林雪平大学

PhD student in AI Security: Information-Theoretic Foundations of Memory Poisoning

项目介绍

We have the power of over 50,000 students and co-workers. Students who provide hope for the future. Co-workers who contribute to Linköping University meeting challenges of today. Our fundamental values rest on credibility, trust and security. By having the courage to think freely and innovate, our actions together, large and small, contribute to a better world. We look forward to receiving your application!

Your work assignments

We are looking for a highly talented and motivated Ph.D. candidate to join our research team in the cutting-edge area of AI security, with a particular focus on information-theoretic foundations of memory poisoning. The project, funded by the Swedish Research Council (VR), aims to develop a rigorous understanding of how malicious information injected into an AI agent’s memory can influence its reasoning and decision-making.

Modern AI systems are rapidly evolving from single-turn chatbots into autonomous agents. These agents use external tools, retrieve information from databases and the web, store memories across interactions, and coordinate with users or other agents. This makes them powerful, but also introduces new security and privacy risks. In particular, if an adversary can corrupt what an agent stores or retrieves, the agent may later make biased, unsafe, or strategically manipulated decisions.

How much poisoned information is needed to manipulate an agent’s behavior? What are the fundamental limits of detecting poisoned memories? How can agents update, retrieve, and communicate memory securely under adversarial conditions?

To establish a foundational understanding of memory poisoning, the project will combine tools from information theory, statistical learning, communication theory, and AI privacy and security. It is suitable for a candidate who is interested in developing rigorous foundations while also validating ideas through selected proof-of-concept attacks, defenses, and experiments with LLM-based agents.

As a PhD student, you devote most of your time to doctoral studies and the research projects of which you are part. Your work may also include teaching or other departmental duties, up to a maximum of 20 per cent of full-time.

Your qualifications

You have graduated at Master’s level in Computer Science, Electrical Engineering, or Applied Mathematics with a minimum of 240 credits, at least 60 of which must be in advanced courses in the subjects mentioned. Alternatively, you have gained essentially corresponding knowledge in another way. The requirement for a degree must be met no later than the time the employment decision is finalized, which occurs when the employment contract is signed.

Applicants must demonstrate strong mathematical maturity, solid programming skills, and an excellent ability to communicate in English, both orally and in writing. You should also be able to work independently, be goal-oriented, communicate clearly, and collaborate effectively with others.

Prior experience in AI security, privacy, or LLMs is beneficial but not required. We especially welcome strong applicants from backgrounds such as information theory, communication theory, signal processing, optimization and learning, applied probability and statistics, cybersecurity, and distributed systems.

Your workplace

You will be based in the Division for Communication Systems (KS) at the Department of Electrical Engineering (ISY), Linköping University. The Division for Communication Systems carries out research, undergraduate and postgraduate education in communications engineering, statistical signal processing, network science, and decentralized machine learning. Welcome to read more about us at: https://liu.se/en/organisation/liu/isy/ks.

For more information about working at ISY, please visit: https://liu.se/en/article/open-positions-at-isy.

You will become a key member of a dynamic and ambitious research team across Linköping University (Asst. Prof. Khac-Hoang Ngo), Chalmers University of Technology (Prof. Alexandre Graell i Amat), and Recorded Future (Dr. Johan Östman). Our team currently consists of 5 PhD students and 2 postdocs.

Research visits to Chalmers and Recorded Future will be organized throughout the Ph.D. The collaboration with Recorded Future will provide exposure to real-world cybersecurity use cases, while the academic focus of the Ph.D. remains on high-quality scientific research and publication.

Check our recent work on AI privacy and security:
• Practical Bayes-Optimal Membership Inference Attacks, NeurIPS 2025, https://arxiv.org/pdf/2505.24089
• Secure Aggregation is Not Private Against Membership Inference Attacks, ECML 2024, https://arxiv.org/pdf/2403.17775
• On Local Mutual-Information Privacy, IEEE ITW2024, https://arxiv.org/pdf/2405.07596v3

Linköping University is ranked 43rd globally in AI research, 12th in Europe, and recognized as leading in Sweden in the field, according to Vinnova’s report about strategic technologies for Sweden. In addition, Linköping has been awarded “Student City of the Year” in Sweden three times.

The employment

When taking up the post, you will be admitted to the program for doctoral studies. More information about the doctoral studies at each faculty is available at Doctoral studies at Linköping University.

The employment has a duration of normally four years’ full-time equivalent. Extension of employment up to five years is based on the degree of teaching and institutional assignment. Further extensions may be granted in exceptional circumstances. You will initially be employed for one year, after which your employment will be renewed for a maximum of two years at a time, depending on your progress through the study plan.

If you have questions about being a Ph.D. student at ISY, please contact isyphdcouncil@groups.liu.se or ask us. We would be happy to put you in contact with one of our current Ph.D. students. 

Starting date by agreement, but no later than December 23, 2026.

Background screening may be carried out before any decision on employment is made.

Salary and employment benefits

The salary of PhD students is determined according to a locally negotiated salary progression. Your starting salary will be around 36, 400 SEK/month. You will enjoy several employee benefits, including a pension.

More information about employment benefits at Linköping University is available here.

Union representatives

Information about union representatives, see Help for applicants.

Application procedure

Apply for the position by clicking the “Apply” button below. Your application must reach Linköping University no later than June 22, 2026.

Applications and documents received after the date above will not be considered.

We welcome applicants with different backgrounds, experiences and perspectives – diversity enriches our work and helps us grow. Preserving everybody’s equal value, rights and opportunities is a natural part of who we are. Read more about our work with: Equal opportunities.

We look forward to receiving your application!

项目概览

wave-1-bottom
访问项目链接 招生网站
北欧, 瑞典 所在地点
带薪岗位制 项目类别
截止日期 2026-06-22
林雪平大学

院校简介

林雪平大学,是瑞典的一所著名的国立综合性大学,以科学工程类专业见长。
查看院校介绍

相关项目推荐

KD博士实时收录全球顶尖院校的博士项目,总有一个项目等着你!