Analysis and Implementation of Nanotargeting on LinkedIn Based on Publicly Available Non-PII

Privacy by Design & User ControlIoT Device PrivacyContent Moderation & Platform GovernanceLawyers & Legal ResearchersPrivacy Policy Makers

Title of the Paper

Analysis and Implementation of Nanotargeting on LinkedIn Based on Publicly Available Non-PII

Paper Information

  • Subject Area: Data Privacy and Advertising Technologies on Social Platforms
  • Keywords: LinkedIn, Online Advertising, User Privacy, Nanotargeting, Non-Personally Identifiable Information (Non-PII)

Research Background and Issues

  • Background: Recent studies have shown that combining a small amount of non-personally identifiable information (Non-PII) can uniquely identify users within large datasets (even on the scale of millions). When such information is used for advertising targeting, it may pose privacy and security risks. However, most prior research in this area has been theoretical, lacking practical experimental validation.

  • Research Question: This study focuses on how publicly available Non-PII related to users' personal characteristics (such as professional skills and locations) can be used for nanotargeting on professional social platforms like LinkedIn, and discusses the associated privacy and legal risks.

  • Significance of the Research: Compared to traditional PII-based advertising targeting methods, the study reveals that nanotargeting attacks based on publicly available, easily accessible Non-PII information are more scalable and easier to execute. This presents new challenges for user privacy protection and advertising platform regulations.

  • Motivation: The authors aim to combine theoretical research with practical validation to quantify and empirically demonstrate the potential and impact of Non-PII in nanotargeting attacks, providing new insights and recommendations for protecting user privacy.

Solution

  • Research Methods and Steps:

    1. Data Collection: Construct a dataset containing skills and location information of 3,352 LinkedIn users and create advertising experiments.
    2. Model Development: Use LinkedIn's ad manager to analyze audience sizes under various combinations of skills and locations, thereby quantifying user uniqueness.
    3. Experimental Validation: Conduct nanotargeting ad experiments to verify the accuracy and practicality of the theoretical model.
    4. Vulnerability Reporting and Validation: Report the findings to LinkedIn and study the effectiveness of their remediation measures.
  • Innovations:

    1. First Proof Using Public Data: Demonstrates that publicly available Non-PII can highly likely uniquely identify specific users.
    2. Broad Applicability of the Method: Shows that user skill data can be obtained using simple techniques, expanding the concept and risk domain of Non-PII nanotargeting.
    3. Integration of Experiments and Models: Provides a research paradigm combining theoretical uniqueness analysis, success rate prediction, and empirical results.

Research Outcomes

  • Key Findings:

    • The study found that combining users' publicly available location information with five relatively uncommon skills achieves a 75% probability of unique identification.
    • In nanotargeting ad experiments involving three authors, an ad configuration with 13 randomly selected skills successfully reached the target users, with the theoretical success rate of nanotargeting attacks closely matching the experimental results.
    • As of November 2023, this attack method poses a potential threat to one-quarter to one-third of LinkedIn users, potentially affecting 258 million to 419 million users.
  • Advantages Compared to Existing Technologies and Solutions:

    • This research is the first to demonstrate the feasibility of large-scale nanotargeting using publicly available Non-PII, expanding the scope of privacy protection research.
    • Provides empirical experimental support, contrasting with previous theoretical studies, and enhances the practical impact of the research.
  • Experiments and Analysis:

    • Each experimental ad cost was extremely low, typically under $1.
    • After the vulnerability was fixed (from November 2023 onwards), LinkedIn fully restricted ad audience groups smaller than 300 people, rendering actual nanotargeting attacks infeasible.
  • Limitations and Future Directions:

    1. In the dataset, 49% of users were from the United States, which may introduce bias.
    2. LinkedIn has now fixed the vulnerability, making it impossible to validate the original research method further.
    3. Future research is recommended to investigate whether similar nanotargeting vulnerabilities exist on other platforms, while strengthening legal and technical frameworks to regulate such behaviors.

Output Format

  • This paper holds significant societal and academic value: it serves as a warning for user privacy protection, the boundaries of Non-PII usage, and the regulation of social platform technology development.
  • Further collaboration with policymakers and data protection agencies is needed to develop standardized defense guidelines and cross-domain data-sharing strategies, enhancing user protection capabilities and platform development accountability.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/147940/2024

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3613904.3642107
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2024
emoji_events
Award
No award tagged
group
Authors
4 authors
sell
Subtopics
Privacy by Design & User Control, IoT Device Privacy, Content Moderation & Platform Governance
work
Professions
Lawyers & Legal Researchers, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
1 related papers