大众的无所不知:元宇宙民主化世界创造中的新威胁
Omniscience for the Masses: New Threats in the Metaverse's Democratized World Creation
浏览论文内容
中文总结 AI 辅助
本文首次系统评估元宇宙世界创建平台的安全与隐私,提出五种利用创作者工具的攻击,可违反空间、视觉和听觉约束实现隐蔽监视,并揭示现有防护不足。
中文摘要 AI 辅助
元宇宙平台日益将其成功归功于用户生成的虚拟世界:这些自包含的社交和交互环境,可由任何普通用户创建,并扩展至数十亿次访问。Roblox、Horizon Worlds和VRChat等平台现在托管着数百万个由创作者构建的世界,这些世界控制着用户如何看到、听到并彼此互动。虽然这种模式促进了快速增长和创造力,但它从根本上将社交互动和世界行为的控制权委托给了不可信的用户。在本文中,我们首次对元宇宙世界创作者进行了系统性的安全和隐私评估。我们调查了25个支持用户创建世界的平台,并分析了它们的世界创建能力。在此分析的指导下,我们设计并实现了五种新颖的攻击,利用创作者提供的工具来违反沉浸式环境中的空间、视觉和听觉约束,从而在无需软件漏洞或开发者级权限的情况下实现隐蔽的用户监视和操纵。我们进一步表明,先前提出的五种攻击可以仅使用标准的世界创建功能来复现。最后,我们发现现有的平台审查、运行时保护和创作者政策不足以缓解恶意世界创作者行为,揭示了用户的隐私期望与世界创作者被授予的权力之间的根本不匹配。
英文摘要
Metaverse platforms increasingly derive their success from user-generated virtual worlds: self-contained social and interactive environments, which can be created by any ordinary user and scale to billions of visits. Platforms such as Roblox, Horizon Worlds, and VRChat now host millions of creator-built worlds that govern how users see, hear, and interact with one another. While this model enables rapid growth and creativity, it fundamentally delegates control over social interactions and world behavior to untrusted users. In this paper, we present the first systematic security and privacy assessment of metaverse world creators. We survey 25 platforms that support user-created worlds and analyze their world-creation capabilities. Guided by this analysis, we design and implement five novel attacks that exploit creator-provided tools to violate spatial, visual, and auditory constraints in immersive environments, enabling covert user surveillance and manipulation without software vulnerabilities or developer-level privileges. We further show that five previously-proposed attacks can be replicated using only standard world-creation features. Finally, we find that existing platform vetting, runtime protections, and creator policies are insufficient to mitigate malicious world-creator behavior, revealing a fundamental mismatch between users' privacy expectations and the powers granted to world creators.
发表机构
- CISPA Helmholtz Center for Information Security(CISPA赫尔姆霍兹信息安全中心)
- University of Illinois Chicago(伊利诺伊大学芝加哥分校)
机构由 AI 辅助整理,请以论文原文为准。