Skip site navigation
Maryland Today
Athletics Arts & Culture Campus & Community People Research
Athletics Arts & Culture Campus & Community People Research

Targeted Ads Come with Unavoidable Privacy Trade-Offs, UMD Study Finds

Tech companies and browser developers have spent years pursuing a seemingly ideal solution to one of the web’s thorniest problems: engineering systems to make online advertising effective without sacrificing user privacy.

New research co-authored at the University of Maryland shows, however, that perfect privacy and useful targeted advertising cannot coexist.

The findings, presented last month at the Privacy Enhancing Technologies Symposium in Canada, challenge a foundational hope in privacy engineering. Rather than treating ad targeting and campaign measurement as separate features, the researchers zoomed out to examine them as two sides of the same coin. 

In doing so, they revealed that trying to protect user privacy for both ad targeting and ad metrics simultaneously creates systemic vulnerabilities—a big-picture conflict that previous studies had overlooked by analyzing each piece in isolation.

Gabe Kaptchuk, a study co-author and UMD assistant professor of computer science, said the work demonstrates why the security of an advertising system cannot be evaluated piece by piece.

“Our research shows that when you connect targeting and performance feedback, the interaction introduces a fundamental, unavoidable layer of information leakage,” he said.

Along with Kaptchuk, the research team includes lead author Kyle Hogan, an electrical engineering and computer science Ph.D. student at the Massachusetts Institute of Technology (MIT); Alishah Chator, assistant professor of mathematics at Baruch College; Mayank Varia, associate professor of computing and data sciences at Boston University; and Srinivas Devadas, the Edwin Sibley Webster Professor of electrical engineering and computer science at MIT.

It’s already established that online tracking has the potential to cause concrete harm. Commercial ad networks can build profiles around sensitive characteristics—identifying, for example, people believed to be “depression-prone” or “credit-reliant.” Such profiling has been shown to enable predatory marketing, discriminatory job or housing advertising, and manipulative political microtargeting.

But the researchers found that efforts to prevent tracking of individuals have overlooked a basic contradiction: The performance metrics advertisers need to evaluate and refine campaigns can itself reveal information about users.

“Simply throwing privacy-enhancing technologies at the problem won't work—we need to be careful about designing interventions,” said Kaptchuk, who has an appointment in the University of Maryland Institute for Advanced Computer Studies and is also a core faculty member in the Maryland Cybersecurity Center. “If we’re unable to make advertising private on a technical level, then we require robust social mechanisms to ensure that advertisers use digital advertising platforms responsibly.”