{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T13:13:36Z","timestamp":1779974016881,"version":"3.53.1"},"reference-count":28,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T00:00:00Z","timestamp":1779926400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Proc. ACM Hum.-Comput. Interact."],"published-print":{"date-parts":[[2026,5,31]]},"abstract":"<jats:p>Recent advances in extended reality (XR) have enabled seamless access to immersive services. However, user authentication in these environments typically relies on conventional methods, such as PIN entry, which remains vulnerable to unauthorized use. This paper investigates gaze behavior as an implicit second authentication factor in XR. Using a Meta Quest Pro headset, participants performed legitimate and impostor login attempts while their gaze data were recorded. Temporal, spatial, and oculomotor metrics revealed distinctive and reproducible gaze dynamics between user roles. Tree-based machine learning models, particularly XGBoost, reliably distinguished legitimate from impostor sessions under user-independent validation (AUC =.84). Calibrating model thresholds further enabled adaptive balancing between security and usability. These findings demonstrate that gaze dynamics can unobtrusively enhance PIN authentication, introducing an adaptive layer that aligns authentication sensitivity with situational risk and user needs in immersive environments.<\/jats:p>","DOI":"10.1145\/3806028","type":"journal-article","created":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T12:44:33Z","timestamp":1779972273000},"page":"1-17","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Gaze as an Implicit Second Authentication Factor when using PIN Mechanisms in Extended Reality ETRA014"],"prefix":"10.1145","volume":"10","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-7136-4625","authenticated-orcid":false,"given":"Eleni","family":"Chrysopoulou","sequence":"first","affiliation":[{"name":"Department of Informatics","place":["Thessaloniki, Greece"]},{"name":"Aristotle University of Thessaloniki","place":["Thessaloniki, Greece"]},{"name":"Human Opsis","place":["Thessaloniki, Greece"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-5412-7125","authenticated-orcid":false,"given":"Maria","family":"Karlaki","sequence":"additional","affiliation":[{"name":"Department of Informatics","place":["Thessaloniki, Greece"]},{"name":"Aristotle University of Thessaloniki","place":["Thessaloniki, Greece"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9805-8400","authenticated-orcid":false,"given":"George E.","family":"Raptis","sequence":"additional","affiliation":[{"name":"Human Opsis","place":["Patras, Greece"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9031-3083","authenticated-orcid":false,"given":"Christos","family":"Katsanos","sequence":"additional","affiliation":[{"name":"Department of Informatics","place":["Thessaloniki, Greece"]},{"name":"Aristotle University of Thessaloniki","place":["Thessaloniki, Greece"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,5,28]]},"reference":[{"key":"e_1_3_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3531073.3531092"},{"key":"e_1_3_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCB48548.2020.9304919"},{"key":"e_1_3_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-48051-9_22"},{"key":"e_1_3_1_5_1","series-title":"(SOUPS\u201921)","volume-title":"Seventeenth Symposium on Usable Privacy and Security","author":"Cho Geumhwan","year":"2021","unstructured":"Geumhwan Cho, Sungsu Kwag, Jun\u00a0Ho Huh, Bedeuro Kim, Choong-Hoon Lee, and Hyoungshick Kim. 2021. Towards Usable and Secure Location-based Smartphone Authentication. In Seventeenth Symposium on Usable Privacy and Security(SOUPS\u201921). USENIX Association, Berkeley, CA, USA, Article 1, 15\u00a0pages."},{"key":"e_1_3_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3546155.3546663"},{"key":"e_1_3_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3448018.3458007"},{"key":"e_1_3_1_8_1","doi-asserted-by":"publisher","unstructured":"Meriem Guerar Luca Verderame Alessio Merlo Francesco Palmieri Mauro Migliardi and Luca Vallerini. 2020. CirclePIN: A Novel Authentication Mechanism for Smartwatches to Prevent Unauthorized Access to IoT Devices. ACM Trans. Cyber-Phys. Syst. 4 3 Article 34 (March 2020) 19\u00a0pages. doi:10.1145\/3365995","DOI":"10.1145\/3365995"},{"key":"e_1_3_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3290607.3313076"},{"key":"e_1_3_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3174910.3174936"},{"key":"e_1_3_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3313831.3376840"},{"key":"e_1_3_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3756884.3766056"},{"key":"e_1_3_1_13_1","doi-asserted-by":"publisher","unstructured":"Christina Katsini Gregory Epiphaniou and Carsten Maple. 2026. AURA-XR: A Risk-based Methodology for the Optimal Selection of User Authentication Mechanisms in Extended Reality. Computers & Security 162 (2026) 22\u00a0pages. doi:10.1016\/j.cose.2025.104779","DOI":"10.1016\/j.cose.2025.104779"},{"key":"e_1_3_1_14_1","doi-asserted-by":"publisher","unstructured":"Nabeela Kausar Ikram\u00a0Ud Din Mudassar\u00a0Ali Khan Ahmad Almogren and Byung-Seo Kim. 2022. GRA-PIN: A Graphical and PIN-Based Hybrid Authentication Approach for Smart Devices. Sensors (Basel) 22 4 (Feb. 2022) 1349. doi:10.3390\/s22041349","DOI":"10.3390\/s22041349"},{"key":"e_1_3_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/NTMS.2018.8328719"},{"key":"e_1_3_1_16_1","doi-asserted-by":"publisher","unstructured":"Yan Li Yao Cheng Weizhi Meng Yingjiu Li and Robert\u00a0H Deng. 2020. Designing Leakage-resilient Password Entry on Head-mounted Smart Wearable Glass Devices. IEEE Transactions on Information Forensics and security 16 (2020) 307\u2013321. doi:10.1109\/TIFS.2020.3013212","DOI":"10.1109\/TIFS.2020.3013212"},{"key":"e_1_3_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3489849.3489880"},{"key":"e_1_3_1_18_1","doi-asserted-by":"publisher","unstructured":"Dillon Lohr and Oleg\u00a0V. Komogortsev. 2022. Eye Know You Too: Toward Viable End-to-End Eye Movement Biometrics for User Authentication. IEEE Transactions on Information Forensics and Security 17 (2022) 3151\u20133164. doi:10.1109\/TIFS.2022.3201369","DOI":"10.1109\/TIFS.2022.3201369"},{"key":"e_1_3_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/ijcb62174.2024.10744483"},{"key":"e_1_3_1_20_1","doi-asserted-by":"publisher","unstructured":"Florian Mathis John\u00a0H. Williamson Kami Vaniea and Mohamed Khamis. 2021. Fast and Secure Authentication in Virtual Reality Using Coordinated 3D Manipulation and Pointing. ACM Transactions on Computer-Human Interaction 28 1 (Jan. 2021) 1\u201344. doi:10.1145\/3428121","DOI":"10.1145\/3428121"},{"key":"e_1_3_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW67616.2025.00063"},{"key":"e_1_3_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3519391.3519411"},{"key":"e_1_3_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-54776-8_16"},{"key":"e_1_3_1_24_1","doi-asserted-by":"publisher","unstructured":"Yiran Shen Hongkai Wen Chengwen Luo Weitao Xu Tao Zhang Wen Hu and Daniela Rus. 2019. GaitLock: Protect Virtual and Augmented Reality Headsets Using Gait. IEEE Transactions on Dependable and Secure Computing 16 3 (2019) 484\u2013497. doi:10.1109\/TDSC.2018.2800048","DOI":"10.1109\/TDSC.2018.2800048"},{"key":"e_1_3_1_25_1","doi-asserted-by":"publisher","unstructured":"Yannick Weiss Steeven Villa Jesse\u00a0W Grootjen Matthias Hoppe Yasin Kale and Florian M\u00fcller. 2024. Exploring Redirection and Shifting Techniques to Mask Hand Movements from Shoulder-Surfing Attacks during PIN Authentication in Virtual Reality. Proc. ACM Hum.-Comput. Interact. 8 MHCI Article 257 (Sept. 2024) 24\u00a0pages. doi:10.1145\/3676502","DOI":"10.1145\/3676502"},{"key":"e_1_3_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/2702123.2702316"},{"key":"e_1_3_1_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-48051-9_21"},{"key":"e_1_3_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3393527.3393551"},{"key":"e_1_3_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2017.7997251"}],"container-title":["Proceedings of the ACM on Human-Computer Interaction"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3806028","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T12:59:54Z","timestamp":1779973194000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3806028"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,28]]},"references-count":28,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2026,5,31]]}},"alternative-id":["10.1145\/3806028"],"URL":"https:\/\/doi.org\/10.1145\/3806028","relation":{},"ISSN":["2573-0142"],"issn-type":[{"value":"2573-0142","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,28]]},"assertion":[{"value":"2026-05-28","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}