CyLab researchers provide evidence-based insights that help policymakers, regulators, and industry leaders develop more effective laws, standards, and best practices. Our work has influenced discussions on topics such as consumer privacy, age verification, election security, and digital platform governance. Through rigorous analysis and interdisciplinary collaboration, our researchers help to ensure that policy decisions are grounded in data and designed to better protect the public.

decorative image

Predicting Social Security Numbers from Public Data

In 2009, Alessandro Acquisti and Ralph Gross published their research findings in the paper “Predicting Social Security Numbers from Public Data,” demonstrating how sensitive personal information could be inferred from seemingly innocuous public records. Using publicly available data from the Social Security Administration's Death Master File and demographic information such as an individual's date and state of birth, the researchers showed that it was possible to predict Social Security numbers (SSNs) with surprising accuracy. The findings were especially striking for people born after 1988, when the Social Security Administration's Enumeration at Birth program dramatically increased the correlation between birth records and SSN assignment patterns. The study revealed that information widely available through voter registration records, commercial databases, and social networking sites could be combined to infer one of the most sensitive identifiers used in American life.

The research challenged a central assumption underlying many privacy and identity theft prevention policies: that Social Security numbers could remain confidential if organizations simply removed or redacted them from public records. Acquisti and Gross demonstrated that because SSNs were assigned according to predictable patterns, they could often be reconstructed from other publicly available information even when the numbers themselves were hidden. Their work showed that the problem was not merely data exposure but the broader interaction of multiple datasets that, when combined, could reveal sensitive information. The researchers warned that Social Security numbers had become insecure "passwords" and argued that relying on them for authentication exposed consumers to unnecessary risks of fraud and identity theft.

Prior to publication, the researchers shared their findings with government agencies and intentionally withheld sensitive technical details that could facilitate misuse. Their analysis helped spur a national conversation about the limitations of SSN-based authentication and the need for stronger identity verification systems. Notably, the Social Security Administration announced plans to randomize Social Security number assignments shortly after the publication of the research, implementing the change in 2011. More broadly, the study influenced debates among policymakers, privacy advocates, and industry leaders about identity theft prevention, demonstrating how rigorous empirical research can reveal systemic weaknesses in digital infrastructure and drive evidence-based policy reform.

Project links:

Silk Road logo

Traveling the Silk Road

In 2012, Nicolas Christin published the landmark study “Traveling the Silk Road: A Measurement Analysis of a Large Anonymous Online Marketplace,” one of the first rigorous academic examinations of the online black market known as Silk Road. Rather than relying on anecdotal evidence or law enforcement estimates, Christin collected and analyzed publicly available data from the site over an eight-month period, including nearly six months of daily measurements. By examining more than 24,000 product listings and using customer feedback as a proxy for completed transactions, he created an unprecedented picture of the marketplace's scale, structure, and economics.

Christin's analysis revealed that Silk Road was overwhelmingly devoted to the sale of illegal drugs and narcotics, and was far larger than many policymakers had realized. The research estimated that sellers collectively generated more than $1.2 million in monthly revenue, while the platform itself earned roughly $92,000 per month in commissions. The study also found that although many vendors disappeared after only a few months, a stable core group of sellers sustained the marketplace and helped it grow steadily over time. By quantifying activity on a platform designed to be anonymous, Christin demonstrated that even hidden online ecosystems could be measured and studied through careful data collection and analysis.

On October 1, 2013, the Federal Bureau of Investigation shut down the Silk Road website, arrested its owner, and seized its assets. At a time when lawmakers and law enforcement agencies were debating how to respond to anonymous online marketplaces, Christin's work provided some of the first credible estimates of Silk Road's size, revenues, and social impact. Through his research, Christin supplied policymakers, journalists, and investigators with empirical evidence that helped shape public understanding of the marketplace and the challenges posed by cryptocurrency-enabled illicit commerce.

Project links:

Decorative image

Combating Information Warfare

For more than a decade, Kathleen Carley has been at the forefront of research into online misinformation, disinformation, and information warfare. Through her work in Carnegie Mellon’s Center for Computational Analysis of Social and Organizational Systems (CASOS) and later as founding director of the Center for Informed Democracy & Social-Cybersecurity (IDeaS), Carley helped establish the emerging field of “social cybersecurity”: the study of how adversaries use social media, bots, coordinated networks, and online influence campaigns to manipulate public opinion and undermine democratic institutions. Her research combined network science, machine learning, and large-scale social media analysis to identify how false narratives spread, and how coordinated actors amplify them online.

A hallmark of Carley's work has been the development of data-driven methods for detecting and measuring online influence operations. Her research team analyzed disinformation campaigns linked to foreign actors, including Russian and Chinese influence efforts, mapped bot networks operating during elections around the world, and developed tools such as BotHunter and other social cyber forensics systems to identify coordinated manipulation on social media platforms. The team's studies revealed how automated accounts and organized networks could artificially amplify narratives, increase polarization, and distort public discourse. By transforming massive volumes of social media data into measurable evidence, Carley and her collaborators provided some of the earliest empirical assessments of the scale and mechanics of online disinformation campaigns.

The creation of the IDeaS Center in 2019 marked a major milestone in translating this research into public policy impact. Supported by a $5 million investment from the Knight Foundation, the center was established to study disinformation, hate speech, propaganda, and information warfare, while also developing tools and policy recommendations to counter their effects on democracy. Carley and her colleagues have worked closely with journalists, policymakers, election officials, and government agencies to improve understanding of online influence operations and strengthen societal resilience against misinformation. Their research has informed public discussions about election security, platform governance, foreign information operations, and responses to emerging threats such as COVID-19 misinformation and AI-generated content.

Project links:

decorative image

Establishing Best Practices for Age Verification Technologies

As lawmakers across the United States and around the world have increasingly proposed age-verification requirements for online services, Carnegie Mellon University researchers have emerged as leading voices examining the privacy, security, and policy implications of those systems.

Through their work at CyLab, Sarah Scheffler, Lorrie Cranor, and a team of student researchers study how age-verification technologies from simple self-attestation checkboxes to government ID uploads and AI-powered facial age estimation affect users and society.

In her 2026 paper, “Adequately Tailoring Age Verification Regulations,” co-authored with Shuang Liu, Scheffler analyzed the rapidly evolving landscape of age-verification laws and proposed a framework for evaluating whether such regulations are appropriately tailored to achieve child-protection goals while minimizing harms to privacy, free expression, and security. The research highlighted that age verification is not merely a technical challenge, but a complex policy issue involving competing social values and tradeoffs.

Alongside this policy analysis, Scheffler, Cranor, and a team of student collaborators conducted large-scale empirical studies examining how real users respond to different forms of age verification. In one experiment, participants seeking access to age-restricted content encountered a range of verification methods, including simple age affirmations, photo ID uploads, and facial age-estimation systems. The findings revealed dramatic differences in user behavior: while nearly all participants were willing to click a checkbox affirming their age, substantially fewer were willing to submit government identification or biometric data, with many abandoning the process entirely.

These results demonstrated that increasingly intrusive verification requirements may undermine usability and compliance while raising significant privacy concerns. The research also warned that many proposed systems collect far more information than necessary, effectively transforming age verification into identity verification.

CyLab research findings have been featured in discussions at the Federal Trade Commission's Age Verification Workshop, as well as international forums convened by the Internet Architecture Board and the World Wide Web Consortium to explore future standards for age assurance systems. Rather than advocating for or against age verification outright, our research provides policymakers with a framework for evaluating which approaches are proportionate, effective, and privacy-preserving. By demonstrating the real-world consequences of different technical designs, the work has helped shift policy discussions away from the assumption that age verification is a simple compliance problem and toward a more nuanced understanding of how child protection, privacy, security, and civil liberties can be balanced in the digital age.

Project links: