Skip to main content
QUICK REVIEW

[論文レビュー] Online Privacy as a Collective Phenomenon

Emre Sarigöl, David García|arXiv (Cornell University)|Sep 22, 2014
Privacy, Security, and Data Protection参考文献 35被引用数 5
ひとこと要約

本稿は、オンラインプライバシーが個人の問題に限らない集団的現象であることを示しており、ユーザーのプライバシーは、その社会的ネットワークのメンバーが自発的に個人情報を公開することで損なわれる。330万人以上のFriendsterユーザーのデータを用いた研究では、友人の公開情報から構築されたシャドー・プロフィールが、特に大規模で均質な社会的ネットワークを持つユーザーに対して、性的指向を高い正確性で予測できることを示しており、プライバシーの損失は個人主義的ではなく、システム的であることが明らかになった。

ABSTRACT

The problem of online privacy is often reduced to individual decisions to hide or reveal personal information in online social networks (OSNs). However, with the increasing use of OSNs, it becomes more important to understand the role of the social network in disclosing personal information that a user has not revealed voluntarily: How much of our private information do our friends disclose about us, and how much of our privacy is lost simply because of online social interaction? Without strong technical effort, an OSN may be able to exploit the assortativity of human private features, this way constructing shadow profiles with information that users chose not to share. Furthermore, because many users share their phone and email contact lists, this allows an OSN to create full shadow profiles for people who do not even have an account for this OSN. We empirically test the feasibility of constructing shadow profiles of sexual orientation for users and non-users, using data from more than 3 Million accounts of a single OSN. We quantify a lower bound for the predictive power derived from the social network of a user, to demonstrate how the predictability of sexual orientation increases with the size of this network and the tendency to share personal information. This allows us to define a privacy leak factor that links individual privacy loss with the decision of other individuals to disclose information. Our statistical analysis reveals that some individuals are at a higher risk of privacy loss, as prediction accuracy increases for users with a larger and more homogeneous first- and second-order neighborhood of their social network. While we do not provide evidence that shadow profiles exist at all, our results show that disclosing of private information is not restricted to an individual choice, but becomes a collective decision that has implications for policy and privacy regulation.

研究の動機と目的

  • 個人のプライバシーが、友人の間接的公開によってどのように影響を受けるかを調査すること。
  • オンライン・ソーシャル・ネットワーク(OSN)プロバイダーが、公開データのみを用いてユーザーおよび非ユーザーのプライベート情報をどの程度推定できるかを定量化すること。
  • ネットワーク構造と公開行動が集団的にプライバシー漏洩リスクをどのように高めるかを分析すること。
  • 個人のプライバシー損失を社会的つながりの集団的行動と結びつける「プライバシー漏洩要因」を導入・検証すること。
  • プライバシーが個人の意思決定であるという仮定に反し、ネットワークを介したシステム的プライバシー危険性を示すこと。

提案手法

  • 性的指向を公開した330万人のFriendsterユーザーの実世界データを用い、大規模なソーシャル・ネットワークを構築した。
  • 友人の公開情報に基づいて、ユーザーおよび非ユーザーの予測プロフィール(シャドー・プロフィール)の構築をモデル化した。
  • 実世界の連絡先リスト共有を反映するため、公開率(ρ ∈ {0.5, 0.7, 0.9})をパrameter化したモデルを用いて、公開行動をシミュレートした。
  • 一次および二次の近隣構造、および同質性(ホモフィリー)を含むネットワーク特徴を用いて、性的指向の予測精度を算出した。
  • ネットワークサイズとホモフィリーがプライバシー漏洩に与える影響を統計的モデリングで評価し、パラメータの各組み合わせについて10回の繰り返しを実施して安定性を確保した。
  • プライバシー漏洩要因は、ネットワークサイズと公開行動の関数として定義され、集団的プライバシー危険性を定量化した。
Figure 1: The network for a subset of Friendster users. The red edges represent assortativity, where the endpoint nodes are in the same sexual orientation class. The node colors correspond to the sexual orientation class.
Figure 1: The network for a subset of Friendster users. The red edges represent assortativity, where the endpoint nodes are in the same sexual orientation class. The node colors correspond to the sexual orientation class.

実験結果

リサーチクエスチョン

  • RQ1OSNプロバイダーは、ユーザーの友人の公開情報のみに基づいて、ユーザーのプライベート情報をどの程度正確に推定できるか?
  • RQ2ユーザーのソーシャル・ネットワークのサイズと均質性は、シャドー・プロフィールによるプライバシー漏洩リスクにどのように影響するか?
  • RQ3OSNにアカウントを持たないことは、より高いプライバシーを保証するのか?それとも、関係する友人が情報を公開することで非ユーザーに対してもプロフィール作成が可能になるのか?
  • RQ4ネットワークメンバーの公開行動が集団的に、性的指向のようなプライベート特徴の予測可能性にどのように影響するか?
  • RQ5ネットワーク構造とアソートラティビティ(同質性)の定量的影響は、ユーザーおよび非ユーザーのプライバシー危険性にどのように現れるか?

主な発見

  • プライバシー漏洩要因は、ユーザーの一次および二次の社会的ネットワークのサイズが大きくなるにつれて顕著に増加し、ネットワークが大きいほどプライバシー危険性が拡大することを示している。
  • 部分的なシャドー・プロフィールにおいて、バイセクシュアル男性の性的指向予測精度は、ヘテロセクシュアル男性よりも高い。これは、ネットワーク内でのホモフィリーが強いことが要因である。
  • 非ユーザーは、個人情報を公開するユーザーとつながっている場合、特にその友人が大規模で均質なネットワークを持つ場合、顕著なプライバシー漏洩リスクにさらされる。
  • 研究では、ネットワークのホモフィリーとプライバシー漏洩の増加の強い相関関係を同定した。特に、友人が高い割合(ρ = 0.9)で連絡先リストを共有する場合に顕著である。
  • アカウントがなくても、友人が機微な情報を公開すれば、個人は高い正確性でプロフィール化可能であるため、単なる非参加ではプライバシーが保護されないことが示された。
  • 結果として、プライバシー損失は個人の選択ではなく、集団的行動の結果として生じるシステム的現象であり、ネットワーク構造がリスクを拡大していることが明らかになった。
Figure 2: Recall and Precision (%) for each class versus $R$ for the partial shadow profile problem. The blue lines and the left y-axis show the recall values, whereas the red lines and the right y-axis show the precision values as $R$ , the partial disclosure parameter, grows. The dashed black line
Figure 2: Recall and Precision (%) for each class versus $R$ for the partial shadow profile problem. The blue lines and the left y-axis show the recall values, whereas the red lines and the right y-axis show the precision values as $R$ , the partial disclosure parameter, grows. The dashed black line

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。