Safeguarding the Social Web: Decentralized Privacy Persistence via Dual-Watermarking
Distributing privacy policies over multimedia content across multiple online social networks
The paper proposes a decentralized, multi-platform privacy enforcement scheme using dual digital watermarking (robust and semi-fragile). It allows users to maintain control over their multimedia content across multiple Online Social Networks (OSNs) without relying on a Trusted Third Party (TTP).
TL;DR
Online Social Networks (OSNs) are currently data silos. If someone steals your photo from Facebook and posts it on VK or Google+, your original privacy settings are useless. This paper introduces a decentralized framework using dual digital watermarking to embed privacy policies directly into the media, allowing different social networks to recognize and enforce your rights—even if you aren't registered on the secondary platform.
The Silo Problem: Why Your Privacy Settings Fail
When you upload a photo to an OSN, you are essentially placing it in a "walled garden." The privacy settings are external to the file. An attacker can simply:
- Download your image.
- Modify it slightly (to bypass simple hash checks).
- Re-upload it to another OSN (Profile Porting) or create a fake account (Identity Theft).
The original OSN has no way of telling the new platform that the image is yours. Current platforms ignore each other due to competition, but the authors argue that for OSNs to evolve, they must cooperate on security—much like how different email providers or telecom networks interact.
Methodology: The Dual-Watermarking Core
The authors propose a "Dual Watermarking" scheme. Unlike standard encryption which locks the file, watermarking embeds information into the pixels themselves without affecting visibility.
1. The Strategy
- Robust Watermark: Acts as a permanent ID. It survives compression, cropping, and resizing. It identifies the owner, the originating OSN, and the timestamp.
- Semi-Fragile Watermark: Acts as a "integrity seal." If someone maliciously alters the image (e.g., photoshopping a face), this watermark breaks, notifying the system of tampering.

2. Decentralized Logic (No TTP)
A critical innovation is the removal of a Trusted Third Party (TTP). Instead of a central "Privacy Police," OSNs share a common watermarking key K.
- Vector Construction: When Alice uploads a photo, OSN1 creates a vector
vcontaining a salted UserID, MediaID, and a Publication License. - Digital Signatures: OSN1 signs this vector. When the image is moved to OSN2, OSN2 extracts the watermark, verifies the signature, and checks the license. If the license says "Non-Distributable," OSN2 blocks the upload.
Empirical Evidence: The Current Vulnerability
The researchers conducted rigorous "black-box" testing on Facebook, Google+, and VK. They uploaded sets of computer-generated and high-resolution images to see if the platforms were already using watermarks.

Key Findings:
- Google+ and VK: Images were often Bit-for-Bit identical to the originals if they were below resolution thresholds. This proves zero watermarking is taking place.
- Facebook: Uses aggressive JPEG compression and metadata stripping, but no evidence of steganographic watermarking was found.
- Result: The industry is currently defenseless against cross-platform identity theft.
Economic Viability: Can OSNs Afford It?
Critics often argue that watermarking millions of images is too computationally expensive. The authors debunked this with a performance benchmark:
- A standard Intel i7-3770 can process ~460,800 images per day.
- To handle Facebook's 350 million daily uploads, the platform would need roughly 760 dedicated servers.
- In the world of hyperscale data centers, this is a negligible cost compared to the legal and reputational risks of massive privacy breaches.
Deep Insight: From Hosting to Certification
The true value of this paper is the conceptual shift of OSNs from Content Hosts to Content Certification Authorities (CCAs).
By adopting this framework:
- Shared Ownership: Two people in a photo can "co-own" the rights.
- Cascading Compliance: If privacy laws change (e.g., GDPR-style mandates), OSNs can update policies across the entire web of trust automatically.
- Revenue Protection: Artists and photographers are more likely to share high-quality work if they know the platform enforces their "Attribution" or "Non-Commercial" licenses via hardware-level triggers.
Conclusion
While technical hurdles like "legacy content" (un-watermarked images already online) exist, the proposed scheme provides a realistic roadmap for a more ethical social web. It balances the OSN's need for data mining with the user's fundamental right to control their digital likeness across the boundaries of service providers.
