Source-linked AI summary

A Survey on Metaverse: Fundamentals, Security, and Privacy

Yuntao Wang, Zhou Su, Ning Zhang, Rui Xing, Dongxiao Liu, Tom H. Luan, Xuemin Shen

arXiv:2203.02662v4cs.CR

TL;DR

The metaverse’s open, immersive, decentralized, and heterogeneous character creates security, privacy, governance, ownership, and interoperability challenges. This paper surveys metaverse fundamentals, proposes a distributed architecture, reviews threats and countermeasures, and identifies directions for future research.

  • Problem

    Open and autonomous metaverse spaces complicate UGC ownership and provenance, expose immersive workplaces to monitoring and intrusion, and create difficulties applying existing laws to virtual crimes.

  • Method

    The paper surveys metaverse fundamentals, introduces a distributed architecture incorporating physical, human, and digital worlds, and reviews security and privacy threats, challenges, and countermeasures.

  • Results

    The survey identifies self-sovereign identity, wearable-signal and biometric authentication, blockchain-based identities, AI-enabled and decentralized governance, and cross-chain authentication as relevant countermeasure directions.

  • Takeaways & Limitations

    The survey aims to inform security and privacy provision in metaverse applications and inspire further technological and sociological research.

Abstract

from arXiv · show

Metaverse, as an evolving paradigm of the next-generation Internet, aims to build a fully immersive, hyper spatiotemporal, and self-sustaining virtual shared space for humans to play, work, and socialize. Driven by recent advances in emerging technologies such as extended reality, artificial intelligence, and blockchain, metaverse is stepping from science fiction to an upcoming reality. However, severe privacy invasions and security breaches (inherited from underlying technologies or emerged in the new digital ecology) of metaverse can impede its wide deployment. At the same time, a series of fundamental challenges (e.g., scalability and interoperability) can arise in metaverse security provisioning owing to the intrinsic characteristics of metaverse, such as immersive realism, hyper spatiotemporality, sustainability, and heterogeneity. In this paper, we present a comprehensive survey of the fundamentals, security, and privacy of metaverse. Specifically, we first investigate a novel distributed metaverse architecture and its key characteristics with ternary-world interactions. Then, we discuss the security and privacy threats, present the critical challenges of metaverse systems, and review the state-of-the-art countermeasures. Finally, we draw open research directions for building future metaverse systems.

I. INTRODUCTION

The metaverse is an evolving next-generation Internet paradigm that blends physical, human, and digital worlds through emerging technologies. Its deployment faces serious security, privacy, scalability, interoperability, and adaptability challenges, motivating this comprehensive survey.

  • The metaverse is a fully immersive, hyper spatiotemporal, and self-sustaining virtual shared space blending physical, human, and digital worlds.
  • Emerging technologies including digital twins, XR, 5G, wearables, AI, blockchain, and NFTs support metaverse creation, interaction, connectivity, and asset ownership.
  • Metaverse development progresses from digital twins to digital natives and eventually surreality, moving from mirrored physical reality toward persistent virtual–physical symbiosis.
  • Security and privacy threats span massive data management, pervasive profiling, unfair AI outcomes, infrastructure safety, and risks inherited from underlying technologies.
  • Immersiveness, hyper spatiotemporality, sustainability, interoperability, scalability, and heterogeneity make existing security countermeasures ineffective or insufficiently adaptable.
  • The survey examines metaverse fundamentals, architecture, technologies, applications, security and privacy threats, countermeasures, challenges, and open research directions.

B. Metaverse Architecture

The proposed metaverse architecture integrates human, physical, and digital worlds through avatars, environments, goods, services, and bidirectional information flows. It emphasizes interconnected virtual worlds and lifecycle protection for real-time data.

  • The metaverse integrates human, physical, and digital worlds into a self-sustaining, hyper spatiotemporal, 3D immersive virtual shared space.
  • Human users control digital avatars through HCI and XR technologies to play, work, socialize, and interact with virtual entities.
  • Physical infrastructures provide sensing, communication, computation, storage, and control capabilities for multimodal data perception and interaction.
  • Interconnected virtual worlds: The digital world consists of interconnected sub-metaverses offering virtual goods, services, and environments to avatar users.
  • Metaverse components: Avatars represent users, while virtual environments provide simulated real or imaginary spaces and virtual goods/services support trade and digital activities.
  • Information flow: Metaverse information comes from real-world inputs and virtual-world outputs, requiring authentication, access control, reliability, traceability, and privacy protection across the data lifecycle.

4) Metaverse Engine:

The metaverse engine processes real-world big data to generate and maintain virtual worlds, enabling immersive avatar control and interactions across human, physical, and digital worlds.

  • The metaverse engine uses real-world big data to generate, maintain, and update virtual worlds through interactivity, AI, digital twins, and blockchain.
  • Users can immersively control avatars through their senses and bodies for collective activities such as car racing, dating, and virtual-item trading.
  • Human, physical, and digital worlds are connected through social networks, IoT sensing and control infrastructure, the Internet, and HCI/XR technologies.
  • Processed physical and human-world information supports large-scale metaverse creation, rendering, services, and distribution of digital creations across sub-metaverses.
  • Metaverse users can move across virtual worlds, while immersive realism engages sensory perception and bodily expression in computer-generated spaces.
  • Hyper spatiotemporality allows users to move across worlds with different time-space dimensions and experience seamless scene transformation.
  • Sustainability requires a decentralized architecture that avoids single points of failure and control by a few powerful entities.

4) Interoperability:

Metaverse interoperability and scalability require seamless movement and asset exchange across heterogeneous worlds, devices, data, networks, and interaction modes.

  • 4) Interoperability: Interoperability allows users to move seamlessly across sub-metaverses and exchange virtual-world rendering or reconstruction assets across platforms.
  • 5) Scalability: Scalability is the capacity to remain efficient as concurrent users, scene complexity, and user/avatar interaction types, scopes, and ranges increase.
  • Heterogeneity spans virtual spaces, physical devices, data types, communication modes, and human psychology, and includes poor system interoperability.
  • Six technologies underlie the metaverse, with XR devices, digital twins, networking, ubiquitous computing, AI, and blockchain supporting its operation.
  • XR devices provide multisensory immersion and broaden interaction beyond phones and laptops, while edge computing and AI rendering can address dizziness and latency.
  • Digital twins mirror real-world objects and systems, using sensory streams, physical models, and historical information for prediction, optimization, self-learning, and self-adaptation.
  • 3) Networking: 6G, SDN, and IoT support ubiquitous access and real-time data transmission, while SDN dynamically allocates virtualized resources according to sub-metaverse demand.
  • 4) Ubiquitous Computing: AI enables personalized services, large-scale scene creation and rendering, multilingual support, and intelligent interactions from multimodal data.

E. Existing Modern Prototypes of Metaverse Applications

Existing metaverse prototypes span games, social and collaborative applications, 3D simulation, and creator economies, while the survey organizes systems by key characteristics and security concerns.

  • 1) Game: Games are presented as the current hottest metaverse application because of their technological maturity, user matching, and content adaptability.
  • 1) Game: Second Life and Roblox illustrate avatar-based worlds where users create virtual architectures, games, skins, clothes, and social experiences.
  • Metaverse social applications include virtual lives, shopping, dating, chatting, travel, and space/time travel, including a Roblox concert attended by over 30 million fans.
  • 3) Online Collaboration: Virtual collaboration supports telecommuting, learning, panels, and meetings through shared virtual rooms and holographic presence across physical locations.
  • Omniverse supports multi-user real-time 3D simulation and visualization of physical objects for industrial applications such as automotive design.
  • Content creation modes include professional-generated, professional- and user-generated, user-generated, and AI-generated content.
  • User-generated content offers high freedom, low cost, diversification, and decentralization, with users producing and freely trading content in platform marketplaces.
  • Decentraland and Cryptovoxels exemplify decentralized virtual worlds with blockchain-supported creator economies, asset trading, and user-built spaces.

A. Threats to Authentication in Metaverse

Metaverse authentication must protect user and avatar identities while supporting trusted interoperability across devices, platforms, domains, and virtual worlds.

  • Identity theft can expose or lose avatars, digital assets, social relationships, digital lives, personal information, and financial details.
  • Impersonation attacks use stolen behavioral, biological, or endpoint data to create digital replicas, fake avatars, or rogue wearable devices.
  • Avatar authentication is difficult because attackers can create AI bots that imitate users’ appearance, voice, and behavior.
  • Trusted authentication must operate quickly and efficiently across platforms, domains, blockchains, virtual worlds, asset exchanges, and avatar transfers.
  • Metaverse services generate biometric, routine, and habit data that different virtual service providers may access for personalized services.
  • Malicious providers may obtain unauthorized access by elevating data privileges through buffer overflows or tampered access-control lists.
  • User and avatar data may be intentionally or unintentionally disclosed for profiling and targeted advertising, while non-interoperability hinders tracing misuse.
  • Centralized, federated, and self-sovereign identities differ in control and administrative structure, with SSI allowing users to share information across domains with consent.

2) Identity Authentication for Wearable Devices:

Wearable-device security in the metaverse spans authentication, cross-domain access, privacy-preserving delegation, and protection of user-generated content and data integrity. The surveyed approaches combine cloud authentication, Bluetooth fingerprinting, blockchain, access control, and usage auditing, while scalability and evolving attack surfaces remain challenges.

  • Identity authentication: Cloud-based mutual authentication protects wearable medical devices against impersonation while supporting password changes and smart-card revocation.The model targets devices with extremely limited computing and storage capacity.
  • Identity authentication: Bluetooth-specific AI fingerprinting identifies wearable devices, with real tests on Google Nest Learning Thermostat and Nike+ Fuelband Fitness Tracker validating feasibility.The method uses representative wearable devices to assess functionality.
  • Cross-domain authentication: Blockchain-based schemes address authentication across administrative domains by reducing reliance on trusted intermediaries and improving cross-domain identity recognition.Cross-domain authentication must support distinct VR/AR service providers and standards.
  • Privacy protection: Wearable-device delegation can protect owners’ privacy during temporary lending, but associated attacks, scalability, and efficiency require further real-world investigation.The scheme provides privacy guarantees for delegated device use.
  • UGC protection: UGC security requires access control, usage control, auditing, and traitor tracing because shared content can contain sensitive information and be illegally redistributed.Blockchain and smart contracts support fine-grained usage policies and transparent policy audits.
  • Summary and lessons learned: Identity autonomy lets users manage UGCs, assets, and behavioral data across sub-metaverses, while biometrics, sensory-signal fusion, blockchain identities, and dynamic authentication remain research directions.The survey highlights continuous-time, cross-chain, and cross-domain authentication as open topics.
  • Data and asset security: Metaverse data faces tampering, false-data injection, sensitive-data management, ownership and provenance disputes, and intellectual-property protection challenges.These risks affect wearable data, physical inputs, UGCs, avatars, and AIGCs across virtual worlds.
  • Data and asset security: Decentralized metaverse governance makes UGC ownership and provenance difficult to trace and convert into protected assets across autonomous virtual worlds.The absence of a centralized authority complicates registration and accountability for content produced by many avatars.

B. Security Countermeasures to Metaverse Data Management

Data-management countermeasures address reliability, synchronization, quality, availability, and immersive interaction across metaverse systems. The surveyed work includes adversarial-learning defenses, digital-twin synchronization, scalable audio streaming, incentive mechanisms, and game-theoretic resource coordination.

  • Data reliability: AI-generated metaverse content can face adversarial and poisoned samples, motivating virtual adversarial, adversarial representation, and adversarial reinforcement learning defenses.These attacks are difficult for humans to detect directly.
  • Data synchronization: Digital-twin research defines synchronization consistency and security requirements, while programmable-logic-controller experiments validate a reliable state-replication method.Trustworthiness of data from disparate silos remains unaddressed in the cited work.
  • Immersive interaction: Peer-to-peer audio streaming uses area of interest and aural soundscape concepts to support scalable, proximal, spatialized interactions in immersive virtual worlds.Area of interest limits the distribution area of audio streams.
  • Data quality: Low-quality sensor inputs and avatar-generated UGC can reduce metaverse QoS and user QoE, making quality control important for service sustainability.A 68-participant VR user study links behavioral features with character believability.
  • Data quality: Game-theoretic and AI methods are used to motivate high-quality data contribution and service provision, including dynamic Stackelberg models for content caching.The content provider acts as leader and edge caching devices act as followers.
  • Data availability: Hierarchical games coordinate digital-twin synchronization and service-provider choices, while related work studies availability through synchronization and QoS.End devices gather physical-object status information and providers select synchronization strategies.
  • Immersive interaction: Degrees of freedom distinguish rotational movement in 3DoF from rotational plus translational movement in 6DoF along the x, y, and z axes.The distinction characterizes movement capabilities relevant to immersive interaction.

3) Secure Data Sharing in XR Environment:

Secure XR data sharing must protect content, physical inputs, identities, and behavioral data across interconnected worlds and devices. The survey emphasizes provenance, access control, privacy throughout the data lifecycle, and inherited vulnerabilities from enabling technologies.

  • Secure sharing: A HoloLens prototype supports inbound and outbound control for secure AR-content sharing among remote or colocated users.The work explores how users map AR content across application designs.
  • Provenance: UGC provenance enables source tracing, generation reproducibility, quality evaluation, and audit trails, but disparate data silos make real-time monitoring difficult.Provenance records may be distributed across distinct blockchains.
  • Provenance: Dynamic watermarking can detect malicious sensor or actuator behavior and support intellectual-property protection and ownership authentication.Blockchain-based provenance architectures organize collection, storage, and verification stages.
  • Provenance: UGC provenance spans ternary worlds and multiple sub-metaverses, creating scalability, trust, efficiency, and response-delay challenges for smart-contract enforcement.The survey calls for further research on smart-contract functionality, efficiency, and security.
  • Systemic security: Metaverse data management inherits vulnerabilities from its constituent technologies, while their interweaving can amplify existing threats.The survey presents countermeasure comparisons for metaverse data management.
  • Privacy risks: Privacy can be violated during data perception, transmission, processing, governance, and storage, including through pervasive profiling of facial, ocular, behavioral, and biometric signals.XR and HCI systems collect more granular user information than conventional interactions.
  • Privacy risks: Virtual workplaces may expose conversations, emails, browsing, behavior, and voice tones while also creating risks from intrusions, snooping, and impostors.The cited examples include Horizon Workroom and Microsoft Mesh.
  • Privacy risks: Transmission, processing, storage, compromised devices, and digital footprints create leakage and profiling risks despite encryption and other protections.Attackers may infer locations, reconstruct sensitive information, compromise cloud or edge storage, or exploit avatar behavior.

B. Privacy Countermeasures in Metaverse

Privacy countermeasures for the metaverse draw on privacy-by-design, differential privacy, federated learning, cryptography, trusted computing, avatar defenses, and personal-boundary controls. The survey also identifies personalization as an unresolved requirement because users and avatars have different privacy demands and service preferences.

  • Privacy-preserving games: AR/VR games collect sensory data, identify objects, and render scenes, creating a pipeline in which privacy and security attacks can target users and environments.The surveyed literature includes case studies, qualitative studies, and location-tracking attacks in metaverse games.
  • Privacy-preserving games: Network-traffic exploitation achieved fine-grained geolocation of players with high accuracy in experiments involving 12 volunteers, alongside proposed mitigation approaches.The result concerns location-based AR games such as Pokémon Go.
  • Privacy-by-design: Privacy-by-design evaluations use nineteen privacy attributes across three levels, while interactive game design distinguishes individual from group privacy.The attributes support qualitative and quantitative privacy evaluation.
  • Privacy-preserving computation: Metaverse privacy-preserving data sharing and processing use differential privacy, federated learning, secure computation, homomorphic encryption, zero-knowledge proofs, and trusted computing.These approaches are applied to UGC sharing, recommendation, prediction, and off-chain processing.
  • Privacy-preserving computation: Authentication, access control, and privacy computing protect UGC confidentiality, while compromising reflections threaten confidentiality of physical inputs.Physical-input protection addresses data entering the metaverse from users and environments.
  • Avatar privacy: Avatar digital footprints include personal information, virtual behaviors, and interactions, which can be protected through disguises, mannequins, invisibility, private enclaves, and lockouts.These mechanisms target virtual stalking and spying that may expose real identities and private information.
  • Personalized privacy: Personalized privacy computing remains necessary because users and avatars have differing privacy demands and service preferences.Existing directions include similarity-based methods, randomized response, and personalized federated learning.
  • Privacy-enhancing industry advances: Meta’s virtual personal-boundary function applies a default private border of 2-foot, alongside real-world public, social, personal, and intimate distance ranges.The four real-world ranges are 350-750 cm, 125-350 cm, 50-125 cm, and within 50 cm.

C. Summary and Lessons Learned

Metaverse privacy and network security remain major concerns because pervasive data collection, inherited technological vulnerabilities, and attacks such as SPoF, DDoS, and Sybil attacks challenge trustworthy operation. Existing defenses include privacy countermeasures, attack monitoring, and reactive or proactive security approaches, but metaverse-specific characteristics limit their adaptability.

  • Privacy: Metaverse privacy risks arise from pervasive collection and processing of granular personal information, including user profiles and biometric data.Centralized platform management can also increase privacy leakage and data-abuse risks.
  • Network Security: Network threats include SPoF, DDoS, and Sybil attacks that can disrupt services, overwhelm centralized servers, or manipulate consensus and voting.Compromised wearable devices may become botnets, while fabricated identities can out-vote genuine blockchain nodes.
  • Security Monitoring: Situational awareness supports security monitoring and early warning across local security domains and distributed sub-metaverses.The cited material distinguishes local monitoring from global awareness of large-scale distributed threats.
  • Countermeasures: Existing security measures are categorized as reactive defenses against known attacks and proactive defenses against future unknown attacks.Reactive approaches generally rely on timely attack trapping, frequent retraining, and decision verification.

2) Global Situational Awareness:

Global situational awareness is presented as a way to understand security states and support early warning for large-scale distributed threats across multiple sub-metaverses. Reviewed approaches use data-driven analysis, evolutionary modeling, reinforcement learning, and collaborative honeynets, while scalability and programmability remain concerns.

  • Global Situational Awareness: Global situational awareness helps monitor security statuses and provide early warning for attacks targeting multiple distributed sub-metaverses.The paper contrasts this with local awareness focused on a single security domain.
  • Global Situational Awareness: Data-driven approaches for global awareness include classifiers for malicious events and reinforcement learning based on evolutionary models of users and attackers.One classifier requires costly expert-labeled events, motivating a further approach that models legitimate users and attackers as an evolutionary game.
  • Global Situational Awareness: Collaborative honeynets trap attackers, monitor their behaviors, and exchange information among coordinated honeypots.The reviewed honeynet-based system uses Docker-built honeypots and a honeynet controller, but has scalability and programmability drawbacks.
  • Lessons Learned: AR, AI, honeypot, and SDN technologies can help construct metaverse situational-awareness systems.The survey identifies global awareness as useful for monitoring and early warning of large-scale distributed threats.

2) Economic Fairness for Manipulation Prevention:

Economic fairness in the metaverse must address strategic manipulation, free-riding, and collusion while balancing fairness against privacy, efficiency, and quality of experience. Blockchain supports decentralized asset provenance and ownership tracing, but interoperability, resilience, efficiency, and privacy–utility trade-offs remain open concerns.

  • Economic Fairness: Strategy-proof auctions and contracts can deter strategic manipulation, but cryptographic privacy mechanisms may burden wearable devices or reduce data utility.The paper identifies a need for mechanisms balancing privacy and utility for users with diverse preferences.
  • Free-Riding Prevention: Optimal seed-bandwidth allocation strategies can mitigate free-riding and promote cooperation, with theoretical analysis establishing a Nash equilibrium.Simulations report effectiveness in free-riding penalization and cooperation promotion.
  • Collusion Prevention: Existing collusion defenses use AI-based detection, cryptography, game theory, and optimization, but future mechanisms must combine fairness goals with privacy preservation.The stated combination includes strategy-proofness, collusion resistance, and free-rider prevention.
  • Creator Economy: Blockchain supports decentralized virtual economies through virtual-currency creation, trusted trading, economic fairness, and ownership traceability.Public ledgers record asset originality and operations, while smart contracts encode ownership-management logic.

B. Physical Safety

Physical and social safety threats arise because metaverse systems connect cyber systems, physical infrastructure, and human society. Reviewed countermeasures draw on cyber insurance and cyber-physical security, but dynamic insurance design and metaverse-specific technological and sociological protections require further work.

  • Cyber Insurance-based Solutions: Cyber insurance can mitigate financial risks to critical infrastructures, but scalable dynamic coalition formation and fair premiums under diverse cyberthreats remain unresolved.The paper specifically notes anti-forensics among the threats requiring further investigation.
  • Cyber-Physical Interaction: Cyber-physical security approaches use security indices, cyber probes, system logs, and topology information to measure and defend infrastructure.These approaches provide lessons for protecting physical safety in the metaverse through cyber–physical interaction.
  • Society Management: Rapid information spreading creates governance challenges because misinformation can produce a stronger butterfly effect in real-world public safety.A proposed node-blocking approach is difficult to apply to fully interactive metaverse settings because it was designed for static social networks.
  • Lessons Learned: Physical and social safety research draws on cyber insurance and CPSS-based approaches, while additional metaverse-specific technological and sociological efforts are required.The survey summarizes these approaches as providing insights rather than complete solutions.

A. Threats to Metaverse Governance

Metaverse governance must address legal, regulatory, collaborative, forensic, and AI-specific threats while balancing decentralization, accountability, and ethical decision-making.

  • Effective public governance combines hard-law compliance with soft-law principles emphasizing transparency, consensus, human rights, and organizational self-discipline.
  • Virtual crimes such as harassment and stalking require metaverse-specific legal definitions and punishments rather than direct application of real-world rules.
  • Misbehaving regulators can paralyze systems, motivating supervised authorities and decentralized punishment and reward mechanisms.
  • Collaborative governance reduces concentration of regulatory rights but remains vulnerable to collusion among regulators, including wormhole-based network partitioning.
  • Metaverse digital forensics must reconstruct cybercrimes across real and virtual worlds despite dynamic platforms, anonymity, and blurred reality boundaries.
  • AI can detect suspicious entities and accounts, but avatar-activity association, bias, interpretability, accountability, and ethics remain unresolved governance challenges.

C. Summary and Lessons Learned

The survey identifies security and privacy challenges arising from metaverse scale, heterogeneity, interoperability, and resource demands. It reviews distributed and technology-specific approaches while outlining research directions for secure, sustainable metaverse systems.

  • The survey concludes that AI-enabled governance, decentralized governance, and trusted digital forensics are important directions requiring further technological and sociological research.
  • Passive bring-in security based on post-deployment patching remains fragile and costly against persistent cyber-physical attack surfaces.
  • Quantum key distribution and quantum-resistant cryptography are proposed as directions for endogenous security against disclosure and quantum threats.
  • Cloud-edge-end orchestration can share resources dynamically, improve QoE and QoS, and support privacy protection through federated edge learning.
  • Heterogeneous blockchains create cross-chain authentication and governance challenges, while relay chains synchronize source-chain information for destination verification.
  • Resource-constrained devices and rising computational demands motivate green architectures, edge-cloud designs, and energy-efficient consensus protocols.
  • Content-centric networking is identified as an alternative architecture for securing user-generated-content dissemination across heterogeneous end devices and virtual worlds.
  • The survey reviews metaverse fundamentals, threats, security challenges, and tailored existing or potential countermeasures within a distributed architecture.
Loading 2203.02662v4…