SecretVR: Differential Privacy Defense Against Membership Inference Privacy Attacks in Virtual Reality
Ripan Kumar Kundu, Khaza Anuarul Hoque · 2025
The convergence of artificial intelligence (AI) and virtual reality (VR) technologies (AI VR) offers innovative applications but raises privacy concerns due to the sensitive nature of data (e.g., eye-tracking). Since adversaries could exploit this data to infer and leak sensitive personal information and manipulate user experiences. We demonstrate that AI VR models such as machine learning (ML)/deep learning (DL) models are vulnerable to membership inference attacks (MIA) and leak users’ information, with a high success rate. To address this, we propose the SecretVR framework, which uses differential privacy (DP)-enabled privacy-preserving mechanism to defend against MIA and thus protect user privacy in AI VR models. Evaluated on seven AI VR models and three different datasets (i.e., cybersickness, emotion, and activity classification), our approach reduces MIA success rates by up to 32% for VR cybersickness classification tasks while maintaining high model utility, with classification accuracies of up to 92.5% using LSTM AI VR models.