BlackTree Security · Infrastructure · Automation · AI

The Tracker Can Disappear. Targeting and Metrics Still Leak the Audience.

Removing cross-site trackers does not automatically make targeted advertising private. New research models the advertising system end to end and finds that targeting choices combined with campaign-performance feedback can reveal information about an audience, even when each component is designed to protect privacy in isolation.

The paper, Making Sense of Private Advertising: A Principled Approach to a Complex Ecosystem, was published in the Proceedings on Privacy Enhancing Technologies and presented at the Privacy Enhancing Technologies Symposium. The University of Maryland highlighted the work on 24 August 2026.

Its central result is not that one named browser or advertising platform has been caught misusing data. It is a systems argument: a minimally useful advertising ecosystem gives advertisers some ability to select an audience and learn how a campaign performed. Those two functions can compose into an information channel that leaks properties of the selected group.

The feedback loop is the privacy boundary

Private-advertising proposals often divide the problem into separate technical components. One mechanism decides which users should receive an ad. Another measures impressions, clicks, conversions or other outcomes. Cryptography, aggregation, noise and trusted execution can reduce what each mechanism exposes.

The researchers argue that evaluating those mechanisms separately misses the important interaction. An advertiser can vary the group it targets and compare the resulting metrics. Repeated queries, overlapping audiences or carefully chosen customer lists can turn campaign feedback into a form of statistical inference.

In other words, the ad is not merely a message. It can also be a probe. The performance report is the response. A privacy analysis that protects the request and the response separately may still fail to protect what the sequence reveals.

This is a familiar security lesson in a different domain. Components that satisfy their own local guarantees can produce a weaker system when combined. The trust boundary sits around the full workflow, not around each API.

Why perfect privacy conflicts with useful advertising

The paper models the end-to-end pipeline and proves that perfect privacy is impossible for even a minimally useful advertising ecosystem under its assumptions. The reason is not a broken encryption primitive. It is the advertiser’s expectation that campaign results support market research.

If the system gives an advertiser no meaningful information about whether one audience responds differently from another, it loses much of the utility advertisers purchase. If it provides useful comparative feedback, some information about the audience must flow back.

The result therefore describes an inherent trade-off. Better cryptography can hide identities, constrain raw data access and reduce unnecessary exposure. It cannot make useful feedback reveal nothing at all. The difficult design question becomes which inferences the system permits, at what granularity and under what controls.

What the research does not prove

The findings need precise boundaries. They do not demonstrate that a specific company has linked anonymous browser activity to named people. They do not show that one deployed platform retains a particular data field, sells it, or uses it for advertising surveillance. They do not establish a browser vulnerability, a permission bypass or malicious exploitation.

The paper also does not make all private-advertising work pointless. Privacy-enhancing technologies can still remove conventional trackers, keep raw browsing histories on a device, aggregate reports, limit cross-site identifiers and reduce the amount of data exposed to intermediaries.

The claim is narrower and more consequential: those protections must be evaluated together with targeting and measurement. A system can improve privacy substantially and still leave an inference channel through the campaign feedback loop.

Targeting-aware metrics change the design question

The authors propose that private-advertising systems become targeting-aware. Metrics should not be released without considering how the advertiser defined the audience and what sensitive attribute might be inferred from the result.

That approach moves beyond a universal rule such as requiring a minimum audience size. Large groups can still be sensitive when they are defined by health, financial status, political affiliation or another contextual attribute. Repeated overlapping campaigns can also extract more information than any single report appears to reveal.

Possible controls include limiting query composition, constraining repeated audience refinements, tracking cumulative privacy loss and applying group-level protections for sensitive characteristics. The policy layer matters as well because no technical definition can capture every social context in which an inference becomes harmful.

The paper’s public artifact is marked Available, Functional and Reproduced by the PoPETs process. That strengthens confidence that the accompanying implementation material can be examined and run. The core impossibility result, however, is a formal and conceptual claim about the model, not an incident report from a live advertising platform.

Why browser vendors and regulators should care

Browser vendors are replacing or constraining legacy tracking mechanisms while trying to preserve advertising measurement. This research says the privacy review cannot stop at whether cookies, device identifiers or raw browsing histories are exposed.

Reviewers also need to ask what an advertiser can learn by choosing audiences, observing outcomes and repeating the process. That is an API-abuse question as much as a data-minimisation question. Legitimate functionality can become an inference primitive when it is composed across time.

Regulators face a similar problem. A platform may truthfully say that it does not disclose individual identities while still enabling sensitive group-level inference. Consent notices and data inventories that focus only on stored identifiers can miss what is derived through interactive use.

Questions defenders and privacy teams should ask

  1. Map the full feedback loop. Document audience creation, ad delivery, measurement, attribution and reporting as one system.
  2. Test composition. Evaluate repeated and overlapping campaigns rather than reviewing one report in isolation.
  3. Identify sensitive group properties. Consider health, finances, political views, employment status and other context-dependent attributes, not only direct identifiers.
  4. Measure cumulative disclosure. Rate limits and aggregation thresholds should account for information gained across multiple queries.
  5. Separate privacy improvement from perfect privacy. A design can be materially better than third-party tracking without eliminating all inference.
  6. Add governance controls. Technical restrictions, advertiser policies, audits and enforcement need to work together when leakage is inherent to useful feedback.

The tracker is not the whole threat model

The web’s privacy debate often treats the identifier as the central problem. Identifiers matter, but this research shows why removing them is not the end of the analysis. An advertiser that can choose a group and observe a useful response can still learn something about that group.

Private advertising should therefore be judged by the inferences the complete system enables, not only by the data each component says it withholds. The tracker can disappear while the feedback loop remains.


Sources

Leave a Reply

Your email address will not be published. Required fields are marked *