Beyond the Headset: A Systematization of Knowledge on Extended Reality Privacy and Security in Healthcare
arXiv:2609.38281 · doi:10.1145/3756884.3766045
Abstract
Extended reality (XR) systems are increasingly used in healthcare applications ranging from surgical planning to remote rehabilitation and mental health support. However, the rich streams of sensor, biometric, behavioral, and environmental data that enable these applications also introduce substantial privacy and security risks. Adversaries may exploit insecure communication, sensor side channels, application-layer vulnerabilities, or data-processing pipelines to infer sensitive information or disrupt clinical workflows. Despite growing interest in XR security and privacy, the healthcare-specific literature remains fragmented. In this Systematization of Knowledge (SoK), we review 65 peer-reviewed studies published between 2017 and 2024 across XR, security, privacy, and healthcare venues. We develop a unified threat taxonomy spanning device, user, network, and cloud layers and introduce XR-PRISM, a quantitative Privacy and Risk Impact Scoring Metric for systematically characterizing security and privacy risks. Our analysis identifies several gaps in the literature: more than 70% of proposed countermeasures lack standardized risk evaluation, fewer than 15% of studied attacks require high attack prerequisites, and reproducibility is limited by the scarcity of publicly released artifacts and datasets. Based on these findings, we outline a research roadmap emphasizing shared benchmark datasets, stronger artifact-release practices, improved cloud-layer protections, and more comprehensive detection, mitigation, and recovery mechanisms. This SoK provides a structured and data-driven foundation for understanding existing risks and guiding the development of more secure, privacy-preserving, and usable XR healthcare systems.
Published in 31st ACM Symposium on Virtual Reality Software and Technology
References in corpus (11)
- Bias and Discrimination in AI: a cross-disciplinary perspective
- Security and Privacy Approaches in Mixed Reality: A Literature Survey
- The Dark Side of Perceptual Manipulations in Virtual Reality
- Privacy-Aware Eye Tracking Using Differential Privacy
- A privacy-preserving approach to streaming eye-tracking data
- Differential Privacy for Eye Tracking with Temporal Correlations
- Security and Privacy in Virtual Reality: A Literature Survey
- Security, Privacy and Safety Risk Assessment for Virtual Reality Learning Environment Applications
- Attack Trees for Security and Privacy in Social Virtual Reality Learning Environments
- Truth in Motion: The Unprecedented Risks and Opportunities of Extended Reality Motion Data
- Exploring Device-Oriented Video Encryption for Hierarchical Privacy Protection in AR Content Sharing