Chalmers tekniska högskola AB

10/07/2026 | News release | Distributed by Public on 10/07/2026 02:36

Andrei Sabelfeld gives this year’s William Chalmers Lecture

Image 1 of 1
Andrei Sabelfeld is this year's William Chalmers Lecturer

From banking and healthcare to the power grid and our cars, almost everything we do today runs on software. At the same time, cyberattacks have become an industry, and advances in AI are creating entirely new security challenges. This year's William Chalmers Lecturer, Andrei Sabelfeld, researches how we can build security into digital systems from the start and stay one step ahead of the attackers.

Andrei Sabelfeld is Professor of Cybersecurity at Chalmers, with an extensive track record of research on making software and digital systems more secure. On Thursday 12 November he will give this year's William Chalmers Lecture, entitled "Can we stay one step ahead of hackers? Secure code, secure AI and a safer future".

It is easy to see why these questions matter more and more. Digital systems now underpin both everyday life and critical infrastructure, and attackers are constantly looking for new ways in.

"An attacker only needs to find a single weakness, while the defender has to close every one of them," says Andrei Sabelfeld.

Building security in from the start

For Andrei Sabelfeld and his research group, cybersecurity is not about creating systems that can never be attacked. The aim is to make it far harder for attackers to succeed, by writing software in a way that rules out whole categories of attack.

"Instead of chasing one vulnerability at a time, we want to build software so that entire classes of attacks stop working. Think of the difference between patching each leak in a house as it appears and designing the house so that the most common leaks cannot occur in the first place."

A key part of the research is controlling how information is allowed to flow within a program, for example so that users' data only goes where they have permitted it to go.

Much of the group's work focuses on web security: browsers, web services and browser extensions. Andrei Sabelfeld explains that the group has exposed campaigns of malicious browser extensions, with millions of users, that quietly hijacked search results or stole data. They have also found vulnerabilities in major web services and helped get them fixed.

"There is no such thing as 100% security. It is about raising the bar for the attacker, and our aim is to raise it substantially and for the long term."

AI brings new security challenges

Part of the research now targets a fast-growing challenge: AI agents. Unlike an AI service that just answers questions, an AI agent can be given the power to act on the user's behalf, such as reading emails, booking trips or making payments.

That brings new risks. An AI agent might, for instance, come across hidden instructions on a web page or in an email and be tricked into doing something the user never intended. Andrei Sabelfeld's group therefore works on secure integration of AI into software and services. The research builds on the idea that an agent should only have access to what it needs for the task, and that information should only go where it is allowed to. Even if the agent is tricked, it then cannot do more than it is actually authorised to do.

"The advances in AI are amazing, but we are now starting to give AI assistants access to our email, our accounts and our money, and letting them act for us. The question is what happens when someone tricks the assistant. AI is only as good as its security. Our call is to build security in from the start rather than patch it on afterwards."

How secure code, AI and the digital systems of the future fit together is the theme of Andrei Sabelfeld's William Chalmers Lecture. He will show how real cyberattacks work, but is careful not to paint too dark a picture.

"There is no need to panic. A simple shift in mindset goes a long way towards staying safer online."

He also wants to show what research can do to meet the new threats.

"Chalmers has world-class security research that goes all the way from fundamental theory to practice: vulnerabilities fixed, users protected, and now more secure AI. That is how we can stay one step ahead of the hackers: by building security in from the start, in the code and in the AI systems."

"A great honour"

The William Chalmers Lecture is a public lecture that Chalmers has held since 1991 in memory of William Chalmers. It is arranged together with the Chalmers Student Union and Chalmersska Ingenjörsföreningen (the Chalmers alumni association) and is given by a distinguished professor who looks back on their field and ahead to where it is going. The lecture is open to everyone.

For Andrei Sabelfeld, the appointment is also recognition of the security research that Chalmers has built up over many years.

"It is a great honour, and a joy that I share with my research group and my colleagues. Chalmers has been building up its security research for more than thirty years, and it means a great deal to see it highlighted like this."

He is especially pleased that the lecture reaches well beyond the research community.

"The best thing about the lecture is that it is for everyone, not only researchers. Cybersecurity affects us all, and I look forward to discussing what we do in a way that everyone can relate to."

About the lecture

The William Chalmers Lecture takes place on Thursday 12 November, 18:00-19:00, in the Runan hall at the Chalmers Student Union building. The lecture is open to everyone and will be given in Swedish under the title "Kan vi ligga steget före hackarna? Säker kod, säker AI och säkrare framtid" ("Can we stay one step ahead of hackers? Secure code, secure AI and a safer future").

Refreshments will be served from 19:10 in the Volvo foyer outside Runan.

Register to the event

Updated 7 October 2026, 08:31Published 7 October 2026, 10:20
Leave feedback
Chalmers tekniska högskola AB published this content on October 07, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on October 07, 2026 at 08:37 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]