FakeBook: Shielding the Unrepresented via Dynamic Graph Evolution
FakeBook: Detecting Fake Profiles in On-Line Social Networks
This paper introduces FakeBook, a framework for detecting Fake Profile Attacks (FPA) in Online Social Networks (OSNs) where the victim has no previous account. The method leverages dynamic graph evolution and social interaction patterns to distinguish between legitimate users and malicious impersonators.
TL;DR
While most security research focuses on protecting existing users, the "FakeBook" paper addresses a more insidious threat: Fake Profile Attacks (FPA) against individuals who do not even have an account on a specific platform. By analyzing 80 real Facebook profiles using a custom "sensing" app, the authors demonstrate that fake profiles exhibit detectable anomalies in their friendship growth rates and internal graph structures because attackers must avoid "high-frequency contacts" to prevent immediate exposure.
Problem & Motivation: The Risk of Being Absent
In the landscape of Online Social Networks (OSNs), your digital shadow can be exploited even if you aren't "online." While Identity Cloning Attacks (ICA) involve copying an existing profile, a Fake Profile Attack (FPA) involves creating a persona for someone who hasn't joined the platform yet.
Current SOTA (State-of-the-Art) methods rely on Similarity Measures—they compare a suspect profile against a known real one. But what if there is no real one? This paper argues that OSN managers need a way to detect impersonation based purely on how the profile "behaves" and "grows" compared to the general population.
Methodology: The Dynamic Signature of Legitimacy
The authors move away from static attribute matching and focus on the Temporal Evolution of the social graph. Their approach is built on three pillars:
1. Growth Rate Stability
Normal users tend to add friends at a relatively stable rate after an initial burst. By sampling friendship accumulation at intervals (3, 5, or 10 days), they calculated a population mean () and standard deviation (). Profiles that deviate significantly from this "social rhythm" are flagged.
2. The Adversarial Dilemma (Avoidance Analysis)
An intelligent attacker (following Kerckhoffs' Principle) knows that connecting with the victim's inner circle (family, spouses, roommates) is suicide. These "high-frequency in-person contacts" would immediately notice the fake account. Therefore, an attacker must exclude these nodes, which fundamentally alters the social graph's topology.
3. Structural Anomalies
The exclusion of these core friends leads to a measurable drop in the Average Degree of the nodes within the profile’s friend network.
Figure 1: Visualizing the linear/stable growth of friends over time for real users.
Experiments & Results: Detecting the Deviants
Using data collected via a Facebook API sensing application, the researchers modeled the impact of the "Avoidance Strategy."
- Average Degree Shift: For a typical user, the average degree of their friendship network is roughly 20.07. When simulating an attacker who avoids the top 20% of the victim's most connected friends (who are likely close real-life contacts), the average degree plummeted to 8.39.
- Clustering and Components: Real profiles typically feature one "Giant Component" and several isolated singletons. Attacker graphs struggle to replicate this natural evolution while simultaneously avoiding the core nodes that provide connectivity.
Figure 2: The noticeable decrease in average degree as the attacker excludes high-degree (close) friends (10%, 20%, 30% removal).
Critical Insight & Conclusion
The core value of this work lies in the Inductive Bias that human social networks are not just random graphs; they are built on foundations of real-world proximity. The "FakeBook" approach turns the attacker's primary survival strategy—avoiding close friends—into their biggest weakness.
Takeaway: Security systems shouldn't just look at who a user claims to be, but how their community structure matures over time.
Limitations: The dataset (80 profiles) is small by modern standards, and the 2012 era of Facebook APIs allowed much deeper data harvesting than today's privacy-restricted environments. Future work must adapt these heuristics to "darker" APIs where friend-of-friend data is limited.
