Measuring Profile Distance: A Metric Approach to OSN Privacy
Measuring profile distance in online social networks
This paper introduces a metric-based method to quantify and visualize privacy in Online Social Networks (OSNs) by representing user profiles as points in n-dimensional Euclidean space. The core contribution is the "Personal Sphere" concept, which uses distance measurements to determine if third-party applications or other user profiles conform to a user's specific privacy preferences.
TL;DR
In the era of expanding Online Social Networks (OSNs), privacy is no longer a binary toggle. This paper proposes a mathematical framework to represent user profiles and application permissions as coordinates in Euclidean space. By defining a "Personal Sphere," the system can quantitatively determine and visualize whether a third-party app (like a Facebook game) violates a user's inherent privacy comfort zone.
Background: The Trust Gap in OSNs
Social networks have evolved from simple profile pages into massive application platforms. While users might set their profiles to "Friends Only," the moment they install an app, they often grant permissions that bypass these protections.
The authors identify a critical Motivation: users suffer from "privacy fatigue" and technical complexity. They cannot easily judge if an application’s request for "birthday access" or "hometown info" is reasonable. The research intuition here is that privacy is a proximity problem—if an application's data demands are "too far" from your personal profile settings, it should be flagged as a threat.
Methodology: Mapping Privacy to Geometry
The core of the paper lies in treating a user profile as a vector in an -dimensional space .
1. The Euclidean Distance
By assigning numerical values to settings (e.g., Only Me = 0, Everyone = 3), any profile becomes a point. The distance between two users and is calculated as:
2. The Personal Sphere
A user defines a Personal Sphere with a radius . Any profile or application falling outside this radius is considered "dissimilar" or "untrustworthy."
3. Application-to-Profile Mapping
The most innovative step is the function , which translates application permission requests (like user_birthday) into the user profile space. This allows the system to treat an app as if it were another "user" and see where it sits relative to your personal sphere.
Figure 1: A 2D visualization using Multi-Dimensional Scaling (MDS) showing a user's personal sphere and surrounding friends.
Case Study: Facebook Application Clusters
The authors applied this method to the Facebook ecosystem, analyzing 15 top applications. They discovered that applications tend to "cluster" in space based on their greed for data.
- Cluster 1 (Low Demand): Apps like Farmville only request basic info and sit close to the user's center.
- Cluster 3 (High Demand): Apps like Causes require birthdays and stream access.
- The Outlier: Are You Interested? requested 11+ permissions, placing it far outside the typical user's personal sphere.
Figure 2: Comparison between the 'Recommended' profile and the 'Friends Only' profile. Note how Cluster 3 and outliers fall outside the sphere as privacy settings tighten.
Critical Insight: Why This Matters
This work shifts privacy from qualitative policies (text-heavy agreements) to quantitative metrics (distance).
Key Takeaways:
- Visualization is Protection: Using MDS to show a user they are "moving" into a dangerous area of the map when installing an app is more effective than a permissions popup.
- Automated Auditing: OSN providers could use this to rank applications by "Privacy Proximity," rewarding developers who follow the principle of least authority.
- Dynamic Adaptation: The radius doesn't have to be static; it can be tuned using machine learning to reflect a user's evolving sensitivity.
Limitations and Future Work
While the Euclidean distance is a strong start, it treats all privacy dimensions as equally weighted. Future iterations should likely use Weighted Euclidean Distance, as a leak of "Contact Info" is arguably more damaging than a leak of "Favorite Books."
The authors conclude that integrating these metrics into the UI of social networks could significantly reduce the "Identity Theft" and "Unauthorized Sharing" issues that plague modern OSNs.
