Research

How can we ensure that automated systems remain trustworthy when they may be subject to faults and attacks?

Research statement

Reliable decisions under uncertainty and attack

My research focuses on making automated systems more reliable when decisions must be made from data that may be uncertain, corrupted, delayed, or manipulated. I am particularly interested in sequential systems, where observations arrive over time and the decisions made affect what happens next. This includes problems in machine learning, autonomous control, and signal processing, with applications where incorrect decisions can have significant real-world consequences. I study how attacks and faults can be detected, their effects mitigated, what guarantees can be provided, and how automated systems should respond to uncertainty and risk. I am also interested in making the assumptions and value judgements behind these systems more explicit and open to discussion.

I study LTI systems and small Machine Learning models, using tools such as interactive multiple model, Kalman filters, adversarial training, statistical tests, and anytime-valid inference. Applications of the problems I consider include: benefit application systems, fraud detection, self driving vehicles, networked control systems, and process control.

Research themes

What I work on

01

Detection of attacks and faults

How can we recognise when the data used by a sequential system has been manipulated or when the system is behaving abnormally? My work includes detection of delay-injection attacks, where observations or feedback are deliberately delayed, as well as related problems such as replay attacks. I use methods from statistical signal processing and control, including Interacting Multiple Model (IMM) filtering, to detect attacks while keeping false alarms low. My research considers both how detection methods can be improved, how their presence affects the system, and how they should be evaluated.

02

Measuring and mitigating attack impact

Whilst attack detection is a good start to securing an autonomous system, it is not always enough, and many important questions remain: what should be done when an attack has been detected? What kind of attacks can avoid detection, and what impact may these have? How do we find the best trade-off between performance under attack and for nominal data? This is the kind of questions I hope to answer when studying how the impact of attacks and faults can be measured. In turn, this allows us to study the impact different types of attacks have, and how these can be reduced.

03

Trustworthy automated systems

Technical guarantees do not by themselves determine whether an automated system is desirable or fair. The choices made when designing, evaluating, and deploying such systems can have consequences that are not captured by the technical formulation of a problem. I therefore also study the ethical assumptions and values embedded in machine learning and automated decision-making. This includes work on competing approaches to ethical evaluation and on how research communities decide which properties of machine learning systems are considered important. My goal is not to separate technical and ethical questions, but to make the connections between them more visible: which assumptions are made, which trade-offs are accepted, and who may be affected by them.