University Students Win Top Prize at Naver Privacy Contest for ‘AI Doxing Prevention’

Photo of author

By Global Team

(second from left) Naver Chief Privacy Officer Lee Jin-gyu and the 10 finalist teams of the “Naver Privacy Challenge” pose for a commemorative photo at Naver’s 1784 headquarters on the 18th. (Photo = Naver)
(second from left) Naver Chief Privacy Officer Lee Jin-gyu and the 10 finalist teams of the “Naver Privacy Challenge” pose for a commemorative photo at Naver’s 1784 headquarters on the 18th. (Photo = Naver)

The risk is growing that artificial intelligence can piece together fragments of posts scattered across the internet to identify a specific person. Naver is continuing an experiment to seek defense ideas from outside the company.

Naver said on the 19th that it held the final round of its privacy idea contest, the “Naver Privacy Challenge,” on the 18th at its 1784 headquarters in Seongnam, Gyeonggi Province. Under the theme “Ways to strengthen personal information protection in the AI era,” the company gathered ideas from university and graduate school students nationwide, and 10 teams competed in the final round.

The top prize went to the “Bapajusshi” team. Their research proposed using AI to analyze the risk that a person could be inferred by combining information spread across multiple online posts, and to help reduce unnecessary exposure. The team received a certificate and 1.5 million won in Naver Pay points.

Even scattered posts can be dangerous

Even if you hide your name when writing online, it is not easy to feel safe. The school you attend, the neighborhood where you live, your workplace and your hobbies can all be left behind in different posts. The phenomenon in which fragmentary information comes together to reveal a person is called the “mosaic effect.” Even on anonymous accounts, if posts accumulate saying things like “I live near ○○ Station” or “my child entered elementary school this year,” the range of possible identities quickly narrows.

In the past, it took effort to assemble the fragments. Now AI can search and combine them in seconds. The Bapajusshi team chose an approach that diagnoses exposure risk in advance and helps users reduce their traces on their own.

Cases have been reported in South Korea and abroad in which generative AI is asked to collect and organize posts written under a specific ID, or in which a filming location is inferred from the background of a photo alone. It has become an environment in which anyone can track personal information without expert knowledge.

The Personal Information Protection Act also regards information that can identify a person when combined with other information as protected data. This means that combining fragmentary information is a risk recognized by law as well. Analysts say the risk of such combination has grown even more as public posts are being used to train AI.

Naver Chief Privacy Officer Lee Jin-gyu said, “In response to the rapidly changing AI era, we are listening to a wide range of opinions to create a safe and innovative online ecosystem,” and added, “We will continue activities to raise awareness of personal information protection among employees, users, and small business owners.”

Naver’s PER continues for its 10th year

Since 2016, Naver has operated PER, a program that rewards user suggestions. It is a system that provides compensation when ideas that strengthen personal information protection lead to actual service improvements.

In the first half of this year, 130 submissions were received and 3.53 million won was paid out for 29 of them. Since the program began, a total of 1,659 suggestions have been submitted, 648 of which have been reflected, and the total compensation amount is about 71.2 million won. About four out of every 10 suggestions submitted have been used to improve services.

The model is similar to a bug bounty in the security industry. A bug bounty is a system in which a company rewards external experts or users for reporting security vulnerabilities. It fills blind spots that are difficult to find with internal personnel alone by leveraging outside eyes. Global tech companies such as Google and Apple have even offered rewards worth hundreds of millions of won for a single report of a serious vulnerability. Naver has extended the same principle to privacy.

In South Korea, public concern over personal information has intensified following last year’s large-scale subscriber data leak at a major telecom company. It has also been repeatedly confirmed that the costs of recovery after an incident and the loss of trust are greater than preventive investment.

For companies, preventing incidents in advance is much cheaper. A revision to the Personal Information Protection Act raised the maximum fine for violations to 3 percent of related revenue. One data breach can cause not only fines but also a collapse in trust, leading to even greater losses. This is why compensation for prevention functions like an insurance premium.

The method of receiving outside suggestions also has the advantage of being less expensive than an external audit while earning user trust. However, some argue that if the rewards are too small, participation may remain a one-time event. The average compensation per case is about 110,000 won.

How can I protect my information in practice?

Company-level management now extends to partner firms as well. Naver has built a monitoring system for subcontractors entrusted with handling personal information and is supporting privacy protection activities for partner companies. Even if an outsourced vendor has an incident, the 피해 ultimately falls on users. The company is also reorganizing its Privacy Center and operating a research group on lawful personal information processing.

The university contest format serves as a channel to identify risks through the eyes of younger users while also securing talent in the privacy field in advance. The judging process itself also serves as a publicity platform to promote the company’s protection policies.

There are also steps users can take right away. It is safer to clean up old posts and unused accounts, and to use different nicknames on different communities. It is important to develop the habit of leaving out content that becomes risky when combined, such as neighborhood, workplace or children’s information.

It is also useful to make use of tools provided by platforms. Checking search exposure history, account login records and personal information usage history can help reduce traces that have spread unnoticed. The government also operates a “Delete Service” that helps remove posts written in childhood. Its purpose is to prevent posts written during childhood and adolescence from affecting people later in adulthood.

As fast as artificial intelligence is advancing, threats to personal information are also accelerating. Whether a model that supplements risks difficult for companies to block with the collective intelligence of users will take hold, and how much of the university ideas will actually be reflected in services, will be key points to watch going forward.