SearcharxivSearch

arXiv · 2609.04592

Hidden In Plain Gaze: Gaze Representations as Privacy Controls for Utility and Re-identification Risk in XR

Abstract

Intelligent extended reality (XR) systems increasingly use eye and head tracking to infer user intent, task, and attention, but the same signals can also reveal biometric identity. We study whether gaze data representation choice can serve as a lightweight privacy control at feature extraction, before adding perturbation or formal privacy mechanisms. Using the egocentric HoloAssist dataset, we compare three gaze representations under matched model capacity: raw gaze, spatial attention heatmaps, and engineered eye-movement features. We evaluate each representation on action recognition as task utility and closed-set user re-identification as privacy leakage. Representation choice substantially changes the privacy-utility tradeoff. Engineered features retain roughly 85% of raw gaze's action-recognition accuracy while reducing re-identification by about an order of magnitude, to roughly four times the chance rate across 206 identities. This reduction attenuates rather than eliminates identity leakage, and the differences across representations show that abstraction alone does not guarantee privacy. Engineered features expose interpretable and auditable structure, giving designers a transparent privacy lever that complements mechanisms such as differential privacy.

Explore related subjects

Keep this discovery

BibTeXRIS

Cory Ilo, Brendan-David John, Doug A. Bowman. 2026-09-04. Hidden In Plain Gaze: Gaze Representations as Privacy Controls for Utility and Re-identification Risk in XR. https://arxiv.org/abs/2609.04592

Cite the original work for its findings. Save a collection to share your selection of sources.

Discover connections

Connections use source metadata and explicit phrase matches, not verified experimental comparisons.

KEEP EXPLORING

Related papers

Between Algorithm (AI) and Intuition (Human): Preserving Designer Agency in AI-Assisted Sensemaking of Qualitative UX Data

The integration of AI into qualitative design research presents a fundamental tension: how do we leverage AI while preserving the subjective, intuitive judgments that define design expertise? This paper examines this question through a case study of analyzing 20 user responses about video conferencing platforms for educational contexts. We argue that AI sensemaking tools risk flattening the rich data patterns, amplifying contradictory textures of user feedback into sterile categories thereby transforming design research from an interpretive craft into a mechanical sorting exercise (rigid and formal). Through comparative analysis of AI-assisted sensemaking versus human-centered approaches to the same dataset, we identify when algorithmic efficiency enhances understanding and when it diminishes the designer's interpretive agency (uncovering hidden needs, critical enquiry, what if enquiries, making decisions, having trade-offs). We present a framework for augmented sensemaking that positions AI as an instrument for amplifying human judgment rather than replacing it. Our findings suggest that the most valuable role for AI in design research is not to eliminate subjectivity, but to make it more intentional, reflective, and accountable.

cs.HC

Beyond Technological Solutionism: Rethinking XR in Healthcare

The healthcare industry's enthusiastic adoption of Extended Reality (XR) technologies obscures a concerning reality: we were building increasingly sophisticated ways to perpetuate fundamentally broken healthcare systems. Through three deeply personal narratives - a rural patient cut off from care infrastructure, an urban professional navigating fragmented services, and a first-generation immigrant confronting cultural barriers - this provocation paper exposes how our obsession with technological innovation often worsens rather than resolves healthcare disparities. By applying the SEIPS 3.0 model to examine diabetes-CVD care coordination, we identify an "innovation paradox" where advanced technology creates new barriers to effective care. Our care interdependencies framework reveals that healthcare outcomes are shaped primarily by human relationships (50-60%), organizational coordination (25-30%), and sociocultural factors (15-20%), not technological sophistication. This research challenges the HCI community to confront its role in perpetuating healthcare inequities, demands a fundamental rethinking and proposes a new framework for healthcare innovation that prioritizes human relationships over technical capability, systemic change over feature sets, and actual care delivery over technological ambition. For healthcare providers, technology developers, and policymakers, our findings suggest that effective care coordination requires us to step back from our techno-solutionist mindset and engage

cs.HC

Epistemic Transfer in AI-Assisted Verification: A Framework and Evaluation Protocol

AI tools can improve claim judgments while leaving open what users can do later without them. This paper develops an evaluation framework for epistemic transfer: the effect of prior AI-assisted verification on delayed judgments of novel claims under a specified access regime. The contribution is a verification-specific synthesis of learning, transfer, and human--AI evaluation, organized around two complementary estimands. The Epistemic Transfer Effect (ETE) compares delayed performance after alternative practice conditions. Tool-Removal Cost (TRC) compares immediate performance with and without assistance after practice; despite its name, it measures a current availability effect, not skill loss or psychological dependence. The proposed randomized protocol includes answer-first and evidence-first interfaces, active practice, a no-additional-practice comparator, and held-out claims. It specifies how to account for learning opportunities introduced by assessment, elicit confidence probabilities, average model predictions over a target population, and handle attrition and uncertainty. Reading ETE and TRC together distinguishes relative capability gains, equivalence, transfer penalties, and unresolved outcomes. A ``verification-on-loan'' profile is explicitly comparator-relative and cannot be inferred from a nonsignificant delayed contrast. A brief illustration from a two-wave verification study shows why these distinctions matter: an uncertain delayed interface contrast and an ordered assisted--unassisted probe cannot establish a clean transfer profile. The framework makes a practical demand: when independent judgment matters, evaluate both what assistance contributes now and what prior use changes later.

cs.HC