Systems Security

Research in this track covers software and infrastructure-level hardware security mechanisms for monitoring and securing AI development and deployment, including side-channel analysis, cluster security, and physical-layer verification. Importantly, this track is distinct from the broader "AI security" framing that refers to adversarial robustness or jailbreaking; the focus here is on securing the systems that advanced AI runs on, including data centers, hardware supply chains, compute clusters, and model weights.

Application process

  • Stage 1: Complete the general application
  • Stage 2: Stream selection questions alongside possibly reference requests
  • Stage 3: Interviews and work-tests

Systems Security track overview

The track focuses on the hardware, software, and infrastructure that frontier AI systems run on. Even if alignment research succeeds, the safety properties it produces only matter in practice if model weights aren't stolen, training and inference compute can't be tampered with, and the systems running advanced AI can be audited and verified. This track exists to build the technical foundations for that. The streams within this track cover model weight protection, side-channel analysis, secure enclaves, hardware supply chain assurance, data center and cluster security, physical-layer verification of compute use, and the technical components that make compute governance and export controls enforceable.

We are looking for fellows with real depth in systems or security work, and fluency in at least one of these areas: security engineering, vulnerability research, cryptography, operating systems and other low-level software, hardware security (e.g., chips, FPGAs, embedded systems), or systems engineering at the infrastructure layer. ML expertise is preferred but not required. What matters is the ability to reason carefully about adversaries, side channels, and trust boundaries. Strong candidates from past cohorts have come from security teams at tech companies, hardware and chip design, cryptography research, government security work, CTF and vulnerability research backgrounds, and embedded systems engineering.

Fellows are matched to mentors based on fit, and projects produce concrete artifacts (e.g., security audits, technical specifications, prototype defenses, attack demonstrations, or proposals for verification protocols) by the end of the program. Target audiences for the work produced in this track include lab security and infrastructure teams, hardware vendors, and the policy actors who need technical groundwork to enforce compute governance and export controls.

Systems Security track streams

In this project, we will explore GPU side-channel attacks to extract information about model usage. A simple example is to observe (via radio, power fluctuations, acoustics, etc.) which experts were used in each forward pass of an MOE model, then use those observations to guess which tokens were produced.

Read more
Mentorship structure
Desired fellow characteristics
Project selection process

The SL5 Task Force will build out a prototype SL5 datacenter this year together with frontier AI labs. This will be a massive research and engineering project with many avenues for spinning out new organizations and research programs. This project is urgent due to this technology being needed in the next 1 to 2 years.

Read more
Mentorship structure
Desired fellow characteristics

Our stream focuses on AI verification, as in how actors can check that the use of AI compute is compliant with policy, especially for enabling international agreements on AI. This sense of verification is much broader than formal verification.

Read more
Mentorship structure
Desired fellow characteristics
Project selection process

Frequently asked questions

What is the MATS Program?
Who are the MATS Mentors?
What are the key dates of the MATS Program?
Who is eligible to apply?
How does the application and mentor selection process work?