TRAP: using TaRgeted Ads to unveil Google personal Profiles
Mauro Conti, Vittoria Cozza, Marinella Petrocchi, Angelo Spognardi

TL;DR
This paper demonstrates how external attackers can exploit Google's targeted advertising system to infer personal user profile information, revealing significant privacy vulnerabilities in online ad services.
Contribution
It introduces a novel attack method that combines Google AdWords data with website data to extract personal information from user profiles.
Findings
The attack is effective in inferring personal data.
It exposes a significant privacy vulnerability.
The results highlight the need for more privacy-aware advertising solutions.
Abstract
In the last decade, the advertisement market spread significantly in the web and mobile app system. Its effectiveness is also due thanks to the possibility to target the advertisement on the specific interests of the actual user, other than on the content of the website hosting the advertisement. In this scenario, became of great value services that collect and hence can provide information about the browsing user, like Facebook and Google. In this paper, we show how to maliciously exploit the Google Targeted Advertising system to infer personal information in Google user profiles. In particular, the attack we consider is external from Google and relies on combining data from Google AdWords with other data collected from a website of the Google Display Network. We validate the effectiveness of our proposed attack, also discussing possible application scenarios. The result of our…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
