PaaS: Reclaiming Privacy as a Fundamental Construct in the Social Age
Enabling Privacy as a Fundamental Construct for Social Networks
This paper introduces Privacy-as-a-Service (PaaS), a framework designed to automate and simplify privacy management in social networks. It features a novel Privacy Risk Score algorithm (based on Item Response Theory) and a proof-of-concept Facebook application, PaMP, which enables automated privacy setting propagation and recommendations.
TL;DR
Social media users are currently losing the privacy war due to "knob fatigue"—the overwhelming complexity of manual settings. This paper proposes Privacy-as-a-Service (PaaS), a framework that replaces manual tweaking with a mathematical Privacy Risk Score. By analyzing the collective behavior of a user's social graph, the system can automatically recommend and propagate optimal privacy settings, transforming privacy from a manual chore into a core architectural service.
The "Cognitive Burden" of Privacy
In the late 2000s, as Facebook and MySpace exploded, a paradox emerged: while users valued their privacy, they almost always accepted default settings. The authors argue that this isn't due to apathy, but rather a significant cognitive burden.
- Manual Knobs: Too many settings (Profile, Search, News Feed) lead to decision paralysis.
- Third-Party Gaps: Platform privacy rarely extends to heterogenous developers.
- Prior Work Failure: Leading platforms treat privacy as an "add-on" rather than a foundational construct, failing to use the social graph—the very thing that defines them—to protect users.
Methodology: The Math Behind the Privacy Score
The core innovation is the formalization of a Privacy Risk Score (). The authors move away from binary "Private/Public" switches to a probabilistic model.
1. Sensitivity ()
Sensitivity captures the inherent "secretness" of a data point (e.g., a phone number vs. a name). It is calculated based on collective reluctance: Where is the total users and is the number of users who chose to disclose that item. If everyone hides it, the sensitivity is 1.
2. Visibility ()
Visibility measures the exposure of user for item . In a dichotomous world, this is handled via a response matrix, but the authors extend this to "polytomous" levels (e.g., sharing with friends-of-friends vs. everyone).
3. Aggregate Risk
The final score is a monotonically increasing function: This formula elegantly captures the intuition: Your risk increases if you reveal sensitive info, and it increases more the further that info spreads.

Real-World Implementation: PaMP
To prove the theory, the team built PaMP (Privacy-aware MarketPlace) on Facebook. Unlike a standard marketplace (like Craigslist), PaMP uses the PaaS backend to:
- Empower targeted marketing: Only show ads to specific audience tiers.
- Privacy Propagation: If your friends have higher privacy standards than you, the app flags this and offers a one-click "strengthen my privacy" button.

Critical Insight: The Power of Social Wisdom
The most profound takeaway is the concept of Privacy Propagation. Instead of asking a user "Do you want to share your birth year?", the system asks "Your peers are 40% more private than you; would you like to match their level?" By leveraging the social graph, the platform creates a "herd immunity" effect against data over-exposure.
Future Outlook
While the current implementation is tethered to Facebook, the vision for PaaS is a set of Universal REST APIs. In a world of fragmented social apps, a centralized, platform-agnostic Privacy Service could act as a digital concierge, managing our "Privacy Index" across the entire web. The authors suggest that future iterations could include "Best Practice" templates from experts to further guide users.
Conclusion
This paper serves as a blueprint for moving privacy from a reactive, manual task to a proactive, algorithmic service. By quantifying risk through the lens of sensitivity and visibility, it provides a scalable way to protect users who would otherwise fall victim to the "default setting" trap.
