST, Ni was a postdoctoral researcher at the City University of Hong Kong (CityUHK), working under the supervision of Professor Cong Wang. He earned his Ph.D. in Computer Science from CityUHK in 2024, a Master of Computing from the Australian National University in 2020, and a Bachelor of Engineering in electrical engineering from Shanghai Jiao Tong University in 2018.
Ni's dissertation research received the CityUHK's Outstanding Research Thesis Award. His work won the Springer Cybersecurity Best Practical Paper Award in 2024, and he was also recognized as a rising star at the 22nd ACM International Conference on Mobile Systems, Applications and Services.