AI Security & Privacy
Robustness against adversarial attacks, prompt injection defence, learning without sharing data, and model confidentiality.

Why we work in this area
Putting a model into production means putting its attack surface into production too. Vision models can be fooled by perturbations invisible to the eye; language models can be steered by the text handed to them. These are not theoretical — they are things we meet in the field.
The second issue is learning without the data ever leaving. Organisations that cannot develop models for data security reasons often realise late that the problem is not the model but the architecture.
What we work on
- Robustness to adversarial examples and measuring performance under attack
- Prompt injection and data exfiltration defences in language models
- Federated learning and training models without centralising data
- Differential privacy and preventing training data from being recovered from the model
- Protection against model theft and reverse engineering
From our research projects
Our threat detection and data protection project intersects directly with this area: a defence approach that does not rely on known signatures, works from behaviour, and adapts itself to new forms of attack.
A technical assessment for your AI project
Your project's feasibility, risks and timeline are assessed in a technical consultation.