The Cybersecurity and Privacy Institute (CPI) at Northeastern University

Real security for a virtual world

The Cybersecurity and Privacy Institute (CPI) at Northeastern University is home to cutting-edge research that secures systems, safeguards data, and strengthens digital trust. Our faculty and students develop the technologies and methods that protect people, organizations, and critical infrastructure from emerging cyber threats. We take an interdisciplinary approach that combines computer science, engineering, law, and the social sciences to understand the broader impact of technology on privacy, security, and society. From encryption and network defense to algorithmic accountability and technology policy, CPI bridges rigorous research and real-world application—advancing both the science and governance of cybersecurity.

What we do

We conduct cutting-edge research to secure systems, safeguard data, and strengthen the foundations of digital trust. Our researchers and students uncover vulnerabilities, design resilient computing systems, and study how technology affects privacy and society. Through partnerships with industry, government, and academia, CPI translates world-class research into real-world solutions that make digital technologies safer for everyone.

Research

Algorithmic auditing

Develops methods to inspect the algorithmic systems that shape online life, including recommendation engines, advertising platforms, and ranking systems, surfacing how they behave and whom they affect.

People

  • Christo Wilson
  • Alan Mislove
  • Laura Edelson

Internet security measurement

Uses large-scale empirical measurement to characterize how the internet actually behaves, from IoT device traffic and network interference to national-scale censorship and information controls.

People

  • David Choffnes
  • Laura Edelson

Embedded device security

Secures the resource-constrained systems embedded in everyday and critical devices, spanning microcontrollers, IoT hardware, and medical implants.

People

  • Ziming Zhao
  • Kevin Fu
  • Guevara Noubir

Privacy

Research studies how personal information is collected, exposed, and protected across modern computing systems, and builds techniques ranging from differential privacy to empirical audits of real-world data flows that give people meaningful control over their data.

People

  • Christo Wilson
  • David Choffnes
  • Jonathan Ullman
  • Alina Oprea
  • Jayshree Sarathy
  • Tianshi Li
  • Guevara Noubir

Trustworthy AI

Examines whether AI and machine learning systems can be trusted under adversarial pressure, probing their robustness, privacy, and security and designing defenses for models and LLM-based agents.

People

  • Jonathan Ullman
  • Alina Oprea
  • Cristina Nita-Rotaru
  • Tianshi Li

AI for cybersecurity

Applies artificial intelligence and reinforcement learning to automate and strengthen cyber defense, building systems that detect and respond to threats faster than human operators alone.

People

  • Alina Oprea

Cryptography

Research develops the mathematical foundations of secure computation, including succinct proof systems and constructions built on well-studied hardness assumptions.

People

  • Zhengzhong Jin

System security

Builds and analyzes the security of computing systems at the hardware and software level, addressing threats such as side-channel attacks, control-flow hijacking, and the integrity of low-level execution environments.

People

  • Ziming Zhao
  • Guevara Noubir

Network security

Investigates the security and privacy of the networks that connect us, identifying vulnerabilities and designing defenses against current and future adversaries.

People

  • David Choffnes
  • Guevara Noubir

Usable security and privacy

Studies how real people understand and act on security and privacy, and designs tools, interfaces, and communication that make protective technologies such as differential privacy and data minimization genuinely usable.

People

  • Jayshree Sarathy
  • Tianshi Li

Security/privacy policy

Connects technical research to law, regulation, and governance, informing how policymakers address issues from data protection and platform accountability to national information controls. Researchers translate empirical findings into evidence that can shape real-world policy.

People

  • David Choffnes
  • Laura Edelson
  • Jayshree Sarathy

Algorithmic Auditing

Develops methods to inspect the algorithmic systems that shape online life, including recommendation engines, advertising platforms, and ranking systems, surfacing how they behave and whom they affect.

People

  • Christo Wilson
  • Alan Mislove
  • Laura Edelson

Internet Security Measurement

Uses large-scale empirical measurement to characterize how the internet actually behaves, from IoT device traffic and network interference to national-scale censorship and information controls.

Embedded Device Security

Secures the resource-constrained systems embedded in everyday and critical devices, spanning microcontrollers, IoT hardware, and medical implants.