Job Information
Organisation/Company: Inria, the French national research institute for the digital sciences
Research Field: Computer science
Researcher Profile: First Stage Researcher (R1)
Application Deadline: 21 Sep 2026 - 00:00 (UTC)
Country: France
Type of Contract: Temporary
Job Status: Full-time
Hours Per Week: 38.5
Offer Starting Date: 1 Nov 2026
Is the job funded through the EU Research Framework Programme? Not funded by a EU programme
Reference Number: 2026-10411
Is the Job related to staff position within a Research Infrastructure? No
Offer Description
The PhD will be hosted by Inria, within the PRIVATICS team in Lyon, with close collaboration involving CNRS/LIRIS Lyon and Inria Lille (MAGNET Team). The project is funded by INESIA’s initiative on the evaluation of AI. The scientific team brings complementary expertise in privacy, security, trustworthy AI, distributed systems, privacy attacks, anonymisation, differential privacy and confidential computing.
The thesis will be co-supervised by:
- Mohamed Maouche, Researcher at Inria
- Raouf Kerkouche, Researcher at Inria
- Sonia Ben Mokhtar, Researcher at CNRS
Scientific context
Recent advances in Large Language Models (LLMs) have enabled the development of agentic artificial intelligence systems. Unlike conventional conversational systems, AI agents can generate action plans, invoke external software tools and APIs, communicate with other agents, and perform actions on behalf of users. These capabilities create opportunities in areas such as personal assistance, healthcare, software development, mobility, supply-chain optimisation and resource management.
At the same time, agentic AI introduces significant privacy and security challenges. Agents may accumulate and process sensitive personal information, use it to interact with external services, and transmit data to tools or other agents that are not fully trusted. Their autonomous and loosely defined interactions can lead to accidental disclosure, malicious extraction of private information, misuse of tools, prompt-injection attacks, or privacy leakage caused by compromised agents and software vulnerabilities.
Assignments
This PhD project will investigate how to evaluate and enforce privacy in agentic AI systems. The central objective is to understand how sensitive information is collected, transformed, transmitted and potentially exposed throughout an agentic workflow, and to design mechanisms that enable agents to interact and act on behalf of users while reducing privacy risks.
The research will address privacy risks at both the client side, where users express their intent through text, voice, images, preferences or contextual data, and the server side, where agentic systems generate action plans, exchange data between agents, and invoke external tools and APIs.
Research Objective
The thesis will develop and evaluate a privacy risk-assessment and privacy-enforcement framework for agentic AI. Specifically, the project will focus on:
- Privacy risk assessment of user data: analysing the sensitivity and uniqueness of information used to express user intent, and estimating the consequences of data leakage, including re-identification risks.
- Sensitive data-flow analysis: tracking how personal and confidential information propagates through agentic workflows, including communication between agents and interactions with external services.
- Action-plan risk analysis: evaluating the sensitivity of generated action plans and assessing how much external tools, APIs and communication partners can be trusted.
- Black-box auditing and privacy attacks: assessing external tools and agentic components through black-box analysis and existing privacy attacks to identify potential information leakage.
- Privacy-enhancing technologies: developing or adapting mechanisms such as data minimisation, anonymisation, encryption, controlled information sharing, differential privacy, privacy proxies and confidential computing.
- Secure agent execution: integrating privacy protections on both the client and server sides so that sensitive data is protected before transmission and action plans can be executed with controlled access to external tools and APIs.
- Empirical evaluation: validating the proposed methods on realistic agentic AI workflows and measuring the trade-offs between privacy, utility, security and system performance.
The expected outcome is a robust agentic framework that supports safe multi-agent interactions while protecting client data, together with practical guidelines and tools for developers and organisations deploying agentic AI systems.
- Conduct original research on privacy and security for LLM-based and multi-agent AI systems.
- Design a toolbox for privacy-risk assessment on both client-side inputs and server-side agent workflows.
- Implement auditing methods for sensitive data flows, external tools and APIs, and agent-to-agent interactions.
- Develop and evaluate privacy-enhancing mechanisms tailored to agentic AI systems.
- Build experimental prototypes and benchmark privacy, utility and system-performance trade-offs.
- Collaborate with researchers from Inria Lyon, Inria Lille and CNRS/LIRIS Lyon.
- Disseminate research findings through peer-reviewed publications and presentations at leading venues in machine learning, privacy, security and distributed systems.
Where to apply
Website: https://jobs.inria.fr/public/classic/en/offres/2026-10411
Requirements
Skills/Qualifications
We are looking for a candidate with:
- Good programming skills, preferably in Python, and strong analytical abilities.
- A solid background in machine learning, computer security, privacy, distributed systems, or a closely related area.
- Knowledge of Large Language Models, agentic AI, privacy-enhancing technologies, or information-flow analysis is a plus.
- Interest in experimental research, system implementation and rigorous evaluation.
- Good written and spoken English.
Languages: FRENCH
Level: Basic
Languages: ENGLISH
Level: Good
Additional Information
Benefits
- Subsidized meals
- Partial reimbursement of public transport costs
- Leave: 7 weeks of annual leave + 10 extra days off due to RTT (statutory reduction in working hours) + possibility of exceptional leave (sick children, moving home, etc.)
- Possibility of teleworking and flexible organization of working hours
- Professional equipment available (videoconferencing, loan of computer equipment, etc.)
- Social, cultural and sports events and activities
- Access to vocational training
- Social security coverage under conditions
2300 euros gross salary /month
Selection process
Applications must include a CV, covering letter, copy of diploma and valid proof of disabled worker status.
Applications must be submitted online via the Inria website. Processing of applications submitted via other channels is not guaranteed.
Website for additional job details: https://jobs.inria.fr/public/classic/en/offres/2026-10411
Work Location(s)
Number of offers available: 1
Company/Institute: Inria
Country: France
City: Villeurbanne
Contact
City: LE CHESNAY CEDEX
Website: http://www.inria.fr
Street: Domaine de Voluceau - Rocquencourt
Postal Code: 78153
This is a Preview Listing…
You must sign in to see the full job description, and to apply.
Manage / Upgrade this job to a Full Job Listing.
Find Your Best Opportunity
Tell them AcademicJobs.com sent you!





 Logo.png)