Arizona State University Leads $5M NSF Initiative to Strengthen Data Protection Through Privacy-Enhancing Technologies

Arizona State University Leads $5M NSF Initiative to Strengthen Data Protection Through Privacy-Enhancing Technologies

Picture two scenarios playing out at universities across the country. In one, medical researchers at separate institutions need to compare patient records to accelerate drug discovery. In the other, cybersecurity professionals want to pool intelligence about attacks targeting their networks. In both cases, collaboration stalls for the same reason: privacy regulations, institutional policies, and legal safeguards prevent sensitive information — from personally identifiable data to intellectual property — from being shared or jointly analyzed.

This tension between scientific progress and data protection is one of the defining challenges of modern research. A new $5 million award from the U.S. National Science Foundation (NSF) Office of Advanced Cyberinfrastructure aims to resolve it. Arizona State University, in partnership with San Diego State University and the University of Utah, will build a national community resource that lets institutions compute on and share insights from sensitive data without ever exposing the data itself.

Here is a detailed look at the project, the privacy-enhancing technologies behind it, and what it means for researchers, institutions, and cybersecurity across the USA. Want to track the project as it develops? Bookmark the official NSF award page and follow Arizona State University’s Research Technology Office for updates.

Why Sensitive Data Stays Locked Away: The Core Challenge in Data Protection

Data protection today follows a familiar pattern: encrypt information during transmission, encrypt it during storage, and restrict who holds the keys. What remains genuinely difficult is computation. Running statistical analyses, training machine learning models, or answering research queries usually requires decrypting data first — creating windows of exposure that are unacceptable for medical records, financial information, and census statistics.

Anonymization is often suggested as a workaround, but experts caution against relying on it. Robert Beverly, director of San Diego State University’s Cybersecurity Center for Research and Education and professor of computer science, notes that many attackers can conduct re-identification attacks, reverse-engineering supposedly anonymous datasets to link records back to specific individuals.

The consequences reach far beyond individual projects. As Beverly observes, there are many cases where privacy concerns preclude researchers from working on data together — an impediment to science itself. Researchers are entrusted with sensitive data and must protect it, yet the safeguards designed to provide that protection often block the very collaboration that discovery requires.

Inside PARAPET: Arizona State University’s National Cyberinfrastructure Project

The response to this challenge is PARAPET — Prototype Architecture for Research Advances using Privacy Enhancing Technologies. Over the next five years, the three-university team will deploy and support this cyberinfrastructure as a testbed and community resource for researchers nationwide.

The project pairs technical innovation with practical governance expertise. At Arizona State University, Carolyn Ellis, director of the ASU Research Technology Office and co-principal investigator on the project, will ensure PARAPET meets rapidly evolving regulatory requirements and will lead efforts to recruit users from across the nation to test the prototype once it is ready.

“Privacy-enhancing technologies have enormous potential to change how we conduct research with sensitive or regulated datasets. We first need to understand how these new capabilities fit within institutional policies, research workflows, and the privacy expectations established through data-sharing agreements.” — Carolyn Ellis, Arizona State University

ASU’s leadership of the national Regulated Research Community of Practice gives the team an institutional perspective that bridges the gap between new technical capabilities and the practical realities of protecting sensitive research data — a bridge missing from many purely technical efforts.

The Privacy-Enhancing Technologies Powering PARAPET

PARAPET combines several advanced techniques, each addressing a different weakness in conventional data protection:

  • Homomorphic encryption: Allows one user to send encrypted data that another user can process without decrypting it. The underlying information is never revealed to anyone except the original owner — even while calculations are performed on it.
  • Federated learning: Enables collaborative AI training without data centralization. Users train models locally on their own devices and share only model updates, allowing a larger national model to improve without raw data ever leaving its source.
  • Differential privacy: Introduces mathematically calibrated noise into results, protecting individual records while preserving the statistical usefulness of the complete dataset.

Together, these tools safeguard data at rest, in transit, and during computation — closing the exposure gaps that traditional encryption leaves open. Curious how these techniques could apply to your own workflows? Have questions about implementing privacy-enhancing technologies in a regulated environment? Write to us — we would welcome hearing about your use case.

Real-World Applications: Where Secure Data Collaboration Matters Most

PARAPET is designed to support data analysis across a range of fields where sensitive information is central:

  • Health care: Medical researchers at different institutions can compare patient data to advance drug discovery without moving protected health information between organizations.
  • Internet security: Cybersecurity professionals can share and analyze intelligence about attacks on their networks to defend against adversaries without exposing their own vulnerabilities.
  • Finance: Institutions can collaboratively detect fraud patterns while keeping customer financial information fully protected.
  • Social sciences: Researchers working with census statistics can run analyses that current rules would otherwise prohibit.

A key design principle sets PARAPET apart from centralized data platforms: instead of requiring organizations to transfer raw data to a central service, it tests methods that allow participating institutions to retain greater control over sensitive research data. Preventative protection is built in as well — encrypted data is locked away so that only approved users on secured networks can access it, meaning information remains inaccessible even if a device is compromised. Which of these fields do you think will benefit first? Share your perspective in the comments below.

Strengthening Cybersecurity Against Future Quantum Threats

Quantum computing poses a heightened, long-term threat to cyber systems. Much of today’s encryption could eventually be broken by sufficiently capable quantum machines — and adversaries are already known to harvest encrypted data now for decryption later. PARAPET’s techniques could help protect against future quantum computing attacks, and the platform will serve as a national-scale testbed where the research community can explore quantum-resistant tools before threats fully materialize.

For organizations planning long-term data protection strategies, this matters. Archived medical, financial, and research records must remain protected for decades. Infrastructure designed with quantum resilience in mind offers a more durable foundation than systems that will need retrofitting under pressure.

Protecting Privacy While Training AI Models Nationwide

With artificial intelligence spreading into virtually every discipline, protecting data as models are built has become essential. PARAPET tackles this directly: users can fine-tune local models on their own devices and share only the model updates with PARAPET. The infrastructure then uses information from those updates to train its larger central model without ever accessing raw data.

Manish Parashar, chief AI officer for the University of Utah and executive director of its Scientific Computing and Imaging Institute, will help manage PARAPET’s hardware and ensure the infrastructure is ready for deployment at national scale.

“Data-driven and AI-enabled research is revolutionizing science, but progress in critical fields such as cybersecurity and public health is hampered by our inability to obtain, create, compute on and share regulated data. PARAPET takes an important step toward solving this problem.” — Manish Parashar, University of Utah

Actionable Steps for Institutions Handling Sensitive Data

While PARAPET is under development, research leaders, compliance officers, and IT teams can begin preparing today for a privacy-enhanced future:

  • Audit your data-sharing workflows. Identify where sensitive data currently leaves your institution and which collaborations stall because of privacy constraints.
  • Review data-sharing agreements with privacy-enhancing technologies in mind. As Ellis emphasizes, new capabilities must fit within institutional policies, research workflows, and established privacy expectations. Flag agreements that could be strengthened by approaches like federated learning.
  • Invest in staff knowledge. Build familiarity with differential privacy, homomorphic encryption, and federated learning among technical and compliance staff now, so adoption accelerates when production systems arrive.
  • Assess quantum readiness. Inventory which datasets require long-term protection and evaluate how current encryption choices hold up against quantum-era threats.
  • Join communities of practice. Groups such as the Regulated Research Community of Practice connect institutions navigating the same questions and offer a channel for participating in national testbeds like PARAPET.

What PARAPET Means for the Future of Research and Data Protection

For researchers, the project signals a shift in what becomes feasible. Collaborations that once required years of legal negotiation over data-sharing agreements may become practical through infrastructure that keeps data protected by design. For institutions, PARAPET offers a working model for balancing openness with compliance. And for the cybersecurity community in the USA, it represents a serious investment in moving privacy-enhancing technologies from academic publications into production systems — an effort Beverly describes as promising to move the whole field forward.

Final Thoughts: Setting a New Standard for Data Protection in the USA

The PARAPET project demonstrates that data protection and scientific collaboration do not have to compete. With $5 million in NSF support, Arizona State University and its partners are building infrastructure where sensitive data can fuel discovery in health care, security, finance, and the social sciences — without ever being exposed. For anyone working with regulated data, the next five years of development at ASU, SDSU, and the University of Utah are worth following closely.

Stay engaged: Explore the full NSF award details, learn how the ASU Research Technology Office supports regulated research nationwide, and subscribe to our updates for the latest on privacy-enhancing technologies, cybersecurity, and AI research. Explore our related articles to keep building your knowledge.