LAMP: Reimagining Social Media Privacy through Atomic Labeling

LAMP - Label-Based Access-Control for More Privacy in Online Social Networks

2016-01-01
Leila Bahri, Barbara Carminati, Elena Ferrari, William Lucia
Summary
Problem
Method
Results
Takeaways
Abstract

This paper introduces LAMP (Label-based Access-control for More Privacy), a fine-grained discretionary access control model for Online Social Networks (OSNs). By adapting Mandatory Access Control (MAC) principles, it enables users to assign security labels to friends and sensitivity labels to individual data atoms like likes and comments.

TL;DR

Online Social Networks (OSNs) suffer from blunt privacy tools that ignore the "dependent" nature of interactions like comments and likes. LAMP (Label-based Access-control for More Privacy) introduces a sophisticated labeling system inspired by military-grade security (MAC) but adapted for personal social use. It allows users to control every individual piece of data they own, even if it's attached to someone else's post.

The Problem: The "All-or-Nothing" Trap of ReBAC

Most OSNs today rely on Relationship-Based Access Control (ReBAC). If you categorize someone as a "Friend," they typically see everything tagged for "Friends." This creates two massive headaches:

  1. Lack of Nuance: You can't easily share a specific photo with just one person in the "Family" group without creating a whole new group.
  2. Dependent Data Chaos: When you comment on a friend's photo, the privacy of your comment is dictated by their photo's settings. You lose ownership of your interaction's visibility.

Methodology: High-Security Logic for Social Sharing

LAMP solves this by giving every object and every friend a Label.

1. The Architecture of a Label

An object's sensitivity is no longer just "Public" or "Private." It consists of:

  • Sensitivity Level (SL): From "Unclassified" to "Very High."
  • Object Type (TY): Whether it's a photo, video, or just a "like."
  • Group Set (GS): Targeted audiences (e.g., {colleagues, family}).

Typical objects' structure in OSNs Figure 1: Visualizing how dependent objects (comments, likes) form a tree structure under independent posts.

2. The Three Pillars of Access (Axioms)

LAMP operates on three mathematical "Axioms" to ensure data doesn't leak:

  • Fundamental Security Property (FSP): A requester can only see an object if their Clearance Level > Object's Sensitivity, and they belong to the permitted Group.
  • Share Higher Property (SHP): When you share a friend's post, LAMP forbids you from "declassifying" it. The copy must be at least as sensitive as the original.
  • Write Higher Property (WHT): If a "low-trust" friend posts on your wall, LAMP automatically assigns that post a high sensitivity to protect you from potential embarrassment.

Experiments: Performance at Scale

A major concern with granular control is latency. If the system has to check 1,000 labels for every comment on a viral post, will it crash?

The authors tested LAMP on the Pokec dataset (1.6 million users).

  • Chained Shares: Even if a post is reshared 50 times in a chain, the system validates access in about 80ms.
  • Massive Interaction Trees: For a post with 10,000 comments/likes, the system can evaluate the entire tree in under 8 seconds.

Performance Results Figure 2: Performance metrics showing linear growth in processing time relative to data complexity.

Critical Insight: Why This Matters

The genius of LAMP isn't just the math—it's the shift in ownership. By treating a "Like" or a "Comment" as a unique object owned by the creator (not the post-owner), LAMP solves the "multi-stakeholder" conflict that has plagued OSN research for a decade. Instead of using complex game theory to "vote" on a privacy setting, LAMP simply enforces the creator's individual label.

Conclusion & Future Work

While LAMP provides a robust technical framework, the authors acknowledge that usability is the next frontier. Manually labeling every friend is a chore. The future of this research lies in Automated Labeling—using AI to suggest sensitivity levels based on past behavior, ensuring high-end privacy doesn't come at the cost of a high-end headache.


Reference: Carminati, L. B., et al. (2016). LAMP - Label-Based Access-Control for More Privacy in Online Social Networks. Insubria University Technical Report.

Find Similar Papers

Try Our Examples

  • Search for recent papers that utilize Mandatory Access Control (MAC) or Lattice-based models to solve privacy conflicts in decentralized social networks.
  • What are the primary limitations of Relationship-Based Access Control (ReBAC) identified in subsequent research after 2016, and how do modern systems address them?
  • Explore how automated machine learning strategies have been applied to assign security labels to OSN users to reduce the manual configuration burden on end-users.
Contents
LAMP: Reimagining Social Media Privacy through Atomic Labeling
1. TL;DR
2. The Problem: The "All-or-Nothing" Trap of ReBAC
3. Methodology: High-Security Logic for Social Sharing
3.1. 1. The Architecture of a Label
3.2. 2. The Three Pillars of Access (Axioms)
4. Experiments: Performance at Scale
5. Critical Insight: Why This Matters
6. Conclusion & Future Work