Completed Computing & AI Mental Health

Threat Detection in XR Using Semantic and Behavioral Data

In plain English

AI plain-English summary

An XR headset that tracks your gaze, gestures, and movements could soon double as a security guard, continuously authenticating your identity and watching for cyberattacks in real time. Current cybersecurity tools for extended reality (XR) devices—such as augmented reality (AR) and virtual reality (VR) headsets—are mostly repurposed from Android smartphones. But XR hardware and user behaviour are fundamentally different: headsets capture real-world actions like hand gestures and eye movements as inputs, and overlays can be manipulated or spoofed. This leaves XR applications vulnerable to shoulder surfing, reverse engineering, and perceptual attacks that alter what a user sees. This project builds a purpose-built endpoint detection and response system that continuously analyses XR-specific data—movement, gaze, and environmental information—to provide three layers of protection: continuous authentication using anthropometric data instead of passwords; dynamic analysis to prevent tampering with XR apps; and detection of cyberattacks that manipulate virtual environments or threaten user safety. If successful, the system could secure XR use in healthcare, manufacturing, and education—sectors where the global XR market is projected to reach $77.76 billion by 2025. Without such tailored security, the rapid adoption of XR devices risks exposing sensitive applications and the workforce to new classes of cyber threats.

View original technical description
For companies developing sensitive XR applications that require safety and security, our product addresses the inadequate mobile-style authentication in XR headsets and the lack of XR-specific cybersecurity. We propose a monitoring solution that continuously analyses XR-specific-data to deliver **Endpoint detection and response**. Unlike competitors who repurpose cybersecurity solutions designed for Android smartphones (such as Guardsquare o Zimperium) our solution is purpose-built for XR devices. The increasing adoption of XR technologies is underscored by the fact that Android, the world's most popular operating system, is preparing to release its XR version. This will enable a plethora of mobile manufacturers to develop XR devices, accelerating the XR/metaverse industry. The penetration of XR technologies into healthcare, manufacturing, and education is rapidly increasing, with the global XR market expected to reach $77.76 billion by 2025\. This growth underscores the critical need for robust cybersecurity systems to safeguard these applications and protect the workforce. Companies developing XR applications require convincing security solutions tailored to XR devices. However, the cybersecurity tools used in these cases are often repurposed from mobile, but the hardware and interaction paradigms of XR devices are fundamentally different from those of mobile and smartphone devices. Cybersecurity mechanisms, such as authentication are repurposed from mobile to XR environments and are more vulnerable to exploitation, such as shoulder surfing in augmented reality (AR). Additionally, user behaviour in XR differs significantly from traditional digital environments, as XR overlays information onto the real world and captures real-world actions---such as gestures, gazes, and movements---as inputs. These differences in behaviour highlight the need for endpoint detection to move beyond traditional methods, incorporating high level actions and spatial semantic. Our project harnesses the unique capabilities of XR devices---tracking movements, gaze, and real-time environmental data---to introduce advanced security mechanisms beyond the scope of traditional mobile devices. By continuously analysing this rich multi-modal data, we enhance security via: **Continuous Authentication:** Seamless and secure login through spatial sensors replacing passwords with robust, anthropometric-based authentication to improve user experience and prevent unauthorized access. **Dynamic Analysis Prevention:** Protecting XR applications from reverse engineering and tampering, safeguarding sensitive information and intellectual property. **Cyberattack Detection:** Monitoring virtual environments for manipulation or deceptive elements to detect and mitigate perceptual cyberattacks, ensuring a secure and trustworthy XR experience, as well as integrity and availability attacks that affect usability or user safety in immersive environments.

View the original record at the funder ↗

Related Research

Grants with similar aims, by meaning.

Using synthetic data and unsupervised learning methods for malware detection
Vouchsec - Conversational XDR Platform for the AI Era
Quantum Resistant DSbD Security Leveraging MicroTokenisation
Tooling to Expedite Pipeline Based Security Testing (REX)
MobSec: Malware and Security in the Mobile Age

Original classification

Collaborative R&D

Plain English summaries and category classifications on this site are generated by AI and may not perfectly reflect the original research.