National Science Foundation funds University of Illinois project to secure artificial intelligence in scientific research

VERITAS won an $896,000 NSF grant to protect scientific computing from poisoned AI models. It uses red-teaming and documentation to catch threats bypassing normal firewalls.

Categorized in: AI News Science and Research
Published on: Jul 30, 2026
National Science Foundation funds University of Illinois project to secure artificial intelligence in scientific research

A University of Illinois-led initiative called VERITAS has landed an $896,000 grant from the National Science Foundation to build AI assurance into the computing infrastructure scientists rely on for research. The three-year project addresses a gap conventional cybersecurity cannot touch: AI models and datasets that have been poisoned, backdoored, or manipulated in ways no firewall will catch.

"We cannot simply bolt traditional cybersecurity onto AI-driven science," said Anita Nikolich, research scientist and director of research and technology innovation at the University of Illinois School of Information Sciences, who leads the project. "When a poisoned dataset or backdoored model produces an answer that looks plausible but is subtly wrong, no firewall or virus scanner is likely to catch it."

Researchers, she said, deserve assurance that the AI systems they use are documented, tested, and behaving as intended. VERITAS is designed to fold that assurance into existing research infrastructure, so scientists do not need to become cybersecurity specialists and security teams do not need to become machine-learning experts.

Standardized documentation for models and datasets

The project's first connected effort is documentation. VERITAS will pilot standardized model cards and dataset datasheets for large scientific computing allocations. These records detail where a model or dataset originated, how it was built or modified, its intended use, and its limitations. The documentation creates a clear trail, making it possible to trace problems back through a workflow when something goes wrong.

A new operational role for AI review

The team will place an AI Assurance Engineer within the National Center for Supercomputing Applications. This engineer will review technically novel AI projects before they go live, scanning model files for unsafe or malicious behavior, checking software for vulnerabilities, and evaluating the degree of autonomy granted to agents. The role sits between researchers and existing security infrastructure, applying ML-specific expertise without requiring every scientist to become a security specialist.

Building security awareness through hands-on challenges

Education forms the third component. Through the National Data Platform Education Hub, VERITAS will create interactive challenges that teach students-and by extension, future researchers-how to identify poisoned datasets, inspect suspect models, evaluate agent permissions, and locate weak points in scientific AI pipelines. Participants will work with real scientific models and datasets, gaining practical experience in AI assurance techniques. For working scientists looking to build these skills directly, the AI Learning Path for Research Scientists offers structured training in evaluating AI systems.

Bringing red-teaming into the research lab

AI red-teaming-deliberately probing systems to expose weaknesses-is familiar in industry but rarely applied to scientific computing. Compromised models or datasets can warp research results long before anyone notices. "AI systems can fail in ways that are difficult to distinguish from legitimate scientific results," said Nikolich. "Proactive red teaming allows us to identify those weaknesses before a vulnerable model or agent becomes embedded in a research pipeline." VERITAS aims to make this practice a standard part of research infrastructure, helping teams strengthen their systems before deployment.

Why this matters for science and research professionals

For working scientists, VERITAS signals a shift toward making AI safety an integrated feature of the tools they use, not an extra step they must manage. The model cards, assurance reviews, and educational challenges all work to catch problems early and provide transparency, so researchers can trust the outputs they build upon. If the approach succeeds, AI assurance could become as routine a part of research cyberinfrastructure as network monitoring. Staying informed about developments in AI for Science & Research will help professionals track how these infrastructure changes affect their daily work.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)