VERITAS, a new project led from the University of Illinois, will pilot ways to make AI assurance an integral part of scientific computing after receiving a three‑year, US$896,000 grant from the U.S. National Science Foundation.
Why existing defences fall short
Researchers and research infrastructure managers increasingly rely on machine‑learning models, large datasets and automated systems. The VERITAS team argues that conventional cybersecurity tools — firewalls, scanners and antiviruses — are poorly suited to spotting the kinds of subtle, domain‑specific manipulations that can compromise scientific AI. A poisoned dataset or a backdoored model can produce plausible‑looking results that are nevertheless wrong in ways that matter for research reproducibility and safety.
“When a poisoned dataset or backdoored model produces an answer that looks plausible but is subtly wrong, no firewall or virus scanner is likely to catch it. The researchers doing our most important scientific work deserve assurance that the AI systems they rely on are documented, tested, and behaving as intended.”
The comment is from Anita Nikolich, who is leading the VERITAS effort as director of research and technology innovation at the University of Illinois School of Information Sciences.
Three linked strands of work
VERITAS brings together specialists in adversarial AI, research cyberinfrastructure, data science and workforce development. The project is structured around three connected efforts intended to insert AI assurance into the workflows and tools researchers already use:
- Documentation: Piloting standardized model cards and dataset datasheets for large scientific computing allocations, to record provenance, intended use and limitations.
- Operational review: Trialling a new role — an AI Assurance Engineer — to evaluate technically novel AI projects before they are deployed on major computing resources.
- Workforce and tooling integration: Combining expertise and practices so that scientists are supported by assurance processes rather than expected to become security specialists themselves.
Those elements are meant to work together so that AI assurance is built into existing research infrastructure rather than bolted on as an afterthought. Nikolich emphasises that the goal is to enable scientists to rely on documented and tested AI systems without having to become cybersecurity or adversarial‑ML experts.
| Item | Detail |
|---|---|
| Funding | US$896,000 from the NSF Cybersecurity Innovation for Cyberinfrastructure programme |
| Duration | Three years |
| Lead institution | University of Illinois School of Information Sciences |
Implications for research integrity and operations
If successful, VERITAS could change how large computing centres and research groups manage AI projects. Standardized documentation — model cards and datasheets — would make it easier to trace where a model or dataset came from and to spot unexpected modifications. An operational reviewer with a mandate to scan model files and check software could catch anomalous behaviours before models are run at scale. Taken together, these steps aim to reduce the risk that undetected manipulations lead to flawed scientific conclusions.
VERITAS also reflects a broader recognition that the threats posed by adversarial interventions in AI are not solely technical problems for cybersecurity teams. The project envisions a division of labour: infrastructure and assurance practices should be embedded into research platforms, while scientists continue to focus on discipline‑specific questions, supported by clearer documentation and engineering checks.
Details about pilot sites, evaluation metrics and wider community adoption plans were not released in the announcement. The project will likely be watched closely by supercomputing centres and research offices that allocate large compute time to AI‑driven projects, including those in Canada where institutions face similar challenges around reproducibility, model provenance and infrastructure security.
By making assurance part of the research lifecycle, VERITAS aims to help ensure that AI systems used in science are traceable, tested and transparent, lowering the chance that subtle manipulations will undermine scientific findings.