Agentic Federated Large Language Models for Autonomous Cyber Threat Hunting
Not stated
- Location
- Portsmouth, United Kingdom
- Funding
- Self-Funded PhD Students Only
- Application deadline
- Year-round applications
About the project
About the Project Applications are invited for a self-funded, 3 year full-time or 6 year part-time PhD project. The PhD will be based in the School of Computing, Mathematics and Physics and will be supervised by Dr Rahim Taheri , Professor Ivan Jordanov and Dr Sajad Homayoun (Aalborg University). This project aims to develop a next-generation cyber threat hunting framework based on Agentic Artificial Intelligence integrated with Federated Large Language Models (LLMs). The proposed system will enable multiple intelligent agents to collaboratively detect, analyse, and respond to cyber threats in a fully decentralised and privacy-preserving manner. Unlike traditional intrusion detection systems, which rely on static models and centralised data, this research introduces a distributed, autonomous, and adaptive architecture where LLM-powered agents operate across multiple nodes (e.g., IoT devices, vehicular networks, and 5G/6G infrastructures). Each agent will be capable of reasoning over security events, sharing insights through federated learning, and making context-aware decisions without exposing sensitive data. The project will investigate how agent coordination, secure model aggregation, and adversarial robustness can be achieved in such environments. It will also explore the integration of explainable AI techniques to ensure transparency and trust in automated decision-making processes. The expected outcome is a scalable and resilient cyber defence system capable of real-time threat hunting, early attack detection, and autonomous mitigation, with applications in critical domains such as connected vehicles, smart infrastructure, and next-generation communication networks. Project Highlights: The work on this project will involve: Integration of Agentic AI + Federated LLMs for cyber threat hunting Privacy-preserving distributed learning (no raw data sharing) Autonomous and adaptive threat detection and response Robust against adversarial and poisoning attacks Explainable and trustworthy decision-making Scalable for IoT, Connected Vehicles, and 5G/6G systems Project description: The rapid growth of distributed systems such as IoT networks, connected vehicles, and 5G/6G infrastructures has significantly increased the complexity and scale of cyber threats. Traditional intrusion detection and threat hunting approaches, which rely on centralised data processing and static models, are no longer sufficient to address evolving, large-scale, and privacy-sensitive attack scenarios. This project proposes a novel framework based on Agentic Artificial Intelligence integrated with Federated Large Language Models (LLMs) for autonomous cyber threat hunting. The core idea is to design a multi-agent system in which intelligent agents operate across distributed environments, collaboratively learning from local data while preserving privacy through federated learning. Each agent will be capable of analysing security events, reasoning using LLMs, and coordinating with other agents to detect and respond to threats in real time. The research will focus on key challenges, including efficient coordination between agents, secure and robust model aggregation, and resilience against adversarial attacks such as data poisoning and model manipulation. In addition, the project will incorporate explainable AI techniques to enhance transparency and trust in automated decision-making. Methodologically, the project will combine deep learning, federated optimisation, multi-agent systems, and cybersecurity analytics. Experimental validation will be conducted using benchmark intrusion detection datasets and realistic network environments. The expected outcome is a scalable, privacy-preserving, and adaptive cyber defence system capable of proactive threat hunting and autonomous response. This research will contribute to advancing secure and trustworthy AI for critical applications in next-generation digital infrastructures. General admissions criteria You'll need a good first degree from an internationally recognised university (minimum upper second class or equivalent, depending on your chosen course) or a Master’s degree in an appropriate subject. In exceptional cases, we may consider equivalent professional experience and/or qualifications. English language proficiency at a minimum of IELTS band 6.5 with no component score below 6.0. International students will require a study visa from UKVI to pursue the degree in the UK. If the research is in a sensitive or technological subject, the student may also need to secure an Academic Technology Approval Scheme (ATAS) certificate from the UK Foreign Office. Specific candidate requirements Strong background in Machine Learning / Deep Learning / AI Knowledge of Cybersecurity, Intrusion Detection, or Network Security Familiarity with Federated Learning or Distributed Systems (desirable) Experience with Large Language Models (LLMs) or NLP (desirable) Programming skills in Python (e.g., PyTorch, TensorFlow) Understanding of adversarial machine learning or AI security (a plus) Ability to conduct independent research and publish in high-quality venues How to Apply We’d encourage you to contact Dr Rahim Taheri ( rahim.taheri@port.ac.uk ) to discuss your interest before you apply, quoting the project code. When you are ready to apply, please follow the ' Apply now ' link on the Computing PhD subject area page and select the link for the relevant intake.. Make sure you submit a personal statement, proof of your degrees and grades, details of two referees, proof of your English language proficiency and an up-to-date CV. Our ‘ How to Apply ’ page offers further guidance on the PhD application process. When applying please quote project code CMP10540529 .