DevSecMLOps: Security-by-Design for Trustworthy Machine Learning Pipelines
D-27
Doctorate Full Doctorate
- Disciplines
- Other (Computer Sciences)
- Laboratory
- TOULOUSE INSTITUTE FOR INFORMATICS RESEARCH (IRIT) - UMR 5505
- Host institution
- UNIVERSITY OF TOULOUSE
Description
ContextMachine Learning Operations (MLOps) have become essential for managing the lifecycle of ML models, ensuring continuous delivery, automation, and reproducibility. However, security practices have not kept pace. Traditional software security methods (static analysis, dynamic scans, vulnerability assessments) are well established, but ML pipelines face unique risks: adversarial attacks, model poisoning, compromised training data, model drift, injection attacks, as well as privacy and compliance challenges (e.g., protecting personally identifiable information, PII). Current MLOps practices lack integrated, end-to-end security mechanisms, are fragmented, and can hinder the agility promised by MLOps. This has led to the emerging field of DevSecMLOps, which adapts DevSecOps principles to ML systems to combine security with agility.
The core problem is the absence of a unified, systematic approach to embed security-by-design across the entire MLOps pipeline, including:
Explicitly incorporating security requirements from the start,
Continuously monitoring and enforcing them across all pipeline stages,
Adapting to evolving threats without slowing deployment.
Without such an approach, AI systems risk being performant but fragile, exposing organizations to critical security and privacy breaches.
Objectives
The PhD will investigate foundational and practical mechanisms of DevSecMLOps, focusing on data privacy and model robustness. Key objectives include:
Integrate security requirements directly into ML workflows, anticipating and mitigating threats such as data poisoning, adversarial manipulation, and privacy leakage.
Explore AI-driven automation for continuous security checks, adversarial testing, and anomaly detection, balancing security rigor with delivery agility.
Develop a methodological and technical framework operationalizing security for ML pipelines, enabling organizations to deploy AI systems that are both performant and trustworthy.
Mission of the PhD candidate
The candidate will:
Conduct a comprehensive study of vulnerabilities across the ML lifecycle and analyze current MLOps practices,
Examine how DevSecOps principles can be extended to ML workflows,
Design security-by-design mechanisms covering all stages (data ingestion, preprocessing, model training, deployment),
Explore ML-based automation for security checks and adversarial testing,
Validate proposed solutions through industrial case studies (Softeam Group), assessing effectiveness in mitigating threats while maintaining reproducibility and delivery speed.
Skills required
The call is open to master's students or professionals; master's students seeking a 6-month internship with the intention of pursuing a PhD are also invited to apply.Bibliography
[1] X. Zhang, Conceptualizing, Applying and Evaluating SecMLOps: A Paradigm for Embedding Security into the ML Lifecycle, Carleton University, 2025. Accessed: Sept. 08, 2025. [Online]. Available: https://hdl.handle.net/20.500.14718/43535[2] B. Eken, S. Pallewatta, N. Tran, A. Tosun, and M. A. Babar, A Multivocal Review of MLOps Practices, Challenges and Open Issues, ACM Comput. Surv., July 2025, doi: 10.1145/3747346.
[3] Hinder, F., Vaquet, V., & Hammer, B. Adversarial Attacks for Drift Detection. 2024. Accessed: Sept. 08, 2025. [Online]. Available: https://arxiv.org/html/2411.16591v1
[4] S. Panchumarthi, DevSecMLOps: A Security Framework for Machine Learning Pipelines, Authorea Preprints. Accessed: Sept. 07, 2025. [Online]. Available: https://www.authorea.com/doi/full/10.36227/techrxiv.175037181.12992346?commit=6b759b374daa544b9579f507221f2da101c2a9f4
[5] Enoiu, E. P., Truscan, D., Sadovykh, A., & Mallouli, W. (2023, August). VeriDevOps software methodology: security verification and validation for DevOps practices. In Proceedings of the 18th International Conference on Availability, Reliability and Security (pp. 1-9).
[6] Nigmatullin, I., Sadovykh, A., Messe, N., Ebersold, S., & Bruel, J. M. (2022, April). RQCODETowards Object-Oriented Requirements in the Software Security Domain. In IEEE International Conference on Software Testing, Verification and Validation Workshops (ICSTW 2022) (pp. 2-6). IEEE.
Keywords
MLOps, software engineering, cybersecurityFunded offer
Dates
Application deadline 21/09/26
Duration36 months
Start date01/10/26
Creation date22/09/25
Languages
Level of french requiredB2 (upper-intermediate)
Level of English requiredB2 (upper-intermediate)
Miscellaneous
Annual tuition fee400 € / year
Contacts
You must connect to be able to display the contacts.
