Research
Northeastern University is a leader in cross-disciplinary collaboration and real-world research. The Cybersecurity and Privacy Institute benefits from integration with the university, including the Khoury College of Computer Sciences and the School of Law. We collaborate with leading universities, tech companies, and defense contractors globally and here in Boston.
In recognition of Northeastern’s strengths in cyber defense, the National Security Agency has designated the university a National Center of Academic Excellence for the BS degree in Computer Science and in Cyber Security, with a concentration in Cyber Operations. Northeastern has also been named a National Center of Academic Excellence in Information Assurance Research and a Center of Excellence in Information Assurance Education by the NSA and the Department of Homeland Security.
Research areas
Algorithmic auditing
Develops methods to inspect the algorithmic systems that shape online life, including recommendation engines, advertising platforms, and ranking systems, surfacing how they behave and whom they affect.
| Researcher | Lab(s) | Project(s) |
|---|---|---|
| Christo Wilson | Lab | |
| Alan Mislove | Lab | |
| Laura Edelson | Cybersafety Research Center |
Internet security measurement
Uses large-scale empirical measurement to characterize how the internet actually behaves, from IoT device traffic and network interference to national-scale censorship and information controls.
| Researcher | Lab(s) | Project(s) |
|---|---|---|
| David Choffnes | Mon(IoT)r Lab | |
| Laura Edelson | Cybersafety Research Center |
Embedded device security
Secures the resource-constrained systems embedded in everyday and critical devices, spanning microcontrollers, IoT hardware, and medical implants.
| Researcher | Lab(s) | Project(s) |
|---|---|---|
| Ziming Zhao | Cacti Lab | |
| Kevin Fu | SPQR Lab | Brain Implant Cybersecurity |
| Guevara Noubir | Lab |
Privacy
Research studies how personal information is collected, exposed, and protected across modern computing systems, and builds techniques ranging from differential privacy to empirical audits of real-world data flows that give people meaningful control over their data.
Trustworthy AI
Examines whether AI and machine learning systems can be trusted under adversarial pressure, probing their robustness, privacy, and security and designing defenses for models and LLM-based agents.
| Researcher | Lab(s) | Project(s) |
|---|---|---|
| Jonathan Ullman | Lab | Audited Private Machine Learning |
| Alina Oprea | Lab | Adversarial machine learning |
| Cristina Nita-Rotaru | LLM agent security | |
| Tianshi Li | PEACH Lab | LLM privacy |
AI for cybersecurity
Applies artificial intelligence and reinforcement learning to automate and strengthen cyber defense, building systems that detect and respond to threats faster than human operators alone.
| Researcher | Lab(s) | Project(s) |
|---|---|---|
| Alina Oprea | Lab | Automated cyber defense |
Cryptography
Research develops the mathematical foundations of secure computation, including succinct proof systems and constructions built on well-studied hardness assumptions.
| Researcher | Lab(s) | Project(s) |
|---|---|---|
| Zhengzhong Jin | Lab | SNARGs for NP from LWE |
System security
Builds and analyzes the security of computing systems at the hardware and software level, addressing threats such as side-channel attacks, control-flow hijacking, and the integrity of low-level execution environments.
| Researcher | Lab(s) | Project(s) |
|---|---|---|
| Ziming Zhao | Cacti Lab | |
| Guevara Noubir | Lab |
Network security
Investigates the security and privacy of the networks that connect us, identifying vulnerabilities and designing defenses against current and future adversaries.
| Person | Lab(s) | Project(s) |
|---|---|---|
| David Choffnes | Lab | |
| Guevara Noubir | Lab |
Usable security and privacy
Studies how real people understand and act on security and privacy, and designs tools, interfaces, and communication that make protective technologies such as differential privacy and data minimization genuinely usable.
| Person | Lab(s) | Project(s) |
|---|---|---|
| Jayshree Sarathy | Lab | |
| Tianshi Li |
Security/privacy policy
Connects technical research to law, regulation, and governance, informing how policymakers address issues from data protection and platform accountability to national information controls. Researchers translate empirical findings into evidence that can shape real-world policy.
| Person | Lab(s) | Project(s) |
|---|---|---|
| David Choffnes | Mon(IoT)r Lab | |
| Laura Edelson | Cybersafety Research Center | The Locknet |