CyLab advances global privacy by pairing technical innovation with policy-driven research that shapes how technologies are governed and deployed. Our researchers study real-world privacy risks ranging from data tracking to AI systems and translate their findings into actionable guidance for lawmakers, regulators, and industry leaders. By collaborating with governments, nonprofits, and companies, CyLab helps craft policies and standards that prioritize user protections while remaining practical to implement. This approach ensures that cutting-edge research doesn’t stay in the lab, but instead informs decisions that strengthen privacy for people worldwide.
On this page:
Developing AI-Enabled Privacy Technologies
For more than 25 years, CyLab faculty member Norman Sadeh and his research teams have worked to make privacy easier for people to understand and control. Rather than expecting users to navigate lengthy privacy policies and dozens of complicated settings on their own, Sadeh has pioneered the use of artificial intelligence to help manage those choices.
Early projects such as MyCampus (2002-2005) and Locaccino (2008-2011) demonstrated that although people’s privacy preferences vary depending on the situation, machine learning can identify patterns in those preferences and predict many of the choices users are likely to make. That research helped establish the concept of personalized privacy assistants: AI-powered tools that learn what people want and help them configure privacy settings accordingly. The team’s work on privacy reminders and mobile permissions has influenced features introduced by major technology companies, including Apple and Google.
Sadeh’s team has also extended this approach to the increasingly complex world of connected devices and smart environments. The group developed CMU’s IoT Privacy Infrastructure and the IoT Assistant app, which help people discover nearby cameras, microphones, sensors, and other connected technologies. The app empowered users to understand what information these smart devices collect and exercise available privacy choices.
Released in 2020, the IoT Assistant attracted more than 17,000 users in its first week, while the underlying infrastructure now contains more than 100,000 descriptions of IoT resources across three continents. Its deployments include nearly 1,500 smart-city sensors in Amsterdam, and the team is working with the City of Long Beach to help residents more effectively discover and control data collection in their surroundings, as required under the California Consumer Privacy Act (CCPA).
Additionally, Sadeh and his collaborators have developed AI technologies that make it possible to evaluate privacy practices on a much larger scale. Their systems use natural language processing to interpret privacy policies and software analysis to compare the data that companies claim their apps collect with the data that the apps actually do collect.
In 2019, the team’s Mobile App Privacy System (MAPS) analyzed more than one million Android apps, uncovering widespread potential compliance problems. This research has moved beyond academia: the California Attorney General’s Office used a customized version of the technology to examine mobile apps for compliance with state privacy law, and the team also worked with the Federal Trade Commission on potential regulatory applications.
More broadly, this line of work laid early foundations for privacy compliance automation and has influenced the development of commercial products such as Google Checks, Google's app compliance offering.
Project links:
- Projet page: Personalized Privacy Assistant Project
- News story: App and infrastructure alert users about data collection around them
- Paper: Personalized Privacy Assistants for the Internet of Things: Providing Users with Notice and Choice
- Paper: Follow My Recommendations: A Personalized Privacy Assistant for Mobile App Permissions
- Paper: Modeling Users' Mobile App Privacy Preferences: Restoring Usability in a Sea of Permission Settings
- Paper: Reconciling Mobile App Privacy and Usability on Smartphones: Could User Privacy Profiles Help?
- Paper: The Best of Both Worlds: Mitigating Trade-offs Between Accuracy and User Burden in Capturing Mobile App Privacy Preferences
- Paper: User-Controllable Learning of Location Privacy Policies with Gaussian Mixture Models
- Paper: Capturing Social Networking Privacy Preferences: Can Default Policies Help Alleviate Tradeoffs Between Expressiveness and User Burden?
- Paper: MAPS: Scaling Privacy Compliance Analysis to a Million Apps
- Paper: Automated Analysis of Privacy Requirements for Mobile Apps
- News story: Mobile App Behavior Often Appears at Odds With Privacy Policies
- Paper: Privacy Settings of Third-Party Libraries in Android Apps: A Study of Facebook SDKs
- Op-ed: No Privacy without AI
Designing California's Official Online Privacy Icon
For many years, CyLab researchers have worked on ways to clearly communicate complex data practices to everyday users, including through privacy nutrition labels for websites and mobile apps, as well as privacy icons.
In response to requirements in 2018's California Consumer Privacy Act, CyLab researchers designed and rigorously tested a privacy “opt-out” icon to accompany “Do not sell my personal information” links on websites. Through extensive user studies, Lorrie Cranor, Hana Habib, Yixin Zou, Alessandro Acquisti, Joel Reidenberg, Norman Sadeh, and Florian Schaub found that a simple, blue stylized toggle icon paired with clear language like “Privacy Options” most effectively conveyed users’ ability to make choices about their data, highlighting the importance of human-centered design in privacy tools.
The research had a direct impact on public policy and industry practices. After presenting their findings to the California Office of the Attorney General, regulators incorporated a version of the team’s icon into official privacy guidance. The icon was later adopted more broadly under the California Privacy Rights Act, where it helps consolidate multiple privacy choices into a single, accessible interface. This approach simplifies what was previously a fragmented and confusing process, making it easier for users to exercise their rights and manage how their personal information is collected and shared online.
Today, the icon appears across a wide range of major websites, demonstrating its real-world impact and scalability. By grounding their work in empirical user testing and interdisciplinary collaboration, the researchers showed that even small design choices, like the shape or color of an icon, can significantly influence user understanding and behavior. Their work underscores how usability-focused privacy research can shape both regulation and everyday online experiences, ultimately making privacy controls more visible, intuitive, and effective for millions of internet users.
Project links:
- News story: CyLab researchers design privacy icon to be used by California law
- News story: CyLab icon connects users with online privacy choices
- Video: PEPR '20 - How to (In)Effectively Convey Privacy Choices with Icons and Link Text
Introducing the Field of Behavioral Economics of Privacy
Alessandro Acquisti and George Loewenstein are widely credited with helping to establish Behavioral Economics of Privacy as a distinct interdisciplinary field by bringing insights from psychology and economics to bear on how individuals actually make privacy decisions. In the early 2000s, Acquisti’s work began challenging the assumption that people behave as fully rational agents when trading off privacy and disclosure. A foundational milestone came with his 2004 paper “Privacy in Electronic Commerce and the Economics of Immediate Gratification,” which showed that individuals often discount long-term privacy risks in favor of short-term rewards. This research introduced a behavioral lens to privacy, emphasizing biases like present bias and bounded rationality.
Acquisti and Loewenstein’s collaboration deepened the field’s theoretical and empirical grounding. Through a series of papers, they argued that the “privacy paradox” can be explained through behavioral concepts such as framing effects, incomplete information, and cognitive limitations. Their 2013 paper with Laura Brandimarte, “Privacy and Human Behavior in the Age of Information,” was published in Science, synthesizing years of research and firmly establishing Behavioral Economics of Privacy as a mature area of study. This work highlighted how context, defaults, and interface design shape disclosure decisions, influencing both academic research and real-world policy debates.
Through these contributions, Acquisti and Loewenstein introduced key theoretical frameworks and helped shift the conversation around privacy toward more realistic models of human behavior. Their work has influenced everything from regulatory approaches to the design of online platforms, encouraging policymakers and technologists to account for systematic biases and decision-making constraints. By integrating empirical experiments with economic theory, they transformed privacy from a purely legal or technical issue into a behavioral and social science domain.
Project links:
- Paper: Privacy in Electronic Commerce and the Economics of Immediate Gratification
- Paper: Privacy and Human Behavior in the Age of Information
Grading Your Smartphone Apps on their Privacy Practices
Jason Hong’s research, spanning 2012 to 2024, tackled the gap between users’ privacy expectations and the reality of how smartphone apps collect data.
A research team led by Hong and Yuvraj Agarwal developed PrivacyGrade.org, a system that analyzed the data collection behaviors of more than one million apps and translated those findings into simple letter grades. By making complex privacy risks easy to understand, the project raised public awareness and encouraged users to rethink which apps they trust, especially in cases where apps requested unnecessary or overly invasive data.
The initiative also had a significant impact across industry and policy. PrivacyGrade findings were shared with multiple research teams, including collaborators at Google, helping inform evaluations of apps on the Play Store and contributing to the development of privacy-enhanced versions of Android. The research team presented their work to major technology companies such as Apple, Facebook, Intel, and Samsung, as well as policymakers including the Federal Trade Commission. These efforts helped spotlight problematic data practices and contributed to enforcement actions against companies that over-collected user information.
Beyond awareness and policy influence, the project also produced practical tools to support better privacy practices. These included systems for analyzing app behavior and developer-facing tools like Matcha, an Android Studio plugin that uses privacy annotations to help generate Google Play Safety Labels. Supported by organizations such as the National Science Foundation and DARPA, this work demonstrates how combining behavioral insights with technical solutions can drive meaningful improvements in transparency and accountability in the app ecosystem.
Project links: