Deadline for receipt of applications: August 14, 2026 23:59 AoE (15 August 2026, 13:59h)
The Cybersecurity (https://networks.imdea.org/es/equipo/grupos-de-investigacion/cybersecurity-group/) and Internet Analytics Groups (https://networks.imdea.org/es/equipo/grupos-de-investigacion/internet-analytics-group/) led by Dr. Guillermo Suarez-Tangil (https://scholar.google.com/citations?hl=en&user=182ZkIgAAAAJ) and Dr. Narseo Vallina-Rodriguez (https://scholar.google.com/citations?hl=en&user=yOlNzfcAAAAJ) at IMDEA Networks Institute have a joint opening for one PhD student in the area of IoT Security and Privacy.
The successful candidate will investigate how apps, websites, and devices collect, share, and synchronize user data across platforms—for example, through identifiers, cookies, fingerprinting, or covert communication channels. The goal is to uncover hidden tracking practices that operate across ecosystems (e.g., mobile, web, IoT, and smart TV environments) and to design scalable analysis and mitigation frameworks.
The research will involve both empirical and methodological contributions:
- Developing automated frameworks to detect and analyze cross-platform data flows using network measurements, static and dynamic app analysis, and large-scale testing infrastructures.
- Studying deterministic and probabilistic tracking mechanisms (e.g., shared identifiers, IP correlation, fingerprinting (see [1]), or behavioral synchronization).
- Investigating how tracking companies and SDKs operate across device and ecosystem boundaries.
- Analyzing the privacy risks associated with the proliferation of Generative AI technologies in browsers, mobile platforms and beyond, as well as emerging platforms such as AR/VR.
- Designing privacy-preserving countermeasures that balance usability, scalability, and effectiveness.
This PhD project offers the opportunity to make fundamental contributions to an emerging research field with high societal, regulatory, and industrial relevance, while working at the intersection of cybersecurity, privacy, data analysis, and network measurement. In fact, the Ph.D. candidate’s contributions will advance our ability to detect and understand how users are tracked across devices, apps, and ecosystems, providing empirical evidence and technical insights to shape privacy engineering and policy at a global scale, with a special focus on the privacy risks of LM-based architectures.
- Full-time paid position for up to 4 years, with competitive salary and benefits.
- Hands-on training in scalable software/firmware analysis and reverse engineering skills, and data analysis.
- A unique opportunity to work in one of the most active research groups in the field of online privacy.
- The opportunity to explore a research problem with massive research, societal and industrial impact (see the new EU Cyber Resilience Act)
- A vibrant, collaborative, multi-cultural and English-speaking research environment.
- A chance to live and work in Madrid, Spain, a cosmopolitan city offering high quality of life, excellent public services, and rich cultural opportunities.
- The expectation to publish in top-tier conferences and journals such as USENIX Security, PETS, NDSS, IMC, WWW or CCS.
- Excellent prospects for a career in academia, research labs, or the privacy-tech industry [11].
- a B.Sc. in Computer Science, Telecommunications Engineering or related field, with a solid academic record. Postgraduate studies (holding a M.Sc. or being currently enrolled in one) will be a plus.
- Data analysis, modeling and applied ML experience is recommended, given the need to identify patterns in large-scale behavioral logs.
- Software reverse engineering (Frida, IDA Pro) experience is recommended, especially in the area of mobile app analysis and JavaScript code analysis.
- [Optional] Experience in LLMs.
- [Optional] Experience in web crawling and JavaScript analysis.
- [Optional] Experience in traffic and protocol analysis.
- [Optional] Experience in mobile app analysis.
- Fluency in written and spoken English,
- Enthusiasm for interdisciplinary research with real-world impact.
IMPORTANT: Please, explicitly select Dr. Suarez-Tangil in your application to better follow up on your application.
Candidates shall submit by the call deadline a CV, a motivation letter, and the contact details of two references through the IMDEA Networks Institute hiring portal, at https://careers.networks.imdea.org/.
Bibliographic References of Relevant Group Research Outputs (See Google Scholar for links to the articles):
[1.] “In the Room Where It Happens: Characterizing Local Communication and Threats in Smart Homes.” A. Girish, T. Hu, V. Prakash, D. J. Dubois, S. Matic, D. Huang, S. Egelman, J. Reardon, J. Tapiador, D. Choffnes, N. Vallina-Rodriguez In Proc. of the 2023 ACM on Internet Measurement Conference, 2023.
[2.] SkillVet: Automated Traceability Analysis of Amazon Alexa Skills. J. Edu, X. Ferrer-Aran, J. Such, G. Suarez-Tangil. IEEE Trans. on Dependable and Secure Computing. 2022.
[3.] “AI in the Gray: Exploring Moderation Policies in Dialogic Large Language Models vs. Human Answers in Controversial Topics.” Vahid Ghafouri, Vibhor Agarwal, Yong Zhang, Nishanth Sastry, Jose Such, Guillermo Suarez-Tangil. 32nd ACM International Conference on Information and Knowledge Management (CIKM).
[4.] Trouble over-the-air: An analysis of FOTA apps in the android ecosystem. Blázquez, E., Pastrana, S., Feal, Á., Gamba, J., Kotzias, P., Vallina-Rodriguez, N., & Tapiador, J. IEEE Symposium on Security and Privacy (SP) 2021
[5.] An Analysis of Pre-installed Android Software. J. Gamba, M. Rashed, A. Razaghpanah, J. Tapiador, N. Vallina-Rodriguez IEEE Symposium on S&P’20 (BEST PRACTICAL PAPER AWARD, AEPD EMILIO ACED AWARD, CNIL-INRIA PRIVACY RESEARCH AWARD)
[6.] Localhost tracking: https://localmess.github.io
[7.] Your Signal, Their Data: An Empirical Privacy Analysis of Wireless-scanning SDKs in Android. Aniketh Girish, Joel Reardon, Juan Tapiador, Srdjan Matic, Narseo Vallina-Rodriguez. PETS Symposium 2025.
[8.] 50 Ways to Leak Your Data: An Exploration of Apps’ Circumvention of the Android Permissions Systems. J. Reardon, A. Feal, P. Wijesekera, A. Elazari Bar On, N. Vallina-Rodriguez, S. Egelman. USENIX Security, 2019 (USENIX’19 DISTINGUISHED PAPER AWARD, CNIL-INRIA PRIVACY RESEARCH AWARD, AEPD EMILIO ACED)
[9.] Apps, Trackers, Privacy, and Regulators: A Global Study of the Mobile Tracking Ecosystem. Abbas Razaghpanah, Rishab Nithyanand, Narseo Vallina-Rodriguez, Srikanth Sundaresan, Mark Allman, Christian Kreibich, Phillipa Gill. NDSS Symposium 2018.
[10.] “Won’t somebody think of the children?” examining COPPA compliance at scale. Irwin Reyes, Primal Wijesekera, Joel Reardon, Amit Elazari Bar On, Abbas Razaghpanah, Narseo Vallina-Rodriguez, Serge Egelman. PETS Symposium 2018. CASPAR BOWDEN PRIVACY RESEARCH AWARD 2020.
[11] https://networks.imdea.org/team/imdea-networks-team/alumni-network
This position could be co-financed by the project “REAL-PETS. Empirical Detection Methods and Privacy-Enhancing Technologies for Real-World Tracking” (Grant Agreement number 101309318), funded by the European Union and the European Cybersecurity Competence Centre through Horizon Europe program call HORIZON-CL3-2025-02-CS-ECCC-03.
IMDEA Networks Institute aims to increase the proportion of women and therefore qualified female applicants are explicitly encouraged to apply. Until a balanced ratio of men and women has been achieved at the institute, preference will be given to women if applicants have similar qualifications. IMDEA Networks Institute actively promotes diversity and equal opportunities. Applicants are not to be discriminated against in personnel selection procedures on the grounds of gender, ethnicity, religion or ideology, age, sexual orientation (anti-discrimination). People with disabilities who have the relevant qualifications are expressly invited to apply
Inquiries on the position can be directed to the thesis supervisor via email, Dr. Guillermo SUAREZ-TANGIL (guillermo.suarez-tangil “at” imdea.org)