Description du poste
Le descriptif de l’offre ci-dessous est en Anglais
Type de contrat : CDD
Niveau de diplôme exigé : Bac + 5 ou équivalent
Fonction : Doctorant
A propos du centre ou de la direction fonctionnelle
-------------------------------------------------------
The Inria research centre in Lyon is the 9th Inria research centre, formally created in January 2022. It brings together approximately 300 people in 19 research teams and research support services.
Its staff are distributed at this stage on 2 campuses: in Villeurbanne La Doua (Centre / INSA Lyon / UCBL) on the one hand, and Lyon Gerland (ENS de Lyon) on the other.
The Lyon centre is active in the fields of software, distributed and high-performance computing, embedded systems, quantum computing and privacy in the digital world, but also in digital health and computational biology.
Contexte et atouts du poste
-------------------------------
The PhD will be hosted by Inria, within the PRIVATICS team in Lyon, with close collaboration involving CNRS/LIRIS Lyon and Inria Lille (MAGNET Team). The project is funded by INESIA’s initiative on the evaluation of AI. The scientific team brings complementary expertise in privacy, security, trustworthy AI, distributed systems, privacy attacks, anonymisation, differential privacy and confidential computing.
The thesis will be co-supervised by:
Mohamed Maouche, Researcher at Inria
Raouf Kerkouche, Researcher at Inria
Sonia Ben Mokhtar, Researcher at CNRS
Scientific context
Recent advances in Large Language Models (LLMs) have enabled the development of agentic artificial intelligence systems. Unlike conventional conversational systems, AI agents can generate action plans, invoke external software tools and APIs, communicate with other agents, and perform actions on behalf of users. These capabilities create opportunities in areas such as personal assistance, healthcare, software development, mobility, supply-chain optimisation and resource management.
At the same time, agentic AI introduces significant privacy and security challenges. Agents may accumulate and process sensitive personal information, use it to interact with external services, and transmit data to tools or other agents that are not fully trusted. Their autonomous and loosely defined interactions can lead to accidental disclosure, malicious extraction of private information, misuse of tools, prompt-injection attacks, or privacy leakage caused by compromised agents and software vulnerabilities.
Mission confiée
-------------------
Assignments :
This PhD project will investigate how to evaluate and enforce privacy in agentic AI systems. The central objective is to understand how sensitive information is collected, transformed, transmitted and potentially exposed throughout an agentic workflow, and to design mechanisms that enable agents to interact and act on behalf of users while reducing privacy risks.
The research will address privacy risks at both the client side, where users express their intent through text, voice, images, preferences or contextual data, and the server side, where agentic systems generate action plans, exchange data between agents, and invoke external tools and APIs.
Research Objective: The thesis will develop and evaluate a privacy risk-assessment and privacy-enforcement framework for agentic AI. Specifically, the project will focus on:
Privacy risk assessment of user data: analysing the sensitivity and uniqueness of information used to express user intent, and estimating the consequences of data leakage, including re-identification risks.
Sensitive data-flow analysis: tracking how personal and confidential information propagates through agentic workflows, including communication between agents and interactions with external services.
Action-plan risk analysis: evaluating the sensitivity of generated action plans and assessing how much external tools, APIs an