Virtual Reality (VR) techniques, serving as the bridge between the real and virtual worlds, have boomed and are widely used in manufacturing, remote healthcare, gaming, etc. Specifically, VR systems offer users immersive experiences that include both perceptions and actions. Various studies have demonstrated that attackers can manipulate VR software to influence users' interactions, including perception and actions. However, such attacks typically require strong access and specialized expertise. In this paper, we are the first to present a systematic analysis of physical attacks against VR systems and introduce False Reality, a new attack threat to VR devices without requiring access to or modification of their software. False Reality disturbs VR system services by tampering with sensor measurements, and further spoofing users' perception even inducing harmful actions, e.g., inducing dizziness or causing users to crash into obstacles, by exploiting perceptual and psychological effects. We formalize these threats through an attack pathway framework and validate three representative pathways via physical experiments and user studies on five commercial VR devices. Finally, we further propose a defense prototype to mitigate such threats. Our findings shall provide valuable insights for enhancing the security and resilience of future VR systems.
翻译:虚拟现实技术作为连接现实世界与虚拟世界的桥梁,已蓬勃发展并广泛应用于制造业、远程医疗、游戏等领域。具体而言,VR系统为用户提供包含感知与动作的沉浸式体验。已有研究表明,攻击者可操控VR软件以影响用户的交互行为(包括感知与动作)。然而此类攻击通常需要强访问权限和专业技能。本文首次系统提出针对VR系统的物理攻击分析,并介绍"虚假现实"这一新型攻击威胁——该攻击无需访问或修改VR设备软件即可实施。通过篡改传感器测量值,利用感知与心理效应干扰VR系统服务,进而欺骗用户感知甚至诱导有害行为(如引发眩晕或导致用户撞击障碍物)。我们通过攻击路径框架形式化定义这些威胁,并在五款商用VR设备上通过物理实验与用户研究验证了三条典型攻击路径。最后,我们进一步提出防御原型以缓解此类威胁。本研究将为增强未来VR系统的安全性与韧性提供重要启示。