The hidden risk of virtual reality – and what to do about it

virtual reality 19

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Jessica Outlaw, Director, Outlaw Center for Immersive Behavioral Science, Concordia University & Susan Persky, Head of Immersive Virtual Environment Testing Area, National Human Genome Research Institute


It seemed like a game when Riley first started the virtual reality (VR) maze. He used a room-scale setup, so by physically walking around his living room, he could solve puzzles and visit different parts of the virtual maze. His friends were networked into the game, so even though they were in their own living rooms, when Riley turned his head he could make eye-contact with them. He could even give them virtual high-fives – slapping avatar hands gave him the sensation of haptic feedback from his controller.

What Riley didn’t know was that the startup that created this game had decided to sell its users’ tracking data. Riley also didn’t know that a 20-minute VR game session recorded 2 million points of data about his body movement, and that an insurance company was one of the customers buying the game data. A month after playing the game, Riley was turned down for a new life-insurance policy. Given his excellent health, he couldn’t understand why. Several appeals later, the insurance company disclosed that Riley’s tracking data from the VR maze game revealed behavioral movement patterns often seen among people in the very early stages of dementia. Later, Riley’s sister, who had not played the VR maze game, was also rejected for life and long-term care insurance policies, as dementia tends to run in families.

This is a hypothetical situation, but the science of using movements tracked in VR to predict dementia, and the technology to do so, are very real. Currently, there are no standards or regulations as to how this data is collected, used or shared.

Virtual and augmented reality (VR and AR) biometric tracking data – micro-movements of head, torso, hands, and eyes – can be medical data. It can diagnose or predict anxiety, depression, schizophrenia, addiction, ADHD, autism spectrum disorder and more about a person’s cognitive and physical function. Because VR and AR applications can detect changes over time in these disease-linked states, developing successful therapeutic interventions will be possible.

The issue here, though, is the unintended consequences that arise when such medically-relevant data is fed into users’ psychometric profiles. Such profiles may start out as relatively harmless, merely predicting when someone might be getting ready to buy a new car. However, sprawling psychographic profiles with medical inputs could leave people vulnerable to the type of scenario outlined above.

Anonymizing VR and AR tracking data is nearly impossible because individuals have unique patterns of movement. No person throws a ball exactly the way that someone else does. Using gaze, head direction, hand position, height, and other behavioral and biological characteristics collected in VR headsets, researchers have personally identified users with 8 to 12 times better accuracy than chance.

In one study where researchers collected data at 95 time points in VR, they could identify an individual with 90% accuracy. Just like zip code, IP address, and voiceprint, VR and AR tracking data should be considered potential ‘personally identifiable information’ (PII) because it can be used to distinguish or trace an individual’s identity, either alone or when combined with other personal or identifying information.

This is an issue that professionals in the medical research world have been grappling with for decades. Researchers have shown that health and medical information like DNA sequences, medical records, and health research data stripped of names and other identifying information, can be traced back to individuals by combining this data with other publicly available data sources. Unlike medical data, however, data collected by VR technologies is currently unregulated, and how it is collected, used and shared is not monitored by any external entity.

In late 2018, VR and AR privacy policy professionals representing major players in hardware and software, as well as experts from academia and non-profits, were invited to attend a privacy summit at Stanford University to review the risks of this technology and to ideate potential solutions. The main areas of concern raised were loss of freedom, harm to reputation, and decrease in access and opportunity due to online identities becoming inseparable from offline ones.

 

VR and AR data misuse could cause people to lose control of their identity and how they choose to present themselves to employers, insurers and others. There was special concern for the vulnerability of children who may be tracked using this technology from a young age and who are not capable of consenting to these risks.

Summit attendees generated a range of solutions that could be employed to protect user privacy, which were subsequently voted on. Some recommendations were:

· Limiting the collection of biometric data by VR and AR devices, either by disallowing collection of raw data, or automatically deleting the data after a defined period to eliminate the possibility of longitudinal data collection

· Explicit communication of the data policy (what’s being collected and how it being used) in plain, clear language

· Not limiting access to an experience based on who opts-in to data collection, and never making opt-in the default setting

· When data policies change, all users should be asked to opt-in again; consent should not be grandfathered through multiple iterations of a company’s privacy policy

· Awareness that acquisition is a weak spot in privacy policy – if one company is acquired by another, user biometrics should not be transferred to the purchasing company without re-consenting users

One solution rose to the top at the summit: the adoption of a system similar to the institutional review boards (IRBs) that exist in universities, medical centers and companies across the world. A traditional IRB reviews researchers’ proposals to ensure that when research participants consent to become part of a research study, the study is conducted in an unbiased way that preserves their autonomy, and that the risks of their participation are minimized. Unlike more general tech advisory boards, IRBs are independent by definition, with diverse membership, and are focused on ethics, justice and respect for those who are the source of research data.

We believe that an IRB model can be successful in the context of VR and AR because potential harms are relatively well-understood, and possible solutions (for example, requiring clear, prospective user consent to data use activities) align with existing IRB approaches. The hope is that this type of review model will be adopted industry-wide for VR and AR. One way it could work is for a centralized group of experts to review the privacy policies of each company. Their role would be to assess the risks to users of each company’s data collection, storage, and usage policies. This independent board would be responsible for identifying the magnitude and probability of harm and recommend steps that can be taken to minimize potential harm to the user.

IRBs were borne out of an unfortunate history of unethical scientific research in which people were unfairly injured, particularly those from disadvantaged backgrounds. Although AR and VR are relatively new consumer technologies, we perceive that the current industry is heading toward an experiment in human behaviour with the potential to harm.

Our proposal is to create an independent voice in VR and AR that advocates for the protection of users. In turn, we believe that these protections will draw more consumers to immersive technology. A significant amount of testing, iteration and refinement would be needed to make a review board strategy viable. Given the correct level of execution, we are optimistic about the potential for this solution to make VR and AR a truly user-friendly technology.

the sting Milestone

Featured Stings

Can we feed everyone without unleashing disaster? Read on

These campaigners want to give a quarter of the UK back to nature

How to build a more resilient and inclusive global system

Stopping antimicrobial resistance would cost just USD 2 per person a year

Coronavirus response: over €1 billion from EU Cohesion policy to support Spain’s recovery

The hidden pandemic: mental illness

JADE Team at the European Business Summit 2017

Populist Eurosceptics helped by Trumpists seriously threaten the EU edifice

A Sting Exclusive: “Entrepreneurship in the Coronavirus (COVID-19) era” written by the Vice-President of Junior Enterprises Europe

‘Endemic’ sexual violence surging in South Sudan: UN human rights office

Eurozone governed by an obscure body and gray procedures

Climate changes and the imminent public health crises

Eurozone recession subsides

More funds needed to counter ‘persistent and multi-faceted humanitarian problems’ in Ethiopia

Cohesion Policy after 2020: preparing the future of EU investments in health

On their epic journeys, migratory birds connect nations and inspire people, UN says on World Day

Rapid action needed for people to meet challenges of changing world of work

Libya ‘in race against time’, but dissolving conflict ‘a realistic prospect’, Security Council hears

Why India can show us how to achieve growth with purpose

Opening – February plenary session, 27 new seats

Telemedicine and the Brazilian reality

This is what great leadership looks like in the digital age

UNESCO food and culture forum dishes up fresh serving of SDGs

‘True’ peace, requires standing up for human rights, says UN chief Guterres

Iran: UN rights chief ‘deeply disturbed’ by continuing executions of juvenile offenders

WhatsApp to face scrutiny from EU regulators task force over data sharing with Facebook

Tuesday’s Daily Brief: funding for Palestine refugees, families today, tech surveillance

UN and African Union in ‘common battle’ for development and climate change financing

China is adding a London-sized electric bus fleet every five weeks

UN investigates systematic sexual violence across South Sudan

They won this year’s Nobel for economics. Here’s why their work matters

Living to 100: why we should plan for more sushi, chocolate and work

COP22 addresses a strong global pledge to effectively implement the Paris Agreement

Restore hope that peace will come to the Middle East, UN negotiator urges Security Council

Seaweed straws and loose-leaf tea: 6 ways to reduce plastic waste

South Sudan ‘heading towards lasting peace and stability’, UN General Assembly told

3 ways activists are being targeted by cyberattacks

Facts and prejudices about work

How global tech companies can champion ethical AI

Universal Health Coverage in the EU: Are we really leaving no one behind?

Easier Schengen Visas for non-EU holiday makers: A crucial issue for south Eurozone countries

Yemen agreement to end southern power struggle ‘important step’ towards peace: UN Special Envoy

System value can power the energy transition in emerging markets

Future of Insurance Claims in Focus at Fourth Annual Connected Claims Europe Summit

The multidisciplinary team facing the multidrug resistant form of Tuberculosis in the state of Amazonas (Brazil)

Ukraine pays the price for lying between Russia and the EU

UN experts urge Turkey to repatriate Irish woman associated with terror group

We won’t win the online security war without people power

Across the world, women outlive men. This is why

A ‘system value’ approach can accelerate the energy transition. Here’s how

How tiny countries top social and economic league tables (and win at football, too)

Geopolitics and investment in emerging markets after COVID-19

The blackened white coat of the doctors

COP21 Breaking News: “There is an ecological debt that the world needs to pay back to Africa”, French President Francois Hollande promises 2 Billion euros by 2020 from Paris

Conference on Future of Europe should start “as soon as possible in autumn 2020”

Roma integration: fight social exclusion, poverty and anti-gypsyism, MEPs demand

Car rentals: EU action leads to clearer and more transparent pricing

Paradise islands of Pacific increasingly vulnerable to climate change, as UN boosts resilience

Key quotes from China’s Premier Li on COVID-19, the economy and US relations

Right2Water initiative: Is the Commission ready to listen to citizens?

Coronavirus: Commission Statement on consulting Member States on proposal to prolong and adjust State aid Temporary Framework

3 ways to stop COVID-19 from drying up start-up talent pools

UN launches ‘South-South Galaxy’ knowledge-sharing platform in Buenos Aires

Investors have a role in securing our shared digital future

More Stings?

Advertising

Speak your Mind Here

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s