Artificial Intelligence

Root cause analysis of cyber security incidents

University of Leeds

Not stated

Location
Leeds, United Kingdom, United Kingdom
Funding
Funded PhD Project (UK Students Only)
Application deadline
30 September 2026

About the project

About the Project One full scholarship is available in the School of Computer Science at the University of Leeds in 2026/27. This scholarship is open only applicants who qualify as Home student for fee purposes and covers tuition fees plus maintenance. The position is to start on 1st February 2027. The School of Computer Science at the University of Leeds invites applications from prospective postgraduate researchers who wish to commence study for a PhD in the academic year 2026/27 for the School of Computer Science EPSRC Industry Scholarship. This fully funded PhD place provides an exciting opportunity to pursue postgraduate research in a range of fields relating to cybersecurity and artificial intelligence. The studentship is only available to candidates eligible for Home student status. Applicants should check their eligibility before applying and clearly confirm their eligibility in their CV and personal statement. Due to funding requirements and project timelines, only applicants who meet the eligibility criteria and can start on the specified date will be considered. Applications that do not meet these requirements will not be shortlisted. Project overview This PhD studentship is an EPSRC industry scholarship, to be held in the School of Computer Science at the University of Leeds. The research will develop AI techniques to conduct root cause analysis (RCA) of cybersecurity incidents. The research will develop machine learning models and natural language processing (NLP) models to perform RCA. RCA is step-by-step method used to find the true underlying reasons behind cybersecurity breaches rather than focusing on the symptoms. Research Approach The research will use multimodal data (e.g., from firewall, network, OS logs etc) to develop a mixed-methods technique to perform RCA. The technique will be integrated within a tool that will enable visualisation of the vulnerabilities leading to a security incident. Potential methods include, but not limited to: Use of BERT models to detect security-related events. Use of machine learning models (e.g., random forest) for attack detection. Use of reasoning models.

Research areas

ArtificialIntelligenceCyberSecurityDataAnalysisDataScienceMachineLearningRootcauseanalysisofcybersecurityincidents