{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T16:12:06Z","timestamp":1784391126096,"version":"3.55.0"},"reference-count":177,"publisher":"Association for Computing Machinery (ACM)","issue":"7","license":[{"start":{"date-parts":[[2024,4,9]],"date-time":"2024-04-09T00:00:00Z","timestamp":1712620800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Qatar University High Impact Internal Grant","award":["QUHI-CENG-23\/24-127"],"award-info":[{"award-number":["QUHI-CENG-23\/24-127"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2024,7,31]]},"abstract":"<jats:p>Metaverse is expected to emerge as a new paradigm for the next-generation Internet, providing fully immersive and personalized experiences to socialize, work, and play in self-sustaining and hyper-spatio-temporal virtual world(s). The advancements in different technologies such as augmented reality, virtual reality, extended reality (XR), artificial intelligence (AI), and 5G\/6G communication will be the key enablers behind the realization of AI-XR metaverse applications. While AI itself has many potential applications in the aforementioned technologies (e.g., avatar generation, network optimization), ensuring the security of AI in critical applications like AI-XR metaverse applications is profoundly crucial to avoid undesirable actions that could undermine users\u2019 privacy and safety, consequently putting their lives in danger. To this end, we attempt to analyze the security, privacy, and trustworthiness aspects associated with the use of various AI techniques in AI-XR metaverse applications. Specifically, we discuss numerous such challenges and present a taxonomy of potential solutions that could be leveraged to develop secure, private, robust, and trustworthy AI-XR applications. To highlight the real implications of AI-associated adversarial threats, we designed a metaverse-specific case study and analyzed it through the adversarial lens. Finally, we elaborate upon various open issues that require further research interest from the community.<\/jats:p>","DOI":"10.1145\/3614426","type":"journal-article","created":{"date-parts":[[2023,8,10]],"date-time":"2023-08-10T11:50:07Z","timestamp":1691668207000},"page":"1-38","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":72,"title":["Secure and Trustworthy Artificial Intelligence-extended Reality (AI-XR) for Metaverses"],"prefix":"10.1145","volume":"56","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6732-7601","authenticated-orcid":false,"given":"Adnan","family":"Qayyum","sequence":"first","affiliation":[{"name":"University of Glasgow, Glasgow, United Kingdom and Information Technology University, Lahore, Pakistan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4799-6488","authenticated-orcid":false,"given":"Muhammad Atif","family":"Butt","sequence":"additional","affiliation":[{"name":"Information Technology University, Lahore, Pakistan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1701-0390","authenticated-orcid":false,"given":"Hassan","family":"Ali","sequence":"additional","affiliation":[{"name":"Information Technology University, Lahore, Pakistan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6170-0922","authenticated-orcid":false,"given":"Muhammad","family":"Usman","sequence":"additional","affiliation":[{"name":"Glasgow Caledonian University, Glasgow, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2052-0500","authenticated-orcid":false,"given":"Osama","family":"Halabi","sequence":"additional","affiliation":[{"name":"Qatar University, Doha, Qatar"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0903-1204","authenticated-orcid":false,"given":"Ala","family":"Al-Fuqaha","sequence":"additional","affiliation":[{"name":"Hamad Bin Khalifa University, Doha, Qatar"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7097-9969","authenticated-orcid":false,"given":"Qammer H.","family":"Abbasi","sequence":"additional","affiliation":[{"name":"University of Glasgow, Glasgow, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4743-9136","authenticated-orcid":false,"given":"Muhammad Ali","family":"Imran","sequence":"additional","affiliation":[{"name":"University of Glasgow, Glasgow, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9466-2475","authenticated-orcid":false,"given":"Junaid","family":"Qadir","sequence":"additional","affiliation":[{"name":"Qatar University, Doha, Qatar"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,4,9]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2870052"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/NFV-SDN47374.2019.9040101"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3127960"},{"key":"e_1_3_2_6_2","article-title":"Incentive-driven federated learning and associated security challenges: A systematic review","author":"Ali Asad","year":"2021","unstructured":"Asad Ali, Inaam Ilahi, Adnan Qayyum, Ihab Mohammed, Ala Al-Fuqaha, and Junaid Qadir. 2021. Incentive-driven federated learning and associated security challenges: A systematic review. TechRxiv (2021).","journal-title":"TechRxiv"},{"key":"e_1_3_2_7_2","article-title":"SPAM-DaS: Secure and privacy-aware misinformation detection as a service","author":"Ali Hassan","year":"2022","unstructured":"Hassan Ali, Rana Tallal Javed, Adnan Qayyum, Amer AlGhadhban, Meshari Alazmi, Ahmad Alzamil, Khaled Al-utaibi, and Junaid Qadir. 2022. SPAM-DaS: Secure and privacy-aware misinformation detection as a service. TechRxiv (2022).","journal-title":"TechRxiv"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/MDAT.2019.2961325"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102791"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3085875"},{"key":"e_1_3_2_11_2","doi-asserted-by":"crossref","unstructured":"H. Ali M. S. Khan A. AlGhadhban M. Alazmi A. Alzamil K. Al-utaibi and J. Qadir. 2023. Condetect: Detecting adversarially perturbed natural language inputs to deep classifiers through holistic analysis. Computers & Security 132 (2023) 103367.","DOI":"10.1016\/j.cose.2023.103367"},{"key":"e_1_3_2_12_2","article-title":"HaS-Nets: A heal and select mechanism to defend DNNs against backdoor attacks for data collection scenarios","author":"Ali Hassan","year":"2020","unstructured":"Hassan Ali, Surya Nepal, Salil S. Kanhere, and Sanjay Jha. 2020. HaS-Nets: A heal and select mechanism to defend DNNs against backdoor attacks for data collection scenarios. arXiv preprint arXiv:2012.07474 (2020).","journal-title":"arXiv preprint arXiv:2012.07474"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/TWC.2021.3060514"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00099"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE43902.2021.00039"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2017.62"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"e_1_3_2_18_2","first-page":"1807","volume-title":"Proceedings of the 29th International Conference on Machine Learning","author":"Biggio Battista","year":"2012","unstructured":"Battista Biggio, B. Nelson, and P. Laskov. 2012. Poisoning attacks against support vector machines. In Proceedings of the 29th International Conference on Machine Learning. ArXiv e-prints, 1807\u20131814."},{"key":"e_1_3_2_19_2","article-title":"When the curious abandon honesty: Federated learning is not private","author":"Boenisch Franziska","year":"2021","unstructured":"Franziska Boenisch, Adam Dziedzic, Roei Schuster, Ali Shahin Shamsabadi, Ilia Shumailov, and Nicolas Papernot. 2021. When the curious abandon honesty: Federated learning is not private. arXiv preprint arXiv:2112.02918 (2021).","journal-title":"arXiv preprint arXiv:2112.02918"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCBB.2018.2858818"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23241"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833641"},{"key":"e_1_3_2_24_2","article-title":"Security and privacy in the metaverse: The threat of the digital human","author":"Buck Lauren","year":"2022","unstructured":"Lauren Buck and Rachel McDonnell. 2022. Security and privacy in the metaverse: The threat of the digital human. In Proceedings of the 1st Workshop on Novel Challenges of Safety, Security and Privacy in Extended Reality.","journal-title":"Proceedings of the 1st Workshop on Novel Challenges of Safety, Security and Privacy in Extended Reality"},{"key":"e_1_3_2_25_2","volume-title":"Secure Hash Standard","author":"Burrows James H.","year":"1995","unstructured":"James H. Burrows. 1995. Secure Hash Standard. Technical Report. Department of Commerce, Washington, DC."},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1155\/2021\/6644861"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.image.2022.116667"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/MCE.2020.3025753"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2019.2907942"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8803803"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3098692"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2019.2926625"},{"key":"e_1_3_2_34_2","volume-title":"Proceedings of the ICML Workshop on Adversarial Machine Learning","author":"Chen Xiaoyi","year":"2021","unstructured":"Xiaoyi Chen, Ahmed Salem, Michael Backes, Shiqing Ma, and Yang Zhang. 2021. BadNL: Backdoor attacks against NLP models. In Proceedings of the ICML Workshop on Adversarial Machine Learning."},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.011.1900577"},{"key":"e_1_3_2_36_2","article-title":"Will metaverse be NextG internet? Vision, hype, and reality","author":"Cheng Ruizhi","year":"2022","unstructured":"Ruizhi Cheng, Nan Wu, Songqing Chen, and Bo Han. 2022. Will metaverse be NextG internet? Vision, hype, and reality. arXiv preprint arXiv:2201.12894 (2022).","journal-title":"arXiv preprint arXiv:2201.12894"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.350"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2019.00215"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/3359626"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPSISA52974.2021.00032"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"e_1_3_2_43_2","article-title":"Dynamic differential-privacy preserving SGD","author":"Du Jian","year":"2021","unstructured":"Jian Du, Song Li, Moran Feng, and Siheng Chen. 2021. Dynamic differential-privacy preserving SGD. arXiv:2111.00173 (2021).","journal-title":"arXiv:2111.00173"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-5906-5_752"},{"key":"e_1_3_2_45_2","article-title":"HotFlip: White-box adversarial examples for text classification","author":"Ebrahimi Javid","year":"2017","unstructured":"Javid Ebrahimi, Anyi Rao, Daniel Lowd, and Dejing Dou. 2017. HotFlip: White-box adversarial examples for text classification. arXiv preprint arXiv:1712.06751 (2017).","journal-title":"arXiv preprint arXiv:1712.06751"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/MTS.2018.2826060"},{"issue":"1","key":"e_1_3_2_47_2","first-page":"8","article-title":"Applying digital twins in metaverse: User interface, security and privacy challenges","volume":"2","author":"Far Saeed Banaeian","year":"2022","unstructured":"Saeed Banaeian Far and Azadeh Imani Rad. 2022. Applying digital twins in metaverse: User interface, security and privacy challenges. J. Metaverse 2, 1 (2022), 8\u201316.","journal-title":"J. Metaverse"},{"key":"e_1_3_2_48_2","unstructured":"M. L. FAT. 2018. Fairness accountability and transparency in machine learning. Retrieved August 22 2023 from https:\/\/www.fatml.org\/"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.02021"},{"key":"e_1_3_2_50_2","article-title":"Life, the metaverse and everything: An overview of privacy, ethics, and governance in metaverse","author":"Fernandez Carlos Bermejo","year":"2022","unstructured":"Carlos Bermejo Fernandez and Pan Hui. 2022. Life, the metaverse and everything: An overview of privacy, ethics, and governance in metaverse. arXiv preprint arXiv:2204.01480 (2022).","journal-title":"arXiv preprint arXiv:2204.01480"},{"key":"e_1_3_2_51_2","article-title":"Adversarial examples for semantic image segmentation","author":"Fischer Volker","year":"2017","unstructured":"Volker Fischer, Mummadi Chaithanya Kumar, Jan Hendrik Metzen, and Thomas Brox. 2017. Adversarial examples for semantic image segmentation. arXiv preprint arXiv:1703.01101 (2017).","journal-title":"arXiv preprint arXiv:1703.01101"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1145\/3173574.3173950"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-81907-1"},{"key":"e_1_3_2_54_2","article-title":"Bae: BERT-based adversarial examples for text classification","author":"Garg Siddhant","year":"2020","unstructured":"Siddhant Garg and Goutham Ramakrishnan. 2020. Bae: BERT-based adversarial examples for text classification. arXiv preprint arXiv:2004.01970 (2020).","journal-title":"arXiv preprint arXiv:2004.01970"},{"key":"e_1_3_2_55_2","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow Ian J.","year":"2014","unstructured":"Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014).","journal-title":"arXiv preprint arXiv:1412.6572"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.12341"},{"key":"e_1_3_2_57_2","article-title":"Towards deep neural network architectures robust to adversarial examples","author":"Gu Shixiang","year":"2014","unstructured":"Shixiang Gu and Luca Rigazio. 2014. Towards deep neural network architectures robust to adversarial examples. arXiv preprint arXiv:1412.5068 (2014).","journal-title":"arXiv preprint arXiv:1412.5068"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1145\/3236009"},{"key":"e_1_3_2_60_2","unstructured":"David Gunning. 2017. Explainable artificial intelligence (XAI). Defense Advanced Research Projects Agency (DARPA) Retrieved August 22 2023 from https:\/\/www.darpa.mil\/program\/explainable-artificialintelligence"},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-48230-5_11"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58610-2_15"},{"key":"e_1_3_2_63_2","volume-title":"Proceedings of the 11th USENIX Workshop on Offensive Technologies (WOOT\u201917)","author":"He Warren","year":"2017","unstructured":"Warren He, James Wei, Xinyun Chen, Nicholas Carlini, and Dawn Song. 2017. Adversarial example defense: Ensembles of weak defenses are not strong. In Proceedings of the 11th USENIX Workshop on Offensive Technologies (WOOT\u201917)."},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1109\/VSMM.2016.7863165"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.300"},{"key":"e_1_3_2_66_2","article-title":"Distilling the knowledge in a neural network","author":"Hinton Geoffrey","year":"2015","unstructured":"Geoffrey Hinton, Oriol Vinyals, and Jeff Dean. 2015. Distilling the knowledge in a neural network. arXiv:1503.02531 (2015).","journal-title":"arXiv:1503.02531"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2021.10.007"},{"key":"e_1_3_2_68_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2019.07.040"},{"key":"e_1_3_2_69_2","article-title":"Artificial intelligence for the metaverse: A survey","author":"Huynh-The Thien","year":"2022","unstructured":"Thien Huynh-The, Quoc-Viet Pham, Xuan-Qui Pham, Thanh Thi Nguyen, Zhu Han, and Dong-Seong Kim. 2022. Artificial intelligence for the metaverse: A survey. arXiv preprint arXiv:2202.10336 (2022).","journal-title":"arXiv preprint arXiv:2202.10336"},{"key":"e_1_3_2_70_2","article-title":"The threat of adversarial attacks on machine learning in network security\u2014A survey","author":"Ibitoye Olakunle","year":"2019","unstructured":"Olakunle Ibitoye, Rana Abou-Khamis, Ashraf Matrawy, and M. Omair Shafiq. 2019. The threat of adversarial attacks on machine learning in network security\u2014A survey. arXiv preprint arXiv:1911.02621 (2019).","journal-title":"arXiv preprint arXiv:1911.02621"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/BigDataSecurityHPSCIDS54978.2022.00050"},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i05.6311"},{"key":"e_1_3_2_73_2","article-title":"Acoustic cues increase situational awareness in accident situations: A VR car-driving study","author":"Ju Uijong","year":"2020","unstructured":"Uijong Ju, Lewis L. Chuang, and Christian Wallraven. 2020. Acoustic cues increase situational awareness in accident situations: A VR car-driving study. IEEE Trans. Intell. Transport. Syst. (2020).","journal-title":"IEEE Trans. Intell. Transport. Syst."},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274740"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN48605.2020.9207635"},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.1109\/IOLTS.2019.8854377"},{"key":"e_1_3_2_78_2","article-title":"Security of virtual reality authentication methods in metaverse: An overview","author":"K\u00fcrt\u00fcnl\u00fco\u011flu P\u0131nar","year":"2022","unstructured":"P\u0131nar K\u00fcrt\u00fcnl\u00fco\u011flu, Beste Akdik, and Enis Karaarslan. 2022. Security of virtual reality authentication methods in metaverse: An overview. arXiv preprint arXiv:2209.06447 (2022).","journal-title":"arXiv preprint arXiv:2209.06447"},{"key":"e_1_3_2_79_2","doi-asserted-by":"publisher","DOI":"10.5555\/3265212"},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.1109\/MTS.2019.2930273"},{"key":"e_1_3_2_81_2","doi-asserted-by":"publisher","DOI":"10.1518\/hfes.46.1.50.30392"},{"key":"e_1_3_2_82_2","article-title":"All one needs to know about metaverse: A complete survey on technological singularity, virtual ecosystem, and research agenda","author":"Lee Lik-Hang","year":"2021","unstructured":"Lik-Hang Lee, Tristan Braud, Pengyuan Zhou, Lin Wang, Dianlei Xu, Zijun Lin, Abhishek Kumar, Carlos Bermejo, and Pan Hui. 2021. All one needs to know about metaverse: A complete survey on technological singularity, virtual ecosystem, and research agenda. arXiv preprint arXiv:2110.05352 (2021).","journal-title":"arXiv preprint arXiv:2110.05352"},{"key":"e_1_3_2_83_2","article-title":"On physical adversarial patches for object detection","author":"Lee Mark","year":"2019","unstructured":"Mark Lee and Zico Kolter. 2019. On physical adversarial patches for object detection. arXiv preprint arXiv:1906.11897 (2019).","journal-title":"arXiv preprint arXiv:1906.11897"},{"key":"e_1_3_2_84_2","article-title":"Textbugger: Generating adversarial text against real-world applications","author":"Li Jinfeng","year":"2018","unstructured":"Jinfeng Li, Shouling Ji, Tianyu Du, Bo Li, and Ting Wang. 2018. Textbugger: Generating adversarial text against real-world applications. arXiv preprint arXiv:1812.05271 (2018).","journal-title":"arXiv preprint arXiv:1812.05271"},{"key":"e_1_3_2_85_2","article-title":"BERT-attack: Adversarial attack against BERT using BERT","author":"Li Linyang","year":"2020","unstructured":"Linyang Li, Ruotian Ma, Qipeng Guo, Xiangyang Xue, and Xipeng Qiu. 2020. BERT-attack: Adversarial attack against BERT using BERT. arXiv preprint arXiv:2004.09984 (2020).","journal-title":"arXiv preprint arXiv:2004.09984"},{"key":"e_1_3_2_86_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01618"},{"key":"e_1_3_2_87_2","article-title":"Hidden backdoor attack against semantic segmentation models","author":"Li Yiming","year":"2021","unstructured":"Yiming Li, Yanjie Li, Yalei Lv, Yong Jiang, and Shu-Tao Xia. 2021. Hidden backdoor attack against semantic segmentation models. arXiv preprint arXiv:2103.04038 (2021).","journal-title":"arXiv preprint arXiv:2103.04038"},{"key":"e_1_3_2_88_2","doi-asserted-by":"publisher","DOI":"10.1145\/3313831.3376590"},{"key":"e_1_3_2_89_2","article-title":"Human-centered explainable ai (XAI): From algorithms to user experiences","author":"Liao Q. Vera","year":"2021","unstructured":"Q. Vera Liao and Kush R. Varshney. 2021. Human-centered explainable ai (XAI): From algorithms to user experiences. arXiv preprint arXiv:2110.10790 (2021).","journal-title":"arXiv preprint arXiv:2110.10790"},{"key":"e_1_3_2_90_2","article-title":"Free-riders in federated learning: Attacks and defenses","author":"Lin Jierui","year":"2019","unstructured":"Jierui Lin, Min Du, and Jian Liu. 2019. Free-riders in federated learning: Attacks and defenses. arXiv preprint arXiv:1911.12560 (2019).","journal-title":"arXiv preprint arXiv:1911.12560"},{"key":"e_1_3_2_91_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.56"},{"key":"e_1_3_2_92_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2018.2848960"},{"key":"e_1_3_2_93_2","volume-title":"Extended Reality in Practice","author":"Marr Bernard","year":"2021","unstructured":"Bernard Marr. 2021. Extended Reality in Practice. Wiley."},{"key":"e_1_3_2_94_2","article-title":"A survey on bias and fairness in machine learning","author":"Mehrabi Ninareh","year":"2019","unstructured":"Ninareh Mehrabi, Fred Morstatter, Nripsuta Saxena, Kristina Lerman, and Aram Galstyan. 2019. A survey on bias and fairness in machine learning. arXiv preprint arXiv:1908.09635 (2019).","journal-title":"arXiv preprint arXiv:1908.09635"},{"key":"e_1_3_2_95_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA52953.2021.00009"},{"key":"e_1_3_2_96_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.artint.2018.07.007"},{"key":"e_1_3_2_97_2","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140451"},{"key":"e_1_3_2_98_2","article-title":"Metachain: A novel blockchain-based framework for metaverse applications","author":"Nguyen Cong T.","year":"2021","unstructured":"Cong T. Nguyen, Dinh Thai Hoang, Diep N. Nguyen, and Eryk Dutkiewicz. 2021. Metachain: A novel blockchain-based framework for metaverse applications. arXiv preprint arXiv:2201.00759 (2021).","journal-title":"arXiv preprint arXiv:2201.00759"},{"key":"e_1_3_2_99_2","article-title":"A survey on metaverse: The state-of-the-art, technologies, applications, and challenges","author":"Ning Huansheng","year":"2021","unstructured":"Huansheng Ning, Hang Wang, Yujia Lin, Wenxi Wang, Sahraoui Dhelim, Fadi Farha, Jianguo Ding, and Mahmoud Daneshmand. 2021. A survey on metaverse: The state-of-the-art, technologies, applications, and challenges. arXiv preprint arXiv:2111.09673 (2021).","journal-title":"arXiv preprint arXiv:2111.09673"},{"key":"e_1_3_2_100_2","doi-asserted-by":"publisher","DOI":"10.1002\/widm.1356"},{"key":"e_1_3_2_101_2","unstructured":"Immersive and Addictive Technologies UK House of Commons DCMS Committee UK Parliament. 2019. Retrieved August 22 2023 from https:\/\/publications.parliament.uk\/pa\/cm201719\/cmselect\/cmcumeds\/1846\/1846.pdf"},{"key":"e_1_3_2_102_2","first-page":"619","volume-title":"Proceedings of the 25th USENIX Security Symposium (USENIX Security\u201916)","author":"Ohrimenko Olga","year":"2016","unstructured":"Olga Ohrimenko, Felix Schuster, C\u00e9dric Fournet, Aastha Mehta, Sebastian Nowozin, Kapil Vaswani, and Manuel Costa. 2016. Oblivious multi-party machine learning on trusted processors. In Proceedings of the 25th USENIX Security Symposium (USENIX Security\u201916). 619\u2013636."},{"key":"e_1_3_2_103_2","doi-asserted-by":"publisher","DOI":"10.3389\/fdata.2019.00013"},{"key":"e_1_3_2_104_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2020.2979670"},{"key":"e_1_3_2_105_2","first-page":"3611","volume-title":"Proceedings of the 31st USENIX Security Symposium (USENIX Security\u201922)","author":"Pan Xudong","year":"2022","unstructured":"Xudong Pan, Mi Zhang, Beina Sheng, Jiaming Zhu, and Min Yang. 2022. Hidden trigger backdoor attack on NLP models via linguistic style manipulation. In Proceedings of the 31st USENIX Security Symposium (USENIX Security\u201922). 3611\u20133628."},{"key":"e_1_3_2_106_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"issue":"441","key":"e_1_3_2_107_2","article-title":"197: Advanced encryption standard (AES)","volume":"197","author":"Pub NIST FIPS","year":"2001","unstructured":"NIST FIPS Pub. 2001. 197: Advanced encryption standard (AES). Fed. Inf. Process. Stand. Pub. 197, 441 (2001).","journal-title":"Fed. Inf. Process. Stand. Pub."},{"key":"e_1_3_2_108_2","doi-asserted-by":"publisher","DOI":"10.1108\/JICES-06-2021-0059"},{"key":"e_1_3_2_109_2","doi-asserted-by":"publisher","DOI":"10.1109\/OJCS.2022.3206407"},{"key":"e_1_3_2_110_2","doi-asserted-by":"publisher","DOI":"10.3389\/fdata.2020.587139"},{"key":"e_1_3_2_111_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102827"},{"key":"e_1_3_2_112_2","doi-asserted-by":"publisher","DOI":"10.1109\/RBME.2020.3013489"},{"key":"e_1_3_2_113_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2020.2975048"},{"key":"e_1_3_2_114_2","first-page":"5231","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Qin Yao","year":"2019","unstructured":"Yao Qin, Nicholas Carlini, Garrison Cottrell, Ian Goodfellow, and Colin Raffel. 2019. Imperceptible, robust, and targeted adversarial examples for automatic speech recognition. In Proceedings of the International Conference on Machine Learning. PMLR, 5231\u20135240."},{"key":"e_1_3_2_115_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.compbiomed.2022.106043"},{"key":"e_1_3_2_116_2","first-page":"114","article-title":"The combination of artificial intelligence and extended reality: A systematic review","author":"Reiners Dirk","year":"2021","unstructured":"Dirk Reiners, Mohammad Reza Davahli, Waldemar Karwowski, and Carolina Cruz-Neira. 2021. The combination of artificial intelligence and extended reality: A systematic review. Front. Virt. Real. 2 (2021), 114.","journal-title":"Front. Virt. Real."},{"key":"e_1_3_2_117_2","doi-asserted-by":"publisher","DOI":"10.1145\/3338498.3358646"},{"key":"e_1_3_2_118_2","doi-asserted-by":"publisher","DOI":"10.1145\/359340.359342"},{"key":"e_1_3_2_119_2","doi-asserted-by":"publisher","DOI":"10.1145\/3546607.3546611"},{"key":"e_1_3_2_120_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11504"},{"key":"e_1_3_2_121_2","doi-asserted-by":"publisher","DOI":"10.1038\/s42256-019-0048-x"},{"key":"e_1_3_2_122_2","doi-asserted-by":"publisher","DOI":"10.1109\/LWC.2018.2867459"},{"key":"e_1_3_2_123_2","doi-asserted-by":"publisher","DOI":"10.1109\/SAHCN.2019.8824956"},{"key":"e_1_3_2_124_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3093005"},{"key":"e_1_3_2_125_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2018.02.007"},{"key":"e_1_3_2_126_2","article-title":"Poison frogs! Targeted clean-label poisoning attacks on neural networks","volume":"31","author":"Shafahi Ali","year":"2018","unstructured":"Ali Shafahi, W. Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein. 2018. Poison frogs! Targeted clean-label poisoning attacks on neural networks. Adv. Neural Inf. Process. Syst. 31 (2018).","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"e_1_3_2_127_2","first-page":"197","volume-title":"Proceedings of the IEEE Canada International Humanitarian Technology Conference","author":"Shahriari Kyarash","year":"2017","unstructured":"Kyarash Shahriari and Mana Shahriari. 2017. IEEE standard review\u2014Ethically aligned design: A vision for prioritizing human wellbeing with artificial intelligence and autonomous systems. In Proceedings of the IEEE Canada International Humanitarian Technology Conference. IEEE, 197\u2013201."},{"key":"e_1_3_2_128_2","article-title":"ARSpy: Breaking location-based multi-player augmented reality application for user location tracking","author":"Shang Jiacheng","year":"2020","unstructured":"Jiacheng Shang, Si Chen, Jie Wu, and Shu Yin. 2020. ARSpy: Breaking location-based multi-player augmented reality application for user location tracking. IEEE Trans. Mob. Comput. 21, 2 (2020).","journal-title":"IEEE Trans. Mob. Comput."},{"key":"e_1_3_2_129_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"e_1_3_2_130_2","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.011.1900630"},{"key":"e_1_3_2_131_2","doi-asserted-by":"publisher","DOI":"10.1145\/3351261"},{"key":"e_1_3_2_132_2","doi-asserted-by":"publisher","DOI":"10.1080\/10447318.2020.1741118"},{"key":"e_1_3_2_133_2","volume-title":"Proceedings of the International Conference on Learning Representations (ICLR\u201918)","author":"Song Yang","year":"2018","unstructured":"Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman. 2018. PixelDefend: Leveraging generative models to understand and defend against adversarial examples. In Proceedings of the International Conference on Learning Representations (ICLR\u201918)."},{"key":"e_1_3_2_134_2","article-title":"Data encryption standard","volume":"112","author":"Standard Data Encryption","year":"1999","unstructured":"Data Encryption Standard et\u00a0al. 1999. Data encryption standard. Fed. Inf. Process. Stand. Pub. 112 (1999).","journal-title":"Fed. Inf. Process. Stand. Pub."},{"key":"e_1_3_2_135_2","article-title":"Certified defenses for data poisoning attacks","volume":"30","author":"Steinhardt Jacob","year":"2017","unstructured":"Jacob Steinhardt, Pang Wei W. Koh, and Percy S. Liang. 2017. Certified defenses for data poisoning attacks. Adv. Neural Inf. Process. Syst. 30 (2017).","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"e_1_3_2_136_2","article-title":"A framework for understanding unintended consequences of machine learning","author":"Suresh Harini","year":"2019","unstructured":"Harini Suresh and John V. Guttag. 2019. A framework for understanding unintended consequences of machine learning. arXiv (2019).","journal-title":"arXiv"},{"key":"e_1_3_2_137_2","article-title":"Intriguing properties of neural networks","author":"Szegedy Christian","year":"2013","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013).","journal-title":"arXiv preprint arXiv:1312.6199"},{"key":"e_1_3_2_138_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2961372"},{"key":"e_1_3_2_139_2","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2018.2873186"},{"key":"e_1_3_2_140_2","article-title":"Adversarial training and robustness for multiple perturbations","volume":"32","author":"Tramer Florian","year":"2019","unstructured":"Florian Tramer and Dan Boneh. 2019. Adversarial training and robustness for multiple perturbations. Adv. Neural Inf. Process. Syst. 32 (2019).","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"e_1_3_2_141_2","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2020.3042638"},{"key":"e_1_3_2_142_2","doi-asserted-by":"publisher","DOI":"10.1109\/IWCMC.2019.8766353"},{"key":"e_1_3_2_143_2","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2021.3049190"},{"key":"e_1_3_2_144_2","doi-asserted-by":"publisher","DOI":"10.1109\/LCNW.2018.8628538"},{"key":"e_1_3_2_145_2","article-title":"Black-box adversarial ML attack on modulation classification","author":"Usama Muhammad","year":"2019","unstructured":"Muhammad Usama, Junaid Qadir, and Ala Al-Fuqaha. 2019. Black-box adversarial ML attack on modulation classification. arXiv (2019).","journal-title":"arXiv"},{"key":"e_1_3_2_146_2","doi-asserted-by":"publisher","DOI":"10.1109\/UCET.2019.8881842"},{"key":"e_1_3_2_147_2","doi-asserted-by":"publisher","DOI":"10.1093\/acprof:oso\/9780190498511.001.0001"},{"key":"e_1_3_2_148_2","doi-asserted-by":"publisher","DOI":"10.1109\/CCNC46108.2020.9045724"},{"key":"e_1_3_2_149_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.09.027"},{"key":"e_1_3_2_150_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2021.3131711"},{"key":"e_1_3_2_151_2","article-title":"A survey on metaverse: Fundamentals, security, and privacy","author":"Wang Yuntao","year":"2022","unstructured":"Yuntao Wang, Zhou Su, Ning Zhang, Rui Xing, Dongxiao Liu, Tom H. Luan, and Xuemin Shen. 2022. A survey on metaverse: Fundamentals, security, and privacy. IEEE Commun. Surv. Tutor. 25, 1 (2022).","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"e_1_3_2_152_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2020.102634"},{"key":"e_1_3_2_153_2","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2008.74"},{"key":"e_1_3_2_154_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3026366"},{"key":"e_1_3_2_155_2","article-title":"Transferable adversarial attacks for image and video object detection","author":"Wei Xingxing","year":"2018","unstructured":"Xingxing Wei, Siyuan Liang, Ning Chen, and Xiaochun Cao. 2018. Transferable adversarial attacks for image and video object detection. arXiv preprint arXiv:1811.12641 (2018).","journal-title":"arXiv preprint arXiv:1811.12641"},{"key":"e_1_3_2_156_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00614"},{"key":"e_1_3_2_157_2","article-title":"Analytic review of using augmented reality for situational awareness","author":"Woodward Julia","year":"2022","unstructured":"Julia Woodward and Jaime Ruiz. 2022. Analytic review of using augmented reality for situational awareness. IEEE Trans. Visualiz. Comput. Graph. 29, 4 (2022).","journal-title":"IEEE Trans. Visualiz. Comput. Graph."},{"key":"e_1_3_2_158_2","article-title":"Just rotate it: Deploying backdoor attacks via rotation transformation","author":"Wu Tong","year":"2022","unstructured":"Tong Wu, Tianhao Wang, Vikash Sehwag, Saeed Mahloujifar, and Prateek Mittal. 2022. Just rotate it: Deploying backdoor attacks via rotation transformation. arXiv preprint arXiv:2207.10825 (2022).","journal-title":"arXiv preprint arXiv:2207.10825"},{"key":"e_1_3_2_159_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00229"},{"key":"e_1_3_2_160_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00935"},{"key":"e_1_3_2_161_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Xie Chulin","year":"2019","unstructured":"Chulin Xie, Keli Huang, Pin-Yu Chen, and Bo Li. 2019. DBA: Distributed backdoor attacks against federated learning. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_2_162_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.153"},{"key":"e_1_3_2_163_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9053747"},{"key":"e_1_3_2_164_2","article-title":"A full dive into realizing the edge-enabled metaverse: Visions, enabling technologies, and challenges","author":"Xu Minrui","year":"2022","unstructured":"Minrui Xu, Wei Chong Ng, Wei Yang Bryan Lim, Jiawen Kang, Zehui Xiong, Dusit Niyato, Qiang Yang, Xuemin Sherman Shen, and Chunyan Miao. 2022. A full dive into realizing the edge-enabled metaverse: Visions, enabling technologies, and challenges. arXiv preprint arXiv:2203.05471 (2022).","journal-title":"arXiv preprint arXiv:2203.05471"},{"key":"e_1_3_2_165_2","article-title":"Feature squeezing: Detecting adversarial examples in deep neural networks","author":"Xu Weilin","year":"2017","unstructured":"Weilin Xu, David Evans, and Yanjun Qi. 2017. Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv preprint arXiv:1704.01155 (2017).","journal-title":"arXiv preprint arXiv:1704.01155"},{"key":"e_1_3_2_166_2","volume-title":"Proceedings of the Network and Distributed Systems Symposium","author":"Xu Weilin","year":"2016","unstructured":"Weilin Xu, Yanjun Qi, and David Evans. 2016. Automatically evading classifiers. In Proceedings of the Network and Distributed Systems Symposium."},{"key":"e_1_3_2_167_2","doi-asserted-by":"publisher","DOI":"10.1007\/s12083-020-01031-z"},{"key":"e_1_3_2_168_2","doi-asserted-by":"publisher","DOI":"10.1109\/OJCS.2022.3188249"},{"key":"e_1_3_2_169_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354261"},{"key":"e_1_3_2_170_2","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1986.25"},{"key":"e_1_3_2_171_2","doi-asserted-by":"publisher","DOI":"10.1017\/ilm.2020.5"},{"key":"e_1_3_2_172_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"e_1_3_2_173_2","article-title":"Defending against neural fake news","volume":"32","author":"Zellers Rowan","year":"2019","unstructured":"Rowan Zellers, Ari Holtzman, Hannah Rashkin, Yonatan Bisk, Ali Farhadi, Franziska Roesner, and Yejin Choi. 2019. Defending against neural fake news. Adv. Neural Inf. Process. Syst. 32 (2019).","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"e_1_3_2_174_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICME46284.2020.9102805"},{"key":"e_1_3_2_175_2","doi-asserted-by":"publisher","DOI":"10.1109\/BigData50022.2020.9378234"},{"key":"e_1_3_2_176_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.153"},{"key":"e_1_3_2_177_2","article-title":"Metaverse: Security and privacy concerns","author":"Zhao Ruoyu","year":"2022","unstructured":"Ruoyu Zhao, Yushu Zhang, Youwen Zhu, Rushi Lan, and Zhongyun Hua. 2022. Metaverse: Security and privacy concerns. arXiv preprint arXiv:2203.03854 (2022).","journal-title":"arXiv preprint arXiv:2203.03854"},{"key":"e_1_3_2_178_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3036801"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3614426","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3614426","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T22:50:30Z","timestamp":1750287030000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3614426"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,9]]},"references-count":177,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2024,7,31]]}},"alternative-id":["10.1145\/3614426"],"URL":"https:\/\/doi.org\/10.1145\/3614426","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,4,9]]},"assertion":[{"value":"2022-10-14","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-08-03","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-04-09","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}