The Privacy Paradox: Why Aggressive Data Mining Hurts Social Network Profits
Privacy Policy in Online Social Network with Targeted Advertising Business
This paper investigates the optimal privacy policy for Social Network Providers (SNPs) balancing social interaction benefits and targeted advertising revenue. Using a three-stage Stackelberg game, it models the interactions between users, advertisers, and the SNP, identifying a threshold-based equilibrium for user information sharing.
TL;DR
A common assumption in big tech is that more data exploitation equals more profit. This paper proves the opposite: in a social network ecosystem, aggressive data harvesting triggers a "chilling effect" where users withhold information to protect their privacy. By using a three-stage Stackelberg game, the researchers show that an optimal privacy policy—one that restricts data exploitation—actually maximizes revenue by maintaining high user social activeness.
Problem & Motivation: The Tug-of-War for Personal Data
Social Network Providers (SNPs) are caught in a fundamental conflict. On one side, Targeted Advertising requires deep dives into user profiles to increase click-through rates. On the other side, Social Interaction—the lifeblood of the platform—thrives only when users feel safe enough to share photos, status updates, and personal preferences.
Prior work often treated these as separate issues. This paper argues they are deeply coupled. If an SNP exploits too much data, users become "dormant" or cautious, leading to a "data drought" that ultimately makes the advertising business less efficient.
Methodology: The Three-Stage Game
The researchers model the ecosystem as a hierarchical game:
- Stage I (The SNP): Sets the privacy policy (, representing the fraction of data exploited) and the advertising price ().
- Stage II (The Users): Decide their information exhibition level () based on social benefits vs. privacy loss.
- Stage III (The Advertiser): Decides whether to invest in ads based on the targeting accuracy provided by the SNP.
The Intuition of Supermodularity
The core of the methodology lies in the Supermodularity of the user game. In simple terms: if your friends are active on the network, you derive more benefit from being active too. This creates a "strategic complement" effect. However, privacy loss acts as a "strategic substitute" that pushes back against this trend.

Key Insight: The Threshold Structure
The study reveals a critical threshold ().
- Below the threshold: Users feel the privacy loss is manageable and share information fully. Here, increasing exploitation () increases SNP revenue.
- Above the threshold: Users begin to strategically reduce their social activeness (). Surprisingly, the study shows that even though the SNP takes a larger slice of the pie, the pie itself shrinks so fast that the total amount of exploited info () actually decreases.
Experiments & Results
The numerical results highlight how the optimal privacy policy stays "flexible." As the value of advertising () increases, the SNP slightly worsens the privacy policy to capture more value, but not to the point where it destroys the user experience.

As shown in the charts above, the optimal increases when users value social interaction more (), suggesting that a "loyal" or "highly social" user base gives the SNP more leeway to exploit data. However, the equilibrium consistently finds a balance that prevents user utility from plummeting.
Critical Analysis & Conclusion
Takeaway
The research provides a mathematical justification for Privacy by Design. It suggests that SNPs shouldn't view privacy regulations purely as a burden; rather, a self-imposed "privacy budget" is essential for long-term platform health and advertiser satisfaction.
Limitations & Future Work
The model assumes a single SNP. In the real world, users can jump to a different platform if one becomes too invasive. Future research incorporating market competition would add another layer of complexity: does competition lead to a "race to the bottom" for privacy, or does it force providers to compete on who respects user data more?
Furthermore, the paper treats all information as a single block. In reality, users might be okay sharing "hobbies" for ads but strictly protect "health data." Differentiating information types would be the next logical step for this framework.
