Generalize sampling-bias findings to privacy measurements

Investigate whether the sampling biases observed in web security measurements generalize to privacy-oriented measurement problems, including privacy metrics associated with HSTS and TLS misconfigurations.

Background

The study evaluates how dataset selection and sampling strategies affect large-scale web security measurements, finding that deterministic Top N sampling can introduce persistent bias and that probability sampling from an inappropriate population can produce systematically incorrect prevalence estimates. The authors note that analogous measurement choices may affect privacy-oriented studies because security misconfigurations such as HSTS and TLS flaws can also expose browsing information or enable tracking. They leave unresolved whether the sampling-bias patterns identified for security measurements extend to privacy metrics and privacy problems more generally.

References

Future work could extend the sampling analysis to privacy metrics and examine whether the biases we observe in security measurements generalizes to privacy problems.

You Get What You Sample: Evaluating Sampling Strategies for Web Security Measurements  (2609.11218 - Zhang et al., 10 Sep 2026) in Section 6.2, “Limitations”