
XC
Xujun Che, Thomas Carr, Depeng Xu, Aidong Lu, Shuhan Yuan
· 1 min read
ResearcharXiv cs.CV
MoSign: Challenge-Response Motion-Watermark Authentication for Anonymous Virtual-Reality Users
arXiv:2609.29603v1 Announce Type: cross
Abstract: Social virtual reality (VR) creates a paradox. A user's body motion is a high-entropy biometric: head and hand trajectories alone re-identify users among tens of thousands with over $94\%$ accuracy, so anonymizing the rendered avatar is a practical necessity. Yet a user often still wants to prove their identity to a chosen party from inside that anonymity. We present MoSign, which recasts digital watermarking as a challenge-response authentication protocol on the motion channel. MoSign embeds a time-varying keyed message into the style latent of a motion variational autoencoder via keystream-whitened Gaussian-Shading: watermarked motion is provably indistinguishable from watermark-free motion, since any detector's advantage reduces to breaking a pseudorandom function, so the mark composes with anonymization. The message is a keyed MAC over an epoch counter, a session nonce, and a deployment context, making MoSign replay-resistant and bounding forgery by the verifier's measured false-accept rate times the adversary's online query budget. A key-holding verifier decides with a sequential test. We identify render$\rightarrow$record$\rightarrow$re-estimate ("recapture") as the realistic VR attack surface: a generic pose estimator strips the necessarily subtle watermark, but a recapture-robust keyed reader recovers it (up to $0.96$ codeword accuracy on a projected-2D channel, $0.81$ through a full render-to-video loop), while without the key recovery stays at chance. On HumanML3D, MoSign authenticates every legitimate user at a false-accept rate of $10^{-4}$ on clean and most channels and stays undetectable (detection AUC $0.51$, chance $0.5$); on the BOXRR-23 VR dataset it carries the mark through a real anonymizer at $0.99$ codeword accuracy and adds no de-anonymization side channel.
Original source
This story was published by arXiv cs.CV and written by Xujun Che, Thomas Carr, Depeng Xu, Aidong Lu, Shuhan Yuan. SyncAI.news shows a preview; the complete article is on the publisher's site.
Read the full story on arxiv.org


