PROTOSS: Stopping Privacy Leaks Before They Happen in Social Networks

PROTOSS: A Run Time Tool for Detecting Privacy Violations in Online Social Networks

2012-08-01
Özgür Kafali, Akin Günay, Pinar Yolum
Summary
Problem
Method
Results
Takeaways
Abstract

PROTOSS is a runtime privacy-checking tool for Online Social Networks (OSNs) that utilizes formal model checking (NuSMV) to detect potential privacy violations. By integrating user relations, privacy agreements modeled as social commitments, and domain-based inference rules, it identifies leakages that occur through indirect information propagation.

TL;DR

Online Social Networks (OSNs) often leak your data not because they break their own rules, but because shared relations make it easy to guess your secrets. PROTOSS is a runtime tool that uses Model Checking and Social Commitments to simulate how information flows through your social circle, flagging "inference-based" privacy violations that standard privacy settings miss.

Background: The Illusion of Privacy Settings

We’ve all seen it: you set your location to "Private," but you tag a friend in a photo who has their location set to "Public." Suddenly, your whereabouts are no longer a secret. This is an inference leakage.

Current OSNs treat privacy as a bilateral agreement between you and the platform. However, the authors argue that in a social setting, privacy is interdependent. Your privacy depends on your relations (friend, colleague, family) and the rules governing those roles.

Methodology: Formalizing Social Rules

The core innovation of PROTOSS lies in its conversion of messy social interactions into a rigorous mathematical model.

1. Social Commitments

Instead of simple "Allow/Deny" rules, the authors use Commitments: C(debtor, creditor, condition, proposition).

  • Example: The OSN (debtor) commits to Charlie (creditor) that if Charlie is at a conference (condition), his location will not be visible to colleagues (proposition).

2. Inference Rules: The "Hidden" Leakage

PROTOSS accounts for the "Physical Intuition" of the world through local rules. For example: visible(location(Y, W), Z) ← visible(with(X, Y), Z) ∧ visible(location(X, W), Z) Translation: If User Z knows X and Y are together, and Z knows where X is, Z automatically knows where Y is.

3. The Architecture

The PROTOSS engine acts as a "Privacy Checker" sitting between the user and the OSN operator. It feeds the social graph and commitments into NuSMV, a symbolic model checker that explores all possible "states" of the network to see if a privacy violation (a CTL formula) could ever become true.

Privacy-aware OSN architecture

Experiments: Why "Dual Roles" Are Dangerous

The researchers tested PROTOSS on scenarios involving three users: Charlie, Sally, and Linus.

  • Case 1 (Safe): If the system only tracks "who is with whom" but doesn't have a rule for sharing raw location data, Charlie’s privacy remains intact even if he is with a public user.
  • Case 2 (Violation): If Linus is both a friend (allowed to see location) and a colleague (restricted from seeing location), a conflict arises. PROTOSS detects that the "Colleague" privacy commitment is violated because the "Friend" relationship leaks the data.

The PROTOSS Interface In the interface above, the right pane displays the result of the NuSMV check, showing whether a specific privacy property holds or is violated based on current network relations.

Critical Insight: Beyond Content Filtering

The value of this work is the realization that Privacy is a graph problem, not a file-permission problem.

While modern platforms like Meta or X focus on filtering what you post, PROTOSS checks the reachability of information through the social graph. By using Computation Tree Logic (CTL), the tool doesn't just look at the current state; it looks at all future possible states—such as what happens if you add a new friend or join a new group.

Limitations and Future Work

  • Scalability: Model checking is computationally expensive (state-space explosion). Running this for millions of users on Facebook would require significant optimization or localized graph partitioning.
  • User Modeling: The tool assumes users can define their relations accurately. In reality, users often struggle with complex privacy categories.

Conclusion

PROTOSS demonstrates that formal methods—usually reserved for hardware verification—have a place in the social web. By treating our social interactions as a state-transition system, it offers a glimpse into a future where OSNs can proactively warn users: "Warning: Tagging this person will reveal your location to your boss."

Find Similar Papers

Try Our Examples

  • Search for recent studies that utilize Model Checking or Formal Methods to detect privacy violations in decentralized or federated social networks.
  • What are the foundational papers on "Social Commitments" in Multi-Agent Systems (MAS), and how has the formal logic for these commitments evolved since the work of Singh (1999)?
  • Investigate how modern Graph Neural Networks (GNNs) are being used to predict or mitigate inference-based privacy leakages in large-scale social graphs compared to formal model checking approaches.
Contents
PROTOSS: Stopping Privacy Leaks Before They Happen in Social Networks
1. TL;DR
2. Background: The Illusion of Privacy Settings
3. Methodology: Formalizing Social Rules
3.1. 1. Social Commitments
3.2. 2. Inference Rules: The "Hidden" Leakage
3.3. 3. The Architecture
4. Experiments: Why "Dual Roles" Are Dangerous
5. Critical Insight: Beyond Content Filtering
6. Limitations and Future Work
7. Conclusion