Search papers, labs, and topics across Lattice.
The paper introduces Privatar, a framework that offloads avatar reconstruction in multi-user virtual reality from headsets to untrusted devices while ensuring privacy against potential data interception. By leveraging frequency-domain decomposition and a novel Horizontal Partitioning (HP) strategy, Privatar minimizes computational overhead and information leakage, allowing for significantly more concurrent users without compromising quality. The approach also incorporates a Distribution-Aware Minimal Perturbation (DAMP) method to enhance privacy guarantees, resulting in a system that supports 2.37 times more users with only a slight increase in reconstruction loss and energy overhead.
Offloading avatar reconstruction can enable over 2.3 times more users in VR while maintaining privacy and minimizing quality loss.
Multi-user virtual reality enables immersive interaction. However, rendering avatars for numerous participants on each headset incurs prohibitive computational overhead, limiting scalability. We introduce a framework, Privatar, to offload avatar reconstruction from headset to untrusted devices within the same local network while safeguarding attacks against adversaries capable of intercepting offloaded data. Privatar's key insight is that domain-specific knowledge of avatar reconstruction enables provably private offloading at minimal cost. (1) System level. We observe avatar reconstruction is frequency-domain decomposable via BDCT with negligible quality drop, and propose Horizontal Partitioning (HP) to keep high-energy frequency components on-device and offloads only low-energy components. HP offloads local computation while reducing information leakage to low-energy subsets only. (2) Privacy level. For individually offloaded, multi-dimensional signals without aggregation, worst-case local Differential Privacy requires prohibitive noise, ruining utility. We observe users' expression statistical distribution are slowly changing over time and trackable online, and hence propose Distribution-Aware Minimal Perturbation. DAMP minimizes noise based on each user's expression distribution to significantly reduce its effects on utility, retaining formal privacy guarantee. Combined, HP provides empirical privacy against expression identification attacks. DAMP further augments it to offer a formal guarantee against arbitrary adversaries. On a Meta Quest Pro, Privatar supports 2.37x more concurrent users at 6.5% higher reconstruction loss and 9% energy overhead, providing a better throughout-loss Pareto frontier over quantization, sparsity and local construction baselines. Privatar provides both provable privacy guarantee and stays robust against both empirical and NN-based attacks.