AI for security applications (WP4)

WP4 focuses on the reliability, security and resilience of artificial intelligence systems in critical applications. The aim is to enhance the trustworthiness of AI models, protection against manipulation, and the overall cyber security of both hardware and software infrastructure. The research covers three main areas. The first is the adaptation of large and small language models for professional domains such as pharmacology, biotechnology, law and the media, including the detection of disinformation and fraudulent content.

The second area involves investigating the two-way interaction between users and machine learning algorithms with the aim of increasing the transparency, controllability and security of decision-making processes. The third area involves analysing the computational complexity of AI models, including exploring the potential of quantum computing and developing computationally efficient alternatives to existing approaches. The outcome of WP4 is safer, more robust and more trustworthy AI systems suitable for deployment in critical and highly regulated sectors.

What problem does the WP solve, and why is it important?

AI systems remain vulnerable to errors, uncertainty in input data and deliberate manipulation

There is a growing risk of models being misused (e.g. disinformation, fraud, adversarial attacks)

There is a lack of sufficiently robust and interpretable models for use in critical and regulated areas

The computational demands of modern models limit their scalability and practical application

Interactions between users and AI systems are not always safe, transparent and controllable

Examples of use / areas of application and benefits

Pharmacology and Biotechnology

  • greater reliability of AI when working with sensitive scientific data
  • reducing the risk of misinterpretation in the analysis of biological and chemical information
  • safer use of AI in environments where high levels of accuracy are required

Law and the regulatory environment

  • greater transparency and explainability of AI decisions
  • safer handling of legal documents and knowledge management systems
  • minimising errors in the interpretation of complex textual sources

Média a informační prostor

  • The media and the information landscape
  • increasing resilience to cyber-attacks and manipulation of the public sphere
  • promoting a trustworthy digital environment

Cyber security and critical IT infrastructure

  • increased resilience of AI systems to adversarial attacks
  • protection of models, data and decision-making processes against misuse
  • strengthening the security of critical digital services

Computationally intensive AI and future architectures (including quantum research)

  • more efficient and scalable AI models
  • reducing the computational demands of existing approaches
  • paving the way for a new computing paradigm in tackling complex problems

Key people

doc. Ing. Tomáš Pevný Ph.D.

Artificial Intelligence Centre | FEL CTU

doc. Ing. Tomáš Pevný Ph.D.

| FEL CTU

Aurél Gábor Gábris, Ph.D.

| FJFI CTU

Ing. Sebastián García, Ph.D.  

| FEL CTU

Ing. Luboš Král, Ph.D

| FEL CTU

Participating institutions

Used technologies and procedures

Achieved and planned results

2026

Abductive explanations of decisions made by artificial intelligence methods

2027

Tools for text cluster analysis with support for temporal data and network structures

Evolutionary software for prompt engineering

A library for interaction between the user and a machine learning system

Knihovna pro interakci mezi uživatelem a systémem strojového učení.

Methods for detecting hallucinations and improving the factual accuracy of texts generated by large language models

Pipelines for automated fact-checking

Privacy-preserving quantum machine learning algorithms for threat detection

2028

Pipelines and tools for fact extraction, document set summarisation and structured summarisation

Methods for the efficient training and inference of large language models (LLMs) with limited computational resources, supported by additional modalities (e.g. image data for OCR)

Small, security-focused language models for critical equipment

2029

Dual-agent offensive-defensive co-evolution

A semi-supervised quantum machine learning algorithm for anomaly detection

2030

A multi-LLM agent-based architecture for AI defence and attack simulation

2031

Agent-based AI architectures for attacking AI agents