[School of Engineering PhD Scholarships] Securing Agentic AI: Trustworthy Delegation and Accountable Actions
Not stated
- Location
- Manchester, United Kingdom
- Funding
- Competition Funded PhD Project (Students Worldwide)
- Application deadline
- Year-round applications
About the project
About the Project Securing Agentic AI: Trustworthy Delegation and Accountable Actions How can we trust AI agents to act on our behalf when they interact with untrusted information, external tools, and other agents? AI agents can retrieve documents, invoke software tools, communicate with services, and delegate tasks. These capabilities create new security challenges. An assistant authorised to analyse confidential documents could be manipulated into sharing them with an unintended recipient. A compromised sub-agent could misuse inherited permissions, while several agents acting concurrently could exceed a shared resource limit. This PhD project will investigate how to constrain agent behaviour and make consequential actions accountable. You will explore how permissions should pass between agents, how security policies can be enforced independently of a language model, and how execution records can connect actions to the authority under which they were performed. The research will combine practical security experiments with formal modelling and protocol design. You will: Build a reproducible environment for studying attacks and defences in collaborative agent workflows involving data access, tool use, and external communication. Design and analyse mechanisms for constrained delegation, including authenticated permissions, resource limits, and revocation. Develop methods for recording and verifying the relationship between authorisation, delegation, and executed actions. Evaluate the resulting systems for security, legitimate task completion, performance, and accountability. The project will be supervised by Dr Zhipeng Wang and Dr Mustafa Mustafa in the Department of Computer Science at The University of Manchester. It builds on the supervisory team's research in applied cryptography, distributed systems, privacy, and emerging agentic AI infrastructures. You will receive training in threat modelling, secure protocol design, formal analysis, systems implementation, and reproducible experimentation, alongside support for academic writing, publication, and responsible vulnerability disclosure. The research will use existing language models and controlled environments, with opportunities to develop open-source tools and publish findings. This project would suit someone who enjoys understanding how systems fail and designing principled solutions. It offers the opportunity to contribute to the foundations of secure AI systems while developing skills spanning cybersecurity, distributed computing, and trustworthy AI. This project is expected to start in September 2027. Before you apply: We strongly recommend that you contact the supervisors for this project before you apply. How to apply: To be considered for this project you must complete a formal application through our online application portal. If you already have an applicant account this link will directly open an application for PhD School of Engineering Scholarships . If you don’t already have an applicant account, please follow the instructions here. . When applying, please specify the full title and supervisor/s of the project, details of your previous study, and names and contact details of two referees. You must also upload a Supporting Statement describing the motivation to apply to the project, your CV and transcripts of awarded and in-progress university qualifications . Please note late or incomplete applications will not be considered. Equality, diversity and inclusion are fundamental to the success of The University of Manchester and central to all our activities. A diverse research community strengthens creativity, productivity and quality, while increasing the societal and economic impact of our work. We welcome applicants from all career paths, backgrounds and sections of the community, regardless of age, disability, ethnicity, gender, gender expression, sexual orientation or transgender status. We welcome applications from candidates returning to study after a career break or experience in other roles. Flexible study arrangements may be available, including part-time study at 50%, 60% or 80%, subject to the requirements of the project and funder. Eligibility : The standard academic entry requirement for this PhD is an upper second-class (2:1) honours degree in a discipline directly relevant to the PhD Computer Science, Cyber Security, Software Engineering, Electrical and Electronic Engineering, Mathematics (or international equivalent) OR any upper-second class (2:1) honours degree and a Master’s degree at merit in a discipline directly relevant to the PhD Computer Science, Cyber Security, Software Engineering, Electrical and Electronic Engineering, Mathematics (or international equivalent). Strong programming skills and analytical ability are essential. Applicants should demonstrate an interest in security and trustworthy AI, with foundational knowledge in at least one relevant area, such as computer security, distributed systems, cryptography, formal methods, or machine learning. Prior experience with large language models or agent frameworks is welcome but not essential. This project will remain open until filled. If your application is submitted by 1 st November 2026, you can expect a decision by 18 th December 2026. If your application is submitted by 15 th January 2027, you can expect a decision by 30 th March 2027. Self or externally funded students can also be considered for this project. FSESoE