Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified...

56
Alessandro Acquisti, Ralph Gross, Fred Stutzman Heinz College, Carnegie Mellon University Work supported by NSF under Grants 0713361 and 0424422, and by the U.S. Army Research Office under Contract DAAD190210389 Black Hat Webcast Series Faces of Facebook: Privacy in the Age of Augmented Reality

Transcript of Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified...

Page 1: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Alessandro Acquisti, Ralph Gross, Fred Stutzman

Heinz College, Carnegie Mellon University

Work supported by NSF under Grants 0713361 and 0424422, and by the  U.S. Army Research Office under Contract DAAD190210389

Black Hat Webcast Series

Faces of Facebook: Privacy in the Age of Augmented Reality

Page 2: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo
Page 3: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

http://www.heinz.cmu.edu/~acquisti/face‐recognition‐study‐

FAQ/

[email protected]

Page 4: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

In 2000, 100 billion photos were shot worldwide

In 2010, 2.5 billion photos per monthwere uploaded by 

Facebook users alone

In 1997, the best face recognizer in FERET program scored 

error rate of 0.54 (false reject rate at false accept rate of 1 in 

1000)

In 2010, the best recognizer scored 0.003 (almost three orders 

of magnitudes better)

Page 5: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Background

Face recognition is entering consumers products

Facebook has licensed Face.com technology to enable

automated tagging

Microsoft has deployed face recognition on Kinect

Google has acquired Neven Vision, Riya, and PittPatt and

deployed face recognition into Picasa

Apple has acquired Polar Rose, and deployed face recognition

into iPhoto

Page 6: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Background

Someone asked during the Webinar: are there

open source face recognizers?

Answer: libface seems to be an example

(http://libface.sourceforge.net/file/Home.html).

However, we have not tested it

Page 7: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Our focus: Converging technologies

Page 8: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Our questions

1.

2.

Page 9: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Agenda

Page 10: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Agenda

Page 11: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiments

Page 12: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

In a nutshellUn-Identified DB

Profiles on Match.com, Prosper.com, etc.

Photo repositories (e.g., Flickr)

Open web cams CCTVs Your face on the street

(Publicly available) Identified DB

Personal Profiles on Facebook.com,  LinkedIn, etc.

Gov’t or corporate databases Organizational rosters

[1]

[3]

[2]

[5][4]

• Additional, sensitive inferences (e.g. sexual orientation, SSN, etc.)

Page 13: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Identified DB in our experiments

Page 14: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 1

Page 15: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 1: Data

Page 16: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 1: Data

Page 17: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 1: Data

Page 18: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 1: Data

Page 19: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 1: Approach

Unidentified Database:Dating site Photos

Identified Database: Facebook Photos

Re-Identified Individual

Page 20: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 1: Evaluation

Page 21: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 1: Evaluation

Page 22: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 1: Results

Page 23: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 1: Results

Page 24: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 1: Comments

Page 25: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 2

Page 26: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 2: Data

Page 27: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 2: Process

Page 28: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 2: Approach

Page 29: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 2: Examples

Facebook image(Possibly) identified

Campus shotUnidentified

Page 30: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Experiment 2: Results

Page 31: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

What we have shown so far

+ =

Page 32: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

What we had done before (Acquisti and Gross 2009)

+ = SSN

Page 33: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Can you do 1+1? Experiment 3

+ = SSN

I.e., predicting SSNs (or other sensitive information) from faces

27% of subjects’ first 5 SSN digits identified with four attempts ‐ starting from their faces

Page 34: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Data “accretion”

Anonymous face

Matchingface

Presumptive name

Inferable sensitive information

Online available information

Facebook, LinkedIn,

Org rosters, …

Demographics, Interests, Friends, …

SSNs, Credit score, Political/sexual orientation, …

Page 35: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Privacy in the Age of Augmented Reality: Real time, peer‐based, sensitive predictions

Page 36: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Privacy in the Age of Augmented Reality: Real time, peer‐based, sensitive predictions

http://money.cnn.com/video/technology/2011/10/05/t‐ts‐

iphone‐camera‐id.cnnmoney/?iid=EL

http://www.bbc.co.uk/news/magazine‐15069858

http://abclocal.go.com/kgo/story?section=news/7_on_your_sid

e&id=8425742

Page 37: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Agenda

Page 38: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Scenarios and trade‐offs

Page 39: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo
Page 40: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Implications: Key themes

Page 41: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Limitations 

Page 42: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Agenda

Page 43: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Data sources

Mining publicly available data

Hacking

Page 44: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Example: Facebook Facebook has implemented a verified identity policy, actively 

promotes tagging of its members, makes names and primary 

photo public to all by default

Other photos accessible by connected profiles, Facebook, 3rd party apps, …

Simple test based on FB’s directory (accessible without login):

~800 million users

Randomly sampled 1906 images 

In 46% exactly one face detected (in 59.7% at least one face detected)

Estimated 90% of members using real names (CMU survey)

Extrapolating: about 330 million uniquely identified faces publicly 

accessible

Page 45: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Accuracy Face recognition research is focusing on:

Lighting

Non‐frontal shots

Facial hair

Metadata

[…]

Page 46: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Cooperative subjects andubiquitous devices

Page 47: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

about 280M)

Up to more than 4 hours to find a potential match

Cost: $2/hr.

Computational costs and extrapolations

Page 48: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

US 14+yro population about 300M

Fewer than 5 minutes to find a potential match

Or, 10 seconds using larger clusters ($60/hr, assuming prices/per 

hour for clusters stay the same)

Computational costs and extrapolations

Page 49: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Extrapolations

Page 50: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Implications – cont’d

Page 51: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Agenda

Page 52: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Solutions?

Page 53: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Solutions?

Page 54: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

Solutions?

Page 55: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

OECD Privacy Guidelines

Use limitation

Purpose specification

Page 56: Faces of Facebook: Privacy in the Age of Augmented Facebook Facebook has implemented a verified identity policy, actively promotes tagging of its members, makes names and primary photo

economics privacy

http://www.heinz.cmu.edu/~acquisti/economics-

privacy.htm

[email protected]

For More Information