Double-Edged Shield: On the Fingerprintability of Customized Ad Blockers

Saiid El Hajj Chehade

34th USENIX Security Symposium (USENIX Security '25) · Day 3 · Privacy 3: Attacks

Overview

This talk, "Double-Edged Shield: On the Fingerprintability of Customized Ad Blockers," presented by Saiid El Hajj Chehade from EPFL, MPI, and CISPA, uncovers a critical and often overlooked vulnerability in the pursuit of online privacy. It demonstrates how the very act of customizing an ad blocker, a tool meant to enhance privacy, can paradoxically compromise a user's anonymity by creating a unique, identifiable fingerprint. This research directly challenges the widespread assumption that users who meticulously configure their privacy-enhancing technologies are the most secure online.

Watch on YouTube · Slides

Visual summary for Double-Edged Shield: On the Fingerprintability of Customized Ad Blockers by Saiid El Hajj Chehade
Visual summary for Double-Edged Shield: On the Fingerprintability of Customized Ad Blockers by Saiid El Hajj Chehade

Key moments

  1. 0:00 Customizing ad blockers compromises privacy, challenging assumptions.
  2. 1:47 Understanding ad blocker configuration: filter lists and settings.
  3. 2:19 Three key research questions on ad blocker fingerprinting.
  4. 3:45 Focusing on fingerprinting privacy power users, not general population.
  5. 4:32 Attacker's goal: detecting active rules to reconstruct filter lists.
  6. 5:55 Detailed explanation of the CSS animation fingerprinting attack.
  7. 7:00 Detailed explanation of the lazy loading fingerprinting attack.
  8. 8:07 Algorithm for selecting optimal rules to test for.

Double-Edged Shield: On the Fingerprintability of Customized Ad Blockers

Speakers: Saiid El Hajj Chehade

Conference: USENIX Security

YouTube: https://www.youtube.com/watch?v=6X_u_jro9ws

Overview

This talk, "Double-Edged Shield: On the Fingerprintability of Customized Ad Blockers," presented by Saiid El Hajj Chehade from EPFL, MPI, and CISPA, uncovers a critical and often overlooked vulnerability in the pursuit of online privacy. It demonstrates how the very act of customizing an ad blocker, a tool meant to enhance privacy, can paradoxically compromise a user's anonymity by creating a unique, identifiable fingerprint. This research directly challenges the widespread assumption that users who meticulously configure their privacy-enhancing technologies are the most secure online.

The significance of this work lies in its focus on "privacy power users"—individuals who employ a sophisticated array of defenses, including ad blockers, Tor for network anonymity, and state-of-the-art machine learning detectors against browser fingerprinting. While these users typically defeat traditional tracking methods, this research reveals a novel attack vector that exploits their personalized ad blocker settings. By exposing how these configurations can be fingerprinted, the talk highlights a fundamental flaw in current privacy paradigms and provides crucial insights for both users and developers striving for genuine online anonymity.

Background

▶ Watch: Customizing ad blockers compromises privacy, challenging assumptions. (0:00)

Online users exhibit a spectrum of privacy awareness and protection. The majority remain susceptible to conventional tracking via cookies and identifiers. A more conscious group employs privacy-enhancing technologies (PETs) like ad blocker web extensions to combat traditional tracking. However, even these users can fall prey to more advanced forms of tracking, such as website fingerprinting. At the apex of this spectrum are "privacy power users," who implement a comprehensive suite of up-to-date protections, including heavily configured ad blockers, Tor for IP and network fingerprinting defense, and advanced browser fingerprinting countermeasures. This talk specifically targets this demographic, questioning whether their extensive efforts truly translate into superior privacy.

An ad blocker's functionality is governed by its configuration, which allows users to block varying levels of advertisements and tracking. These configurations are typically managed through specific settings, often presented as "red knobs" in the user interface. While the default setting usually blocks advertisement containers and tracking domains upon installation, users can further customize their protection by activating or deactivating options like social media buttons, cookie notices, and fingerprinting domains. Each such setting corresponds to an underlying filter list, which in turn activates a collection of filtering rules. These rules instruct the browser on whether to block a network request or hide a web element. Consequently, two users with different ad blocker configurations will possess different active rules, leading to distinct states when loading the same web page.

Prior work on web extension fingerprinting primarily focused on detecting the mere presence or absence of an extension, yielding a single bit of information. In contrast, this research aims to extract multiple bits by identifying the specific settings a user has enabled. This is crucial because privacy power users, who might appear indistinguishable under previous fingerprinting attacks (generating the same "F1" fingerprint), become uniquely identifiable when their individual ad blocker configurations are exposed. The research differentiates itself by specifically targeting these power users, who often bypass existing fingerprinting techniques, and demonstrating how their anonymity set can be significantly reduced.

A key challenge in targeting privacy power users is their robust defenses against traditional fingerprinting. State-of-the-art fingerprinting detectors actively scan JavaScript code for suspicious patterns, rendering JavaScript-based attacks ineffective. To circumvent this, the researchers developed a new approach: stylistic or scriptless fingerprinting. This method avoids JavaScript altogether and is designed to be stealthy, minimizing malicious network activity and the number of rules tested to avoid raising alarms. The attack's effectiveness is rooted in exploiting fundamental differences in how web pages render under varying ad blocker configurations, rather than relying on marginal or easily patched vulnerabilities.

Key Findings

▶ Watch: Three key research questions on ad blocker fingerprinting. (2:19)

The research yielded several significant findings that underscore the vulnerability of customized ad blocker configurations:

Firstly, the study successfully designed and implemented practical scriptless attacks capable of fingerprinting ad blocker settings. These attacks, detailed in the technical deep dive, demonstrate that it is feasible for a malicious website to detect a user's specific filter list activations without relying on JavaScript or extensive network requests, thereby evading common detection mechanisms.

Secondly, the effectiveness of these attacks was quantified using entropy, a standard measure of fingerprint uniqueness. The developed attacks achieved an entropy of 0.6, which is competitive with and similar to the results of prior, more traditional fingerprinting studies. This indicates a substantial reduction in user anonymity, moving users from a large pool of indistinguishable individuals to a much smaller, more identifiable set.

Thirdly, the evaluation on a dataset of real-world user configurations revealed a concerning degree of identifiability. In a baseline scenario, assuming all rules were detectable, more than 20% of users in the dataset were found to be uniquely identifiable. Even with the more constrained and stealthy CSS animation attack, 18% of users could be uniquely identified. Furthermore, by testing only a small subset of rules known as cosmetic rules, the attack could still uniquely identify approximately 16% of users. This demonstrates that even a limited attack surface can compromise a significant portion of privacy-conscious users.

A crucial confirmation of the research hypothesis was observed in the distribution of users across anonymity set sizes. The study distinctly found that privacy power users, characterized by having made numerous changes to their default ad blocker configurations, had a significantly smaller anonymity set size. For instance, these users were distinguishable among approximately 16 other users, a stark contrast to the average user who might be indistinguishable among more than 128 users. This empirically validates the claim that advanced privacy setups, when customized, can paradoxically make users more unique.

Finally, the stability of these fingerprints over time was investigated through a historical study of GitHub commits to filter lists. The research found that the identified "equivalences" (associations between groups of rules and filter lists) remained correct for up to three years, despite substantial changes and updates to the filter lists by maintainers. This remarkable stability is attributed to the high redundancy in the number of rules that reveal the same set of lists, indicating that these fingerprints are not fleeting but rather persistent identifiers.

Technical Deep Dive

▶ Watch: Attacker's goal: detecting active rules to reconstruct filter lists. (4:32)

The core of the attack lies in detecting which specific filtering rules are active on a user's browser and then inferring their underlying ad blocker filter list configuration. Given that the target audience—privacy power users—likely employs defenses against traditional JavaScript-based fingerprinting, the researchers developed novel scriptless fingerprinting techniques. These attacks leverage standard browser rendering optimizations and features to covertly signal the presence or absence of a blocked element.

The talk detailed two primary scriptless attack vectors: the CSS Animation Attack and the Lazy Loading Attack.

CSS Animation Attack

This attack exploits two fundamental browser behaviors:

  1. Optimization for hidden elements: Browsers will not execute styles or load resources for elements that are hidden from view.
  2. Ad blocker mechanism: Ad blockers often hide blocked elements using CSS rules (e.g., display: none; or visibility: hidden;).

To detect if a specific rule is active, the attacker crafts a web page element that the rule is designed to block. Let's call this detector-one. The attacker then applies a background-image style to this detector-one element, with the image source pointing to a unique URL on the attacker's server (e.g., signals/123).

  • Scenario 1: Rule is active. If the targeted ad blocker rule is active, it will hide the detector-one element via CSS. Due to browser optimization, the browser will not attempt to load the background-image. No request is sent to the attacker's server.
  • Scenario 2: Rule is inactive. If the rule is inactive, the detector-one element remains visible. The browser will then request the background-image from the attacker's server. This request serves as a signal to the attacker that the specific rule is inactive.

A crucial refinement to this attack involves adding a 1-second CSS animation before the background-image style is applied. This delay accounts for the slight processing time some ad blockers, like uBlock Origin, might require to identify and block an element. Without this delay, the image might be requested before the ad blocker has a chance to hide the element, leading to a false positive.

Lazy Loading Attack

The Lazy Loading attack leverages a common web optimization feature where images are only fetched by the browser when they are about to become visible within the user's viewport.

The attack setup involves stacking two elements vertically:

  1. An element designed to be blocked by a specific ad blocker rule (shown in red in the presentation).
  2. An image element, placed directly below the first, whose source points to the attacker's server (shown in blue).
  • Scenario 1: Rule is inactive. The ad blocker rule is not active, so the "red" element is not blocked and remains visible on the page. This "red" element occupies space, pushing the "blue" signal image below the user's initial visible viewport threshold. As a result, the browser's lazy loading mechanism does not fetch the "blue" image, and no request is sent to the attacker.
  • Scenario 2: Rule is active. The ad blocker rule is active, so the "red" element is blocked and effectively removed from the page layout. This causes the "blue" signal image to shift upwards, potentially pushing it above the lazy loading threshold and into the visible viewport. Consequently, the browser fetches the "blue" image, sending a request to the attacker's server, which signals that the rule is active.

Rule Selection Algorithm

A significant challenge in implementing these attacks is the sheer number of potential rules. A single filter list can contain more than 100,000 rules. Testing all of them would be impractical and likely detectable. Therefore, the researchers designed an algorithm to identify the most effective rules for fingerprinting, aiming to maximize fingerprint quality with the minimum number of tests to remain stealthy.

The algorithm is based on two key observations:

  1. Unique Rules: Users primarily control which filter lists are active. Detecting a rule that is unique to a specific filter list directly reveals whether that list is active.
  2. Shared Rules (Equivalences): Filter lists can share rules. For example, a rule for a common website might appear in both German and Austrian filter lists. Detecting such shared rules doesn't pinpoint a single list but rather indicates that a group of lists (an equivalence) might be active. The study found around 400 such equivalences.

To optimize rule selection, the researchers adapted algorithms developed by Golia for two distinct fingerprinting scenarios:

  • Targeted Fingerprinting: In this scenario, the attacker focuses on a specific user and aims to find, for instance, the best 10 tests that will minimize the anonymity set size for that individual user.
  • General Fingerprinting: Here, the goal is to find a set of tests (e.g., the best 10 tests) that minimizes the average anonymity set size across the entire population of privacy power users. This is equivalent to maximizing the channel entropy for this user group.

The evaluation of these attacks was conducted on a dataset of real user configurations, derived from publicly available GitHub issues where users report problems to ad blocker maintainers. These reports often include the list of active filter lists at the time of the issue. The study focused on two popular ad blockers, AdGuard and uBlock Origin, which offer a large number of filter lists. The final dataset comprised 18,000 configurations for AdGuard and 5,900 for uBlock Origin, a size consistent with other fingerprinting studies.

Demo / Proof of Concept

▶ Watch: Detailed explanation of the CSS animation fingerprinting attack. (5:55)

While the talk did not feature a live, interactive demonstration in the traditional sense, the described CSS Animation Attack and Lazy Loading Attack constitute the practical implementation and proof of concept for the proposed fingerprinting methodology. The researchers explicitly state, "We designed and implemented practical scriptless attacks," indicating that these attack vectors were built and tested.

The subsequent evaluation of these attacks against a substantial dataset of real-world user configurations serves as the empirical proof of concept. By analyzing 18,000 AdGuard and 5,900 uBlock Origin user reports, the study demonstrated the practical effectiveness of these techniques in identifying unique ad blocker configurations. The quantitative results—such as 18% unique identifiability with the CSS animation attack and 0.6 entropy—provide concrete evidence that these scriptless attacks are not merely theoretical but are effective in reducing the anonymity of privacy power users in a real-world context. The "demo" is thus in the empirical validation of the implemented attacks.

Defensive Implications

▶ Watch: Algorithm for selecting optimal rules to test for. (8:07)

The findings of this research present significant challenges for both ad blocker developers and privacy-conscious users, as effective mitigation strategies are not straightforward and often involve trade-offs. The talk explored several potential defenses:

  1. Forcing all users to activate all filter lists: This approach would standardize configurations, making all users appear identical. However, the researchers found that this leads to "considerate performance" degradation and significantly longer page loads for both AdGuard and uBlock Origin. This is largely impractical, as activating hundreds of thousands of rules would consume excessive resources and negatively impact the user experience, making the ad blocker cumbersome to use.
  1. Globally activating rules that lead to high-fidelity fingerprints: This strategy involves identifying the rules most critical for fingerprinting and globally activating them for all users, regardless of their chosen filter lists. While promising, the study found that to reduce fingerprint entropy below a desirable threshold of 0.3, more than 400,000 rules would need to be universally activated. This again points to the performance issues encountered with the previous mitigation, suggesting that such a broad activation would likely be detrimental to user experience. The researchers noted that this defense "needs to be investigated further," implying that a more nuanced, targeted approach might be required if this strategy is to be viable.
  1. Disallowing browser features contributing to the attack: The attacks leverage standard browser features like CSS animations and lazy loading. A direct mitigation could involve browsers disallowing or restricting these features in contexts where fingerprinting is a concern. However, the study revealed that such features are utilized by a "non-negligible portion of websites." Globally disabling them would inevitably lead to "breakages" on many legitimate websites, disrupting functionality and user experience. This necessitates a more "fine-tuned locking of the features," which would be complex to implement without causing unintended side effects. For example, a browser might need to dynamically assess the context in which these features are used to differentiate between legitimate use and potential fingerprinting attempts, a task that is inherently difficult and prone to errors.

In conclusion, the research highlights that while advanced privacy setups are valuable, their customization introduces a new attack surface. The most straightforward mitigations either severely impact performance or break website functionality, posing a dilemma for developers. The paper, as mentioned by the speaker, provides more detailed recommendations for maintainers, users, and browser developers, suggesting that a multi-faceted approach involving better defaults, user education, and potentially browser-level enhancements will be necessary to address this sophisticated form of tracking.

Key Takeaways

  • Customized ad blocker configurations can inadvertently create unique fingerprints, compromising the anonymity of even the most privacy-conscious users.
  • "Privacy power users," who typically employ advanced defenses, are particularly susceptible to this novel form of tracking, as their personalized settings can distinguish them from others in their anonymity set.
  • The research introduces practical scriptless fingerprinting attacks (e.g., CSS Animation and Lazy Loading) that bypass traditional JavaScript-based detection by exploiting fundamental browser rendering behaviors.
  • These scriptless attacks are highly effective, achieving 0.6 entropy and uniquely identifying a significant percentage (e.g., 18%) of users in real-world datasets, demonstrating their competitive power against prior fingerprinting methods.
  • Ad blocker fingerprints are remarkably stable over time, with identified equivalences remaining valid for up to three years despite filter list updates, due to the inherent redundancy in filtering rules.
  • Mitigation strategies are challenging, often requiring significant trade-offs between privacy, browser performance, and website compatibility, necessitating further research and careful implementation.

About the Speaker(s)

Saiid El Hajj Chehade is the speaker for "Double-Edged Shield: On the Fingerprintability of Customized Ad Blockers." He is affiliated with multiple prominent research institutions: EPFL (École Polytechnique Fédérale de Lausanne) in Switzerland, the Max Planck Institute (MPI), and CISPA Helmholtz Center for Information Security. His work, as presented in this talk, demonstrates expertise in web privacy, security, and advanced fingerprinting techniques, particularly in the context of privacy-enhancing technologies like ad blockers. His research focuses on identifying and understanding novel vulnerabilities that can compromise user anonymity online.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid, counterintuitive privacy research that empirically validates a non-obvious attack surface: the more you customize your ad blocker, the more you stick out. The scriptless attack primitives are clever, the dataset is real-world, and the core finding — that privacy power users have smaller anonymity sets than average users — is exactly the kind of result that deserves conference airtime.

Heather Calloway (CISO) — WEAK

Technically rigorous research that surfaces a real and counterintuitive privacy paradox — power users made more identifiable by their own defenses. But the talk never escapes the lab. It has no governance angle, no institutional accountability thread, and no actionable path for the people who actually manage privacy risk at scale.

→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)

All talks from 34th USENIX Security Symposium (USENIX Security '25)