Bessemerstraße 51, First Floor, Berlin 12103, Germany
PhD

AI-Driven Security-by-Design Assistant (PhD)

France University of Toulouse (Laboratory: IRIT / Doctoral school: Toulouse MITT - ED 475)

In modern software development, pressure for rapid delivery often pushes security to the background. Yet, design-level flaws account for more than half of reported vulnerabilities, leading to costly fixes and major breaches. The Security-by-Design paradigm seeks to address this by embedding security early, during requirements and design. However, this ambition faces several challenges: lack of specialized expertise, absence of systematic methods to refine abstract goals (confidentiality, integrity, availability) into actionable design, and limited tools for engineers without cybersecurity training. Advances in AI, especially NLP and machine learning, open new opportunities to automatically extract and structure security knowledge, and to provide intelligent, interactive support to practitioners.

Research questions:
The key issue is integrating security systematically at the requirements and design phases, while ensuring accessibility for non-expert engineers. This raises several questions:

How can AI extract and organize vulnerable assets from heterogeneous sources (CAPEC, CWE, ATT&CK)?

How to refine high-level security objectives into formal, verifiable design patterns?

How to embed this knowledge in an assistant that offers real-time feedback and recommendations without disrupting agile development?

Objectives:
The PhD will develop the ReqSecDes framework by combining AI-driven extraction and formalization of vulnerable assets with tool-supported assistance bridging requirements and secure design. Expected results:

Automated Vulnerable Asset Library: NLP/ML methods to extract vulnerabilities, threats, mitigations, and structure them in an ontology.

Formal Taxonomy of Security Properties: refinement of security goals into verifiable design patterns, checked with formal methods.

Interactive Security Assistance: algorithms linking system specifications with the asset library, providing real-time, context-aware recommendations in modeling tools.

Validation: industrial case studies to assess vulnerability reduction and usability by non-experts.

Expected contributions
The candidate will:

Survey the state of the art in security requirements engineering, asset-based approaches, and AI/NLP in cybersecurity.

Design and train NLP/ML models to extract and link vulnerable assets.

Develop a formal taxonomy of security properties, verify it, and integrate it into modeling environments.

Implement a prototype of an interactive assistant with real-time reasoning and feedback.

Validate the approach via case studies with industrial partners, measuring effectiveness and adoption.

Skills required

The call is open to master-degree students or professionals ; Master’s students seeking a 6-month internship, with the intention of continuing into a PhD, are also welcome to apply.

Apply for this program

Open the free assessment form for AI-Driven Security-by-Design Assistant (PhD), share your profile, and our counseling team will guide you through the application.