{"id":"https://openalex.org/W4385522522","doi":"https://doi.org/10.56553/popets-2023-0101","title":"Locality-Sensitive Hashing Does Not Guarantee Privacy! Attacks on Google's FLoC and the MinHash Hierarchy System","display_name":"Locality-Sensitive Hashing Does Not Guarantee Privacy! Attacks on Google's FLoC and the MinHash Hierarchy System","publication_year":2023,"publication_date":"2023-08-03","ids":{"openalex":"https://openalex.org/W4385522522","doi":"https://doi.org/10.56553/popets-2023-0101"},"language":"en","primary_location":{"id":"doi:10.56553/popets-2023-0101","is_oa":true,"landing_page_url":"https://doi.org/10.56553/popets-2023-0101","pdf_url":"https://petsymposium.org/popets/2023/popets-2023-0101.pdf","source":{"id":"https://openalex.org/S4210183172","display_name":"Proceedings on Privacy Enhancing Technologies","issn_l":"2299-0984","issn":["2299-0984"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320322","host_organization_name":"De Gruyter Open","host_organization_lineage":["https://openalex.org/P4310320322","https://openalex.org/P4310313990"],"host_organization_lineage_names":["De Gruyter Open","De Gruyter"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings on Privacy Enhancing Technologies","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://petsymposium.org/popets/2023/popets-2023-0101.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5069753715","display_name":"Florian Turati","orcid":null},"institutions":[{"id":"https://openalex.org/I35440088","display_name":"ETH Zurich","ror":"https://ror.org/05a28rw58","country_code":"CH","type":"education","lineage":["https://openalex.org/I2799323385","https://openalex.org/I35440088"]}],"countries":["CH"],"is_corresponding":false,"raw_author_name":"Florian Turati","raw_affiliation_strings":["ETH Zurich","ETH Zurich Zurich, Switzerland"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"ETH Zurich","institution_ids":["https://openalex.org/I35440088"]},{"raw_affiliation_string":"ETH Zurich Zurich, Switzerland","institution_ids":["https://openalex.org/I35440088"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102989278","display_name":"Karel Kub\u00ed\u010dek","orcid":"https://orcid.org/0000-0002-7419-2784"},"institutions":[{"id":"https://openalex.org/I35440088","display_name":"ETH Zurich","ror":"https://ror.org/05a28rw58","country_code":"CH","type":"education","lineage":["https://openalex.org/I2799323385","https://openalex.org/I35440088"]}],"countries":["CH"],"is_corresponding":false,"raw_author_name":"Karel Kubicek","raw_affiliation_strings":["ETH Zurich","ETH Zurich Zurich, Switzerland"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"ETH Zurich","institution_ids":["https://openalex.org/I35440088"]},{"raw_affiliation_string":"ETH Zurich Zurich, Switzerland","institution_ids":["https://openalex.org/I35440088"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5029976737","display_name":"Carlos Cotrini","orcid":null},"institutions":[{"id":"https://openalex.org/I35440088","display_name":"ETH Zurich","ror":"https://ror.org/05a28rw58","country_code":"CH","type":"education","lineage":["https://openalex.org/I2799323385","https://openalex.org/I35440088"]}],"countries":["CH"],"is_corresponding":false,"raw_author_name":"Carlos Cotrini","raw_affiliation_strings":["ETH Zurich","ETH Zurich Zurich, Switzerland"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"ETH Zurich","institution_ids":["https://openalex.org/I35440088"]},{"raw_affiliation_string":"ETH Zurich Zurich, Switzerland","institution_ids":["https://openalex.org/I35440088"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5025344654","display_name":"David Basin","orcid":"https://orcid.org/0000-0003-2952-939X"},"institutions":[{"id":"https://openalex.org/I35440088","display_name":"ETH Zurich","ror":"https://ror.org/05a28rw58","country_code":"CH","type":"education","lineage":["https://openalex.org/I2799323385","https://openalex.org/I35440088"]}],"countries":["CH"],"is_corresponding":false,"raw_author_name":"David Basin","raw_affiliation_strings":["ETH Zurich","ETH Zurich Zurich, Switzerland"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"ETH Zurich","institution_ids":["https://openalex.org/I35440088"]},{"raw_affiliation_string":"ETH Zurich Zurich, Switzerland","institution_ids":["https://openalex.org/I35440088"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.4684,"has_fulltext":true,"cited_by_count":9,"citation_normalized_percentile":{"value":0.85563421,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":98},"biblio":{"volume":"2023","issue":"4","first_page":"117","last_page":"131"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.994700014591217,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.994700014591217,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11045","display_name":"Privacy, Security, and Data Protection","score":0.9930999875068665,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T11980","display_name":"Human Mobility and Location-Based Analysis","score":0.9873999953269958,"subfield":{"id":"https://openalex.org/subfields/3313","display_name":"Transportation"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7596994638442993},{"id":"https://openalex.org/keywords/locality-sensitive-hashing","display_name":"Locality-sensitive hashing","score":0.72026127576828},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5969945192337036},{"id":"https://openalex.org/keywords/hash-function","display_name":"Hash function","score":0.5779883861541748},{"id":"https://openalex.org/keywords/anonymity","display_name":"Anonymity","score":0.4742385745048523},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.47137367725372314},{"id":"https://openalex.org/keywords/differential-privacy","display_name":"Differential privacy","score":0.4292919635772705},{"id":"https://openalex.org/keywords/hierarchy","display_name":"Hierarchy","score":0.42183858156204224},{"id":"https://openalex.org/keywords/locality","display_name":"Locality","score":0.4184260666370392},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.22266334295272827},{"id":"https://openalex.org/keywords/hash-table","display_name":"Hash table","score":0.15917351841926575},{"id":"https://openalex.org/keywords/law","display_name":"Law","score":0.09198540449142456}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7596994638442993},{"id":"https://openalex.org/C74270461","wikidata":"https://www.wikidata.org/wiki/Q1625299","display_name":"Locality-sensitive hashing","level":4,"score":0.72026127576828},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5969945192337036},{"id":"https://openalex.org/C99138194","wikidata":"https://www.wikidata.org/wiki/Q183427","display_name":"Hash function","level":2,"score":0.5779883861541748},{"id":"https://openalex.org/C178005623","wikidata":"https://www.wikidata.org/wiki/Q308859","display_name":"Anonymity","level":2,"score":0.4742385745048523},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.47137367725372314},{"id":"https://openalex.org/C23130292","wikidata":"https://www.wikidata.org/wiki/Q5275358","display_name":"Differential privacy","level":2,"score":0.4292919635772705},{"id":"https://openalex.org/C31170391","wikidata":"https://www.wikidata.org/wiki/Q188619","display_name":"Hierarchy","level":2,"score":0.42183858156204224},{"id":"https://openalex.org/C2779808786","wikidata":"https://www.wikidata.org/wiki/Q6664603","display_name":"Locality","level":2,"score":0.4184260666370392},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.22266334295272827},{"id":"https://openalex.org/C67388219","wikidata":"https://www.wikidata.org/wiki/Q207440","display_name":"Hash table","level":3,"score":0.15917351841926575},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.09198540449142456},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.56553/popets-2023-0101","is_oa":true,"landing_page_url":"https://doi.org/10.56553/popets-2023-0101","pdf_url":"https://petsymposium.org/popets/2023/popets-2023-0101.pdf","source":{"id":"https://openalex.org/S4210183172","display_name":"Proceedings on Privacy Enhancing Technologies","issn_l":"2299-0984","issn":["2299-0984"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320322","host_organization_name":"De Gruyter Open","host_organization_lineage":["https://openalex.org/P4310320322","https://openalex.org/P4310313990"],"host_organization_lineage_names":["De Gruyter Open","De Gruyter"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings on Privacy Enhancing Technologies","raw_type":"journal-article"},{"id":"pmh:oai:www.research-collection.ethz.ch:20.500.11850/626664","is_oa":true,"landing_page_url":"http://hdl.handle.net/20.500.11850/626664","pdf_url":null,"source":{"id":"https://openalex.org/S4306402302","display_name":"Repository for Publications and Research Data (ETH Zurich)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I35440088","host_organization_name":"ETH Zurich","host_organization_lineage":["https://openalex.org/I35440088"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Proceedings on Privacy Enhancing Technologies, 2023 (4)","raw_type":"info:eu-repo/semantics/publishedVersion"},{"id":"doi:10.3929/ethz-b-000626664","is_oa":true,"landing_page_url":"https://doi.org/10.3929/ethz-b-000626664","pdf_url":null,"source":{"id":"https://openalex.org/S7407051236","display_name":"ETH Z\u00fcrich Research Collection","issn_l":null,"issn":[],"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article-journal"}],"best_oa_location":{"id":"doi:10.56553/popets-2023-0101","is_oa":true,"landing_page_url":"https://doi.org/10.56553/popets-2023-0101","pdf_url":"https://petsymposium.org/popets/2023/popets-2023-0101.pdf","source":{"id":"https://openalex.org/S4210183172","display_name":"Proceedings on Privacy Enhancing Technologies","issn_l":"2299-0984","issn":["2299-0984"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320322","host_organization_name":"De Gruyter Open","host_organization_lineage":["https://openalex.org/P4310320322","https://openalex.org/P4310313990"],"host_organization_lineage_names":["De Gruyter Open","De Gruyter"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings on Privacy Enhancing Technologies","raw_type":"journal-article"},"sustainable_development_goals":[{"score":0.6499999761581421,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":false},"content_urls":{"pdf":"https://content.openalex.org/works/W4385522522.pdf"},"referenced_works_count":20,"referenced_works":["https://openalex.org/W192724328","https://openalex.org/W1736726159","https://openalex.org/W1873763122","https://openalex.org/W1988580225","https://openalex.org/W2019076926","https://openalex.org/W2106040044","https://openalex.org/W2118509786","https://openalex.org/W2132069633","https://openalex.org/W2145349611","https://openalex.org/W2159024459","https://openalex.org/W2219888463","https://openalex.org/W2606450996","https://openalex.org/W2618419749","https://openalex.org/W2963073614","https://openalex.org/W2963248348","https://openalex.org/W3101314853","https://openalex.org/W3105251391","https://openalex.org/W4213178287","https://openalex.org/W4229001818","https://openalex.org/W4230940751"],"related_works":["https://openalex.org/W3038283795","https://openalex.org/W2604501336","https://openalex.org/W2734500670","https://openalex.org/W2558166297","https://openalex.org/W2315671126","https://openalex.org/W2000601968","https://openalex.org/W2144265691","https://openalex.org/W2033383639","https://openalex.org/W3108918257","https://openalex.org/W3016124764"],"abstract_inverted_index":{"Recently":[0],"proposed":[1],"systems":[2],"aim":[3],"at":[4],"achieving":[5],"privacy":[6,52,141],"using":[7,69,87,131],"locality-sensitive":[8],"hashing.":[9],"We":[10,91],"show":[11,64],"how":[12,65],"these":[13,56],"approaches":[14],"fail":[15],"by":[16,99],"presenting":[17],"attacks":[18,45,71],"against":[19],"two":[20],"such":[21],"systems:":[22],"Google's":[23],"FLoC":[24],"proposal":[25],"for":[26,36,55,82],"privacy-preserving":[27,42],"targeted":[28],"advertising":[29],"and":[30,51,72],"the":[31,47,59,79,96,106,126,133],"MinHash":[32],"Hierarchy,":[33],"a":[34,41,110],"system":[35],"processing":[37],"location":[38,107],"trajectories":[39],"in":[40],"way.":[43],"Our":[44],"refute":[46,138],"pre-image":[48],"resistance,":[49],"anonymity,":[50],"guarantees":[53],"claimed":[54],"systems.":[57],"In":[58,135],"case":[60],"of":[61,78,84,109,112,125],"FLoC,":[62],"we":[63,103,117,137],"to":[66,73,122],"deanonymize":[67],"users":[68,86],"Sybil":[70],"reconstruct":[74],"10%":[75,124],"or":[76],"more":[77],"browsing":[80],"history":[81],"30%":[83],"its":[85],"Generative":[88],"Adversarial":[89],"Networks.":[90],"achieve":[92],"this":[93],"only":[94],"analyzing":[95],"hashes":[97],"used":[98],"FLoC.":[100],"For":[101],"MinHash,":[102],"precisely":[104],"identify":[105],"trajectory":[108,121],"subset":[111],"individuals":[113],"and,":[114],"on":[115],"average,":[116],"can":[118],"limit":[119],"users'":[120],"just":[123,132],"possible":[127],"geographic":[128],"area,":[129],"again":[130],"hashes.":[134],"addition,":[136],"their":[139],"differential":[140],"claims.":[142]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":3}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2023-08-04T00:00:00"}
