Privacy Risks with Facebook's PII-Based Targeting: Auditing a Data Broker's Advertising Interface
Giridhari Venkatadri, Athanasios Andreou, Yabing Liu, Alan Mislove, Krishna P. Gummadi, Patrick Loiseau, Oana Goga
摘要
Sites like Facebook and Google now serve as de facto data brokers, aggregating data on users for the purpose of implementing powerful advertising platforms. Historically, these services allowed advertisers to select which users see their ads via targeting attributes. Recently, most advertising platforms have begun allowing advertisers to target users directly by uploading the personal information of the users who they wish to advertise to (e.g., their names, email addresses, phone numbers, etc.); these services are often known as custom audiences. Custom audiences effectively represent powerful linking mechanisms, allowing advertisers to leverage any PII (e.g., from customer data, public records, etc.) to target users. In this paper, we focus on Facebook's custom audience implementation and demonstrate attacks that allow an adversary to exploit the interface to infer users' PII as well as to infer their activity. Specifically, we show how the adversary can infer users' full phone numbers knowing just their email address, determine whether a particular user visited a website, and de-anonymize all the visitors to a website by inferring their phone numbers en masse. These attacks can be conducted without any interaction with the victim(s), cannot be detected by the victim(s), and do not require the adversary to spend money or actually place an ad. We propose a simple and effective fix to the attacks based on reworking the way Facebook de-duplicates uploaded information. Facebook's security team acknowledged the vulnerability and has put into place a fix that is a variant of the fix we propose. Overall, our results indicate that advertising platforms need to carefully consider the privacy implications of their interfaces.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper17
- Auditing for Discrimination in Algorithms Delivering Job AdsBasileal Imana, Aleksandra Korolova, John S. HeidemannWWW 2021 · 被引用 105 次
- Measuring the Facebook Advertising EcosystemAthanasios Andreou, Márcio Silva, Fabrício Benevenuto, Oana Goga 等NDSS 2019 · 被引用 76 次
- What Makes a "Bad" Ad? User Perceptions of Problematic Online AdvertisingEric Zeng, Tadayoshi Kohno, Franziska RoesnerCHI 2021 · 被引用 55 次
- Unveiling and Quantifying Facebook Exploitation of Sensitive Personal Data for Advertising PurposesJosé González Cabañas, Ángel Cuevas, Rubén CuevasUSENIX Security 2018 · 被引用 54 次
- Quantity vs. Quality: Evaluating User Interest Profiles Using Ad Preference ManagersMuhammad Ahmad Bashir, Umar Farooq, Maryam Shahid, Muhammad Fareed Zaffar 等NDSS 2019 · 被引用 41 次
它引用的顶会 Paper1
相关 Paper
- Cart-ology: Intercepting Targeted Advertising via Ad Network Identity EntanglementChangSeok Oh, Chris Kanich, Damon McCoy, Paul PearceCCS 2022 · 被引用 1 次
- Exploring the Online Micro-targeting Practices of Small, Medium, and Large BusinessesSalim Chouaki, Islem Bouzenia, Oana Goga, Beatrice RoussillonCSCW 2022 · 被引用 11 次
- Targeted Deanonymization via the Cache Side Channel: Attacks and DefensesMojtaba Zaheri, Yossi Oren, Reza CurtmolaUSENIX Security 2022
- Investigating Ad Transparency Mechanisms in Social Media: A Case Study of Facebooks ExplanationsAthanasios Andreou, Giridhari Venkatadri, Oana Goga, Krishna P. Gummadi 等NDSS 2018 · 被引用 68 次
- A Security Analysis of the Facebook Ad LibraryLaura Edelson, Tobias Lauinger, Damon McCoyS&P 2020 · 被引用 43 次
