arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

GAZEleak:通过外部观测针对眼动追踪XR设备的密码推断攻击

GAZEleak: Passcode Inference Against Eye-tracking XR Devices Through External Observation

Hwanjo Heo, Junhee Lee, Jinwoo Kim

arXiv 2609.35040首次发表:更新:

AI 中文总结

本研究提出GAZEleak侧信道攻击,仅通过外部拍摄的头部运动视频,利用眼头运动耦合机制推断XR设备的6位密码,实验验证了受控条件下的攻击可行性,凸显了凝视交互的隐私泄露风险。

AI 中文摘要

Apple Vision Pro等混合现实头显用“凝视即指针”交互取代了触摸屏:佩戴者注视目标后通过空中捏合手势完成确认。由于显示屏位于头显内部,且眼动追踪模块与第三方软件隔离,人们普遍认为这类输入无法被旁观者观测到——这是一种针对困扰手机和笔记本电脑的“肩窥”攻击的内置防御机制。我们提出了GAZEleak,一种侧信道攻击方法,在严格的本地物理观察者威胁模型下,仅通过头部运动的外部视频即可恢复凝视驱动的输入:攻击者仅需在房间对面拍摄佩戴者,无需在设备上安装任何软件。该攻击利用了眼-头运动系统的中枢耦合机制:视线转移会伴随与目标相关的微小头部调整,这些调整会体现为亚度级的姿态变化,可通过普通消费级视频恢复。GAZEleak实现了一套基于测量的稀疏光流推断流水线,用于破解用户的6位设备密码。在由3名知晓攻击假设的作者受试者组成的正面视角初步数据集上,采用无受害者标注数据的跨人协议时,GAZEleak在56%(18个测试密码中的10个)的测试中能将真实密码列入前10个猜测结果;对于暴露程度最高的受试者,其所有密码都能被列入前10。攻击性能存在个体差异:暴露程度最低的受试者没有任何密码进入前10,但其猜测密码的中位排名为12786,而非无信息排序下预期的500000。这些结果提供了初步证据,表明在受控条件下,与凝视耦合的头部运动可能泄露密码信息,同时也推动了针对不同用户、行为和拍摄场景的更广泛评估需求。

英文摘要

Mixed-reality headsets such as Apple Vision Pro replace the touch screen with gaze-as-pointer interaction: the wearer looks at a target and confirms with an air pinch. Because the display is inside the headset and the eye tracker is walled off from third-party software, such input is widely assumed to be unobservable to bystanders---a built-in defense against the shoulder-surfing that plagues phones and laptops. We present GAZEleak, a side-channel attack that recovers gaze-driven input from external video of head motion alone, under a strictly local, physical-observer threat model: the adversary only films the wearer from across the room and installs no software on the device. The attack exploits the centrally coupled eye-head motor program: gaze shifts recruit small, target-dependent head reorientations that project into sub-degree pose changes recoverable from commodity video. GAZEleak implements a measurement-based, sparse-optical-flow inference pipeline for users' 6-digit device passcodes. On a preliminary front-view dataset from three author-subjects who were aware of the attack hypothesis, GAZEleak places the true code within the top ten guesses for 56% (10 of 18) of test codes under a cross-person protocol with no labeled victim data, and for every code of the most exposed subject. The performance is subject-dependent: no passcode from the least exposed subject reaches the top ten, although its median guessed passcode rank is 12,786 rather than 500,000 expected from an uninformative ordering. These results provide preliminary evidence that gaze-coupled head motion can expose passcode information under controlled conditions, while motivating broader evaluation across users, behaviors, and capture settings.

CommentsThe vendor requests more time to review our responsible disclosure

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑