Privacy-Preserving Gaze Interaction: Reducing Re-Identification Without Degrading Utility
cs.HC, cs.CR
Submitted: 2025-11-13
Updated: 2026-09-07
Comments: 16 pages, 4 Figures, 4 Tables, Under Review
License: http://creativecommons.org/licenses/by-nc-sa/4.0/
The gist: Gaze-based interaction is emerging as a standard input modality on consumer extended-reality (XR) devices.
Terminology
Abstract
Gaze-based interaction is emerging as a standard input modality on consumer extended-reality (XR) devices. Yet each gaze input constitutes an involuntary biometric disclosure, as the same signal that selects a button can also identify the user who produced it. Reducing identity information without degrading interaction is difficult: most prior methods are validated on small datasets or optimized for only one of the two competing objectives. We introduce a dual-assessment framework that scores any real-time gaze transformation on two axes at once: interaction utility, measured through an offline gaze-interaction simulation and an operational spatial-accuracy metric, and privacy preservation, measured through the Rank-1 Identification Rate (IR) of a state-of-the-art re-identification adversary. We test the framework on 23 conditions: one raw baseline and 22 privacy variants from eight lightweight signal-processing families using two publicly available datasets (GazeBase and GazeBaseVR). Deterministic operators produce no significant change in identity on either dataset, because a subject-invariant mapping preserves the relative geometry a biometric embedding exploits. Identity drops sharply only when identity-uncorrelated randomness is injected per sample. Smoothing applied afterwards to recover signal quality partially restores identifiability on both datasets. The best-balanced configuration reduces the Rank-1 IR by 64.3 percentage points on GazeBase and 67.9 points on GazeBaseVR, while leaving target-selection success essentially unchanged on both datasets. Privacy-preserving gaze interaction is therefore not zero-sum. However, the reduction in identifiability is achieved by injecting randomness rather than by improving signal fidelity.
Sources
- Establishing a Baseline for Gaze-driven Authentication Performance in VR: A Breadth-First Investigation on a Very Large Dataset
- Privacy Enhancement for Gaze Data Using a Noise-Infused Autoencoder
- Adam: A Method for Stochastic Optimization
Related papers
- EduGage: A Multimodal Dataset and Benchmark for Sensor-Based Momentary Assessment of Engagement in Self-Guided Video Learning
- EvoDesign: Agentic Editable Diagram Creation via Design Expertise Evolution
- HAGI++: Head-Assisted Gaze Imputation and Generation
- Linking Behaviour and Perception to Evaluate Meaningful Human Control over Partially Automated Driving
- Review of Explainable Decision Support and Adaptive Human-Machine Interfaces for Automation Transparency in Maritime Autonomous Surface Ships
- Towards Cognitive Process-Aware Proactive Writing Support