课题基金 / 基金详情

Collaborative Research: EAGER: Enhancing Security and Privacy of Augmented Reality Mobile Applications through Software Behavior Analysis

Collaborative Research: EAGER: Enhancing Security and Privacy of Augmented Reality Mobile Applications through Software Behavior Analysis
合作研究:EAGER:通过软件行为分析增强增强现实移动应用程序的安全性和隐私性
批准号:
2318486
负责人:
Xusheng Xiao
金额:
$15.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-10-01 至 2025-06-30

项目摘要

项目成果

Xusheng Xiao的其他基金

相似基金

相关文献

中文摘要
翻译
增强现实(AR)移动应用程序将虚拟现实(VR)与现实相结合,为导航、虚拟会议、虚拟展览、游戏和翻译等任务提供革命性的用户体验。为了使虚拟物体看起来附着在现实世界的物体上(例如,墙壁和人脸等表面),AR应用程序将虚拟物体放置在相对于AR设备识别的现实世界物体(称为可追踪物)的位置(称为锚点)。然而,AR应用程序可以通过AR框架软件api检索和操纵AR设备的相机输出(即通常是用户的部分或全部视力),这导致了独特的安全和隐私问题,例如破坏VR艺术和跟踪旁观者。AR应用程序的现有防御机制(例如,Android智能手机中的权限系统)没有模拟AR元素(例如,可追踪和锚)的独特行为,并且过于粗糙,无法检测和减轻AR应用程序潜在的特权滥用。该项目的目标是(i)开发一种新颖的软件分析框架,以检测和减轻VR应用程序的安全和隐私风险;(ii)对真实的AR应用程序(例如AR辅助驾驶和共享AR艺术)进行大规模研究,以研究其独特的安全问题。更具体地说,该项目将开发静态和动态程序分析,重点关注独特的AR元素(例如,可追踪器和锚),以检测两种主要类型的特权滥用:滥用对摄像机输出的读取访问权限和滥用对屏幕的写入权限。特别是,该项目将开发(1)可跟踪锚分析,正式模拟AR元素的软件行为及其在AR软件中的生命周期;(2)基于异常检测模型的读写滥用异常检测技术。然后,该项目将通过应用开发的技术对大量真实的VR应用程序进行研究,以评估技术的有效性并发现独特的安全问题。这个项目的成功将会带来更安全的AR应用和AR系统,研究将加深对AR应用安全风险和漏洞的理解。拟议的研究还将实现对动态生成的虚拟对象的细粒度AR访问控制。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Augmented Reality (AR) mobile apps mix virtual reality (VR) with reality to provide revolutionary user experience in tasks such as navigation, virtual meetings, exhibitions, gaming, and translation. To make virtual objects appear to be attached to real-world objects (e.g., surfaces such as walls and human faces), AR apps place virtual objects at a location (called anchors) relative to the real-world objects (called trackables) identified by the AR devices. However, AR apps’ privilege to retrieve and manipulate camera output from AR devices (i.e., often part or the whole of users’ eyesight), enabled by AR framework software APIs, result in unique security and privacy concerns, such as vandalism of VR arts and tracking bystanders. Existing defense mechanisms of AR apps (e.g., the permission system in an Android smartphone) do not model the unique behaviors of AR elements (e.g., trackables and anchors) and are too coarse grained to detect and mitigate potential privilege abuses of AR apps. The goal of the project is to (i) develop a novel software analysis framework that detects and mitigates VR app’s security and privacy risks, and (ii) conduct a large scale study on real AR apps (e.g. AR-assisted Driving and shared AR arts) to study their unique security issues.More specifically, the project will develop static and dynamic program analysis with a focus on the unique AR elements (e.g., trackables and anchors) to detect two major types of privilege abuses: abuses of read access to camera output and abuses of write abuses to screen. In particular, the project will develop (1) trackable-anchor analysis that formally models the software behaviors of AR elements and their life cycles in AR software; and (2) anomaly detection techniques for read and write abuses using anomaly detection models. The project will then conduct a study on a large number of real VR apps by applying the developed techniques to evaluate the effectiveness of the techniques and uncover unique security issues. The success of this project will lead to more secure AR apps and AR systems, and the study will deepen the understanding of the security risks and vulnerabilities in AR apps. The proposed research will also enable finer-grained AR access control on dynamically generated virtual objects.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CAREER: Enhancing Mobile Application Security through Contextual Integrity and User Awareness
  • 批准号:
    2318483
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2023
  • 负责人:
    Xusheng Xiao
  • 依托单位:
Collaborative Research: EAGER: Enhancing Security and Privacy of Augmented Reality Mobile Applications through Software Behavior Analysis
  • 批准号:
    2221842
  • 项目类别:
    Standard Grant
  • 资助金额:
    $15.0万
  • 财政年份:
    2022
  • 负责人:
    Xusheng Xiao
  • 依托单位:
CAREER: Enhancing Mobile Application Security through Contextual Integrity and User Awareness
  • 批准号:
    2046953
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2021
  • 负责人:
    Xusheng Xiao
  • 依托单位:
SaTC: CORE: Small: Scalable Cyber Attack Investigation using Declarative Queriesand Interrogative Analysis
  • 批准号:
    2028748
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2020
  • 负责人:
    Xusheng Xiao
  • 依托单位:
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
Cell Research
Cell Research
Cell Research (细胞研究)