vix.ing · top · new · best · stats · spec

Locality-Sensitive Hashing Does Not Guarantee Privacy! Attacks on Google's FLoC and the MinHash Hierarchy System

2023/02/27 by Florian Turati, Carlos Cotrini, Karel Kubíček +2 · 1 voice · 1 citation
Computer Science · Social Sciences · #Human Mobility and Location-Based Analysis #Internet Traffic Analysis and Secure E-voting #Privacy, Security, and Data Protection #cs.CR

paper · pdf · doi:10.56553/popets-2023-0101

arxiv published 2023/02/27 · arxiv updated 2023/02/27 · openalex publication_date 2023/08/03 · openalex created_date 2023/08/04 · openalex updated_date 2026/08/02

Abstract

Recently proposed systems aim at achieving privacy using locality-sensitive hashing. We show how these approaches fail by presenting attacks against two such systems: Google's FLoC proposal for privacy-preserving targeted advertising and the MinHash Hierarchy, a system for processing location trajectories in a privacy-preserving way. Our attacks refute the pre-image resistance, anonymity, and privacy guarantees claimed for these systems. In the case of FLoC, we show how to deanonymize users using Sybil attacks and to reconstruct 10% or more of the browsing history for 30% of its users using Generative Adversarial Networks. We achieve this only analyzing the hashes used by FLoC. For MinHash, we precisely identify the location trajectory of a subset of individuals and, on average, we can limit users' trajectory to just 10% of the possible geographic area, again using just the hashes. In addition, we refute their differential privacy claims.

Citations

Cited by

Discussions

Related