A Common Pool of Privacy Problems: Legal and Technical Lessons from a Large-Scale Web-Scraped Machine Learning Dataset

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Hong, Rachel, Hutson, Jevan, Agnew, William, Huda, Imaad, Kohno, Tadayoshi, Morgenstern, Jamie
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914449631215616
author Hong, Rachel
Hutson, Jevan
Agnew, William
Huda, Imaad
Kohno, Tadayoshi
Morgenstern, Jamie
author_facet Hong, Rachel
Hutson, Jevan
Agnew, William
Huda, Imaad
Kohno, Tadayoshi
Morgenstern, Jamie
contents We investigate the contents of web-scraped data for training AI systems, at sizes where human dataset curators and compilers no longer manually annotate every sample. Building off of prior privacy concerns in machine learning models, we ask: What are the legal privacy implications of web-scraped machine learning datasets? In an empirical study of a popular training dataset, we find significant presence of personally identifiable information despite sanitization efforts. Our audit provides concrete evidence to support the concern that any large-scale web-scraped dataset may contain legally defined personal data. We use these findings of a real-world dataset to inform our legal analysis with respect to existing privacy and data protection laws. We surface various legal risks of current data curation practices that may propagate personal information to train downstream models. Based on our empirical and legal analyses, we argue for reorientation of current frameworks of "publicly available" information to meaningfully limit the development of AI built upon indiscriminate scraping of the internet.
format Preprint
id arxiv_https___arxiv_org_abs_2506_17185
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle A Common Pool of Privacy Problems: Legal and Technical Lessons from a Large-Scale Web-Scraped Machine Learning Dataset
Hong, Rachel
Hutson, Jevan
Agnew, William
Huda, Imaad
Kohno, Tadayoshi
Morgenstern, Jamie
Cryptography and Security
Computers and Society
We investigate the contents of web-scraped data for training AI systems, at sizes where human dataset curators and compilers no longer manually annotate every sample. Building off of prior privacy concerns in machine learning models, we ask: What are the legal privacy implications of web-scraped machine learning datasets? In an empirical study of a popular training dataset, we find significant presence of personally identifiable information despite sanitization efforts. Our audit provides concrete evidence to support the concern that any large-scale web-scraped dataset may contain legally defined personal data. We use these findings of a real-world dataset to inform our legal analysis with respect to existing privacy and data protection laws. We surface various legal risks of current data curation practices that may propagate personal information to train downstream models. Based on our empirical and legal analyses, we argue for reorientation of current frameworks of "publicly available" information to meaningfully limit the development of AI built upon indiscriminate scraping of the internet.
title A Common Pool of Privacy Problems: Legal and Technical Lessons from a Large-Scale Web-Scraped Machine Learning Dataset
topic Cryptography and Security
Computers and Society
url https://arxiv.org/abs/2506.17185