Miguel Angel Lopez, Anish S. Narkar, Jan J. Michalak, Jeffrey Lubin, Brendan David-John · · 2026
DOI: 10.1145/3842203.3844597
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Gaze data is increasingly used to support applications and interfaces in Mixed Reality (MR). At the same time, gaze data has the potential to leak sensitive information about the user's status and cognitive state. An attacker with access to this gaze data could exploit inferences about user status to identify when they are vulnerable. Privacy mechanisms add noise to gaze data streams to obfuscate events and extracted features to protect against such inferences. In this paper, we present formal guarantees which bound how reliably an attacker can accurately identify the user's saccades (rapid eye movements) that leak information about the user's status; and link this bound to the level of noise injected by a sample-level Gaussian noise privacy mechanism. We formulate a complementary formal bound on data utility based on noise level when gaze pointing is used for selection. These bounds enable a formal analysis of privacy-utility trade-offs. We conducted an MR user study with 27 participants' data to validate our formal guarantees against spatial attacks. Our findings suggest that we can place mathematical bounds on continuous signals through fundamental events that define the signal, and limit the information leaked about user status and ultimately balance privacy and utility in critical MR settings.
No comments yet — start the discussion below.