About the role
You find ways to learn from useful signals without casually exposing the people behind them, and you test privacy methods against explicit adversaries rather than against good intentions. The premise you will spend a lot of time correcting: keeping raw data on a device does not by itself make a learning system private.
The work
Research differential privacy, federated learning, secure aggregation or related techniques where they fit the problem. Measure privacy-utility tradeoffs and leakage from updates or outputs. Work with cryptography and product teams on deployable guarantees and understandable consent.
What good looks like
In your first 90 days, deliver a threat model, a reproduced baseline and a privacy evaluation with clearly stated assumptions.
Evidence we look for
Bring rigorous privacy or ML research expertise. Explain why keeping raw data on a device does not by itself make a learning system private.
What we need to see
- Rigorous privacy or machine-learning research expertise
- You can explain why on-device data is not automatically private, and design accordingly
- You define an adversary before claiming a guarantee
- You can quantify a privacy and utility tradeoff honestly
Nice to have
- Differential privacy in production rather than in theory
- Federated learning, secure aggregation, or MPC
- Membership-inference or extraction attack research
The exercise
Evaluate a proposed federated training scheme for update leakage, malicious clients and withdrawal after participation.
Where and how we work
In the office together five days a week, in any of these cities. Remote-friendly around your family, arranged one person at a time.