Cybersecurity Risks of Social Network Data Aggregation: Leveraging Machine Learning and LLMs in Cloud Environments

Alex Kaplunovich · 2024

Social networks have become an integral part of modern life, providing APIs that enable the extraction of vast amounts of user data. Individuals frequently and willingly upload personal information, including photographs, opinions, and geographical locations, across various online platforms. Motivated by the amount of this data, our study aims to quantify the extent of personal information that can be harvested using automated cloud-based serverless architectures, social network APIs, and state-of-the-art Data Science techniques. This paper serves as a compelling exposé on the fragility of digital privacy, demonstrating how easily user data can be aggregated and analyzed through contemporary cloud computing technologies. Utilizing advanced Machine Learning graph models, we extracted a multitude of data points such as geolocations, social connections, similar user profiles, and even made accurate predictions about potential influencers and missing social connections within a user's network. Scalable serverless cloud solutions like NoSQL DynamoDB were employed to store aggregated data. Our findings underscore the imperative for individuals to exercise caution in safeguarding their personal information online, as user data can be collected, aggregated, and clustered with ease using modern Generative AI LLMs, RAG and ML techniques. Moreover, our study highlights the risks associated with metadata from camera photos uploaded to social networks. This metadata often includes timestamps, geolocation coordinates, and device information, which can be exploited to track activities, movements, and locations of individuals, effectively turning smartphones into IoT devices that provide continuous data streams. This aspect adds a critical layer to the discussion on cybersecurity, as it exposes how seemingly harmless data can be leveraged for surveillance and profiling. Additionally, we urge social platforms to carefully evaluate the types of user data accessible to third parties to mitigate potential security risks.

Read the paper · More papers on PaperTik