Monday, July 27, 2026

 


New project to safeguard AI systems used in scientific research






University of Illinois School of Information Sciences




As artificial intelligence becomes central to scientific discovery, researchers face a growing but often overlooked risk: the AI models, datasets, and automated systems they depend on can be compromised in ways that conventional cybersecurity tools are not designed to detect.

A new project called VERITAS (VERified Infrastructure for Trustworthy AI in Science), led by principal investigator Anita Nikolich, research scientist and director of research and technology innovation at the University of Illinois School of Information Sciences, will address this gap by establishing AI Assurance as a core function of scientific research infrastructure. Funded through a three-year, $896,000 grant from the National Science Foundation's Cybersecurity Innovation for Cyberinfrastructure program, VERITAS brings together experts in adversarial AI, research cyberinfrastructure, data science, and workforce development. The project aims to develop practical methods for documenting, reviewing, and stress-testing AI systems before they are used in high-impact scientific workflows.

A blind spot in how science secures AI

Traditional cybersecurity focuses on preventing unauthorized access, catching malware, and stopping data theft. AI-enabled research introduces additional risks that may not trigger conventional security alerts.

A poisoned dataset, for example, may appear statistically normal while causing a model to produce unreliable results. A backdoored model downloaded from a public repository may contain no recognizable malware and may operate normally until a particular input activates its hidden behavior. An autonomous AI agent may have excessive permissions that allow it to alter data, invoke laboratory tools, or manipulate a research workflow.

In each case, the infrastructure may appear secure while the scientific result is compromised.

"We cannot simply bolt traditional cybersecurity onto AI-driven science," said Nikolich. "When a poisoned dataset or backdoored model produces an answer that looks plausible but is subtly wrong, no firewall or virus scanner is likely to catch it. The researchers doing our most important scientific work deserve assurance that the AI systems they rely on are documented, tested, and behaving as intended."

According to Nikolich, rather than requiring scientists to become cybersecurity experts or expecting cybersecurity teams to become machine-learning specialists, VERITAS will integrate AI Assurance into the research infrastructure scientists already use. The project has three connected components:

Model and data documentation. VERITAS will pilot standardized model cards and dataset datasheets for large scientific computing allocations. Similar to nutrition labels on packaged food, these documents describe where a model or dataset came from, how it was created or modified, its intended use, its known limitations, and the assumptions researchers should understand before reusing it. The goal is to improve transparency, reproducibility, and the ability to trace problems through complex AI workflows.

Operational AI security services. VERITAS will pilot a new AI Assurance Engineer role at the National Center for Supercomputing Applications (NCSA). The engineer will review selected technically novel AI projects before deployment, scan model files for unsafe or malicious behavior, examine software for vulnerabilities, and assess the risks around uses of autonomous agents. 

Model and data integrity challenges. Through the National Data Platform (NDP) Education Hub, VERITAS will create hands-on challenges that train students to detect poisoned data, inspect potentially compromised models, evaluate agent permissions, and identify weaknesses in scientific AI workflows. 

Finding vulnerabilities before they become scientific failures

AI red-teaming—deliberately attacking an AI system to find its weaknesses before an adversary does—is now a well-established field. It has rarely been brought into scientific research, where a manipulated model produces a false result that can pass for legitimate science. VERITAS is among the first efforts to adapt the practice to scientific cyberinfrastructure. 

"AI systems can fail in ways that are difficult to distinguish from legitimate scientific results," said Nikolich. "Proactive red teaming allows us to identify those weaknesses before a vulnerable model or agent becomes embedded in a research pipeline. The objective is to help research teams make their systems more trustworthy and resilient."

Building the AI Assurance workforce

VERITAS will also help prepare students for careers at the intersection of machine learning, cybersecurity, and scientific computing. Participants in the project's challenges will work with realistic scientific models, datasets, and infrastructure using NDP while learning about responsible disclosure practices.

By embedding documentation, security review, adversarial assessment, and workforce development into existing scientific cyberinfrastructure, VERITAS seeks to create a model for AI Assurance that can be adopted by supercomputing centers, research institutions, and national-scale AI infrastructure providers.

"AI is now part of the scientific workflow," Nikolich said. "We need to protect its integrity just as seriously as we protect the networks and computing systems around it."


AI model advances scientific discovery with soil carbon research




Cornell University




ITHACA, N.Y. – A new computer model from Cornell University researchers is one of the first artificial intelligence tools to advance scientific discovery in agriculture and biogeochemistry and is 50 times more efficient than its predecessors.

In a paper published in the journal Geoscientific Model Development, the researchers demonstrated the AI on processes behind the important issue of soil organic carbon, as the Earth’s soils hold roughly three-quarters of the world’s terrestrial carbon and more carbon than the atmosphere and all the world’s plants combined.

Scientists have been exploring ways to use AI for research purposes, but most common AI tools, such as ChatGPT, mainly repurpose existing information. Researchers have also used AI to extract patterns from data. But the new model, called the Biogeochemistry-Informed Neural Network (BINN) goes a step further by predicting biological processes that are not yet well understood and suggesting factors that control them.

“BINN is very easy to use and can be democratized among the scientific community in various disciplines,” said Yiqi Luo, the senior author of the study. “This is one of the first tools of this type that can promote scientific research with AI.”

Soil scientists know the mechanisms by which soils acquire organic carbon – plants extract and sequester carbon from carbon dioxide to grow, and when those plants die, organic matter from stems, leaves and roots decompose into smaller and smaller bits to become part of the earth. But what is not well known are the speed of these processes and how many such processes are required to break down the litter.

“We use AI and data to tell us quantitatively how fast and how many of these kinds of processes are required,” said Haodi Xu, a doctoral student in Luo’s lab, and co-first author of the study.

When compared to previous models, BINN computed 50 times faster. The accuracy of predictions of quantities of soil organic carbon was found to be very similar to the previous models. But previous models contained spatial biases, meaning that when making predictions across the contiguous U.S., it might favor the data from one area versus another. The researchers found less spatial bias with BINN.

For additional information, read this Cornell Chronicle story.

Cornell University has dedicated television and audio studios available for media interviews.

-30-

 

No comments: