Search papers, labs, and topics across Lattice.
This paper investigates the privacy implications of interactive targeted advertising on TikTok, Facebook, and Instagram. It finds that advertisers can identify users who fulfill specific targeting criteria by observing those who interact with their ads, despite platform promises to protect user data. The authors propose design modifications to enhance user transparency and prevent unintentional disclosure of sensitive attributes.
Social media platforms' interactive ad designs let advertisers bypass privacy promises and identify users based on their engagement with targeted ads.
Popular social media platforms TikTok, Facebook and Instagram allow third-parties to run targeted advertising campaigns on sensitive attributes in-platform. These ads are interactive by default, meaning users can comment or ``react''(e.g., ``like'', ``love'') to them. We find that this platform-level design choice creates a privacy loophole such that advertisers can view the profiles of those who interact with their ads, thus identifying individuals that fulfill certain targeting criteria. This behavior is in contradiction to the promises made by the platforms to hide user data from advertisers. We conclude by suggesting design modifications that could provide users with transparency about the consequences of ad interaction to protect against unintentional disclosure.