Exploiting Innocuous Activity for Correlating Users Across Sites

We study how potential attackers can identify accounts on differentsocial network sites that all belong to the same user, exploitingonly innocuous activity that inherently comes with posted content.We examine three specific features on Yelp, Flickr, and Twitter: thegeo-location attached to a user’s posts, the timestamp of posts, andthe user’s writing style as captured by language models. We showthat among these three features the location of posts is the mostpowerful feature to identify accounts that belong to the same userin different sites. When we combine all three features, the accuracyof identifying Twitter accounts that belong to a set of Flickr usersis comparable to that of existing attacks that exploit usernames.


