Table of Contents
A different username does not make an online account anonymous by itself. Posts can reveal a distinctive combination of jobs, locations, hobbies, dates, writing habits, and life events. Large language models can extract those clues at scale and compare them with public profiles on other services.
No single tool can guarantee anonymity. The practical defense is to reduce the number of clues available, keep identities separated, and understand the difference between hiding network information and hiding what your own words reveal.
What LLM deanonymization research found
A 2026 study titled Large-scale online deanonymization with LLMs tested systems that extract identity-relevant features, search for likely matches, and reason over the strongest candidates. Across datasets involving Hacker News, LinkedIn, and Reddit, the authors reported results of up to 68% recall at 90% precision in one evaluation setting.
That wording matters: 90% precision is not the same as correctly identifying 90% of every anonymous user. Performance depended on the dataset, available public clues, candidate pool, and evaluation method. The study nevertheless shows that matching previously separate profiles can now be automated more effectively than older baseline methods.

Clues that can connect separate accounts
- the same or similar username, avatar, biography, or profile link;
- a rare combination of employer, city, school, age range, or career history;
- repeated references to the same events, health issues, purchases, or travel;
- specialized vocabulary, punctuation, spelling patterns, and posting schedule;
- photos containing landmarks, reflections, documents, or reusable metadata;
- cross-posted text, code, images, or links that also appear under a real name.
A single clue may be harmless. Several weak clues can become identifying when combined, especially if a model can search many sites and rank possible matches.
Separate identities before posting
Use a unique username, email address, profile image, and recovery path for a pseudonymous account. Do not link it to a public profile, synchronize contacts, or reuse a biography from another service. Avoid logging into unrelated personal accounts in the same browser session when the threat model requires stronger separation.
Keep topics compartmentalized. If an account exists to discuss one sensitive subject, adding detailed stories about work, family, neighborhood, or daily routine creates unnecessary links to the offline person.
Reduce identifying details in the content
Before publishing, ask whether the post needs an exact location, date, employer, job title, age, or sequence of events. Generalize details that do not change the meaning. Delay real-time location posts, and crop screenshots so they do not show names, notifications, tabs, document titles, or unique account information.
Do not invent an elaborate false identity with specific claims. Maintaining a fictional biography can create contradictions, mislead other people, and produce a new consistent pattern that is still linkable. The safer approach is data minimization: disclose less rather than manufacture more.
What a VPN and Tor can—and cannot—do
A VPN hides the destination of your traffic from the local network and substitutes the VPN server's IP address for websites you visit. The VPN provider can still be in a privileged position, and cookies, account logins, browser fingerprints, payments, and post content can identify you.
Tor Browser routes traffic through the Tor network and is designed to make users' browsers look more alike, reducing some tracking and fingerprinting risks. Download it only from the official Tor Project and avoid installing extra extensions or changing settings without understanding how those changes affect fingerprinting.

Neither a VPN nor Tor rewrites the personal facts in a post. Network privacy and content privacy solve different problems and must be considered together.
Review old public traces carefully
Search for past usernames, distinctive phrases, avatars, and links to see what connects them. Remove unnecessary profile details where the service allows it, but remember that deletion may not erase quotes, archives, search caches, screenshots, or copies held by other users.
Before deleting a large history, consider whether preserving evidence is important for harassment reports, legal matters, or account recovery. On a high-risk account, consult a qualified digital-security organization rather than making broad changes that could draw attention or destroy needed records.
Do not rely on AI rewriting as a guarantee
An AI tool can change tone or wording, but sending sensitive text to another service creates a separate privacy decision. Rewritten content may preserve the same facts, and a consistent “generated” voice can introduce new patterns. Do not upload private details merely to ask a model to make them anonymous.

A practical pre-post checklist
- Remove details that are not necessary for the message.
- Check the image, file name, visible interface, and metadata.
- Search a distinctive sentence to see whether it appears elsewhere.
- Confirm that the account does not reuse identifiers from a real-name profile.
- Consider whether posting now reveals a current location or routine.
- Assume that public text can be copied, archived, and analyzed later.
People facing stalking, domestic abuse, political repression, or professional retaliation need a threat model tailored to their situation. These steps reduce exposure, but they are not a promise of anonymity against a determined investigator with access to platform records or other data sources.
Reader Comments 0
Sign in with email or Google to join the discussion.