arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

缩小差距:后Cookie时代扩展标识符的纵向分析

Bridging the Gap: A Longitudinal Analysis of Extended Identifiers in the Post-Cookie Era

Michael Smith, Riley Grossman, Krzysztof Franaszek, Antonio Torres-Agüero, Pritam Sen, Cristian Borcea, Yi Chen

arXiv 2609.02069首次发表:更新:

发表机构

Indiana University Bloomington; New Jersey Institute of Technology; Adalytics(印第安纳大学布鲁明顿分校; 新泽西理工学院; Adalytics)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文通过41个月的纵向研究,分析后Cookie时代EID的使用情况,发现其广泛普及但存在准确性不足、隐私风险及欧盟网站未获用户同意等问题,引发对其替代第三方Cookie的担忧。

AI 中文摘要

由于浏览器限制导致第三方Cookie逐渐被淘汰,在线广告生态系统正转向扩展标识符(EIDs)作为替代方案。EIDs是持久的用户标识符,例如哈希后的电子邮件地址,用于跨域和跨设备关联用户。本文开展了一项为期41个月的纵向研究,调查了来自616539个网站、发送给6家主要需求方平台(SSP)的超过1.45亿次HTTP头部竞价请求中的EID使用情况。研究结果显示,EIDs在数字广告生态系统中被广泛使用且日益普及,到2025年5月已覆盖83.76%的研究网站。我们对18家热门EID提供商的分析显示,这些提供商占据了数据集中所有传输EID的99.42%,这引发了对EID能否替代第三方Cookie追踪的担忧。在准确性方面,仅一家身份提供商能持续识别访问者为自声明的机器人爬虫,且许多提供商会为同一访问者定期传输多个EID。我们还发现了EID的隐私问题,其中12家提供商创建的持久EID可跨访问、网站、设备和月份识别同一用户。最后,我们发现16家提供商在欧盟网站上传输EID时未获得用户同意。

英文摘要

As third-party cookies fade because of browser restrictions, the online advertising ecosystem is turning to extended identifiers (EIDs) as an alternative. EIDs are persistent user identifiers, such as hashed email addresses, that are employed to link users across domains and devices. This paper presents a 41-month longitudinal study examining EID usage in over 145 million HTTP header bidding requests sent to six major supply-side platforms (SSPs) from 616,539 websites. Our findings show that EIDs are widely used and are becoming increasingly prevalent in the digital advertising ecosystem, reaching 83.76% of studied websites by May 2025. Our analysis of the 18 popular EID providers that account for 99.42% of all transmitted EIDs in our dataset raises concerns about the readiness of EIDs as an alternative to third-party cookie tracking. In terms of accuracy, only one identity provider consistently recognizes and identifies that the visitor is a self-identified bot crawler, and many providers regularly transmit multiple EIDs for the same visitor. We also identify privacy concerns with EIDs, as 12 of the providers create persistent EIDs that can identify the same user across visits, websites, devices, and months. Finally, we found that 16 providers transmit EIDs on EU websites without user consent.

Comments10 pages

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑