Browser fingerprinting often provides an attractive alternative to third-party cookies for tracking users across the web. In fact, the increasing restrictions on third-party cookies placed by common web browsers and recent regulations like the GDPR may accelerate the transition. To counter browser fingerprinting, previous work proposed several techniques to detect its prevalence and severity. However, these rely on 1) centralized web crawls and/or 2) computationally intensive operations to extract and process signals (e.g., information-flow and static analysis). To address these limitations, we present FP-Fed, the first distributed system for browser fingerprinting detection. Using FP-Fed, users can collaboratively train on-device models based on their real browsing patterns, without sharing their training data with a central entity, by relying on Differentially Private Federated Learning (DP-FL). To demonstrate its feasibility and effectiveness, we evaluate FP-Fed's performance on a set of 18.3k popular websites with different privacy levels, numbers of participants, and features extracted from the scripts. Our experiments show that FP-Fed achieves reasonably high detection performance and can perform both training and inference efficiently, on-device, by only relying on runtime signals extracted from the execution trace, without requiring any resource-intensive operation.
翻译:浏览器指纹通常为跨网站追踪用户提供了第三方Cookie的诱人替代方案。事实上,主流浏览器对第三方Cookie日益严格的限制以及GDPR等近期法规的实施,可能会加速这一转变。为对抗浏览器指纹,已有研究提出了多种检测其流行度与严重性的技术。然而,这些技术要么依赖集中式网络爬虫,要么需要计算密集型操作来提取和处理信号(例如信息流分析和静态分析)。为解决上述局限,我们提出了FP-Fed——首个用于浏览器指纹检测的分布式系统。借助FP-Fed,用户可基于真实浏览模式协作训练设备端模型,通过依赖差分隐私联邦学习(DP-FL),无需与中央实体共享训练数据。为验证其可行性与有效性,我们在包含18.3万个流行网站的测试集上评估了FP-Fed的性能,测试涉及不同隐私级别、参与者数量及从脚本中提取的特征。实验表明,FP-Fed在仅依赖执行轨迹提取的运行时信号、无需任何资源密集型操作的情况下,能够达到合理的高检测性能,并在设备端高效完成训练与推理。