Please Forget Where I Was Last Summer: The Privacy Risks of Public Location (Meta)Data
Kostas Drakonakis, Panagiotis Ilia, Sotiris Ioannidis, Jason Polakis
摘要
The exposure of location data constitutes a significant privacy risk to users as it can lead to de-anonymization, the inference of sensitive information, and even physical threats. In this paper we present LPAuditor, a tool that conducts a comprehensive evaluation of the privacy loss caused by publicly available location metadata. First, we demonstrate how our system can pinpoint users' key locations at an unprecedented granularity by identifying their actual postal addresses. Our experimental evaluation on Twitter data highlights the effectiveness of our techniques which outperform prior approaches by 18.9%-91.6% for homes and 8.7%-21.8% for workplaces. Next we present a novel exploration of automated private information inference that uncovers "sensitive" locations that users have visited (pertaining to health, religion, and sex/nightlife). We find that location metadata can provide additional context to tweets and thus lead to the exposure of private information that might not match the users' intentions. We further explore the mismatch between user actions and information exposure and find that older versions of the official Twitter apps follow a privacy-invasive policy of including precise GPS coordinates in the metadata of tweets that users have geotagged at a coarse-grained level (e.g., city). The implications of this exposure are further exacerbated by our finding that users are considerably privacy-cautious in regards to exposing precise location data. When users can explicitly select what location data is published, there is a 94.6% reduction in tweets with GPS coordinates. As part of current efforts to give users more control over their data, LPAuditor can be adopted by major services and offered as an auditing tool that informs users about sensitive information they (indirectly) expose through location metadata.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- On (The Lack Of) Location Privacy in Crowdsourcing ApplicationsSpyros Boukoros, Mathias Humbert, Stefan Katzenbeisser, Carmela TroncosoUSENIX Security 2019 · 被引用 28 次
- Swipe Left for Identity Theft: An Analysis of User Data Privacy Risks on Location-based Dating AppsKarel Dhondt, Victor Le Pochat, Yana Dimova, Wouter Joosen 等USENIX Security 2024 · 被引用 4 次
- Everyone's Privacy Matters! An Analysis of Privacy Leakage from Real-World Facial Images on Twitter and Associated User BehaviorsYuqi Niu, Weidong Qiu, Peng Tang, Lifan Wang 等CSCW 2025 · 被引用 3 次
- Health Hazard, Handle with Care: Investigating the Privacy Risks of Android's Health ConnectKonstantinos Spyridakis, Ioannis Arkalakis, Michalis Diamantaris, Sotiris Ioannidis 等USENIX Security 2026
- Carnus: Exploring the Privacy Threats of Browser Extension FingerprintingSoroush Karami, Panagiotis Ilia, Konstantinos Solomos, Jason PolakisNDSS 2020
它引用的顶会 Paper3
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Knock Knock, Who's There? Membership Inference on Aggregate Location DataApostolos Pyrgelis, Carmela Troncoso, Emiliano De CristofaroNDSS 2018 · 被引用 293 次
- walk2friends: Inferring Social Links from Mobility ProfilesMichael Backes, Mathias Humbert, Jun Pang, Yang ZhangCCS 2017 · 被引用 123 次
相关 Paper
- How does misconfiguration of analytic services compromise mobile privacy?Xueling Zhang, Xiaoyin Wang, Rocky Slavin, Travis D. Breaux 等ICSE 2020 · 被引用 21 次
- Privacy Leakage from a Thousand Words: Millipixel Location Recovery from Dot MapsYuntao Du, Tanishq Pauskar, Hao Wang, Jing Su 等CCS 2026
- Raising Awareness of Location Information Vulnerabilities in Social Media Photos using LLMsYing Ma, Shiquan Zhang, Dongju Yang, Zhanna Sarsenbayeva 等CHI 2025 · 被引用 11 次
- A Run a Day Won't Keep the Hacker Away: Inference Attacks on Endpoint Privacy Zones in Fitness Tracking Social NetworksKarel Dhondt, Victor Le Pochat, Alexios Voulimeneas, Wouter Joosen 等CCS 2022 · 被引用 11 次
- Doxing via the Lens: Revealing Location-related Privacy Leakage on Multi-modal Large Reasoning ModelsWeidi Luo, Tianyu Lu, Qiming Zhang, Xiaogeng Liu 等ICLR 2026 · 被引用 13 次
