arXiv:2608.00826v1 [cs.CR] 1 Aug 2026
XR-PRISM: Data-Driven Privacy and Risk Impact Scoring Metric for Extended Reality in Healthcare Nafisa Anjum*
M. Rasel Mahmud†
Dept. of Computer Science
Assistant Professor of Computer Science
Kennesaw State University
Kennesaw State University
A BSTRACT Extended Reality (XR) technologies are transforming healthcare, enabling immersive training, remote consultation, and patient rehabilitation; yet their rich sensor and data pipelines introduce novel privacy and safety vulnerabilities. To date, there is no unifying, quantitative framework to assess these risks. In this paper, we survey 65 peer-reviewed XR security and privacy studies (2017–2024), synthesizing a four-layer (Device, Network, User, Cloud) threat taxonomy and catalog of defenses. Building on this foundation, we propose XR-PRISM, a six-factor, weighted Privacy and Risk Impact Scoring Metric that integrates threat likelihood, system vulnerabilities, attack surface, safety impact, privacy impact, and control effectiveness into a single actionable score. Our analysis uncovers that over 70% of countermeasures lack standardized risk evaluations and fewer than 15% of the attacks need high expertise to be launched. XR-PRISM offers practitioners a transparent, data-driven tool for prioritizing and mitigating security and privacy risks in XR healthcare deployments. Index Terms: Extended Reality(XR), Healthcare, Quantitative Framework, Risk Score 1 I NTRODUCTION Extended Reality (XR), encompassing Virtual Reality (VR), Augmented Reality (AR), and Mixed Reality (MR), is transforming healthcare by enabling immersive training, remote consultation, patient rehabilitation, and mental-health therapies. Many VR-based assistive feedback improved balance and gait impairments [16, 15]. Yet, the very high-fidelity motion traces, physiological signals, biometric identifiers, and rich environmental context that make XR so powerful also expose patients and providers to unprecedented security and privacy (S&P) risks. Moreover, machine learning (ML) and deep learning (DL) components are becoming integral to XR systems—powering gesture recognition, environment mapping, anomaly detection, and personalized therapy. While some works document individual vulnerabilities [10], there is still no unifying framework that systematically characterizes these threats, and most defenses lack rigorous, standardized risk evaluations or recovery mechanisms once prevention fails. To fill this gap, we conduct a Systematization of Knowledge (SoK) by surveying 65 peerreviewed XR S&P studies (2017–2024) and contribute: • Four-layer taxonomy: Deconstructing XR into Device, Network, User, and Cloud layers, and classifying threats and countermeasures within each. • Threat–defense mapping: Rigorous analysis of representative attack vectors and defenses, highlighting prerequisites, attacker expertise, efficacy, and overhead. * e-mail: [email protected] † e-mail: [email protected]
• XR-PRISM: A six-factor, weighted Privacy and Risk Impact Scoring Metric that integrates threat likelihood, XR system vulnerabilities, attack surface, safety impact, privacy impact, and control effectiveness into a single actionable score. 2
R ELATED W ORK
The security domain has examined risk assessment, where risk is frequently quantified in relation to the probability and consequences of a security threat[14]. Wagner et al.[23] proposes a way to measure and depict privacy risk that takes into account a number of variables as well as various scenarios and attacker types. Wu et al.[25] proposes a framework on disclosed personal identifiable information. A method for determining a business process’s fundamental components and evaluating their security quantitatively was put out by Bhattacharjee et al.[3]. To facilitate privacy impact evaluation during the early stages of information system development, Ahamdian et al.[1] presented a model-based privacy analysis. But existing research either quantify risks for enterprise workflows or discrete user-provided attributes only. They do not address the unique characteristics of XR for comparable risk scores or support both preventive and post-compromise evaluations; despite a rapidly growing corpus of work on XR applications in healthcare. This outlines a lack of mechanisms for scoring combined safety and privacy impacts in clinical XR deployments. 3
M ETHODOLOGY
In this section , we first organize an XR system pipeline into four concentric layer architecture. Subsequently, we conduct a comprehensive investigation evaluating S&P publications in XR. Architecture. Modern XR headsets integrate multiple sensors—Inertial Measurement Units (IMUs), optical trackers, and eye-gaze modules to capture significant data from the user and the environment at high sampling rates[19]. We conceptualize XR system pipeline as four concentric layers: (1) User layer: Biometric and behavioral signals (gestures, voice commands, EMG, heart rate) captured via wearables and controllers. (2) Device layer: Onboard compute and firmware responsible for sensor fusion, local rendering, and real-time data preprocessing. (3) Network layer: Encrypted transport channels (Wi-Fi 6E, 5G, BLE) conveying telemetry, video streams, and control commands between headsets and edge or cloud endpoints. (4) Cloud layer: Remote compute for analytics, long-term storage, federated learning, and compliance-enforced data repositories. In healthcare settings, XR has proven effective for motor rehabilitation (stroke gait training, balance therapy), cognitive therapy (exposure treatment for phobias), and surgical assistance (AR overlays for anatomical guidance), with multiple clinical trials reporting statistically significant improvements in patient outcomes[26].
Groups
Attacker's Effort
AI Models
Table 1: Keyword Strategies for XR-Healthcare Terms motion gesture voice
Systematization. We performed a PRISMA–compliant [6] systematic literature review (SLR) over four databases: IEEE Xplore, ACM Digital Library, USENIX Proceedings, and PubMed. Our search combined six keyword groups covering: 1 XR Modality, 2 Healthcare Context, 3 Security Focus, 4 Privacy Focus, 5 Defense Mechanisms, 6 Quantitative Metrics; the details of the terms in each group are included in Table 1. Our initial query (2017–2024) returned 207 records. After removing 91 duplicates, title/abstract screening, and full-text assessment in teams, we select inclusion criteria—peer-reviewed studies that 1 analyze XR threats or 2 propose defenses with experimentation and metrics. Studies that explicitly analyze threats or propose defenses—attacks, side-channels, authentication, data protection or recovery mechanisms in XR environments that can also be applied to the healthcare industry were considered as the prime focus. Finally, we retained 65 publications now available in our GitHub 1 . For each paper, we extracted: • Attack attributes: XR layer targeted, attack vector and component, adversary prerequisites (hardware/software access), required expertise of attacker, and impact or the degree to which an attack exposes sensitive patient data based on the performance. • Defense attributes: Defense group, mitigation vector, overhead, maintainability, efficacy based on evaluation reported, and defense stage (prevention (P), detection (D), recovery(R)). These attributes were aggregated into our four-layer threat taxonomy. We then applied thematic analysis to identify gaps such as underexplored recovery mechanisms and inconsistent risk reporting and distilled the six core factors for our XR-PRISM quantitative framework detailed in Sec.5. 4
OVERVIEW OF T HREATS AND D EFENSES Target: Device Layer. In shared virtual environments, Yang et al.[27] create and execute a novel class of keystroke inference attacks that allow an attacker (VR user) to retrieve material typed by another VR user by looking at their avatar. Slocum et al.[20] demonstrate how an attacker can easily extract stream head tracking data from an AR/VR device, segment it, and categorize it to get private text data. Target: User Layer. Gopal et al.[11] introduces Hidden Reality (HR Model), a video-based side-channel attack that demonstrates how, even if the virtual screen in VR devices is not directly visible to adversaries, indirect observations could be used to acquire the user’s personal data. Target: Network Layer. Arafat et al.[2] introduced VR-Spy, a brand-new human activity-based side-channel attack that infers text inputs from virtual reality devices. The fundamental concept 1 https://github.com/User32-blip/SoK-XR-in-Healthcare
XR-USER
feedback
Phishing Credential Theft Spoofing Privacy Inference
XR DEVICE
fusion and render
secure transport NETWORK
auth. payload
Hardware Tampering Malware Injection Side-Channel Sensor Spoofing
MitM DoS Eavesdropping Data exfiltration
CLOUD
inference
Access to Credentials Insider Threat Adversarial Models Authorization
Storage
virtual reality OR augmented reality OR mixed reality OR extended reality Healthcare Context healthcare OR tele-rehabilitation OR therapy Security Focus security OR attack OR threat Privacy Focus privacy OR differential privacy OR PHI (Protected Health Information) Defense Mechanisms mitigation OR countermeasure OR access control OR encryption OR obfuscation Quantitative Metrics risk assessment OR CVSS (Common Vulnerability Scoring System[8]) OR framework XR Modality
Figure 1: Threat model of an XR system.
of VR-Spy is that each virtual keystroke has a distinct gesture pattern in the CSI waveforms based on the side-channel information of fine-granular hand movements. Target: Cloud Layer. Tseng et al.[22] exploited the fact that VR platforms typically trust any code running in a VR app with direct, unmediated access to the user’s body-tracking streams and environment model. 5 XR-PRISM Our findings show that most XR side-channel and inference attacks require only minimal privileges (scores of 1–2) and modest expertise—few demand specialized hardware or deep reverseengineering. Healthcare XR deployments blend rich sensory inputs, real-time rendering, haptic feedback, and sensitive biometric streams, creating intertwined security and privacy exposures. To quantify and prioritize these exposures, we extend a Multi-Criteria Decision Analysis (MCDA)[13] based scoring framework to jointly assess both security and privacy risks. This approach consists of two main steps: 1 Scaling key parameters as per threat characteristics and 2 Calculating the RiskScore for taking immediate mitigation action. These key elements together form the XR-PRISM (XR-Privacy and Risk Impact Scoring Metric). Key Risk Factors for Weighting The proposed structure in [9] is intended to evaluate a cyber system’s risk using threats, vulnerabilities and consequences as the most significant criteria in order to choose the best remedial strategy. Expanding on their idea and the CVSS scoring system, the scoring mechanism developed here scores each risk factor from 1 (low risk) to 10 (high risk). We began by assigning weights to the six risk criteria, namely, 1 Threat Likelihood, 2 System Vulnerabilities, 3 Attack Surface, 4 Safety Impact, 5 Privacy Impact and 6 Control Effectiveness; shown in Table 4. These weights would be obtained from XR security specialists using established procedures [4] in an empirical implementation of this paradigm, depending on the attributes of the XR healthcare system. We treat these weights as initial heuristics; we plan a Delphi-style expert elicitation to empirically calibrate them. The values of the scale have been interpreted as per NIST SP 800-30 guidelines [12] but are susceptible to change on the basis of L. Formula and Scoring Interpretation Subsequent to defining and quantifying the parameters, the overall risk score is calculated using a weighted sum in Eq.1. Control Effectiveness (C) is subtracted from 10, which is the highest score, because stronger controls reduce risk. We score six factors on a 1–10 scale and compute a single RiskScore as a weighted sum: RiskScore = LWL +V WV + AWA + Is WIs + I p WIp + (10 −C)WC (1) where: • L (Threat Likelihood): probability of an attack, informed by incident data and exploitability indices.
Table 2: An overview of XR Attack Methods (
Approach
Layer
TyPose [20] Hand gesture [11] VR-Spy [2] Run Malicious Code [22]
Keystroke Inference Exploit typing gesture Wireless Sniffing Remote code execution
Group
High) Complexity
Attack Vector
Component
IMU/head tracking Side-Channel Virtual Keystrokes Software
On-device motion sensors Video segment CSI data Cloud storage
Table 3: An overview of XR Defense Approaches (
Approach
Medium
Dimension
Technique
Device User Network Cloud
Low
Mitigation
Low
Medium
Requisite
High) Deployability
Defense Vector
Trade-off Keystroke inference [27] Biometric Auth.[24] ShareAR[18]
Data Obfuscation Authentication Access Control
Limit access to telemetry Head-neck motion Physical-world controls
Risk Factor
Description
Threat Likelihood (L) System Vulnerabilities (V ) Attack Surface (A) Safety Impact (Is ) Privacy Impact (I p ) Control Effectiveness (C)
Probability of attack Known XR platform flaws Exposure of interfaces Patient-harm User identification Strength of auth, encryption
Efficacy
Stage P P P
Weight(W )
RiskScore
Risk Level
Mitigation Action
0.15 0.15 0.10 0.30 0.20 0.10
1–3 4–6 7–8 9–10
Low Moderate High Critical
Monitor routinely;no immediate change Deploy preventive controls Immediate mitigation; elevate priority Emergency response; consider system shutdown
• A (Attack Surface): number and exposure level of sensors, APIs, and network links • Is (Safety Impact): potential for patient harm (haptics, motionsickness) • I p (Privacy Impact): severity of PHI leakage or behavioral profiling • C (Control Effectiveness): strength of authentication, encryption, and session isolation (higher C is more effective). We choose weights to reflect the paramount importance of patient safety and data confidentiality: WV = 0.15, WA = 0.10, WIp = 0.20, WC = 0.10,
Maintenance
Table 5: Risk Score Interpretation
• V (System Vulnerabilities): count and severity of known flaws in firmware, runtime, and architecture.
WL = 0.15, WIs = 0.30,
Robustness
Hand tracking API IMU telemetry App-level APIs
Table 4: Risk Assessment Model Parameters
Impact
Expertise
(2)
with ∑ W = 1.00. Using the formula, the risk score that is calculated is assigned Risk Levels from Low to Critical as per Table 5. From the risk level, the required mitigation priority and appropriate action to be undertaken for the threat can be determined. An organization prioritizes outcomes and controls that can manage the risks with the most negative impacts and that are most cost-effective for their risk management results by using the principles outlined in NIST SP 800-53: Security and Privacy Controls for Information Systems and Organizations [7]. XR-PRISM extends beyond CVSS by explicitly folding in safety and privacy impacts—critical in healthcare XR, via two dedicated factors, Safety Impact and Privacy Impact each weighted heavily to reflect patient-harm and PHI leakage concerns. XR-PRISM can also integrate modifiers for privacy controls such as differential privacy noise budgets[5], secure multi-party computation, or anonymization thresholds to penalize residual inference risk.
Example. A tele-therapy VR system suffers a motion-replay attack that risks both user disorientation and PHI inference. Experts rate: L = 6, V = 5, A = 7, Is = 8, I p = 9, C = 4. (3) RiskScore = 6 · 0.15 + 5 · 0.15 + 7 · 0.10 + 8 · 0.30 + 9 · 0.20 + (10 − 4) · 0.10 = 6.5
(4) placing it in the **High** tier. We therefore recommend urgent deployment of signed telemetry, anomaly detection at the edge, and end-to-end encryption of all biometric streams. 6
R ESEARCH G APS
By examining the information XR S&P publications through extracting information outlined in Sec.3, we now concentrate on determining research gaps and suggestions for further research. Low Prerequisites for Most Attacks. A data analysis of papers similar to Table 2 illustrates that the majority of documented attack methods demand minimal prerequisites; only a handful [20, 28] reach a High prerequisite level. This skew toward low-barrier exploits suggests that XR systems are broadly exposed to attacks by relatively unsophisticated adversaries, underscoring the urgent need to elevate baseline security measures. ML/DL Threat Surfaces. Modern XR systems increasingly embed machine learning for gesture recognition, anomaly detection, and personalization thus opening new vulnerabilities. Examples include adversarial perturbations that mislead model outputs, model-inversion that reconstructs sensitive training data [17], and inference attacks that extract behavioral profiles. To score these, XR-PRISM can be expanded to incorporate exploitability metrics from ML robustness benchmarks to gauge how easily adversarial inputs can be generated. Predominance of Preventative Controls. Nearly all surveyed defenses are preventative—aimed at blocking attacks before they occur; yet there is a dearth of mechanisms for detection, forensics, or automated recovery post-compromise. We note that fewer
Number of Papers
12
Category Both Defenses Threats
10 8 6 4
2024
2023
Year
2022
2021
2020
2019
2018
0
2017
2
Figure 2: Publications by Year and Category
than over 70% of countermeasures lack standardized risk evaluations, and only 15% include user-study driven usability assessments. This lack of holistic, end-to-end security frameworks. Underexplored Cloud-Layer Threats and Defenses. Even though works like the COVID-19 XR-IoMT system [21] hinges on a 5G-backed cloud infrastructure to aggregate, process, and secure sensitive medical data, emerging cloud threats such as poisoning federated learning updates to degrade model integrity or side-channel inference on aggregated telemetry are largely unstudied. 7
C ONCLUSION
The delivery of care and possibly the safety and well-being of people may be impacted if an attacker compromises a clinical XR device and tampers with the content of a clinical XR immersive session. In this paper, we provide the first comprehensive systematization of knowledge on XR privacy and security in healthcare, surveying 65 studies and organizing threats and defenses into a four-layer taxonomy; we introduce XR-PRISM, a weighted sixfactor risk-scoring framework that unifies into a single actionable metric which can be utilized to interpret the required level of action for threat mitigation. Future work will apply XR-PRISM to real XR healthcare case studies, e.g., VR stroke rehabilitation and AR guided surgery, and validate scores against incident logs and practitioner feedback. R EFERENCES [1] A. S. Ahmadian, D. Strüber, V. Riediger, and J. Jürjens. Supporting privacy impact assessment by model-based privacy analysis. In Proceedings of the 33rd Annual ACM Symposium on Applied Computing, pp. 1467–1474, 2018. 1 [2] A. Al Arafat, Z. Guo, and A. Awad. Vr-spy: A side-channel attack on virtual key-logging in vr headsets. In 2021 IEEE Virtual Reality and 3D User Interfaces (VR), pp. 564–572. IEEE, 2021. 2, 3 [3] J. Bhattacharjee, A. Sengupta, and C. Mazumdar. A quantitative methodology for security risk assessment of enterprise business processes. In ICISSP, pp. 388–399, 2016. 1 [4] D. M. Buede and W. D. Miller. The engineering design of systems: models and methods. John Wiley & Sons, 2024. 2 [5] B. David-John, D. Hosfelt, K. Butler, and E. Jain. A privacypreserving approach to streaming eye-tracking data. IEEE Transactions on Visualization and Computer Graphics, 27(5):2555–2565, 2021. 3 [6] A. Fink. Conducting research literature reviews: From the internet to paper. Sage publications, 2019. 2 [7] J. T. Force and T. Initiative. Security and privacy controls for federal information systems and organizations. NIST Special Publication, 800(53):8–13, 2013. 3 [8] Forum of Incident Response and Security Teams (FIRST). Common vulnerability scoring system version 3.1: Specification document. Technical report, FIRST, 2019. 2
[9] A. A. Ganin, P. Quach, M. Panwar, Z. A. Collier, J. M. Keisler, D. Marchese, and I. Linkov. Multicriteria decision framework for cybersecurity risk assessment and management. Risk Analysis, 40(1):183–199, 2020. 2 [10] A. Giaretta. Security and privacy in virtual reality: a literature survey. Virtual Reality, 29(1):10, 2024. 1 [11] S. R. K. Gopal, D. Shukla, J. D. Wheelock, and N. Saxena. Hidden reality: Caution, your hand gesture inputs in the immersive virtual world are visible to all! In 32nd USENIX security symposium (USENIX Security 23), pp. 859–876, 2023. 2, 3 [12] Joint Task Force Transformation Initiative. Guide for conducting risk assessments. Technical Report SP 800-30 Rev. 1, National Institute of Standards and Technology, Gaithersburg, MD, 2012. 2 [13] I. Linkov and E. Moberg. Multi-criteria decision analysis: environmental applications and case studies. CRC Press, 2011. 2 [14] D. Maclean. The nist risk management framework: Problems and recommendations. Cyber Security: A Peer-Reviewed Journal, 1(3):207– 217, 2017. 1 [15] M. R. Mahmud, M. Stewart, A. Cordova, and J. Quarles. Auditory feedback for standing balance improvement in virtual reality. In 2022 IEEE Conference on Virtual Reality and 3D User Interfaces (VR), pp. 782–791, 2022. doi: 10.1109/VR51125.2022.00100 1 [16] M. R. Mahmud, M. Stewart, A. Cordova, and J. Quarles. Auditory feedback to make walking in virtual reality more accessible. In 2022 IEEE International Symposium on Mixed and Augmented Reality (ISMAR), pp. 847–856, 2022. doi: 10.1109/ISMAR55827.2022.00103 1 [17] A. Qayyum, M. A. Butt, H. Ali, M. Usman, O. Halabi, A. Al-Fuqaha, Q. H. Abbasi, M. A. Imran, and J. Qadir. Secure and trustworthy artificial intelligence-extended reality (ai-xr) for metaverses. ACM Computing Surveys, 56(7):1–38, 2024. 3 [18] K. Ruth, T. Kohno, and F. Roesner. Secure {Multi-User} content sharing for augmented reality applications. In 28th USENIX Security Symposium (USENIX Security 19), pp. 141–158, 2019. 3 [19] X. Sheng, S. Mao, Y. Yan, and X. Yang. Review on slam algorithms for augmented reality. Displays, p. 102806, 2024. 1 [20] C. Slocum, Y. Zhang, N. Abu-Ghazaleh, and J. Chen. Going through the motions:{AR/VR} keylogging from user head motions. In 32nd USENIX Security Symposium (USENIX Security 23), pp. 159–174, 2023. 2, 3 [21] Y. Tai, B. Gao, Q. Li, Z. Yu, C. Zhu, and V. Chang. Trustworthy and intelligent covid-19 diagnostic iomt through xr and deeplearning-based clinic data access. IEEE Internet of Things Journal, 8(21):15965–15976, 2021. 4 [22] W.-J. Tseng, E. Bonnail, M. McGill, M. Khamis, E. Lecolinet, S. Huron, and J. Gugenheimer. The dark side of perceptual manipulations in virtual reality. In Proceedings of the 2022 CHI Conference on Human Factors in Computing Systems, pp. 1–15, 2022. 2, 3 [23] I. Wagner and E. Boiten. Privacy risk assessment: from art to science, by metrics. In International Workshop on Data Privacy Management, pp. 225–241. Springer, 2018. 1 [24] X. Wang and Y. Zhang. Nod to auth: Fluent ar/vr authentication with user head-neck modeling. In Extended Abstracts of the 2021 CHI Conference on Human Factors in Computing Systems, pp. 1–7, 2021. 3 [25] N. Wu and R. Tamilselvan. A personal privacy risk assessment framework based on disclosed pii. In 2023 7th International Conference on Cryptography, Security and Privacy (CSP), pp. 86–91. IEEE, 2023. 1 [26] J. O. Yang and J. S. Lee. Utilization exercise rehabilitation using metaverse (vr· ar· mr· xr). Korean Journal of Applied Biomechanics, 31(4):249–258, 2021. 1 [27] Z. Yang, Z. Sarwar, I. Hwang, R. Bhaskar, B. Y. Zhao, and H. Zheng. Can virtual reality protect users from keystroke inference attacks? In 33rd USENIX Security Symposium (USENIX Security 24), pp. 2725– 2742, 2024. 2, 3 [28] Y. Zhang, C. Slocum, J. Chen, and N. Abu-Ghazaleh. It’s all in your head (set): Side-channel attacks on {AR/VR} systems. In 32nd USENIX Security Symposium (USENIX Security 23), pp. 3979–3996, 2023. 3