发表机构
Kennesaw State University(肯尼索州立大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究系统化梳理了2017-2024年间65篇XR医疗保健安全与隐私文献,提出统一威胁分类和定量评分指标XR-PRISM,并指出对策评估缺失、攻击门槛低等空白,为未来研究提供路线图。
AI 中文摘要
扩展现实(XR)系统在医疗保健中的应用日益广泛,涵盖从手术规划到远程康复和心理支持等多个领域。然而,支撑这些应用的丰富传感器、生物特征、行为和环境数据流也引入了重大的隐私和安全风险。 adversaries 可能利用不安全的通信、传感器侧信道、应用层漏洞或数据处理流程来推断敏感信息或干扰临床工作流程。尽管对XR安全和隐私的兴趣日益增长,但针对医疗保健的文献仍然零散。在这项知识系统化(SoK)工作中,我们回顾了2017年至2024年间发表在XR、安全、隐私和医疗保健领域的65篇同行评审研究。我们开发了一个统一的威胁分类体系,涵盖设备、用户、网络和云层,并引入了XR-PRISM,一种用于系统表征安全和隐私风险的定量隐私与风险影响评分指标。我们的分析识别了文献中的几个空白:超过70%的拟议对策缺乏标准化风险评估,不到15%的研究攻击需要高攻击前提条件,并且由于公开可用的工件和数据集的稀缺性,可复现性受到限制。基于这些发现,我们概述了一个研究路线图,强调共享基准数据集、更强的工件发布实践、改进的云层保护以及更全面的检测、缓解和恢复机制。这项SoK为理解现有风险和指导开发更安全、保护隐私且可用的XR医疗保健系统提供了结构化和数据驱动的基础。
英文摘要
Extended reality (XR) systems are increasingly used in healthcare applications ranging from surgical planning to remote rehabilitation and mental health support. However, the rich streams of sensor, biometric, behavioral, and environmental data that enable these applications also introduce substantial privacy and security risks. Adversaries may exploit insecure communication, sensor side channels, application-layer vulnerabilities, or data-processing pipelines to infer sensitive information or disrupt clinical workflows. Despite growing interest in XR security and privacy, the healthcare-specific literature remains fragmented. In this Systematization of Knowledge (SoK), we review 65 peer-reviewed studies published between 2017 and 2024 across XR, security, privacy, and healthcare venues. We develop a unified threat taxonomy spanning device, user, network, and cloud layers and introduce XR-PRISM, a quantitative Privacy and Risk Impact Scoring Metric for systematically characterizing security and privacy risks. Our analysis identifies several gaps in the literature: more than 70% of proposed countermeasures lack standardized risk evaluation, fewer than 15% of studied attacks require high attack prerequisites, and reproducibility is limited by the scarcity of publicly released artifacts and datasets. Based on these findings, we outline a research roadmap emphasizing shared benchmark datasets, stronger artifact-release practices, improved cloud-layer protections, and more comprehensive detection, mitigation, and recovery mechanisms. This SoK provides a structured and data-driven foundation for understanding existing risks and guiding the development of more secure, privacy-preserving, and usable XR healthcare systems.
CommentsPublished in 31st ACM Symposium on Virtual Reality Software and Technology