Six years of studies compose into a stack; the stack becomes a default. The tree is the design space; the chart is the year it ships.
Doctor of Philosophy in Computer Science, Virginia Polytechnic Institute and State University.
Context-aware extended reality (XR) systems tailor their interfaces to the user’s situation, but the sensing that makes this possible — outward-facing cameras, microphones, and eye trackers — creates substantial privacy risk for users and for the bystanders captured alongside them. This dissertation argues that privacy in context-aware XR is necessary, feasible, and never automatic, and develops a framework for achieving it. The central claim is that the same gaze signal that can drive interface adaptation also encodes the user’s identity, so privacy cannot be obtained by abstention or by treating gaze as a benign substitute for the camera; it must be engineered into how the signal is represented and mediated.
The argument is developed through three studies organized as a decision tree with two complementary strategies, avoidance and mitigation. GoldiLocks Zoning establishes the foundation, showing that gaze alone, read as passive context, can drive useful adaptation without imaging the environment, making avoidance of the camera viable. InPlainGaze examines the residual risk that avoidance leaves behind, demonstrating that the representation in which gaze is encoded is a privacy lever: a learned engineered-feature representation preserves most task-relevant utility while substantially attenuating re-identification — and, counterintuitively, a more abstract heatmap representation leaks more identity, showing that abstraction alone does not guarantee privacy. ARPA addresses the case in which environmental capture is unavoidable, studying how the autonomy of a human-in-the-loop privacy assistant shapes users’ situated awareness and the cognitive burden of managing exposure, and finding that automation redistributes that burden rather than removing it.
Synthesized, the studies contribute more than three systems: they yield an intermediate-level framework — avoidance and mitigation, with representational veiling as its core mechanism — for building context-aware XR that does not require users to surrender their identity to benefit from adaptation. The dissertation closes by arguing that such protection can become an ambient, on-device default rather than an expert-only setting, and by charting the open branches of the design space the framework reveals.
“A stream never captured cannot betray you.”
The foundation: gaze alone, read as passive context, can drive useful adaptation without imaging the environment — making avoidance of the camera viable. GoldiLocks zoning places VR notifications by watching where attention already lives, task-agnostic, no world capture.
Subtraction is the first move: sense only what the adaptation needs. But avoidance leaves a residual risk behind — the gaze stream itself. The system adapts; so must we.
“Veil the identity. Never blind the system.”
The representation in which gaze is encoded is a privacy lever. A learned engineered-feature representation preserves most task-relevant utility while substantially attenuating re-identification — representational veiling, the framework’s core mechanism.
Counterintuitively, a more abstract heatmap representation leaks more identity. Abstraction alone does not guarantee privacy — the veil must be engineered, not assumed.
“I see the lie before it wears a face.”
When environmental capture is unavoidable, a human-in-the-loop privacy assistant manages exposure. ARPA studies how the assistant’s autonomy shapes situated awareness and the cognitive burden of managing what leaks.
The finding: automation redistributes the burden rather than removing it. Protection must become an ambient, on-device default — not an expert-only setting. That default is what DIBIA exists to build.