[Paper Review] SoK: Data Privacy in Virtual Reality
This Systematic Mapping Study (SoK) proposes a comprehensive taxonomy of data privacy threats and defenses in virtual reality (VR), analyzing 74 studies to classify sensitive data attributes, 34 attacks, and 35 defenses. It identifies critical privacy gaps—especially in hardware-level protections and provable privacy guarantees—and outlines key research opportunities to secure the emerging metaverse.
The adoption of virtual reality (VR) technologies has rapidly gained momentum in recent years as companies around the world begin to position the so-called "metaverse" as the next major medium for accessing and interacting with the internet. While consumers have become accustomed to a degree of data harvesting on the web, the real-time nature of data sharing in the metaverse indicates that privacy concerns are likely to be even more prevalent in the new "Web 3.0." Research into VR privacy has demonstrated that a plethora of sensitive personal information is observable by various would-be adversaries from just a few minutes of telemetry data. On the other hand, we have yet to see VR parallels for many privacy-preserving tools aimed at mitigating threats on conventional platforms. This paper aims to systematize knowledge on the landscape of VR privacy threats and countermeasures by proposing a comprehensive taxonomy of data attributes, protections, and adversaries based on the study of 68 collected publications. We complement our qualitative discussion with a statistical analysis of the risk associated with various data sources inherent to VR in consideration of the known attacks and defenses. By focusing on highlighting the clear outstanding opportunities, we hope to motivate and guide further research into this increasingly important field.
Motivation & Objective
- To systematize the landscape of VR privacy threats and countermeasures due to the rapid rise of the metaverse and pervasive data collection in VR.
- To identify a fundamental imbalance between offensive and defensive research, with few defenses deployed despite abundant attack studies.
- To propose a holistic threat, defense, and data attribute taxonomy to guide future research and industry collaboration.
- To highlight underexplored yet high-impact privacy opportunities in VR, particularly around physiological signals, hardware-level protections, and immersive stimuli.
Proposed method
- Conducted a systematic literature review of 74 publications filtered from over 1,700 sources, focusing on VR privacy threats and defenses.
- Developed a nine-class taxonomy of sensitive data attributes in VR, including biometric, spatial, and behavioral telemetry.
- Proposed a threat model categorizing 34 attacks based on data sources and adversary capabilities, such as metadata and eye-tracking inference.
- Classified 35 privacy defenses, including those based on trusted execution environments (TEEs), differential privacy, and input obfuscation.
- Performed quantitative and qualitative analysis to assess privacy guarantees, usability, and performance trade-offs in existing defenses.
- Used 10 research questions to guide the synthesis and extracted 12 findings and 6 future work directions to inform next-generation VR privacy research.
Experimental results
Research questions
- RQ1What are the key data attributes in VR that pose significant privacy risks, and how are they classified in terms of sensitivity and collectibility?
- RQ2How do existing VR attacks exploit immersive interfaces and real-time telemetry to profile or identify users?
- RQ3What are the major gaps in current defense mechanisms, particularly regarding provable privacy guarantees and hardware-level protections?
- RQ4Why is there a lack of deployment of academic privacy defenses in commercial VR platforms despite their proliferation?
- RQ5What are the most promising yet under-researched privacy opportunities in VR, especially concerning physiological signals and immersive stimuli?
Key findings
- Only 17% of surveyed defense studies provided provable privacy guarantees, indicating a major gap in formal privacy assurance for VR systems.
- The most effective attacks were (A31) Metadata and (A1) MetaData, which enable both user identification and broad profiling using minimal telemetry data.
- There is a critical lack of hardware-level privacy defenses, such as firmware-level protections or trusted execution environments (TEEs), despite their potential to harden VR systems.
- No academic defense was deployed in industry, and no open-source code was found in reviewed papers, highlighting a severe disconnect between academia and industry in VR privacy.
- Defenses primarily focused on video feed data, leaving spatial and inertial telemetry—key attack vectors—underprotected and vulnerable to adversarial interference.
- Future research should prioritize protections for VR-native stimuli (e.g., audio, haptics, stereoscopic vision) and explore TEEs for GPU and client-side processing to enhance end-to-end privacy.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.