Using Salient Object Detection to Identify Manipulative Cookie Banners that Circumvent GDPR
2510.26967v1
cs.CY, cs.AI, cs.CV, cs.HC
2025-11-04
Авторы:
Riley Grossman, Michael Smith, Cristian Borcea, Yi Chen
Abstract
The main goal of this paper is to study how often cookie banners that comply
with the General Data Protection Regulation (GDPR) contain aesthetic
manipulation, a design tactic to draw users' attention to the button that
permits personal data sharing. As a byproduct of this goal, we also evaluate
how frequently the banners comply with GDPR and the recommendations of national
data protection authorities regarding banner designs. We visited 2,579 websites
and identified the type of cookie banner implemented. Although 45% of the
relevant websites have fully compliant banners, we found aesthetic manipulation
on 38% of the compliant banners. Unlike prior studies of aesthetic
manipulation, we use a computer vision model for salient object detection to
measure how salient (i.e., attention-drawing) each banner element is. This
enables the discovery of new types of aesthetic manipulation (e.g., button
placement), and leads us to conclude that aesthetic manipulation is more common
than previously reported (38% vs 27% of banners). To study the effects of user
and/or website location on cookie banner design, we include websites within the
European Union (EU), where privacy regulation enforcement is more stringent,
and websites outside the EU. We visited websites from IP addresses in the EU
and from IP addresses in the United States (US). We find that 13.9% of EU
websites change their banner design when the user is from the US, and EU
websites are roughly 48.3% more likely to use aesthetic manipulation than
non-EU websites, highlighting their innovative responses to privacy regulation.