← Latest papers
💻 computer science

I Know What You Did Last Summer: Identifying VR User Activity Through VR Network Traffic

This paper demonstrates that machine learning models can identify specific VR applications and user activities with over 90% accuracy by analyzing encrypted network traffic from Meta Quest Pro headsets, requiring less than 10 minutes of data per application.

Original authors: Sheikh Samit Muhaimin, Spyridon Mastorakis

Published 2026-03-13
📖 5 min read🧠 Deep dive

Original authors: Sheikh Samit Muhaimin, Spyridon Mastorakis

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine you are wearing a high-tech virtual reality (VR) headset. You are in a digital world, playing basketball, painting a masterpiece, or just chatting with friends. You think you are safe because your headset encrypts your data—like putting your conversation inside a locked, unbreakable safe.

But what if someone standing outside your house could listen to the sound of the safe's lock clicking and know exactly what you are doing inside?

That is exactly what this paper, "I Know What You Did Last Summer," discovered. The researchers found that even if the content of your VR traffic is locked up tight, the pattern of the data flowing in and out is like a unique fingerprint. By analyzing these patterns, they can tell exactly which app you are using and what you are doing in it, with over 90% accuracy.

Here is a breakdown of their findings using simple analogies:

1. The "Digital Footprint" Analogy

Think of your VR headset as a car driving down a highway. Even if the car is covered in a tarp (encryption) so no one can see the passengers or the cargo, the engine noise and the vibration of the tires on the road are unique.

  • Driving fast on a bumpy road (like throwing a virtual ball) makes a specific rumble.
  • Idling at a stoplight (doing nothing) makes a low hum.
  • Talking makes a rhythmic pulsing sound.

The researchers realized that by listening to the "engine noise" of the network traffic (the size of data packets, how fast they arrive, and how often they stop), they could guess exactly what the "car" was doing, even without seeing inside.

2. The "Musical Score" of Your Actions

The researchers collected data from 25 different VR apps (like RecRoom, Gorilla Tag, and Meta Horizon Worlds). They treated the network traffic like a musical score.

  • Walking in a game creates a steady, rhythmic beat.
  • Talking creates a burst of high-pitched notes.
  • Pausing creates a sudden silence.

They used Machine Learning (AI) as a "super-listener." This AI was trained to recognize these rhythms.

  • The Result: The AI could identify which game you were playing 92.4% of the time.
  • The Result: It could identify if you were walking, talking, or throwing a ball 91% of the time.

3. The "Short Memory" Surprise

You might think, "Okay, but the hacker would need to watch me for hours to learn my habits, right?"
Wrong.
The researchers found that the "super-listener" only needed to hear less than 10 minutes of your traffic for each app to learn the pattern perfectly. It's like hearing someone speak for a minute and immediately knowing their accent and what they are likely to say next. You don't need to listen to them for a whole day to know who they are.

4. The "Universal Translator"

One of the scariest findings was that the AI didn't just learn one game; it learned the universal language of VR actions.

  • If the AI learned what "Walking" sounds like in Gorilla Tag, it could also recognize "Walking" in RecRoom, even if it had never seen that specific app before.
  • Why? Because the underlying technology (the "engine" that runs the game) is often the same. Just as a piano sounds different depending on the song, the way the keys are pressed (the network traffic) remains similar across different songs (apps).

5. The "Shadow" in the Room

The paper outlines a "Threat Model" (a scenario of how a bad guy could do this):

  1. The Setup: A hacker sits on the same Wi-Fi network as you (like a neighbor listening through the wall).
  2. The Capture: They don't need to break your encryption. They just record the "clicks" and "whirs" of the data packets.
  3. The Guess: They feed this data into their AI.
  4. The Reveal: The AI tells them: "Oh, you are currently in the 'Meta Horizon Worlds' gym, and you just punched a virtual punching bag."

Why Should You Care?

This isn't just about knowing you played a game. It's about privacy.

  • Profiling: If a hacker knows you play violent games, talk to specific people, or spend hours in educational apps, they can build a detailed profile of your personality and habits.
  • Social Engineering: They could use this info to trick you. "Hey, I saw you playing basketball in VR, want to join a real-life league?" (It sounds friendly, but it's a trap based on stolen data).
  • The Illusion of Safety: We often think encryption makes us invisible. This paper proves that encryption hides the content, but not the behavior.

The Bottom Line

The paper concludes that VR users are currently more exposed than they think. Even with encryption, the "shape" of your data leaks your secrets. The researchers suggest that while we can't stop the data from flowing, we need better ways to "mask" the rhythm of that flow so that the "super-listener" AI can't tell what we are doing.

Until then, remember: In the digital world, how you move is just as revealing as what you say.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →