Semantics-Aware Cookie Purpose Compliance
Baiqi Chen, Jiawei Lyu, Tingmin Wu, Mohan Baruwal Chhetri, Guangdong Bai
摘要
In response to stringent data protection regulations, websites typically display a cookie banner to inform users about the usage and purposes of cookies, seeking their explicit consent before installing any cookies into their browsers. However, a systematic approach for reliably assessing compliance between the website-declared purpose and the semantic-intended purpose of cookies (denoted as potential cookie purpose violation) has been notably absent. Websites may still, whether intentionally or unintentionally (e.g., due to third-party libraries imported), mis-declare cookies that may be abused for tracking purposes. We address this gap with Coover (cookie value examiner). We advocate that the value of the cookie is a more reliable indicator of its semantic-intended purpose compared to other features, such as expires and meta-information, which can be easily obfuscated. Coover decomposes the cookie value into primitive segments representing minimal semantic units, and fine-tunes a GPT-3.5 model to automatically interpret their value-inferred semantics. Based on the interpretation, it classifies cookies into four GDPR-defined purposes. We benchmark Coover against two widely-used content management providers (CMPs) i.e., CookiePedia and Cookie Script, and the state-of-the-art cookie classifier named CookieBlock. It achieves an F1 score of 95%, significantly outperforming other methods. To understand the status quo of potential cookie purpose violation on the web, we employ Coover to analyze Alexa Top 1k websites. Remarkably, out of 15,339 cookies across these websites, only 3.1% quality as truly necessary cookies, while 44.1% of websites suffer from issues of potential purpose violation. Our work serves as a wake-up call to web service providers and encourages further regulatory interventions to rectify non-compliance issues within the web infrastructure.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper9
- Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their InfluenceMidas Nouwens, Ilaria Liccardi, Michael Veale, David R. Karger 等CHI 2020 · 被引用 491 次
- Do Cookie Banners Respect my Choice? : Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent FrameworkCélestin Matte, Nataliia Bielova, Cristiana Teixeira SantosS&P 2020 · 被引用 212 次
- Dark Patterns and the Legal Requirements of Consent Banners: An Interaction Criticism PerspectiveColin M. Gray, Cristiana Teixeira Santos, Nataliia Bielova, Michael Toth 等CHI 2021 · 被引用 175 次
- "Okay, whatever": An Evaluation of Cookie Consent InterfacesHana Habib, Megan Li, Ellie Young, Lorrie Faith CranorCHI 2022 · 被引用 103 次
- User Tracking in the Post-cookie Era: How Websites Bypass GDPR Consent to Track UsersEmmanouil Papadogiannakis, Panagiotis Papadopoulos, Nicolas Kourtellis, Evangelos P. MarkatosWWW 2021 · 被引用 99 次
相关 Paper
- Automating Cookie Consent and GDPR Violation DetectionDino Bollinger, Karel Kubicek, Carlos Cotrini, David A. BasinUSENIX Security 2022
- Automated Large-Scale Analysis of Cookie Notice ComplianceAhmed Bouhoula, Karel Kubicek, Amit Zac, Carlos Cotrini 等USENIX Security 2024 · 被引用 25 次
- Navigating Cookie Consent Violations Across the GlobeBrian Tang, Duc Bui, Kang G. ShinUSENIX Security 2025
- CSChecker: Revisiting GDPR and CCPA Compliance of Cookie Banners on the WebMingxue Zhang, Wei Meng, You Zhou, Kui RenICSE 2024 · 被引用 5 次
- Automated Cookie Notice Analysis and EnforcementRishabh Khandelwal, Asmit Nayak, Hamza Harkous, Kassem FawazUSENIX Security 2023
