{"id":"https://openalex.org/W4394769792","doi":"https://doi.org/10.1145/3597503.3639082","title":"An Empirical Study on Oculus Virtual Reality Applications: Security and Privacy Perspectives","display_name":"An Empirical Study on Oculus Virtual Reality Applications: Security and Privacy Perspectives","publication_year":2024,"publication_date":"2024-04-12","ids":{"openalex":"https://openalex.org/W4394769792","doi":"https://doi.org/10.1145/3597503.3639082"},"language":"en","primary_location":{"id":"doi:10.1145/3597503.3639082","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3597503.3639082","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the IEEE/ACM 46th International Conference on Software Engineering","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5050963307","display_name":"Hanyang Guo","orcid":"https://orcid.org/0000-0002-5687-2655"},"institutions":[{"id":"https://openalex.org/I141568987","display_name":"Hong Kong Baptist University","ror":"https://ror.org/0145fw131","country_code":"HK","type":"education","lineage":["https://openalex.org/I141568987"]},{"id":"https://openalex.org/I157773358","display_name":"Sun Yat-sen University","ror":"https://ror.org/0064kty71","country_code":"CN","type":"education","lineage":["https://openalex.org/I157773358"]}],"countries":["CN","HK"],"is_corresponding":true,"raw_author_name":"Hanyang Guo","raw_affiliation_strings":["Department of Computer Science, Hong Kong Baptist University, Hong Kong, Hong Kong","School of Software Engineering, Sun Yat-Sen University, Zhuhai, China","Department of Computer Science, Hong Kong Baptist University, Hong Kong, Hong Kong School of Software Engineering, Sun Yat-Sen University, Zhuhai, China"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Hong Kong Baptist University, Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I141568987"]},{"raw_affiliation_string":"School of Software Engineering, Sun Yat-Sen University, Zhuhai, China","institution_ids":["https://openalex.org/I157773358"]},{"raw_affiliation_string":"Department of Computer Science, Hong Kong Baptist University, Hong Kong, Hong Kong School of Software Engineering, Sun Yat-Sen University, Zhuhai, China","institution_ids":["https://openalex.org/I141568987"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5072659343","display_name":"Hong\u2010Ning Dai","orcid":"https://orcid.org/0000-0001-6165-4196"},"institutions":[{"id":"https://openalex.org/I141568987","display_name":"Hong Kong Baptist University","ror":"https://ror.org/0145fw131","country_code":"HK","type":"education","lineage":["https://openalex.org/I141568987"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Hong-Ning Dai","raw_affiliation_strings":["Department of Computer Science, Hong Kong Baptist University, Hong Kong, Hong Kong"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Hong Kong Baptist University, Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I141568987"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100400376","display_name":"Xiapu Luo","orcid":"https://orcid.org/0000-0002-9082-3208"},"institutions":[{"id":"https://openalex.org/I14243506","display_name":"Hong Kong Polytechnic University","ror":"https://ror.org/0030zas98","country_code":"HK","type":"education","lineage":["https://openalex.org/I14243506"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Xiapu Luo","raw_affiliation_strings":["Department of Computing, The Hong Kong Polytechnic University, Hong Kong, Hong Kong"],"affiliations":[{"raw_affiliation_string":"Department of Computing, The Hong Kong Polytechnic University, Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I14243506"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5000582109","display_name":"Zibin Zheng","orcid":"https://orcid.org/0000-0002-7878-4330"},"institutions":[{"id":"https://openalex.org/I157773358","display_name":"Sun Yat-sen University","ror":"https://ror.org/0064kty71","country_code":"CN","type":"education","lineage":["https://openalex.org/I157773358"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zibin Zheng","raw_affiliation_strings":["School of Software Engineering, Sun Yat-Sen University, Zhuhai, China"],"affiliations":[{"raw_affiliation_string":"School of Software Engineering, Sun Yat-Sen University, Zhuhai, China","institution_ids":["https://openalex.org/I157773358"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5038469922","display_name":"G. F. Xu","orcid":"https://orcid.org/0009-0001-7221-7845"},"institutions":[{"id":"https://openalex.org/I141568987","display_name":"Hong Kong Baptist University","ror":"https://ror.org/0145fw131","country_code":"HK","type":"education","lineage":["https://openalex.org/I141568987"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Gengyang Xu","raw_affiliation_strings":["Department of Computer Science, Hong Kong Baptist University, Hong Kong, Hong Kong"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Hong Kong Baptist University, Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I141568987"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5095381762","display_name":"Fengliang He","orcid":"https://orcid.org/0009-0005-1248-1539"},"institutions":[{"id":"https://openalex.org/I141568987","display_name":"Hong Kong Baptist University","ror":"https://ror.org/0145fw131","country_code":"HK","type":"education","lineage":["https://openalex.org/I141568987"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Fengliang He","raw_affiliation_strings":["Department of Computer Science, Hong Kong Baptist University, Hong Kong, Hong Kong"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Hong Kong Baptist University, Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I141568987"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5050963307"],"corresponding_institution_ids":["https://openalex.org/I141568987","https://openalex.org/I157773358"],"apc_list":null,"apc_paid":null,"fwci":6.1848,"has_fulltext":false,"cited_by_count":17,"citation_normalized_percentile":{"value":0.97167169,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"13"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9904999732971191,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9855999946594238,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7871919870376587},{"id":"https://openalex.org/keywords/virtual-reality","display_name":"Virtual reality","score":0.6943824291229248},{"id":"https://openalex.org/keywords/android","display_name":"Android (operating system)","score":0.6673121452331543},{"id":"https://openalex.org/keywords/mobile-device","display_name":"Mobile device","score":0.5257278680801392},{"id":"https://openalex.org/keywords/mobile-apps","display_name":"Mobile apps","score":0.48856863379478455},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4809771776199341},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.45910313725471497},{"id":"https://openalex.org/keywords/human\u2013computer-interaction","display_name":"Human\u2013computer interaction","score":0.42736732959747314},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.23416456580162048}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7871919870376587},{"id":"https://openalex.org/C194969405","wikidata":"https://www.wikidata.org/wiki/Q170519","display_name":"Virtual reality","level":2,"score":0.6943824291229248},{"id":"https://openalex.org/C557433098","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android (operating system)","level":2,"score":0.6673121452331543},{"id":"https://openalex.org/C186967261","wikidata":"https://www.wikidata.org/wiki/Q5082128","display_name":"Mobile device","level":2,"score":0.5257278680801392},{"id":"https://openalex.org/C2988145974","wikidata":"https://www.wikidata.org/wiki/Q620615","display_name":"Mobile apps","level":2,"score":0.48856863379478455},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4809771776199341},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.45910313725471497},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.42736732959747314},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.23416456580162048},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3597503.3639082","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3597503.3639082","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the IEEE/ACM 46th International Conference on Software Engineering","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.6700000166893005}],"awards":[{"id":"https://openalex.org/G1378608539","display_name":null,"funder_award_id":"62032025","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":47,"referenced_works":["https://openalex.org/W2067081213","https://openalex.org/W2084864601","https://openalex.org/W2088944946","https://openalex.org/W2100385966","https://openalex.org/W2114381667","https://openalex.org/W2166743230","https://openalex.org/W2320204756","https://openalex.org/W2462703038","https://openalex.org/W2514626402","https://openalex.org/W2603382267","https://openalex.org/W2789713441","https://openalex.org/W2885553494","https://openalex.org/W2911560572","https://openalex.org/W2912135847","https://openalex.org/W2912208904","https://openalex.org/W2933955319","https://openalex.org/W2936448087","https://openalex.org/W2944393316","https://openalex.org/W2950367216","https://openalex.org/W2963826402","https://openalex.org/W3002424663","https://openalex.org/W3016972006","https://openalex.org/W3045502942","https://openalex.org/W3090522550","https://openalex.org/W3112086075","https://openalex.org/W3114045853","https://openalex.org/W3163673547","https://openalex.org/W3183619015","https://openalex.org/W3196201577","https://openalex.org/W3212310756","https://openalex.org/W4206462734","https://openalex.org/W4206484811","https://openalex.org/W4211092666","https://openalex.org/W4224230548","https://openalex.org/W4230005434","https://openalex.org/W4246237463","https://openalex.org/W4255044316","https://openalex.org/W4283375988","https://openalex.org/W4285811653","https://openalex.org/W4296746025","https://openalex.org/W4296983654","https://openalex.org/W4309484364","https://openalex.org/W4312546215","https://openalex.org/W4313563619","https://openalex.org/W4315562192","https://openalex.org/W4320525735","https://openalex.org/W4385187265"],"related_works":["https://openalex.org/W3034529322","https://openalex.org/W2115913271","https://openalex.org/W2113597336","https://openalex.org/W2155505549","https://openalex.org/W2357479218","https://openalex.org/W1819546284","https://openalex.org/W2165251242","https://openalex.org/W2887633424","https://openalex.org/W2059650074","https://openalex.org/W4285504728"],"abstract_inverted_index":{"Although":[0],"Virtual":[1],"Reality":[2],"(VR)":[3],"has":[4,163],"accelerated":[5],"its":[6],"prevalent":[7],"adoption":[8],"in":[9,55,246,256],"emerging":[10],"metaverse":[11],"applications,":[12],"it":[13],"is":[14],"not":[15,130],"a":[16,37,147,179,236],"fundamentally":[17],"new":[18],"technology.":[19],"On":[20,51],"one":[21],"hand,":[22,54],"most":[23],"VR":[24,39,61,69,96,140,158,186,222,225,247,289],"operating":[25],"systems":[26],"(OS)":[27],"are":[28],"based":[29],"on":[30,183,278],"off-the-shelf":[31],"mobile":[32,49,59],"OS":[33],"(e.g.,":[34,90,106],"Android).":[35],"As":[36],"result,":[38],"apps":[40,62,97,192,223,262],"also":[41,109,252],"inherit":[42],"privacy":[43,121,150,217,242,258],"and":[44,77,92,123,149,169,197,201,216,230,241,263],"security":[45,112,124,148,214,239],"deficiencies":[46],"from":[47,193],"conventional":[48,58],"apps.":[50,141,159,187,248,276,290],"the":[52,83,136,154,174,190,194,206,257,266,271,275,285],"other":[53],"contrast":[56],"to":[57,135],"apps,":[60],"can":[63],"achieve":[64],"immersive":[65],"experience":[66],"via":[67,205],"diverse":[68,139],"devices,":[70],"such":[71],"as":[72],"head-mounted":[73],"displays,":[74],"body":[75],"sensors,":[76],"controllers":[78],"though":[79],"achieving":[80],"this":[81,143],"requires":[82],"extensive":[84],"collection":[85,269],"of":[86,116,138,220,238,260,265,274,288],"privacy-sensitive":[87],"human":[88],"biometrics":[89],"hand-tracking":[91],"face-tracking":[93],"data).":[94],"Moreover,":[95,249],"have":[98,129],"been":[99],"typically":[100],"implemented":[101],"by":[102,224],"3D":[103],"gaming":[104],"engines":[105],"Unity),":[107],"which":[108],"contain":[110],"intrinsic":[111],"vulnerabilities.":[113],"Inappropriate":[114],"use":[115],"these":[117,127,221,261,279],"technologies":[118],"may":[119],"incur":[120],"leaks":[122,219,243],"vulnerabilities":[125,215,240],"although":[126],"issues":[128],"received":[131],"significant":[132],"attention":[133],"compared":[134],"proliferation":[137],"In":[142],"paper,":[144],"we":[145,177,281],"develop":[146],"assessment":[151],"tool,":[152],"namely":[153],"VR-SP":[155,161,175],"detector":[156,162],"for":[157,284],"The":[160],"integrated":[164],"program":[165],"static":[166],"analysis":[167,171],"tools":[168],"privacy-policy":[170,231,272],"methods.":[172],"Using":[173],"detector,":[176],"conduct":[178],"comprehensive":[180],"empirical":[181],"study":[182],"500":[184],"popular":[185,195],"We":[188,212,233],"obtain":[189],"original":[191],"Oculus":[196,208],"SideQuest":[198],"app":[199,226],"stores":[200],"extract":[202],"APK":[203],"files":[204],"Meta":[207],"Quest":[209],"2":[210],"device.":[211],"evaluate":[213],"data":[218,268],"analysis,":[227,229],"taint":[228],"analysis.":[232],"find":[234],"that":[235],"number":[237],"widely":[244],"exist":[245],"our":[250],"results":[251],"reveal":[253],"conflicting":[254],"representations":[255],"policies":[259],"inconsistencies":[264],"actual":[267],"with":[270],"statements":[273],"Based":[277],"findings,":[280],"make":[282],"suggestions":[283],"future":[286],"development":[287]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":11},{"year":2024,"cited_by_count":5}],"updated_date":"2026-03-12T08:34:05.389933","created_date":"2025-10-10T00:00:00"}
