Author: Madelaine Millar
Date: 11.24.25

This story is part four of a six-part Khoury News series called “Research that hits home,” which showcases researchers who come from — or form close partnerships with — the communities they study. Previous installments covered research into queer online communities, user-friendly social media, and inclusive video game design 

Leah Rosenbloom found their interest in digital privacy as an 11th grader. Or, perhaps more accurately, it found them. 

In 2010, Rosenbloom’s school district in Lower Merion, Pennsylvania, was caught using webcams on school-issued laptops to collect pictures of students in their homes — all without their knowledge or consent.  

“It was one of the first instances of public coming-to-consciousness that this was a possibility,” said Rosenbloom, who covered the story for their high school paper. “The report came out with the extent and details of this surveillance, and it was extremely upsetting and traumatizing. We were the first generation, I think, to start putting stickers on our webcams.” 

And now, as the internet and social media present both vast opportunity and serious threats to activists and organizers — the “safety/visibility tradeoff” — it poses a key question: Could modern tools help activists tailor the amount of risk they take on while pushing for change?  

Rosenbloom thinks the answer may be yes. 

A cryptography postdoctoral researcher in Northeastern’s SEALab with a background in grassroots organizing, Rosenbloom co-developed the new encrypted annotation system tigro, which aims to allow grassroots organizers to better tailor their approach to collective digital privacy — and maybe help the public have better online conversations in the process. It’s a product Rosenbloom created not only because of their interest in correcting institutional harms like what had happened at their high school, or in the technical ways that overreaching surveillance can be interrupted, but also because of the nearly two decades they have spent in grassroots organizing. 

The Tigro logo, which shows a tiger's face in front of blades of tall grass

tigro’s logo 

“Creating space for myself in academia means creating space for questions of collective privacy and security to be rigorously examined, sustainably,” they said. “At the same time, the value of soaking up context in a nonformal setting cannot be overstated. People have ways of knowing their communities that are so difficult to articulate and so deeply rooted.” 

For example, organizing helped Rosenbloom understand that privacy and security are collective practices. Research and rights frameworks surrounding many modern privacy-preserving technologies focus on individual users, but because communication necessarily includes multiple parties, a conversation is only as secure as its least-protected member. That’s why Rosenbloom envisions a culture and tools that prioritize peoples’ ability to control when information about themselves is gathered and shared. 

Consent around information-sharing informs another of Rosenbloom’s more unconventional research practices: frequently choosing not to publish their work.  

“Publishing is very valuable for the academic community and to move advocacy in a particular direction; there’s a legitimizing force to publication. But community work … conversations with people, doing collective privacy workshops and trainings — those activities are a big driving force behind why I do research and where I get my ideas and questions,” Rosenbloom said. “My objective is to get information into the hands of the people who can most benefit from it, and it’s much more efficient to run trainings and disseminate information through organizing networks than through traditional publishing channels.” 

Sometimes, though, publication can be a good way to get information and tools into the right hands. Rosenbloom and their fellow researchers Seny Kamara, Zachary Espiritu, Tarik Moataz, Amine Bahi, and John Wilkinson have chosen that route for tigro.  

Tigro allows users to make encrypted comments and annotations on posts, events, and other online data that will be visible only to those people — and for as long as — the user chooses. For example, if an organization posts about an upcoming protest, tigro would allow activists to leave notes to one another on the post about organizers, risks, and safety measures without posting those sensitive details to the internet at large. Users can have a secure, private conversation, on their own terms, about a public item in a shared digital space. 

“Cryptography is good at keeping information completely private, and social media is good at making everything public. But there are not many gradations in the middle,” Rosenbloom said. “When you come in from an epistemic justice lens — what do humans need, on human scales, for human organizing at the grassroots level — you come up with these technical tradeoffs and solutions that are more geared towards that.”  

Although tigro was designed for activists with stringent privacy needs, the idea of individualized, private comment sections on public posts has broader appeal. Tigro annotations could organize thousands of public social media comments into private, focused conversations, or keep important information from getting drowned out in a massive group chat. This is a common feature of tools developed using epistemically just principles; by solving for a more extreme version of a problem that exists at the margins, researchers also make progress on less extreme and more common versions of the problem.  

“One of the problems that tigro addresses … is context collapse,” Rosenbloom said, describing the feeling of many people all talking at equal volume at the same time and in the same channel. “This type of tool where people are allowed fine-grain control over what is shared, with whom, and in what time span, has a wider applicability.”  

Rosenbloom is grateful to their Khoury College advisors and mentors, Michael Ann DeVito and Ada Lerner, and to their SEALab peers for creating an environment in which they can bring their whole self to their research. They encourage Northeastern to follow DeVito and Lerner’s example by explicitly supporting trans students and by limiting the school’s use of surveillance and policing technologies.  

“Michael Ann, Ada, and all our lab mates have provided an environment where I can really be myself. I don’t have to censor myself, I can speak my mind,” Rosenbloom said. “Everyone really makes an effort to see one another as whole human beings, to invite and welcome and affirm one another, which I think is beautiful and needed in a work environment.” 

Rosenbloom looks forward to further exploring the balance of security and publicity in activism and to growing the cryptography and digital privacy community at Khoury College. They encouraged students curious about researching their own communities to sign up for their course “Abolition Technology” in the spring of 2026 or to simply stop by the SEALab for a chat.  

“We need a lot more people doing work to reach towards these notions of epistemic justice and autonomy, and many, many more voices represented,” they said. 

The Khoury Network: Be in the know

Subscribe now to our monthly newsletter for the latest stories and achievements of our students and faculty

This field is for validation purposes and should be left unchanged.

Author: Will Beeker
Date: 11.20.25

Does liking the color yellow imply driving a school bus? 

That’s the question posed by a paper that introduces the idea of “semantic leakage” in AI language models. Terra Blevins, who joined Khoury College as an assistant professor this fall, co-authored the work as a PhD student at the University of Washington while also working as a visiting researcher at Facebook. 

Semantic leakage occurs when irrelevant information in a user’s prompt “leaks” into the AI’s response, resulting in erroneous or nonsensical answers. Blevins and her colleagues posed numerous fill-in-the-blank style questions to several of the most popular large language models, which illustrated a pervasive problem.  

Here are a few examples from OpenAI’s GPT-4o model: 

Prompt: He likes yellow. He works as a 
GPT4O: school bus driver 

Prompt: He likes ants. His favorite food is 
GPT4O: ant-covered chocolate, a unique delicacy that combines the crunch of ants with the sweetness of chocolate 

Prompt: It was her turn to speak, and she got cold feet. A day later she stayed at home because she got hurt in her 
GPT4O: ankle 

Prompt: He is a doctor. His favorite song is 
GPT4O: Stayin’ Alive by the Bee Gees 

In general, humans know not to make these sorts of assumptions. We know that just because someone likes yellow doesn’t make them a bus driver. And although we can sometimes make these kinds of associations unconsciously, in AI models something very different is going on.   

“Language models are not trained to learn language the way we do. They’re trained to do next-word prediction, so a lot of what they learn is very surface level,” Blevins says. “It’s a very high-level semantic representation where these concepts get entangled in the model space.” 

Blevins and her colleagues tested for semantic leakage in Open AI’s GPT3.5, GPT4, and GPT4o models, as well as all variations of Meta’s Llama models. They compared test prompts (e.g. “He likes yellow. He works as a ___”) with control prompts that did not contain extra semantic signals (e.g. “He works as a”). They used more than 100 prompts, running each prompt 10 times to check for variations in responses. As part of the experiment, humans unassociated with the research were brought in to judge two different prompt-and-response pairs from the language models, deciding which pair was more semantically similar.  

The researchers found that GPT4o leaked more than GPT4 and GPT3.5. For the Llama variations, the “instruction-tuned” models — those that have been fine-tuned by humans — leaked more than pretrained models, which are only trained generally on vast datasets. In other words, the more highly developed the model, the more it leaked.  

“This semantic leakage isn’t just something that’s happening in little toy settings. It’s a pervasive issue with the models,” Blevins says.  

Semantic leakage could have broad implications for the training of AI models. For example, the problem of bias in AI models, especially racial and gender bias, has been a thorny issue for researchers and the public. If training data contains bias, it can easily seep into the model.  

“You can think of these other types of bias as specific cases of semantic leakage that are higher impact because there are negative consequences, but the underlying driving mechanism is likely the same,” Blevins explains. “The model learns these biases because it has these correlations in the training data. Our training data has human bias and that gets compounded in the model.” 

It’s not exactly clear how to prevent semantic leakage, but the fact that it’s more pronounced in better-performing instruction-tuned models may provide researchers with a hint.  

“The better models are learning a better representation of language,” Blevins says. “We don’t use a language model out of the box. We’ll do some more training to make it better as a chatbot, for instance, and that’s how you get things like GPT-4o. Something about that post-training emphasizes this behavior and makes the leakage more likely.” 

To further understand this phenomenon, the researchers tested prompts in English, Mandarin Chinese, Hebrew, and mixtures of those languages, finding varying levels of leakage each time.  

“Multilingual language models don’t learn all languages equally well, and so they’re usually much better at English than they are at other languages,” Blevins says. “The models don’t work that well for low-resource languages due to a lot of things, including the ‘curse of multilinguality.’ If you train a model naively on a mixture of data, the high-resource languages out-compete the low-resource ones, so they’re just better represented by the model.”  

But even as researchers grapple with these unpredictable behaviors, Blevins sees breakthroughs on the horizon.  

“I’m really excited about how we can take the way we do multilingual training now and improve it to benefit some of these low-resource languages that we don’t have a lot of data for,” she says.

The Khoury Network: Be in the know

Subscribe now to our monthly newsletter for the latest stories and achievements of our students and faculty

This field is for validation purposes and should be left unchanged.

Author: Madelaine Millar
Date: 11.17.25

This story is part three of a six-part Khoury News series called “Research that hits home,” which showcases researchers who come from — or form close partnerships with — the communities they study. Previous installments covered research into queer online communities and user-friendly social media.

In 2014, a female game developer was falsely accused of sleeping with a journalist to get a positive review of her game, and the internet exploded. Within months, there were dozens of victims of the misogynistic online harassment campaign #GamerGate, and diversity in video games had become a hot-button issue that many studios were reluctant to touch. A decade later, the industry is still feeling the effects, with many studios and developers feeling ill-equipped to bring questions of race and identity into their games.  

But to Alexandra To — assistant professor at Khoury College and the College of Arts, Media and Design; leader of the multidisciplinary ATo Lab; and passionate games nerd — diversity in gaming is neither radioactive nor an item to check off. When developers and researchers treat racial and cultural differences in an epistemically just way that respects the knowledge and stories of minoritized people, those differences become a chance for creativity in an art form she loves. 

“My work is developing a framework around engaging race in games. I ask people to poke at that, to make something new and different that is aware of race and culture,” To said. “Games are just storytelling in a new medium … even the rules and mechanics of a game are things that you can play with and change and think about from a perspective of racial and cultural diversity.” 

READ: Timeless games for ageless players: How Bob De Schutter builds games for forgotten audiences 

As To has interviewed game developers of color, she’s discovered a range of reasons developers might not engage with identity in their games. Some had proposed ideas but were shut down by larger studios. Others were fearful of being doxxed or harassed the way developers had been during #GamerGate. Still others were happy to make autobiographical games but were wary of including characters with identities like queerness that their team didn’t share.  

“That parallels so much of why people are afraid to engage with race — they don’t want to offend someone or do something harmful, which is important,” To said. “But to not put any queer characters in our games ever? That is not the answer.” 

To’s research has also uncovered ways that game developers are handling race and culture creatively, going beyond darkening a character’s skin tone to weave different ways of thinking into the stories themselves. For example, a lot of popular media follows the “hero’s journey,” a story template in which a single hero is forced into an adventure, struggles, grows, and returns home to save the day. But a lone hero overcoming adversity far from home is only one type of story that a game can tell.   

“For example, the cooking game Venba follows this Indian immigrant family in 1980s Canada. The levels involve cooking culturally relevant foods, and there’s fun mechanics around a recipe book that’s torn or water stained, and you’re trying to figure it out,” To said, noting that the game’s story, goals, obstacles, mechanics, and interaction design immerse the player in the immigrant mother’s life, rather than simply slotting a nonwhite person into the hero’s journey. “The main character primarily speaks Tamil, and she has a young son who primarily speaks English. As the viewer, you see all the text in English, but you can tell when her son is speaking in English because some of the words blur or scroll on the screen too quickly. There’s narrative design there in the UI.” 

A screenshot from the game Venba, which shows an animated Indian immigrant family in a kitchen where a child is asking to order pizza

Another of her favorite examples is the puzzle game “Never Alone.” The game was developed in collaboration with the indigenous Alaskan Iñupiat people from a traditional story and is spoken entirely in the Iñupiaq language.  

“It’s engaging in cultural preservation for a language that was dying, and that game is incredibly popular globally; the subtitles have been translated into at least a dozen languages,” To said. “There’s this sliding scale of race and culture in gaming, from simple representations that can be extremely meaningful to people to this really deep, culturally rich storytelling.” 

Both in her interview studies and in her work as a PhD advisor, To has learned to engage productively and respectfully with lived experiences that differ from her own, as she hopes to help game developers do. Her best advice is to become someone who people are comfortable correcting, as it opens the door for trusting collaborations, meaningful insights, and beautiful products.  

“You have to show that you’re going to engage thoughtfully and carefully, that you’re not going to punish people for pushing back,” she said. “My students and I disagree, debate, and sharpen each other’s ideas all the time, and that’s a great thing … Calling up all these different elements of your identity and putting that into your art is just a joyful experience.”  

Looking forward, To is excited to share more tools for engaging with race in gaming and to get feedback about her frameworks’ applicability in the industry. She also wants to get back to her roots and design more games herself; she’s currently working on the early stages of a tabletop role-playing game about transmuting grief, dread, and fear into rage. The game is deeply informed by her and her collaborators’ experiences as racialized and queer people in the United States, and it typifies the ways that centering epistemic justice can shape stories in exciting and new ways.  

“True diversity is getting to engage with many kinds of characters, stories and people, both like yourself and unlike yourself. It’s good to engage in empathy and perspective sharing, and to learn about other values and cultures and experiences,” To said. “I love that about games — we’re not just passively consuming, but actively co-creating as we engage with the media.”

The Khoury Network: Be in the know

Subscribe now to our monthly newsletter for the latest stories and achievements of our students and faculty

This field is for validation purposes and should be left unchanged.