Logo del repository
  1. Home
 
Opzioni

Re-Identification Attacks against the Topics API

Jha, Nikhil
•
Trevisan, Martino
•
Leonardi, Emilio
•
Mellia, Marco
2024
  • journal article

Periodico
ACM TRANSACTIONS ON THE WEB
Abstract
Recently, Google proposed the Topics API framework as a privacy-friendly alternative for behavioural advertising as a possible solution to balance user’s privacy and advertisement effectiveness. Using the Topics API, the browser builds a user profile based on navigation history, which advertisers can access. The Topics API aim at becoming the new standard for behavioural advertising, thus it is necessary to fully understand its operation and find possible limitations. In this paper, we evaluate the robustness of the Topics API to a re-identification attack. To build a user profile, we suppose an attacker accumulates over time the topics a user exposes to different websites. The attacker later re-identifies the same user matching the profiles of their audience. We leverage real traffic traces and realistic population models, and we present increasingly powerful attack threats. We find that the Topics API mitigates but cannot prevent re-identification from taking place, as there is a sizeable chance that a user’s profile remains unique within a website’s audience and the attacker successfully matches it with the profile of the same user on a second website. Depending on environmental factors, the probability of correct re-identification can reach , considering a pool of 1 000 users. We offer the code and data we use in this work to stimulate further studies and the tuning of the Topic API parameters.
DOI
10.1145/3675400
WOS
WOS:001315133900001
Archivio
https://hdl.handle.net/11368/3079198
info:eu-repo/semantics/altIdentifier/scopus/2-s2.0-85201864149
https://dl.acm.org/doi/10.1145/3675400
Diritti
closed access
license:copyright editore
license uri:iris.pri02
FVG url
https://arts.units.it/request-item?handle=11368/3079198
Soggetti
  • Web Privacy

  • Anonymity

  • Behavioral Advertisin...

  • Topics API

google-scholar
Get Involved!
  • Source Code
  • Documentation
  • Slack Channel
Make it your own

DSpace-CRIS can be extensively configured to meet your needs. Decide which information need to be collected and available with fine-grained security. Start updating the theme to match your nstitution's web identity.

Need professional help?

The original creators of DSpace-CRIS at 4Science can take your project to the next level, get in touch!

Realizzato con Software DSpace-CRIS - Estensione mantenuta e ottimizzata da 4Science

  • Impostazioni dei cookie
  • Informativa sulla privacy
  • Accordo con l'utente finale
  • Invia il tuo Feedback