Policing the Decentralized Web: Privacy-Preserving Abuse Detection

Privacy-Preserving Abuse Detection in Future Decentralised Online Social Networks

2016-01-01
Álvaro García-Recuero, Jeffrey Burdges, Christian Grothoff
Summary
Problem
Method
Results
Takeaways
Abstract

This paper proposes a privacy-preserving framework for detecting abusive behavior in decentralized online social networks (DOSNs) using supervised machine learning combined with secure multi-party computation. By leveraging specialized Private Set Intersection (PSI) protocols, the system computes graph-based features without exposing sensitive user interaction data, achieving detection performance comparable to human baselines.

TL;DR

As the world moves toward decentralized online social networks (DOSNs) to escape mass surveillance, a new problem emerges: How do we stop trolls and abusers without a central authority reading our private messages? This paper introduces a supervised learning approach that uses cryptographic "blinded" protocols to calculate social graph features, enabling a system that flags abuse while keeping user identities and subscriptions strictly private.

The Paradox of Decentralized Safety

In a centralized platform like Twitter or Facebook, the provider has a "god view" of all data, making it easy to spot spam clusters and harassment campaigns. In a decentralized network, data is end-to-end encrypted and metadata is hidden. While this is great for privacy, it is a haven for "The Four Ds" of abuse: Deny, Disrupt, Degrade, and Deceive.

The authors argue that we must move the detection logic to the edge (the user's local device). However, a local classifier needs features. If those features represent who you follow or who follows you, sharing them with a sender to verify their "reputation" would destroy privacy.

Methodology: Cryptographic Feature Engineering

The core innovation lies in how the system calculates the "Social Overlap" between two users without either user revealing their contact list.

1. Robust Feature Selection

The authors analyzed a wide array of Twitter data but quickly realized an Adaptive Adversary could easily fake many features (like hashtag counts or retweet ratios). They narrowed the focus to features that are "expensive" to forge:

  • Account Age: Verified via a decentralized timestamping service.
  • Invasive Predicate: Whether the interaction is mutual.
  • Subscriber Intersections: Measuring if your trusted circle overlaps with the sender's.

2. The PSI and BLS Protocols

To calculate the size of the intersection between Alice's and Bob's subscriber sets (), the paper introduces a multi-stage cryptographic handshake:

  • Scalar Blinding: Alice and Bob exchange hashed sets blinded by ephemeral private keys, ensuring they only learn the count of shared contacts, not the identities.
  • BLS Signatures: To prevent Bob from using "Sybil" (fake) accounts, subscribers provide Boneh-Lynn-Shacham (BLS) signatures. These allow Bob to prove a contact is "real" to Alice without Alice knowing who that contact is.

Abuse Detection Feature Set and Adversarial Analysis

Experiments & Results

The researchers tested several classifiers, including Decision Trees (DT), Random Forests (RF), and Gradient Boosting (GB).

  • Baseline Performance: Without privacy constraints, the models performed nearly as well as human reviewers.
  • Adversarial Settings: When the feature set was stripped down to only those resistant to manipulation (Account Age, etc.), the Gradient Boosting (GB) model remained the most resilient.

Performance Comparison of Classifiers

The results show that even with a "strong adaptive adversary," the system achieves an F-score of 0.42 for abusive messages. While this isn't perfect, it is a powerful signal that can be used to re-rank timelines—pushing likely abuse to the bottom rather than outright censoring it.

Critical Insight: Rank, Don't Ban

The authors suggest a shift in philosophy: Abuse detection in DOSNs should be used for ranking, not binary filtering. By integrating these scores into a local timeline construction, users are protected from seeing harmful content first, without the need for a "Ministry of Truth" to decide what can and cannot be sent.

Limitations & Future Work

The main drawback is that a determined adversary can still "age" accounts by letting them sit dormant for years. The authors propose that future work should investigate combining Proof-of-Work (PoW) with group size estimation to significantly increase the cost of creating the fake accounts required to manipulate the "Subscriber Intersection" metric.

Conclusion

This work provides a vital blueprint for the next generation of social media. It proves that we can build "Immune Systems" for the web that don't require us to trade away our anonymity or privacy to be safe from harassment.

Find Similar Papers

Try Our Examples

  • Search for recent papers that utilize State-of-the-Art Graph Neural Networks (GNNs) for decentralized and privacy-preserving abuse detection in social media.
  • What is the original paper for Private Set Intersection with Cardinality (PSI-CA) by De Cristofaro et al., and how does this paper's scalar-based variation specifically optimize for DOSN workloads?
  • Explore research that applies Zero-Knowledge Proofs (ZKPs) or Trusted Execution Environments (TEEs) as alternatives to Secure Multi-Party Computation for verifying user metadata in decentralized networks.
Contents
Policing the Decentralized Web: Privacy-Preserving Abuse Detection
1. TL;DR
2. The Paradox of Decentralized Safety
3. Methodology: Cryptographic Feature Engineering
3.1. 1. Robust Feature Selection
3.2. 2. The PSI and BLS Protocols
4. Experiments & Results
5. Critical Insight: Rank, Don't Ban
6. Limitations & Future Work
7. Conclusion