Sunlight: Fine-grained Targeting Detection at Scale with Statistical Confidence

Sunlight: Fine-grained Targeting Detection at Scale with Statistical Confidence
复制标题

Sunlight:具有统计可信度的大规模细粒度目标检测

DOI:
10.1145/2810103.2813614
复制
发表时间:
2015
期刊:
Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Daniel J. Hsu
Daniel J. Hsu
中科院分区:
--
文献类型:
--
作者:
Mathias Lécuyer;Riley Spahn;Yannis Spiliopolous;A. Chaintreau;Roxana Geambasu;Daniel J. Hsu

文献摘要

被引文献

相似文献

我们提出了阳光,一个系统,检测网络上的目标现象的原因-如个性化的广告,建议,或内容-在大规模和坚实的统计信心。当今的网络越来越复杂,越来越难以渗透,因为无数的服务收集,分析,使用和交换用户的个人信息。没有人知道谁拥有什么数据,他们出于什么目的使用它,以及这些使用如何影响用户。现有的少数研究揭示了有问题的影响-例如歧视性定价和广告-但它们要么规模太小,无法概括,要么缺乏对结果信心的正式评估,使其难以信任或解释。Sunlight通过采用统计学中成熟的方法来解决目标检测的特定问题,为个人数据测量带来了一种有原则且可扩展的方法。我们的方法将不同的操作正式分为四个关键阶段:可扩展的假设生成,可解释的假设形成,统计显著性检验和多重检验校正。每个阶段都有来自统计学的多个机制的实例,每个都有不同的假设和权衡。Sunlight提供模块化设计,允许探索这个巨大的设计空间。我们探索这个空间的一部分,彻底评估分析和实验的权衡。我们的探索揭示了可扩展性和信心之间微妙的紧张关系。Sunlight的默认功能达到了一种平衡,提供了第一个可以以细粒度、大规模诊断目标的系统,并对其结果进行了可靠的统计证明。我们通过在网络上运行两个针对目标的测量研究来展示我们的系统,这两个研究都是同类研究中规模最大的。我们的研究--关于Gmail和网络上的广告定位--揭示了统计上合理的证据,与谷歌关于缺乏敏感和禁止主题定位的两项声明相矛盾。
We present Sunlight, a system that detects the causes of targeting phenomena on the web -- such as personalized advertisements, recommendations, or content -- at large scale and with solid statistical confidence. Today's web is growing increasingly complex and impenetrable as myriad of services collect, analyze, use, and exchange users' personal information. No one can tell who has what data, for what purposes they are using it, and how those uses affect the users. The few studies that exist reveal problematic effects -- such as discriminatory pricing and advertising -- but they are either too small-scale to generalize or lack formal assessments of confidence in the results, making them difficult to trust or interpret. Sunlight brings a principled and scalable methodology to personal data measurements by adapting well-established methods from statistics for the specific problem of targeting detection. Our methodology formally separates different operations into four key phases: scalable hypothesis generation, interpretable hypothesis formation, statistical significance testing, and multiple testing correction. Each phase bears instantiations from multiple mechanisms from statistics, each making different assumptions and tradeoffs. Sunlight offers a modular design that allows exploration of this vast design space. We explore a portion of this space, thoroughly evaluating the tradeoffs both analytically and experimentally. Our exploration reveals subtle tensions between scalability and confidence. Sunlight's default functioning strikes a balance to provide the first system that can diagnose targeting at fine granularity, at scale, and with solid statistical justification of its results. We showcase our system by running two measurement studies of targeting on the web, both the largest of their kind. Our studies -- about ad targeting in Gmail and on the web -- reveal statistically justifiable evidence that contradicts two Google statements regarding the lack of targeting on sensitive and prohibited topics.