arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.29603cs.CRcs.CVcs.MM

MoSign:面向匿名虚拟现实用户的挑战-响应运动水印认证

MoSign: Challenge-Response Motion-Watermark Authentication for Anonymous Virtual-Reality Users

Xujun Che, Thomas Carr, Depeng Xu, Aidong Lu, Shuhan Yuan

首次发表
浏览论文内容

中文总结 AI 辅助

MoSign将数字水印重构为挑战-响应认证协议,在运动通道上嵌入密钥化消息,实现匿名VR用户的可验证身份认证,同时保持不可检测性并抵御重捕获攻击。

中文摘要 AI 辅助

社交虚拟现实(VR)制造了一个悖论。用户的身体运动是一种高熵生物特征:仅凭头部和手部轨迹就能在数万名用户中以超过94%的准确率重新识别用户身份,因此对渲染的虚拟化身进行匿名化是实际必要之举。然而,用户往往仍希望在这种匿名性内向选定的一方证明自己的身份。我们提出MoSign,它将数字水印重新构想为运动通道上的挑战-响应认证协议。MoSign通过密钥流白化的高斯阴影(Gaussian-Shading)将时变密钥消息嵌入到运动变分自编码器的风格潜空间中:带水印的运动与无水印的运动在可证明意义上不可区分,因为任何检测器的优势都归结为破解伪随机函数,因此水印可与匿名化组合使用。该消息是基于纪元计数器、会话随机数和部署上下文的密钥化MAC,使MoSign具有抗重放能力,并将伪造概率限制为验证者测得的误接受率乘以对手的在线查询预算。持有密钥的验证者通过序贯检验做出决策。我们将渲染→记录→重新估计(“重捕获”)识别为现实中的VR攻击面:通用姿态估计器会剥离必然微妙的水印,但抗重捕获的密钥化读取器能够恢复水印(在投影2D通道上码字准确率高达0.96,在完整渲染到视频环路中为0.81),而没有密钥时恢复成功率仅相当于随机猜测。在HumanML3D上,MoSign在干净及大多数通道上以10⁻⁴的误接受率认证每一位合法用户,并保持不可检测性(检测AUC为0.51,随机水平为0.5);在BOXRR-23 VR数据集上,它通过真实匿名器以0.99的码字准确率携带水印,且不引入任何去匿名化侧信道。

英文摘要

Social virtual reality (VR) creates a paradox. A user's body motion is a high-entropy biometric: head and hand trajectories alone re-identify users among tens of thousands with over $94\%$ accuracy, so anonymizing the rendered avatar is a practical necessity. Yet a user often still wants to prove their identity to a chosen party from inside that anonymity. We present MoSign, which recasts digital watermarking as a challenge-response authentication protocol on the motion channel. MoSign embeds a time-varying keyed message into the style latent of a motion variational autoencoder via keystream-whitened Gaussian-Shading: watermarked motion is provably indistinguishable from watermark-free motion, since any detector's advantage reduces to breaking a pseudorandom function, so the mark composes with anonymization. The message is a keyed MAC over an epoch counter, a session nonce, and a deployment context, making MoSign replay-resistant and bounding forgery by the verifier's measured false-accept rate times the adversary's online query budget. A key-holding verifier decides with a sequential test. We identify render$\rightarrow$record$\rightarrow$re-estimate ("recapture") as the realistic VR attack surface: a generic pose estimator strips the necessarily subtle watermark, but a recapture-robust keyed reader recovers it (up to $0.96$ codeword accuracy on a projected-2D channel, $0.81$ through a full render-to-video loop), while without the key recovery stays at chance. On HumanML3D, MoSign authenticates every legitimate user at a false-accept rate of $10^{-4}$ on clean and most channels and stays undetectable (detection AUC $0.51$, chance $0.5$); on the BOXRR-23 VR dataset it carries the mark through a real anonymizer at $0.99$ codeword accuracy and adds no de-anonymization side channel.

发表机构

  • University of North Carolina at Charlotte(北卡罗来纳大学夏洛特分校)
  • Utah State University(犹他州立大学)

机构由 AI 辅助整理,请以论文原文为准。

↑