Poporo: Using Formal Methods to Stop Accidental Privacy Leaks in Social Networks

Identifying Transitivity Threats in Social Networks

Sorren Hanvey, Néstor Cataño
Summary
Problem
Method
Results
Takeaways
Abstract

This paper introduces a formal verification approach to identify "transitivity threats" in social networks—unintended data exposure caused by automated content propagation. The authors present Poporo, a tool that utilizes predicate calculus and SMT solvers to ensure user-defined privacy policies are not breached by secondary actions like commenting or tagging.

TL;DR

Transitivity threats—where sharing a comment accidentally exposes the original private post to a wider audience—are a major privacy loophole in modern social networks. This paper introduces Poporo, a formal verification tool that models social interactions using predicate calculus to detect these leaks before they happen, ensuring that secondary actions never grant more access than the original owner intended.

The "Invisible" Privacy Breach: Transitivity

In the world of Facebook and LinkedIn, privacy isn't just about your settings; it's about your friends' actions.

Imagine User A shares a photo with a "Close Friends" list. User B (a friend) comments on it. In most platforms, the system's "Transitivity" logic automatically shares B's comment—and by extension, A's photo—with all of B's friends. Suddenly, strangers are viewing A's private content. This is a Transitivity Threat.

The root cause is a conflict of interest: platforms want to grow their network (higher connectivity), which often requires weakening strict privacy silos.

Methodology: Math as a Privacy Shield

The authors argue that natural language policies are too vague to catch these edge cases. Instead, they treat social network interactions as state transitions in a formal system.

1. The Matelas Model

The core of the system is Matelas, a formal specification layer written in Event-B. It defines social operations (like transmit_tolist) as mathematical events with "Guards" (pre-conditions) and "Actions" (post-conditions).

2. The Verification Pipeline

To make these complex models usable for real-world Java-based social networks, the researchers developed a multi-stage translation pipeline:

  • Event-B → JML: Mathematical specifications are turned into Java Modeling Language (JML) contracts.
  • VCGen (Verification Condition Generator): The tool calculates the "Weakest Precondition"—the minimum state required for an action to be safe.
  • SMT Solver (Yices): An automated logic engine checks if the new action's permissions are a mathematical subset of the original policy.

Poporo Tool Architecture Fig 1: The architecture of Poporo showing the flow from Policy Definition to SMT Verification.

Real-World Application: The "Comment" Scenario

The paper validates Poporo using two typical conflicting policies:

  • Original Policy: "Only my 'Close Friends' can see this photo."
  • Comment Policy: "Share my comment with my 'Work' colleagues."

Poporo extracts the relationship between these two lists. If Work is not a strict subset of Close Friends, the SMT solver flags a violation. Instead of discovering the leak after the post goes viral, the user receives a warning: "Your action might be a threat to the owner's privacy."

Original User Policy Specification Fig 2: A formal representation of a user's original privacy policy in the system.

Critical Insight: Why This Matters

Unlike existing methods like XACML (which are too rigid) or RBAC (which assume fixed roles), the Poporo approach is:

  1. Dynamic: It checks policies "on the fly" as content is shared.
  2. Transitive-Aware: It is specifically designed for the "chained" nature of social media data flow.
  3. User-Centric: It converts complex formal logic into a simple binary decision for the end user: Proceed or Stop.

Conclusion & Future Look

While Poporo provides a robust theoretical framework, its current limitation lies in user participation—users must still define their lists accurately. However, as social networks move toward more decentralized (Web3) or automated (AI-driven) moderation, integrating formal verification like Poporo into the "Social Protocol" itself could provide an ironclad guarantee of privacy that human-readable terms and conditions simply cannot match.

Find Similar Papers

Try Our Examples

  • Find recent papers that apply Formal Methods or SMT solvers to modern decentralized social media privacy models.
  • What are the foundational papers for the Matelas predicate calculus framework, and how has it evolved since this research?
  • Search for studies investigating the application of Relationship-Based Access Control (ReBAC) in preventing data leakage in multi-user content environments.
Contents
Poporo: Using Formal Methods to Stop Accidental Privacy Leaks in Social Networks
1. TL;DR
2. The "Invisible" Privacy Breach: Transitivity
3. Methodology: Math as a Privacy Shield
3.1. 1. The Matelas Model
3.2. 2. The Verification Pipeline
4. Real-World Application: The "Comment" Scenario
5. Critical Insight: Why This Matters
6. Conclusion & Future Look