{"id":"https://openalex.org/W4416258714","doi":"https://doi.org/10.1145/3774904.3793060","title":"When Ads Become Profiles: Uncovering the Invisible Risk of Web Advertising at Scale with LLMs","display_name":"When Ads Become Profiles: Uncovering the Invisible Risk of Web Advertising at Scale with LLMs","publication_year":2026,"publication_date":"2026-04-09","ids":{"openalex":"https://openalex.org/W4416258714","doi":"https://doi.org/10.1145/3774904.3793060"},"language":"en","primary_location":{"id":"doi:10.1145/3774904.3793060","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3774904.3793060","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Web Conference 2026","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1145/3774904.3793060","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Baiyu Chen","orcid":"https://orcid.org/0009-0000-8617-9635"},"institutions":[{"id":"https://openalex.org/I31746571","display_name":"UNSW Sydney","ror":"https://ror.org/03r8z3t63","country_code":"AU","type":"education","lineage":["https://openalex.org/I31746571"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Baiyu Chen","raw_affiliation_strings":["The University of New South Wales, Sydney, NSW, Australia"],"raw_orcid":"https://orcid.org/0009-0000-8617-9635","affiliations":[{"raw_affiliation_string":"The University of New South Wales, Sydney, NSW, Australia","institution_ids":["https://openalex.org/I31746571"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5002217875","display_name":"Benjamin Tag","orcid":"https://orcid.org/0000-0002-7831-2632"},"institutions":[{"id":"https://openalex.org/I31746571","display_name":"UNSW Sydney","ror":"https://ror.org/03r8z3t63","country_code":"AU","type":"education","lineage":["https://openalex.org/I31746571"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Benjamin Tag","raw_affiliation_strings":["The University of New South Wales, Sydney, NSW, Australia"],"raw_orcid":"https://orcid.org/0000-0002-7831-2632","affiliations":[{"raw_affiliation_string":"The University of New South Wales, Sydney, NSW, Australia","institution_ids":["https://openalex.org/I31746571"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5000564739","display_name":"Hao Xue","orcid":"https://orcid.org/0000-0003-1700-9215"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Hao Xue","raw_affiliation_strings":["Hong Kong University of Science and Technology (Guangzhou), Guangzhou, Guangdong, China"],"raw_orcid":"https://orcid.org/0000-0003-1700-9215","affiliations":[{"raw_affiliation_string":"Hong Kong University of Science and Technology (Guangzhou), Guangzhou, Guangdong, China","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5023853044","display_name":"Daniel Angus","orcid":"https://orcid.org/0000-0002-1412-5096"},"institutions":[{"id":"https://openalex.org/I160993911","display_name":"Queensland University of Technology","ror":"https://ror.org/03pnv4752","country_code":"AU","type":"education","lineage":["https://openalex.org/I160993911"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Daniel Angus","raw_affiliation_strings":["Queensland University of Technology, Brisbane, QLD, Australia"],"raw_orcid":"https://orcid.org/0000-0002-1412-5096","affiliations":[{"raw_affiliation_string":"Queensland University of Technology, Brisbane, QLD, Australia","institution_ids":["https://openalex.org/I160993911"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5090893421","display_name":"Flora D. Salim","orcid":"https://orcid.org/0000-0002-1237-1664"},"institutions":[{"id":"https://openalex.org/I31746571","display_name":"UNSW Sydney","ror":"https://ror.org/03r8z3t63","country_code":"AU","type":"education","lineage":["https://openalex.org/I31746571"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Flora Salim","raw_affiliation_strings":["The University of New South Wales, Sydney, NSW, Australia"],"raw_orcid":"https://orcid.org/0000-0002-1237-1664","affiliations":[{"raw_affiliation_string":"The University of New South Wales, Sydney, NSW, Australia","institution_ids":["https://openalex.org/I31746571"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.00159199,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"9604","last_page":"9615"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.3158999979496002,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.3158999979496002,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T12262","display_name":"Hate Speech and Cyberbullying Detection","score":0.13210000097751617,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11045","display_name":"Privacy, Security, and Data Protection","score":0.07739999890327454,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.6625999808311462},{"id":"https://openalex.org/keywords/profiling","display_name":"Profiling (computer programming)","score":0.6251999735832214},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.6068000197410583},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.5996999740600586},{"id":"https://openalex.org/keywords/corporate-governance","display_name":"Corporate governance","score":0.48240000009536743},{"id":"https://openalex.org/keywords/targeted-advertising","display_name":"Targeted advertising","score":0.382999986410141},{"id":"https://openalex.org/keywords/pipeline","display_name":"Pipeline (software)","score":0.3813000023365021},{"id":"https://openalex.org/keywords/matching","display_name":"Matching (statistics)","score":0.37439998984336853},{"id":"https://openalex.org/keywords/generative-grammar","display_name":"Generative grammar","score":0.3718000054359436}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.6625999808311462},{"id":"https://openalex.org/C187191949","wikidata":"https://www.wikidata.org/wiki/Q1138496","display_name":"Profiling (computer programming)","level":2,"score":0.6251999735832214},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6086000204086304},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.6068000197410583},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.5996999740600586},{"id":"https://openalex.org/C39389867","wikidata":"https://www.wikidata.org/wiki/Q380767","display_name":"Corporate governance","level":2,"score":0.48240000009536743},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.4259999990463257},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4163999855518341},{"id":"https://openalex.org/C2777459780","wikidata":"https://www.wikidata.org/wiki/Q1628411","display_name":"Targeted advertising","level":2,"score":0.382999986410141},{"id":"https://openalex.org/C43521106","wikidata":"https://www.wikidata.org/wiki/Q2165493","display_name":"Pipeline (software)","level":2,"score":0.3813000023365021},{"id":"https://openalex.org/C165064840","wikidata":"https://www.wikidata.org/wiki/Q1321061","display_name":"Matching (statistics)","level":2,"score":0.37439998984336853},{"id":"https://openalex.org/C39890363","wikidata":"https://www.wikidata.org/wiki/Q36108","display_name":"Generative grammar","level":2,"score":0.3718000054359436},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3709999918937683},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.367900013923645},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.3528999984264374},{"id":"https://openalex.org/C166052673","wikidata":"https://www.wikidata.org/wiki/Q83021","display_name":"Empirical evidence","level":2,"score":0.34779998660087585},{"id":"https://openalex.org/C120936955","wikidata":"https://www.wikidata.org/wiki/Q2155640","display_name":"Empirical research","level":2,"score":0.33980000019073486},{"id":"https://openalex.org/C518677369","wikidata":"https://www.wikidata.org/wiki/Q202833","display_name":"Social media","level":2,"score":0.3319000005722046},{"id":"https://openalex.org/C49937458","wikidata":"https://www.wikidata.org/wiki/Q2599292","display_name":"Probabilistic logic","level":2,"score":0.31630000472068787},{"id":"https://openalex.org/C26760741","wikidata":"https://www.wikidata.org/wiki/Q160402","display_name":"Perception","level":2,"score":0.31459999084472656},{"id":"https://openalex.org/C143275388","wikidata":"https://www.wikidata.org/wiki/Q92438","display_name":"Microblogging","level":3,"score":0.31369999051094055},{"id":"https://openalex.org/C32896092","wikidata":"https://www.wikidata.org/wiki/Q189447","display_name":"Risk management","level":2,"score":0.2992999851703644},{"id":"https://openalex.org/C195324797","wikidata":"https://www.wikidata.org/wiki/Q33742","display_name":"Natural language","level":2,"score":0.29179999232292175},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.2888999879360199},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.2874999940395355},{"id":"https://openalex.org/C49630185","wikidata":"https://www.wikidata.org/wiki/Q6980675","display_name":"Natural experiment","level":2,"score":0.2842999994754791},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.27480000257492065},{"id":"https://openalex.org/C2778755073","wikidata":"https://www.wikidata.org/wiki/Q10858537","display_name":"Scale (ratio)","level":2,"score":0.27219998836517334},{"id":"https://openalex.org/C2780792186","wikidata":"https://www.wikidata.org/wiki/Q193206","display_name":"Anecdote","level":2,"score":0.2662999927997589},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.26019999384880066},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.2565999925136566},{"id":"https://openalex.org/C167966045","wikidata":"https://www.wikidata.org/wiki/Q5532625","display_name":"Generative model","level":3,"score":0.25619998574256897}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.1145/3774904.3793060","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3774904.3793060","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Web Conference 2026","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2509.18874","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2509.18874","pdf_url":"https://arxiv.org/pdf/2509.18874","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"pmh:doi:10.48550/arxiv.2509.18874","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},{"id":"doi:10.48550/arxiv.2509.18874","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2509.18874","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.1145/3774904.3793060","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3774904.3793060","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Web Conference 2026","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Regulatory":[0],"limits":[1],"on":[2,10],"explicit":[3],"targeting":[4],"have":[5],"not":[6,188],"eliminated":[7],"algorithmic":[8],"profiling":[9,175,213],"the":[11,38,111,162,198,225,229,238],"Web,":[12],"as":[13,78,206],"optimisation":[14],"systems":[15],"still":[16],"adapt":[17],"ad":[18,67,98,122,203,226],"delivery":[19],"to":[20,62,82,90,109],"users'":[21],"private":[22,64,117,135],"attributes.":[23],"The":[24,242],"widespread":[25],"availability":[26],"of":[27,115,161],"powerful":[28],"zero-shot":[29],"multimodal":[30],"Large":[31],"Language":[32],"Models":[33],"(LLMs)":[34],"has":[35],"dramatically":[36],"lowered":[37],"barrier":[39],"for":[40,45,191,232],"exploiting":[41],"these":[42,60],"latent":[43],"signals":[44,61],"adversarial":[46,79],"inference.":[47],"We":[48,70],"investigate":[49],"this":[50,88],"emerging":[51],"societal":[52],"risk,":[53],"specifically":[54],"how":[55],"adversaries":[56],"can":[57,130],"now":[58],"exploit":[59],"reverse-engineer":[63],"attributes":[65,118],"from":[66,101,119],"exposure":[68],"alone.":[69],"introduce":[71],"a":[72,91,106,159,189,192,207,221],"novel":[73],"pipeline":[74],"that":[75,127,184,202,214],"leverages":[76],"LLMs":[77,129],"inference":[80],"engines":[81],"perform":[83],"natural":[84],"language":[85],"profiling.":[86],"Applying":[87],"method":[89],"longitudinal":[92],"dataset":[93],"comprising":[94],"over":[95],"435,000":[96],"Facebook":[97],"impressions":[99],"collected":[100],"891":[102],"users,":[103],"we":[104],"conducted":[105],"large-scale":[107],"study":[108],"assess":[110],"feasibility":[112],"and":[113,142,150,166,228],"precision":[114],"inferring":[116],"passive":[120],"online":[121],"observations.":[123],"Our":[124],"results":[125],"demonstrate":[126],"off-the-shelf":[128],"accurately":[131],"reconstruct":[132],"complex":[133],"user":[134],"attributes,":[136],"including":[137],"party":[138],"preference,":[139],"employment":[140],"status,":[141],"education":[143],"level,":[144],"consistently":[145],"outperforming":[146],"strong":[147],"census-based":[148],"priors":[149],"matching":[151],"or":[152],"exceeding":[153],"human":[154],"social":[155],"perception":[156],"at":[157,246],"only":[158],"fraction":[160],"cost":[163],"(223\u00d7":[164],"lower)":[165],"time":[167],"(52\u00d7":[168],"faster)":[169],"required":[170],"by":[171],"humans.":[172],"Critically,":[173],"actionable":[174],"is":[176,187,244],"feasible":[177],"even":[178],"within":[179],"short":[180],"observation":[181],"windows,":[182],"indicating":[183],"prolonged":[185],"tracking":[186],"prerequisite":[190],"successful":[193],"attack.":[194],"These":[195],"findings":[196],"provide":[197],"first":[199],"empirical":[200],"evidence":[201],"streams":[204],"serve":[205],"high-fidelity":[208],"digital":[209],"footprint,":[210],"enabling":[211],"off-platform":[212],"inherently":[215],"bypasses":[216],"current":[217],"platform":[218],"safeguards,":[219],"highlighting":[220],"systemic":[222],"vulnerability":[223],"in":[224,237],"ecosystem":[227],"urgent":[230],"need":[231],"responsible":[233],"web":[234],"AI":[235,240],"governance":[236],"generative":[239],"era.":[241],"code":[243],"available":[245],"https://github.com/Breezelled/when-ads-become-profiles.":[247]},"counts_by_year":[],"updated_date":"2026-06-12T08:23:45.883708","created_date":"2025-10-10T00:00:00"}
