🤖 AI Summary
This study addresses the critical privacy and security threats facing medical Extended Reality (XR) applications, where existing research remains fragmented and lacks unified evaluation standards. Employing a systematic knowledge synthesis methodology, this work comprehensively reviews 65 publications through a multidimensional analysis spanning device, network, and cloud layers. It introduces the first unified threat taxonomy for medical XR and proposes XR-PRISM, a quantitative risk scoring metric. The analysis reveals significant gaps in the literature, notably that over 70% of proposed security countermeasures lack standardized evaluation protocols. By bridging these systematic knowledge deficiencies, this research establishes a data-driven foundation and a strategic roadmap for advancing the security posture of medical XR systems.
📝 Abstract
Extended reality (XR) systems are increasingly used in healthcare applications ranging from surgical planning to remote rehabilitation and mental health support. However, the rich streams of sensor, biometric, behavioral, and environmental data that enable these applications also introduce substantial privacy and security risks. Adversaries may exploit insecure communication, sensor side channels, application-layer vulnerabilities, or data-processing pipelines to infer sensitive information or disrupt clinical workflows. Despite growing interest in XR security and privacy, the healthcare-specific literature remains fragmented. In this Systematization of Knowledge (SoK), we review 65 peer-reviewed studies published between 2017 and 2024 across XR, security, privacy, and healthcare venues. We develop a unified threat taxonomy spanning device, user, network, and cloud layers and introduce XR-PRISM, a quantitative Privacy and Risk Impact Scoring Metric for systematically characterizing security and privacy risks. Our analysis identifies several gaps in the literature: more than 70% of proposed countermeasures lack standardized risk evaluation, fewer than 15% of studied attacks require high attack prerequisites, and reproducibility is limited by the scarcity of publicly released artifacts and datasets. Based on these findings, we outline a research roadmap emphasizing shared benchmark datasets, stronger artifact-release practices, improved cloud-layer protections, and more comprehensive detection, mitigation, and recovery mechanisms. This SoK provides a structured and data-driven foundation for understanding existing risks and guiding the development of more secure, privacy-preserving, and usable XR healthcare systems.