Beyond the Headset: A Systematization of Knowledge on Extended Reality Privacy and Security in Healthcare
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "Beyond the Headset".
Elias: Extended reality (XR) systems offer transformative potential for healthcare, but they simultaneously introduce novel and poorly understood privacy and security vulnerabilities that adversaries can exploit.
Nadia: First, who's behind it and why it matters.
Paper summary: Nadia: So, we're looking at this paper titled "Beyond the Headset: A Systematization of Knowledge on Extended Reality Privacy and Security in Healthcare," and what it claims is that extended reality systems, which are used for things like surgical planning or remote rehab, have serious privacy and security holes because they create new vulnerabilities.
Elias: Exactly, Nadia; the core thesis is that adversaries can exploit unencrypted signaling, sensor side-channels, and flaws in how applications work to steal patient information or mess up medical procedures. This paper sets out to fix the problem by creating a unified threat taxonomy that covers device, network, user, and cloud layers.
Priya: From my angle as a privacy researcher, what really matters is that this survey synthesizes sixty-five peer-reviewed works from two thousand seventeen to two thousand twenty-four to give us one comprehensive view of these threats in the XR healthcare environment.
Nadia: Right, so they aren't just listing problems; they are building a framework to analyze how those problems connect across the whole system architecture. This sounds like a really useful starting point for anyone trying to secure these emerging technologies.
Elias: They introduce this quantitative evaluation frame called XR-PRISM, which is designed specifically to score security and privacy risks by explicitly folding in safety and privacy impacts alongside traditional metrics.
Priya: That quantitative approach is key because it moves beyond just saying something is risky; it gives us a measurable way to prioritize what needs fixing based on real impact.
Nadia: I'm interested in how they structured this threat mapping, since that’s where the practical exploitation details live—how cheap can an attacker get in?
Elias: They break down the XR pipeline into four concentric layers: User, Device, Network, and Cloud, which is then mapped onto the MITRE ATT andCK for ICS Matrix to describe adversary goals and methods.
Priya: That layer-based approach helps connect abstract security concepts directly to where in the system a vulnerability actually manifests.
Conclusion: Nadia: So, looking at "Beyond the Headset: A Systematization of Knowledge on Extended Reality Privacy and Security in Healthcare," what do we get from this work regarding the authors' main message?
Elias: The paper presents a systematic literature review that synthesizes sixty-five studies to create a unified threat taxonomy across all layers of XR healthcare infrastructure. This SoK is important because it brings together research scattered across different venues into one coherent map of security and privacy issues.
Priya: What I find significant is how they set up this knowledge representation mechanism, which allows researchers to see the connections between different types of threats in a structured way.
Nadia: It seems like the authors are calling for a more systematic approach to researching XR security and privacy because, as they point out, there haven't been many thorough SoKs done on this area yet.
Elias: And they conclude with a call to action for the research community to focus on these gaps identified in their survey. This suggests that the next step is moving from surveying threats to developing more targeted defenses based on this taxonomy.
Priya: The implication for the field is that it provides a necessary foundation for anyone trying to build robust healthcare XR applications by showing exactly what vulnerabilities exist across those four layers.
Nadia: If we take this paper, "Beyond the Headset: A Systematization of Knowledge on Extended Reality Privacy and Security in Healthcare," what does it practically mean for the future of patient care technology?
Elias: It means that understanding where patients' sensitive data is most vulnerable in VR or AR medical tools helps us design systems that are inherently more resilient from the start.
Priya: By focusing on safety impact with a weight of zero point three zero in their XR-PRISM framework, they emphasize that patient harm isn't just a side effect; it needs to be a primary driver in risk assessment decisions.
Nadia: So, in simple terms, the big idea here is that we need better organization so we can stop guessing where these system flaws are hiding and start defending them systematically.
Nafisa Anjum, M. Rasel Mahmud
Kennesaw State University
cs.CR, cs.HC
Submitted: 2026-09-29
Updated: 2026-09-29
Comments: Published in 31st ACM Symposium on Virtual Reality Software and Technology
Code: https://github.com/User32-blip/SoK-XR-in-Healthcare
License: http://creativecommons.org/licenses/by/4.0/
Importance score: 79/100
The gist: Extended reality (XR) systems offer transformative potential for healthcare, but they simultaneously introduce novel and poorly understood privacy and security vulnerabilities that adversaries can
Key concepts
- Systematization of Knowledge (SoK)
- A structured literature review process used to synthesize 65 academic papers on XR healthcare security and privacy. It involves mapping keywords across six specific groups to systematically identify and organize existing research, ensuring a comprehensive overview of the field.
- XR-PRISM
- A new quantitative framework designed to score security and privacy risks in XR technologies. It extends traditional metrics by explicitly weighting factors like patient safety impact (Safety Impact) and privacy concerns, providing a more holistic risk assessment than standard tools.
- Threat Taxonomy Layers
- A four-layer model used to categorize threats in XR systems: User, Device, Network, and Cloud. This structure helps researchers understand where an attack occurs—whether it targets raw sensors (Device), network traffic (Network), application logic (Cloud), or user interaction (User).
- Attack Vector Classification
- The method used to describe *how* an attack is executed, such as side-channel attacks, UI spoofing, or firmware manipulation. This classification helps map specific methods against the high-level goals of an adversary defined by the MITRE ATT&CK for ICS Matrix.
Terminology
Summary
Extended reality (XR) systems offer transformative potential for healthcare, but they simultaneously introduce novel and poorly understood privacy and security vulnerabilities that adversaries can exploit. This Systematization of Knowledge (SoK) surveys 65 peer-reviewed works published between 2017 and 2024 to synthesize a unified threat taxonomy spanning device, network, user, and cloud layers, introducing the quantitative evaluation framework XR-PRISM to rigorously assess security and privacy risks in XR healthcare technologies.
Systematization Methodology
The research employed a structured systematic literature review (SLR) process augmented by quantitative analysis to ensure an unbiased survey of security and privacy in the XR healthcare infrastructure. The methodology involved several detailed steps, as outlined in Figure 1:
-
Academic Databases: The SLR conducted searches across IEEE Xplore, ACM Digital Library, USENIX Proceedings, and PubMed.
-
Keyword Mapping: Search terms were organized into six groups—XR Modality (e.g., virtual reality), Healthcare Context (e.g., medical), Security Focus (e.g., attack or threat), Privacy Focus (e.g., PHI), Defense Mechanisms, and Quantitative Metrics—to generate targeted search queries like
virtual reality AND healthcare OR PHI AND security.
-
Screening: A threshold year of 2017 was applied, resulting in 207 records initially, which were narrowed down to 116 unique records after removing duplicates and irrelevant studies.
-
Assessment for Final Scope: Inclusion criteria focused on studies that explicitly analyze threats or propose defenses in XR environments applicable to healthcare, while exclusion criteria removed general security papers without a healthcare implication or those lacking sufficient methodological detail.
Threat Modeling and Taxonomy
The paper deconstructs the XR pipeline into four concentric layers—User, Device, Network, and Cloud—to provide a data-driven classification of threats. This structure is mapped onto the MITRE ATT&CK for ICS Matrix to organize tactics
which indicate the adversary’s high-level goals or why,
and specific methods or how.
The threat model categorizes attacks based on:
-
Architectural Layer: Identifying whether the threat exploits raw sensor streams (Device), network traffic (Network), application logic (Cloud), or what the user sees/interacts with (User).
-
Attack Vector: Describing the mechanism used, such as side-channel, network injection, UI spoofing, or firmware manipulation.
-
XR Target Component: Categorizing the specific part of the system being targeted.
Risk Assessment Framework (XR-PRISM)
To quantify and prioritize exposures, the authors introduce XR-PRISM (Privacy and Risk Impact Scoring Metric), which extends traditional metrics like CVSS and DREAD by explicitly folding in safety and privacy impacts. The framework uses a weighted sum formula:
RiskScore = LWL +V WV +AWA +Is WIs +Ip WIp + (10−C)WC.
Key risk factors are weighted according to the following parameters:
** Threat Likelihood (L)**
** System Vulnerabilities (V)**
** Attack Surface (A)**
**Safety Impact (Is)
with a weight of 0.30, reflecting patient harm. **
Privacy Impact (Ip)
Evaluation Criteria for Defenses
The evaluation of proposed defenses is structured around several criteria to assess their effectiveness and practical limitations:
-
Defense Group: Grouped into three categories—Data Obfuscation, Access Control, and Authentication—based on implementation rather than just the risk layer they address.
-
Mitigation: Describes the process of implementation (e.g., using noise or rate-limiting) and its impact on security.
-
Deployability: Assesses overhead through criteria like Trade-off (measuring latency/immersion loss), Maintenance, and Efficacy (using Attack Success Rate).
-
Stage: Classifies defenses into Prevention Defense (P), Detection Defense (D), or Recovery mechanism (R).
Key Findings and Gaps
The analysis reveals several critical gaps in current research:
-
Low Prerequisites for Most Attacks:
The majority of documented attack methods demand minimal prerequisites—most techniques score a 1 or 2 on the 'Requisite' scale.
This suggests XR systems arebroadly exposed to attacks by relatively unsophisticated adversaries.
-
Scarcity of Countermeasures: Only about 20% of total papers catalog countermeasures against the dozens of attacks surveyed, revealing a
pronounced mismatch between threat volume and mitigation effort,
particularly in network and cloud layer defenses.
Improvements for AI systems
Based on the provided scientific paper, here are specific improvements that can be made to AI systems in Extended Reality (XR) healthcare, along with what those improved systems can achieve:
-
Improved Security Through Context-Aware Threat Modeling and Risk Scoring:
-
Enhanced Privacy Preservation via Layered Defense Strategies:
-
Development of Adaptive, End-to-End Recovery Mechanisms:
Specific Improvements and System Capabilities:
-
The paper introduces the quantitative framework, XR-PRISM (Privacy and Risk Impact Scoring Metric), which moves beyond generic CVSS/DREAD scores by explicitly weighting safety impact (0.30) and privacy impact (0.20).
-
By applying this to AI systems, developers can move from reactive patching to proactive risk management based on specific threat vectors identified in the taxonomy (e.g., identifying if a motion-based attack is likely due to low prerequisite expertise but high patient safety impact).
-
The paper's four-layer architecture (User, Device, Network, Cloud) allows for targeted defense implementation:
-
AI systems can be designed with specific
gatekeeper
APIs (as suggested in Table 4) at the User Layer to enforce context-aware policies (e.g., automatically triggering a privacy manager when gaze behavior suggests sensitive data is being recorded). -
To address the
Lack of Shared Code and Reproducibility
gap, AI research should prioritize: -
The development of standardized, open benchmark suites with shared datasets for XR security testing to ensure that defenses are rigorously evaluated against a wide array of attack techniques identified in Table 3 (e.g., testing a defense against Keystroke Inference attacks using standardized motion telemetry).
-
To counter the
Predominance of Preventative over Detective and Recovery Controls
gap, AI systems must integrate: -
AI-driven anomaly detection models deployed at the Network and Cloud Layers to monitor for signs of compromise (e.g., detecting unusual network traffic patterns indicative of a Man-in-the-Middle attack) rather than relying solely on pre-emptive blocking mechanisms.
-
The framework suggests developing AI models capable of predicting control effectiveness:
-
An
Adaptive Defense Orchestrator
that uses the XR-PRISM score to dynamically adjust mitigation strategies in real-time (e.g., automatically switching from low-overhead noise addition to full video encryption if the RiskScore crosses a defined threshold).
Specific Capabilities of the Improved AI System:
The improved AI system, guided by this research, can perform the following specific functions:
-
An AI-driven risk assessor that provides a
RiskScore
(0–10) for any proposed XR healthcare application based on its threat model against the four layers. -
A real-time security monitor that detects and classifies active threats (e.g., distinguishing between an unauthorized session token theft and a simple network DoS attack).
-
An adaptive defense engine that dynamically adjusts privacy controls (like gaze data suppression or sensor rate limiting) based on the current operational risk score, ensuring a balance between high immersion/usability and necessary security/privacy guarantees for PHI.
-
A continuous learning system that incorporates findings from
Exclusion Criteria
(e.g., analyzing new attack artifacts) to continuously update the threat taxonomy and improve the efficacy of existing countermeasures over time.
Abstract
Extended reality (XR) systems are increasingly used in healthcare applications ranging from surgical planning to remote rehabilitation and mental health support. However, the rich streams of sensor, biometric, behavioral, and environmental data that enable these applications also introduce substantial privacy and security risks. Adversaries may exploit insecure communication, sensor side channels, application-layer vulnerabilities, or data-processing pipelines to infer sensitive information or disrupt clinical workflows. Despite growing interest in XR security and privacy, the healthcare-specific literature remains fragmented. In this Systematization of Knowledge (SoK), we review 65 peer-reviewed studies published between 2017 and 2024 across XR, security, privacy, and healthcare venues. We develop a unified threat taxonomy spanning device, user, network, and cloud layers and introduce XR-PRISM, a quantitative Privacy and Risk Impact Scoring Metric for systematically characterizing security and privacy risks. Our analysis identifies several gaps in the literature: more than 70% of proposed countermeasures lack standardized risk evaluation, fewer than 15% of studied attacks require high attack prerequisites, and reproducibility is limited by the scarcity of publicly released artifacts and datasets. Based on these findings, we outline a research roadmap emphasizing shared benchmark datasets, stronger artifact-release practices, improved cloud-layer protections, and more comprehensive detection, mitigation, and recovery mechanisms. This SoK provides a structured and data-driven foundation for understanding existing risks and guiding the development of more secure, privacy-preserving, and usable XR healthcare systems.
Sources
- Vibrotactile Feedback to Make Real Walking in Virtual Reality More Accessible
- Inferring Private Personal Attributes of Virtual Reality Users from Head and Hand Motion Data
- A systematic literature review on Virtual Reality and Augmented Reality in terms of privacy, authorization and data-leaks
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs