New project to safeguard AI systems used in scientific research
As artificial intelligence becomes central to scientific discovery, researchers face a growing but often overlooked risk: the AI models, datasets, and automated systems they depend on can be compromised in ways that conventional cybersecurity tools are not designed to detect.
A new project called VERITAS (VERified Infrastructure for Trustworthy AI in Science), led by principal investigator Anita Nikolich, research scientist and director of research and technology innovation at the University of Illinois School of Information Sciences, will address this gap by establishing AI Assurance as a core function of scientific research infrastructure. Funded through a three-year, $896,000 grant from the National Science Foundation's Cybersecurity Innovation for Cyberinfrastructure program, VERITAS brings together experts in adversarial AI, research cyberinfrastructure, data science, and workforce development. The project aims to develop practical methods for documenting, reviewing, and stress-testing AI systems before they are used in high-impact scientific workflows.
A blind spot in how science secures AI
Traditional cybersecurity focuses on preventing unauthorized access, catching malware, and stopping data theft. AI-enabled research introduces additional risks that may not trigger conventional security alerts.
A poisoned dataset, for example, may appear statistically normal while causing a model to produce unreliable results. A backdoored model downloaded from a public repository may contain no recognizable malware and may operate normally until a particular input activates its hidden behavior. An autonomous AI agent may have excessive permissions that allow it to alter data, invoke laboratory tools, or manipulate a research workflow.
In each case, the infrastructure may appear secure while the scientific result is compromised.
"We cannot simply bolt traditional cybersecurity onto AI-driven science," said Nikolich. "When a poisoned dataset or backdoored model produces an answer that looks plausible but is subtly wrong, no firewall or virus scanner is likely to catch it. The researchers doing our most important scientific work deserve assurance that the AI systems they rely on are documented, tested, and behaving as intended."
According to Nikolich, rather than requiring scientists to become cybersecurity experts or expecting cybersecurity teams to become machine-learning specialists, VERITAS will integrate AI Assurance into the research infrastructure scientists already use. The project has three connected components:
Model and data documentation. VERITAS will pilot standardized model cards and dataset datasheets for large scientific computing allocations. Similar to nutrition labels on packaged food, these documents describe where a model or dataset came from, how it was created or modified, its intended use, its known limitations, and the assumptions researchers should understand before reusing it. The goal is to improve transparency, reproducibility, and the ability to trace problems through complex AI workflows.
Operational AI security services. VERITAS will pilot a new AI Assurance Engineer role at the National Center for Supercomputing Applications (NCSA). The engineer will review selected technically novel AI projects before deployment, scan model files for unsafe or malicious behavior, examine software for vulnerabilities, and assess the risks around uses of autonomous agents.
Model and data integrity challenges. Through the National Data Platform (NDP) Education Hub, VERITAS will create hands-on challenges that train students to detect poisoned data, inspect potentially compromised models, evaluate agent permissions, and identify weaknesses in scientific AI workflows.
Finding vulnerabilities before they become scientific failures
AI red-teaming—deliberately attacking an AI system to find its weaknesses before an adversary does—is now a well-established field. It has rarely been brought into scientific research, where a manipulated model produces a false result that can pass for legitimate science. VERITAS is among the first efforts to adapt the practice to scientific cyberinfrastructure.
"AI systems can fail in ways that are difficult to distinguish from legitimate scientific results," said Nikolich. "Proactive red teaming allows us to identify those weaknesses before a vulnerable model or agent becomes embedded in a research pipeline. The objective is to help research teams make their systems more trustworthy and resilient."
Building the AI Assurance workforce
VERITAS will also help prepare students for careers at the intersection of machine learning, cybersecurity, and scientific computing. Participants in the project's challenges will work with realistic scientific models, datasets, and infrastructure using NDP while learning about responsible disclosure practices.
By embedding documentation, security review, adversarial assessment, and workforce development into existing scientific cyberinfrastructure, VERITAS seeks to create a model for AI Assurance that can be adopted by supercomputing centers, research institutions, and national-scale AI infrastructure providers.
"AI is now part of the scientific workflow," Nikolich said. "We need to protect its integrity just as seriously as we protect the networks and computing systems around it."
AI model advances scientific discovery with soil carbon research
Cornell University
ITHACA, N.Y. – A new computer model from Cornell University researchers is one of the first artificial intelligence tools to advance scientific discovery in agriculture and biogeochemistry and is 50 times more efficient than its predecessors.
In a paper published in the journal Geoscientific Model Development, the researchers demonstrated the AI on processes behind the important issue of soil organic carbon, as the Earth’s soils hold roughly three-quarters of the world’s terrestrial carbon and more carbon than the atmosphere and all the world’s plants combined.
Scientists have been exploring ways to use AI for research purposes, but most common AI tools, such as ChatGPT, mainly repurpose existing information. Researchers have also used AI to extract patterns from data. But the new model, called the Biogeochemistry-Informed Neural Network (BINN) goes a step further by predicting biological processes that are not yet well understood and suggesting factors that control them.
“BINN is very easy to use and can be democratized among the scientific community in various disciplines,” said Yiqi Luo, the senior author of the study. “This is one of the first tools of this type that can promote scientific research with AI.”
Soil scientists know the mechanisms by which soils acquire organic carbon – plants extract and sequester carbon from carbon dioxide to grow, and when those plants die, organic matter from stems, leaves and roots decompose into smaller and smaller bits to become part of the earth. But what is not well known are the speed of these processes and how many such processes are required to break down the litter.
“We use AI and data to tell us quantitatively how fast and how many of these kinds of processes are required,” said Haodi Xu, a doctoral student in Luo’s lab, and co-first author of the study.
When compared to previous models, BINN computed 50 times faster. The accuracy of predictions of quantities of soil organic carbon was found to be very similar to the previous models. But previous models contained spatial biases, meaning that when making predictions across the contiguous U.S., it might favor the data from one area versus another. The researchers found less spatial bias with BINN.
For additional information, read this Cornell Chronicle story.
Cornell University has dedicated television and audio studios available for media interviews.
-30-
Journal
Geoscientific Model Development
AI underwater robots can now track diver stress via exhaled bubbles
University of Minnesota breakthrough marks the first time robotic vision has been used to monitor human respiration rate underwater
image:
During an open-water experiment in the Caribbean Sea off the coast of Barbados, the researcher team tested the autonomous underwater vehicles (AUVs).
view moreCredit: Photo provided by Junaed Sattar
MINNEAPOLIS / ST. PAUL (07/27/2026) - University of Minnesota Twin Cities researchers have developed a first-of-its-kind AI system that allows underwater companion robots to monitor a diver’s health in real-time, simply by "watching" their exhaled bubbles.
Published in The International Journal of Robotics Research, the paper marks the first time robotic vision has been used to estimate a diver’s Human Respiration Rate (HRR).
Scuba diving, particularly in extreme environments, is inherently risky and places humans under intense physical stress — ranging from exhaustion to life-threatening respiratory distress. By tracking the frequency and volume of bubbles exhaled from a diver’s regulator, camera-equipped robots can now detect signs of stress, hyperventilation or exhaustion in real-time.
This non-contact approach solves a long-standing challenge where traditional medical sensors and wearables often fail underwater because thick wetsuits or drysuits block the contact needed for accurate readings. Wireless data transmission through water is also severely limited.
“Our goal was to give divers a dedicated robotic safety partner to provide a second set of ‘eyes’ capable of reading physiological stress underwater,” said Junaed Sattar, Associate Professor in the Department of Computer Science and Engineering and senior author on the paper. “This work is a first step towards assessing not just one but a group of divers in the robot's field of view.”
To train the AI model, the research team developed a "fuzzy labeling" system. Because underwater footage can be murky, they manually categorized thousands of images while using synchronized audio cues made up of the distinct sound of regulator exhalations to teach the robot exactly what a breath looks like.
“While monitoring breathing is a standard vital sign on land, doing so underwater presents immense technical challenges,” said Demetrious Kutzke, a Ph.D. student in the Robotics & Vision Laboratory at the University of Minnesota and the study’s lead author.
To meet these challenges, the team compiled an extensive dataset of audio and visual recordings from various environments to ensure the AUV could operate in different water temperatures and levels of clarity. Data collection spanned locations from Lake Superior in Duluth, Minn. and Square Lake in Stillwater, Minn., to the Caribbean Sea off the coast of Barbados.
At the core of the field trials was a communication system called HREyes, where the robot could notify its human dive partner of their status, categorizing their breathing as "below-normal" (<14 breaths/min), "normal" (14–20 breaths/min) or "above-normal" (>20 breaths/min). By converting these visual observations into breaths-per-minute, the robot can determine if a diver is under duress.
Looking ahead, the team plans to pair breathing-rate data with the analysis of diver movement. Merging these metrics will provide a comprehensive “wellness profile" to ensure maximum safety during deep-sea explorations.
In addition to Sattar and Kutzke, the research team included Vennela Dupati, undergraduate student in the Department of Computer Science and Engineering and the Department of Electrical and Computer Engineering.
This research was supported in part by the Science, Mathematics, and Research for Transformation (SMART) Scholarship from the U.S. Department of Defense and the National Science Foundation.
Read the full paper entitled, “Robotic estimation of single scuba diver respiration rate for safety in underwater human-robot collaboration,” on the Sage Journal’s website.
Aerial perspective of the field evaluation setup.
Credit
Junaed Sattar
Journal
The International Journal of Robotics Research
Article Title
Robotic estimation of single scuba diver respiration rate for safety in underwater human-robot collaboration

No comments:
Post a Comment