Your Friends, Your Privacy: Why Hiding Your Data Isn't Enough on Social Networks
Do online social network friends still threaten my privacy?
This paper investigates the privacy risks of attribute prediction in Online Social Networks (OSNs), specifically focusing on how information shared by a user's friends can reveal their own hidden Personally Identifiable Information (PII). Through an empirical study of 1.2 million Facebook profiles, the authors demonstrate that sensitive attributes like location and age can be predicted with high accuracy (e.g., 56.3% for current city) using simple statistical estimators based on friends' public data.
TL;DR
Even if you lock down your profile, your friends are accidentally leaking your location, age, and background. This paper proves that a simple "majority vote" of your friends' public data can pinpoint your city with over 56% accuracy and estimate your age within a few years. In the world of Online Social Networks (OSNs), privacy is a "team sport"—and your team might be losing.
The "Collateral Privacy" Problem
We have been taught that privacy is about our settings. We hide our birthdays, our current cities, and our workplaces. However, this study by researchers at the Karlsruhe Institute of Technology (KIT) highlights a persistent vulnerability: Homophily.
Homophily is the sociological tendency of "birds of a feather to flock together." In OSNs, your friends are likely to be of a similar age, live in the same area, and share similar interests. The researchers posed a critical question: Can an attacker who knows only who your friends are and what they share publicly figure out your "hidden" details?
Methodology: The "Alpha-Profile" Approach
The authors sampled 1.2 million profiles in a compliant manner (ensuring no raw PII was stored permanently). They focused on 6,400 "alpha-profiles" who provided a public friends list and compared their hidden attributes with the public attributes of their friends.
Figure 1: The visualization of friendships sampled shows a global distribution, proving the systemic nature of these correlations.
Deep Dive: Location and Age
1. The Geography of Friendship
The study found that if an attacker simply looks at the city most frequently listed by your friends, they will correctly guess your city 56.3% of the time. If they expand the search to the top three cities listed among friends, the accuracy jumps to 80.2%.
Figure 3: Cumulative Distribution Function (CDF) showing the probability of successful city prediction based on friends' data.
2. The Age Gap
Age prediction is even more surgical. While very few people (about 1.8% in the study) share their birth year publicly, those few provide enough signal for everyone else. By calculating the average age of friends, attackers can predict a user's age within 4 years with high reliability, especially for those born in the 1990s.
Figure 10: The tighter the social circle (especially in younger groups), the more accurate the age prediction becomes.
Why Some Attributes Are "Safe"
Interestingly, not everything is predictable. The study noted that attributes like Favorite Music, Employer, or Books show very low correlation (often less than 10% overlap). Unlike location or age, which are often shared constraints (people living in the same town), tastes and workplaces are diverse even among close friends.
Critical Insight: The "Lower Bound" of Risk
What makes this research particularly unsettling is that the authors used a minimal knowledge attacker model. They didn't use advanced machine learning, neural networks, or deep-web scraping. They used basic statistics that anyone with a simple script could replicate.
If a "simple" attacker can achieve 56-80% accuracy, a sophisticated attacker (using pattern learning or cross-platform linking) would likely achieve near-perfect results.
Conclusion & Future Outlook
The primary takeaway is clear: Hiding your data while leaving your friends list public is a false sense of security.
The authors are currently leveraging these findings to build a "Privacy App" that quantifies this risk for users in real-time. Until such tools are standard, the best defense remains a proactive one: curate who can see your connections, not just your profile details. As long as friends lists remain public, your privacy is never entirely your own.
