← Latest papers
💻 computer science

XR-PRISM: Data-Driven Privacy and Risk Impact Scoring Metric for Extended Reality in Healthcare

This paper introduces XR-PRISM, a data-driven six-factor risk scoring metric and a four-layer threat taxonomy designed to quantify, prioritize, and mitigate security and privacy risks in healthcare Extended Reality deployments by synthesizing findings from 65 peer-reviewed studies.

Original authors: Nafisa Anjum, M. Rasel Mahmud

Published 2026-08-04
📖 3 min read☕ Coffee break read

Original authors: Nafisa Anjum, M. Rasel Mahmud

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine a world where your doctor doesn't just look at an X-ray on a screen, but you can step inside a 3D model of your own heart to see how it beats. Or where a physical therapist guides your movements from miles away, watching your every step through a virtual headset. This is the promise of Extended Reality (XR) in healthcare—a mix of Virtual Reality (VR), Augmented Reality (AR), and Mixed Reality (MR) that turns medical training, therapy, and surgery into immersive adventures. But just like a high-tech house with too many smart locks and cameras, these systems are collecting a massive amount of private data: your heartbeat, your eye movements, your voice, and even your muscle signals. While this data makes the technology powerful, it also creates a new kind of danger. If a hacker gets in, they don't just steal a password; they might mess with your therapy, steal your medical secrets, or even hurt you by making you dizzy or disoriented. The big question for scientists and doctors is: How do we measure how dangerous these risks are, and how do we decide which ones to fix first?

Enter a new study by researchers Nafisa Anjum and M. Rasel Mahmud from Kennesaw State University, who are trying to bring order to this chaotic digital frontier. They looked at 65 different research papers about XR security and privacy published between 2017 and 2024. Think of this as a massive "treasure hunt" where they sorted through hundreds of clues to find a pattern. They discovered that most existing ways of measuring risk were like using a ruler to measure temperature—they just didn't fit the unique shape of XR problems. So, they built something new called XR-PRISM.

Imagine XR-PRISM as a high-tech "risk thermometer" or a video game scorecard for safety. Instead of just saying "this is bad," it gives a specific number from 1 to 10 based on six different ingredients: how likely a hacker is to attack, how many holes exist in the system, how much data is exposed, how much it could hurt a patient physically, how much it could ruin a patient's privacy, and how good the current security guards are at stopping the bad guys. The researchers found that over 70% of the security fixes currently being used lack a standardized way to check their risk, and surprisingly, fewer than 15% of the attacks require a genius-level hacker to launch—they are often easy to pull off.

The paper suggests that by using this new scoring system, hospitals and tech companies can finally stop guessing and start making smart choices. If a VR therapy system gets a "Critical" score of 9 or 10, it means an emergency response is needed immediately, perhaps even shutting the system down. If it's a "Low" score of 1 or 3, it just needs routine monitoring. The authors aren't claiming they have solved every problem in the world; rather, they are offering a transparent, data-driven tool that helps practitioners prioritize which risks to tackle first, ensuring that the amazing future of medical XR remains safe for everyone.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →