Collaborative Research: EAGER: Enhancing Security and Privacy of Augmented Reality Mobile Applications through Software Behavior Analysis
Collaborative Research: EAGER: Enhancing Security and Privacy of Augmented Reality Mobile Applications through Software Behavior Analysis
批准号:
2318486
负责人:
Xusheng Xiao
金额:
$15.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-10-01 至 2025-06-30
中文摘要
增强现实(AR)移动的应用程序将虚拟现实(VR)与现实相结合,在导航、虚拟会议、展览、游戏和翻译等任务中提供革命性的用户体验。为了使虚拟对象看起来附接到现实世界对象(例如,例如,当虚拟物体(例如墙壁和人脸等表面)移动时,AR应用将虚拟物体放置在相对于由AR设备识别的真实世界物体(称为可跟踪物体)的位置(称为锚点)处。然而,AR应用从AR设备检索和操纵相机输出的特权(即,通常是用户视力的一部分或全部),由AR框架软件API实现,导致独特的安全和隐私问题,例如破坏VR艺术和跟踪旁观者。AR应用程序的现有防御机制(例如,Android智能手机中的许可系统)不对AR元素的独特行为进行建模(例如,可跟踪和锚点),并且太粗粒度而无法检测和减轻AR应用的潜在权限滥用。该项目的目标是(i)开发一个新的软件分析框架,以检测和减轻VR应用程序的安全和隐私风险,(ii)对真实的AR应用程序(例如AR辅助驾驶和共享AR艺术)进行大规模研究,以研究其独特的安全问题。更具体地说,该项目将开发静态和动态程序分析,重点关注独特的AR元素(例如,可跟踪和锚)来检测两种主要类型的特权滥用:对相机输出的读访问的滥用和对屏幕的写滥用的滥用。特别是,该项目将开发(1)可跟踪锚点分析,正式建模AR软件中AR元素的软件行为及其生命周期;以及(2)使用异常检测模型的读写滥用异常检测技术。然后,该项目将通过应用开发的技术对大量真实的VR应用程序进行研究,以评估技术的有效性并发现独特的安全问题。 该项目的成功将带来更安全的AR应用程序和AR系统,该研究将加深对AR应用程序中安全风险和漏洞的理解。该奖项反映了NSF的法定使命,并通过使用基金会的智力价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Augmented Reality (AR) mobile apps mix virtual reality (VR) with reality to provide revolutionary user experience in tasks such as navigation, virtual meetings, exhibitions, gaming, and translation. To make virtual objects appear to be attached to real-world objects (e.g., surfaces such as walls and human faces), AR apps place virtual objects at a location (called anchors) relative to the real-world objects (called trackables) identified by the AR devices. However, AR apps’ privilege to retrieve and manipulate camera output from AR devices (i.e., often part or the whole of users’ eyesight), enabled by AR framework software APIs, result in unique security and privacy concerns, such as vandalism of VR arts and tracking bystanders. Existing defense mechanisms of AR apps (e.g., the permission system in an Android smartphone) do not model the unique behaviors of AR elements (e.g., trackables and anchors) and are too coarse grained to detect and mitigate potential privilege abuses of AR apps. The goal of the project is to (i) develop a novel software analysis framework that detects and mitigates VR app’s security and privacy risks, and (ii) conduct a large scale study on real AR apps (e.g. AR-assisted Driving and shared AR arts) to study their unique security issues.More specifically, the project will develop static and dynamic program analysis with a focus on the unique AR elements (e.g., trackables and anchors) to detect two major types of privilege abuses: abuses of read access to camera output and abuses of write abuses to screen. In particular, the project will develop (1) trackable-anchor analysis that formally models the software behaviors of AR elements and their life cycles in AR software; and (2) anomaly detection techniques for read and write abuses using anomaly detection models. The project will then conduct a study on a large number of real VR apps by applying the developed techniques to evaluate the effectiveness of the techniques and uncover unique security issues. The success of this project will lead to more secure AR apps and AR systems, and the study will deepen the understanding of the security risks and vulnerabilities in AR apps. The proposed research will also enable finer-grained AR access control on dynamically generated virtual objects.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CAREER: Enhancing Mobile Application Security through Contextual Integrity and User Awareness
-
批准号:2318483
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2023
-
负责人:Xusheng Xiao
-
依托单位:
Collaborative Research: EAGER: Enhancing Security and Privacy of Augmented Reality Mobile Applications through Software Behavior Analysis
-
批准号:2221842
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2022
-
负责人:Xusheng Xiao
-
依托单位:
CAREER: Enhancing Mobile Application Security through Contextual Integrity and User Awareness
-
批准号:2046953
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2021
-
负责人:Xusheng Xiao
-
依托单位:
SaTC: CORE: Small: Scalable Cyber Attack Investigation using Declarative Queriesand Interrogative Analysis
-
批准号:2028748
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2020
-
负责人:Xusheng Xiao
-
依托单位:
CRII: SaTC: Enhancing Mobile App Security by Detecting Icon-Behavior Contradiction
-
批准号:1755772
-
项目类别:Standard Grant
-
资助金额:$17.49万
-
财政年份:2018
-
负责人:Xusheng Xiao
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: