Bots can Snoop: Uncovering and Mitigating Privacy Risks of Bots in Group Chats
Kai-Hsiang Chou, Yi-Min Lin, Yi-An Wang, Jonathan Weiping Li, Tiffany, Hyun-Jin Kim, Hsu-Chun Hsiao

TL;DR
This paper reveals privacy risks posed by chatbots in group chats, demonstrating their potential to access and link user information, and introduces SnoopGuard, a protocol that enhances privacy while maintaining security.
Contribution
The paper identifies privacy vulnerabilities in current group messaging protocols and proposes SnoopGuard, a novel secure protocol that limits chatbot access and preserves user anonymity.
Findings
Chatbots often access more messages than necessary.
There is a 3.6% chance chatbots recognize users across groups.
SnoopGuard maintains privacy with acceptable message overhead.
Abstract
New privacy concerns arise with chatbots on group messaging platforms. Chatbots may access information beyond their intended functionalities, such as sender identities or messages unintended for chatbots. Chatbot developers may exploit such information to infer personal information and link users across groups, potentially leading to data breaches, pervasive tracking, or targeted advertising. Our analysis of conversation datasets shows that (1) chatbots often access far more messages than needed, and (2) when a user joins a new group with chatbots, there is a 3.6% chance that at least one of the chatbots can recognize and associate the user with their previous interactions in other groups. Although state-of-the-art (SoA) group messaging protocols provide robust end-to-end encryption and some platforms have implemented policies to limit chatbot access, no platforms successfully combine…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Spam and Phishing Detection
