centered image

First Workshop on Enhancing Security, Privacy, and Trust in Extended Reality (XR) Systems: Call for Participation on October 30, 2025

Extended Reality (XR) is a comprehensive term that includes Augmented Reality (AR), Mixed Reality (MR), and Virtual Reality (VR). XR bridges physical and digital worlds, creating interactive, immersive experiences that merge with the real world. It offers numerous applications across education, training, manufacturing, collaborative 3D design, art, and multiplayer gaming.

Despite these benefits, XR systems introduce unique security, privacy, and trust challenges due to the intimate connection between users, their XR devices, and their immediate environments. The potential attacks can involve information flooding to induce latency and physical discomfort, injecting misleading virtual content to distract or deceive users, subverting personal area networks to create confusion, spoofing alarms, assessing user status through eye tracking, and accessing onboard cameras to gather environmental information without the user's awareness. Additionally, XR apps can access sensitive real-time inputs like eye gaze, head movement, hand gestures, and even biosignals, and users' immediate environment. These signals, while critical for immersive experiences, open up novel attack surfaces such as keystroke inference, emotional profiling, and behavioral tracking.

This workshop will explore the security, privacy, and trust challenges in XR systems, along with potential solutions. Topics of interest include, but are not limited to:

Keynote Speakers

Matthew Wilding, Program Manager of the Information Innovation Office at DARPA

Matthew Wilding

Matthew Wilding joined DARPA in 2022 to develop, execute, and transition programs in software engineering and critical system assurance.

Wilding came to DARPA from Collins Aerospace, where he managed the trusted methods group, working with Collins product groups and government research sponsors to pioneer rigorous development methods and apply them to computer-based products. He served as a company subject matter expert on formal verification, and he led the machine-checked verification of a separation kernel in the AAMP7 microprocessor’s firmware and the development of the Turnstile high-assurance network guard.

Earlier in his career, Wilding founded and led a digital vision research group, researched how to use automated theorem provers to establish hardware and software correctness, and worked as a software engineer.

Keynote: Intrinsic Cognitive Security

DARPA’s Intrinsic Cognitive Security (ICS) program is using mathematical approaches, known as formal methods, to guarantee that mixed reality (MR) system designs mitigate potential cognitive effects. MR merges real and virtual worlds in real time. Cognitive effects that have been demonstrated in virtual settings include manipulating emotion, inducing cybersickness, causing confusion or anxiety, and reducing trust in equipment. Cognitive engineering principles are applied to commercial MR systems designs, but today’s methods do not ensure that systems operate safely when facing an adversary intent on interfering with a mission.

This talk describes challenges faced by MR system developers and highlights ICS research progress.

Heather Zheng, Neubauer Professor of Computer Science, University of Chicago

Heather Zheng

Heather Zheng is the Neubauer Professor of Computer Science at University of Chicago. She received her PhD from University of Maryland, College Park. Prior to joining University of Chicago in 2017, she spent 6 years in industry labs (Bell-Labs and Microsoft Research Asia) and 12 years as a faculty at University of California at Santa Barbara. At UChicago, she co-directs the SAND Lab (Security, Algorithms, Networking and Data). She was one of MIT Technology Review’s Innovators under 35 in 2005; her research on cognitive radios was featured by MIT Technology Review as one of the 10 Emerging Technologies in 2006. More recently, her work on protecting human artists against unethical data exploration received the USENIX Internet Defense Prize, the Chicago Innovation Award, a special mention in TIME Magazine Best Inventions of 2023, and the Community Impact Award from the Concept Art Association in 2024. She is a fellow of ACM and IEEE, and has served on several editorial boards and steering committees for journals and conferences.

Keynote: The Impact of AI/ML on XR Security

The boundaries between the physical and digital (virtual) worlds are rapidly dissolving. Users are increasingly dependent on computing devices, such as extended reality (XR) systems, to engage with physical environments and one another. These devices, in turn, are becoming heavily reliant on AI/ML to enable and enhance such interactions. However, the rapid development, accessibility and adoption of AI/ML have also intensified the complexity and uncertainty of the security landscape, particularly in the dynamic between attackers and defenders. In this talk, I will present some of our recent work exploring how AI/ML is shaping security and privacy challenges within XR systems.

Invited Talks

1. Extended Reality Security for Multiple Users and for LLM-Integrated Systems

As mixed reality systems become popular, new threats to their security and privacy arise, and it is important to understand these emerging threat models and their possible defenses. In this talk, we will discuss recent and ongoing work on mixed reality security, focusing on two aspects. First, we will discuss application-level attacks arising in multi-user scenarios, where multiple users collaborate in a shared mixed reality experience. A subset of malicious users can exploit commercial mixed reality platforms to cause undesirable effects to other users. Second we will present our recent work on LLM-integrated XR systems, where we analyze emerging vulnerabilities, demonstrate proof-of-concept attacks across major XR platforms, and discuss potential mitigation strategies.

Jiasi Chen, Associate Professor of Electrical Engineering and Computer Science, University of Michigan, Ann Arbor

Jiasi Chen

Jiasi Chen is an Associate Professor of Electrical Engineering and Computer Science at the University of Michigan, Ann Arbor. She received her Ph.D. from Princeton University and her B.S. from Columbia University. Her research focus is on multimedia systems, mobile computing, and extended reality and its security. Her projects typically involve mathematical optimization coupled with systems implementation. She is a recipient of an NSF CAREER award and industry gifts from Meta, Adobe, and AT&T.

Yicheng Zhang, Assistant Professor of Electrical and Computer Engineering, George Mason University

Yicheng Zhang

Yicheng Zhang is an incoming tenure-track Assistant Professor in the Department of Electrical and Computer Engineering at George Mason University (GMU). He is completing his Ph.D. in Electrical and Computer Engineering at the University of California, Riverside, advised by Prof. Nael Abu-Ghazaleh. He also holds an M.S. in Computer Engineering from the University of California, Irvine, and a B.S. in Electrical Engineering from Sichuan University. His research focuses on system and architecture security, with particular expertise in augmented reality and virtual reality (AR/VR) security, GPU/FPGA side-channel attacks, and secure system design. His work has been published at leading conferences and journals, including USENIX Security, IEEE Symposium on Security and Privacy, IEEE DSN, IEEE TIFS, and IEEE ISMAR. He actively contributes to the academic community by serving on program committees and reviewing for major security venues. He has received multiple recognitions for his research, including the UCR Dissertation Completion Fellowship Award in 2025. His work has also been featured by media outlets such as UCR News, ZME Science, Tech Xplore, and Analytics Insight.

2. Privacy Issues in Extended Reality Systems: Past, Present, and Future

Extended Reality (XR) technology has become integral to critical sectors such as healthcare, military, and education. Despite its benefits, XR devices necessitate the continuous collection of vast personal data streams—including body movements, eye tracking, and environmental scans—to facilitate interactive experiences. This data collection raises significant security and privacy concerns. In this presentation, I will begin by outlining the threat model inherent in XR environments and highlight the privacy issues identified in recent academic research. I will discuss my recent work on XR privacy, such as deducing the 360-degree videos users are viewing based on their head movement trajectories and examining privacy policy compliance issues in XR applications from major platforms. I will conclude by exploring additional potential threats within XR systems and the future intersection of XR and generative AI.

Xiaokuan Zhang, Assistant Professor of Computer Science, George Mason University

Xiaokuan Zhang

Xiaokuan Zhang is a tenure-track Assistant Professor in the Department of Computer Science at George Mason University (GMU). Before joining GMU, he spent one year working as a postdoctoral researcher at Georgia Tech. He holds a Ph.D. in Computer Science from Ohio State University. Dr. Zhang's research focuses on system security and privacy, with particular expertise in extended reality (XR) security, Web3/DeFi security, and Rust security. His work is regularly presented at leading security conferences, including ACM CCS, IEEE Security and Privacy, USENIX Security, and NDSS. He also actively contributes to the academic community by serving on the program committees of these conferences. Dr. Zhang has received an ACM CCS Distinguished Paper Award, an ACM SIGSOFT Distinguished Paper Award, and two Springer Cybersecurity Awards for Best Practical Research Paper. His research has been a top 10 finalist in the NYU CSAW best applied security paper competition on three occasions. Additionally, he has received academic research awards from the Ethereum Foundation in 2023 and 2024.

3. Context Matters:  Making Socially Acceptable Play Experiences Designed for Pre-existing Public Spaces

Talk information: TBA

Evie Powell, Games Researcher and Developer, Niantic, Inc.

Evie Powell

Dr. Evie Powell is a games researcher and developer that specializes in immersive experiences and natural user interfaces. Her background includes working on natural user interfaces via the Kinect technology at Xbox (Microsoft); working on AR experiences and next-gen technology solutions to help with spinal fusion surgery at Proprio; and building delightful colocated AR experiences by leading the Pokemon Playgrounds project at Niantic.  With a unique career that spans from live saving technology to games for wellness, Dr. Powell integrates game design and UX design to create meaningful experiences that help people learn, play, and work differently. Dr. Powell graduated from The University of North Carolina at Charlotte with her Ph.D in Computer Science where her research centered on socially pervasive game experiences and context aware gaming using mobile technologies.

Program

08:00 – 08:30: Breakfast

08:30 – 08:40: Brief Opening Remarks

08:40 – 09:40: Keynote 1: Heather Zheng

9:40 – 10:10: Session 1: Privacy, Security, and DRM in XR

10:10 – 10:30: Coffee Break

10:30 – 11:00: Invited Talk 1: Jiasi Chen (Michigan)

11:00 – 11:30: Invited Talk 2: Xiaokuan Zhang (George Mason)

11:30 – 12:00: Invited Talk 3: Evie Powell (Niantic, via Zoom)

12:00 – 12:10: Lightning Presentations (9 Posters/Demos)

  1. Demo: More Than Just Compressions: Attentional Tunneling in Augmented Reality–Guided Cardiopulmonary Resuscitation

    Zhehan Qu, Tianyi Hu, Maria Gorlatova (Duke University)

  2. Validating Safety Guarantees of LSTM Models in MR Context

    Kaiming Huang (The Pennsylvania State University), Peng Wu (Northeastern University) , Mahdi Imani (Northeastern University) , Tian Lan (George Washington University), Gang Tan (The Pennsylvania State University)

  3. Demo: Evaluating Attention Vulnerabilities to Distraction with an AR Trail Making Test (AR-TMT)

    Sihun Baek, Zhehan Qu, Maria Gorlatova (Duke University)

  4. Understanding Security and Privacy Challenges in Enterprise Mixed Reality Spatial Sharing

    Mengyu Chen, Youngwook Do, Feiyu Lu, Blair MacIntyre (JPMorganChase)

  5. Demonstrating Visual Information Manipulation Attacks in Augmented Reality: A Hands-On Miniature City-Based Setup

    Yanming Xiu, Maria Gorlatova (Duke University)

  6. Demo: Investigating Immersive Attacks with REALITYCHECK

    Muhammad Shoaib, Wajih Ul Hassan (University of Virginia)

  7. Poster: Exploring Privacy Challenges in Using Volumetric Video for Educational VR

    Yu Liu (University of Southern California), Qiao Jin (North Carolina State University), Feng Qian (University of Southern California)

  8. Demo: Perception Graph for Cognitive Attack Reasoning in Augmented Reality

    Rongqian Chen (George Washington University), Shu Hong (George Washington University), Rifatul Islam (Kennesaw State University) , Mahdi Imani (Northeastern University), Gang Tan (Penn State) , Tian Lan (George Washington University)

  9. Poster: Time-Aware LSTM for Gaze Prediction in Mixed Reality Under Latency Perturbations

    Shu Hong (George Washington University) , Rongqian Chen (George Washington University), Rifatul Islam (Kennesaw State University) , Mahdi Imani (Northeastern University) , Gang Tan (Pennsylvania State University) , Tian Lan (George Washington University)

12:10 – 13:30: Lunch + Poster/Demo Session

13:30 – 14:30: Keynote 2: Matthew Wilding

14:30 – 15:00: Session 2: Threat Detection and Cognitive Security

15:00 – 15:20: Coffee Break

15:20 – 16:20: Panel

16:20 – 16:50: Session 3: User Behavior, Authentication, and Experience

16:50 – 17:00: Award Presentation & Concluding Remarks

Organizers

Technical Program Committee

Important Dates

Submission Guidelines