Beyond the Headset: A Systematization of Knowledge on Extended Reality Privacy and Security in Healthcare

summary

Video file (mp4)

The gist

Extended reality (XR) systems offer transformative potential for healthcare, but they simultaneously introduce novel and poorly understood privacy and security vulnerabilities that adversaries can

In short

This research surveys 65 peer-reviewed works from 2017-2024 to create a unified threat taxonomy for Extended Reality (XR) healthcare systems. It introduces XR-PRISM, a quantitative framework to score security and privacy risks across device, network, user, and cloud layers. The study reveals that most attacks require minimal prerequisites while countermeasures are scarce.

Key concepts

Systematization of Knowledge (SoK)
A structured literature review process used to synthesize 65 academic papers on XR healthcare security and privacy. It involves mapping keywords across six specific groups to systematically identify and organize existing research, ensuring a comprehensive overview of the field.
XR-PRISM
A new quantitative framework designed to score security and privacy risks in XR technologies. It extends traditional metrics by explicitly weighting factors like patient safety impact (Safety Impact) and privacy concerns, providing a more holistic risk assessment than standard tools.
Threat Taxonomy Layers
A four-layer model used to categorize threats in XR systems: User, Device, Network, and Cloud. This structure helps researchers understand where an attack occurs—whether it targets raw sensors (Device), network traffic (Network), application logic (Cloud), or user interaction (User).
Attack Vector Classification
The method used to describe *how* an attack is executed, such as side-channel attacks, UI spoofing, or firmware manipulation. This classification helps map specific methods against the high-level goals of an adversary defined by the MITRE ATT&CK for ICS Matrix.

Terminology used across episodes

This episode discusses

The paper

Beyond the Headset: A Systematization of Knowledge on Extended Reality Privacy and Security in Healthcare · Read on arXiv

Nafisa Anjum, M. Rasel Mahmud

Kennesaw State University

Extended reality (XR) systems are increasingly used in healthcare applications ranging from surgical planning to remote rehabilitation and mental health support. However, the rich streams of sensor, biometric, behavioral, and environmental data that enable these applications also introduce substantial privacy and security risks. Adversaries may exploit insecure communication, sensor side channels, application-layer vulnerabilities, or data-processing pipelines to infer sensitive information or disrupt clinical workflows. Despite growing interest in XR security and privacy, the healthcare-specific literature remains fragmented. In this Systematization of Knowledge (SoK), we review 65 peer-reviewed studies published between 2017 and 2024 across XR, security, privacy, and healthcare venues. We develop a unified threat taxonomy spanning device, user, network, and cloud layers and introduce XR-PRISM, a quantitative Privacy and Risk Impact Scoring Metric for systematically characterizing security and privacy risks. Our analysis identifies several gaps in the literature: more than 70% of proposed countermeasures lack standardized risk evaluation, fewer than 15% of studied attacks require high attack prerequisites, and reproducibility is limited by the scarcity of publicly released artifacts and datasets. Based on these findings, we outline a research roadmap emphasizing shared benchmark datasets, stronger artifact-release practices, improved cloud-layer protections, and more comprehensive detection, mitigation, and recovery mechanisms. This SoK provides a structured and data-driven foundation for understanding existing risks and guiding the development of more secure, privacy-preserving, and usable XR healthcare systems.

DOI: 10.1145/3756884.3766045

Transcript

Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.

Nadia: Today's paper: "Beyond the Headset".

Elias: Extended reality (XR) systems offer transformative potential for healthcare, but they simultaneously introduce novel and poorly understood privacy and security vulnerabilities that adversaries can exploit.

Nadia: First, who's behind it and why it matters.

Paper summary: Nadia: So, we're looking at this paper titled "Beyond the Headset: A Systematization of Knowledge on Extended Reality Privacy and Security in Healthcare," and what it claims is that extended reality systems, which are used for things like surgical planning or remote rehab, have serious privacy and security holes because they create new vulnerabilities.

Elias: Exactly, Nadia; the core thesis is that adversaries can exploit unencrypted signaling, sensor side-channels, and flaws in how applications work to steal patient information or mess up medical procedures. This paper sets out to fix the problem by creating a unified threat taxonomy that covers device, network, user, and cloud layers.

Priya: From my angle as a privacy researcher, what really matters is that this survey synthesizes sixty-five peer-reviewed works from two thousand seventeen to two thousand twenty-four to give us one comprehensive view of these threats in the XR healthcare environment.

Nadia: Right, so they aren't just listing problems; they are building a framework to analyze how those problems connect across the whole system architecture. This sounds like a really useful starting point for anyone trying to secure these emerging technologies.

Elias: They introduce this quantitative evaluation frame called XR-PRISM, which is designed specifically to score security and privacy risks by explicitly folding in safety and privacy impacts alongside traditional metrics.

Priya: That quantitative approach is key because it moves beyond just saying something is risky; it gives us a measurable way to prioritize what needs fixing based on real impact.

Nadia: I'm interested in how they structured this threat mapping, since that’s where the practical exploitation details live—how cheap can an attacker get in?

Elias: They break down the XR pipeline into four concentric layers: User, Device, Network, and Cloud, which is then mapped onto the MITRE ATT andCK for ICS Matrix to describe adversary goals and methods.

Priya: That layer-based approach helps connect abstract security concepts directly to where in the system a vulnerability actually manifests.

Conclusion: Nadia: So, looking at "Beyond the Headset: A Systematization of Knowledge on Extended Reality Privacy and Security in Healthcare," what do we get from this work regarding the authors' main message?

Elias: The paper presents a systematic literature review that synthesizes sixty-five studies to create a unified threat taxonomy across all layers of XR healthcare infrastructure. This SoK is important because it brings together research scattered across different venues into one coherent map of security and privacy issues.

Priya: What I find significant is how they set up this knowledge representation mechanism, which allows researchers to see the connections between different types of threats in a structured way.

Nadia: It seems like the authors are calling for a more systematic approach to researching XR security and privacy because, as they point out, there haven't been many thorough SoKs done on this area yet.

Elias: And they conclude with a call to action for the research community to focus on these gaps identified in their survey. This suggests that the next step is moving from surveying threats to developing more targeted defenses based on this taxonomy.

Priya: The implication for the field is that it provides a necessary foundation for anyone trying to build robust healthcare XR applications by showing exactly what vulnerabilities exist across those four layers.

Nadia: If we take this paper, "Beyond the Headset: A Systematization of Knowledge on Extended Reality Privacy and Security in Healthcare," what does it practically mean for the future of patient care technology?

Elias: It means that understanding where patients' sensitive data is most vulnerable in VR or AR medical tools helps us design systems that are inherently more resilient from the start.

Priya: By focusing on safety impact with a weight of zero point three zero in their XR-PRISM framework, they emphasize that patient harm isn't just a side effect; it needs to be a primary driver in risk assessment decisions.

Nadia: So, in simple terms, the big idea here is that we need better organization so we can stop guessing where these system flaws are hiding and start defending them systematically.

More episodes

← Home