Lucas Bourtoule

Senior Security Engineer

Experience

Trail of Bits Sep 2023 – Present
Senior Security Engineer — ML Assurance
Remote
  • Conduct ML Assurance security audits for clients, assessing the security of systems that integrate AI — from model deployment to tool use and external service interactions.
  • Published research on isolation failures in agentic browsers, showing how lack of trust-zone separation resurfaces decades-old web vulnerabilities in AI agents.
  • Lead the Model Inspector project within the R&E team: a tool for generating AI bill-of-materials and detecting vulnerabilities through the analysis of these AIBOMs. I authored the initial proposal that ranked 4th at the U.S. Army’s xTech Scalable AI competition, and was awarded a $2M SBIR contract.
Mithril Security Jun 2022 – Sep 2023
Startup developing data privacy solutions for AI.
Head of R&D
Paris, France (remote)
  • Managed a five-engineer R&D team: project planning, HR follow-up, and technical guidance.
  • Defined the technical roadmap in close collaboration with the CEO and CTO.
Cybersecurity Software Engineer
  • Designed a TEE-based solution to train AI models on the cloud with private data from several providers.
  • Built data privacy and intellectual property solutions using confidential computing, differential privacy, federated learning, and adversarial machine learning.
TotalEnergies Sep 2021 – Jun 2022
Data Engineer
Pau, France
  • Designed AI modules for document classification, deduplication, named entity extraction, and layout analysis.
  • Deployed and maintained AI tooling: annotation platforms, resource management, web services, and databases.
  • Industrialized data science pipelines for production: containerization, orchestration, cloud migration, and highly parallel computations on an HPC supercomputer.
CleverHans Lab Sep 2019 – Sep 2021
Research Assistant
Toronto, Canada
  • Co-authored SISA, a technique that improves unlearning time by up to 4.63× with the strongest privacy guarantees, to facilitate compliance with data regulations.
  • Participated in DARPA’s Guaranteeing AI Robustness Against Deception (GARD) project: presented at a conference in Washington DC and researched the security of audio pipelines.
  • Maintained CleverHans, a widely used library of attacks against Machine Learning systems.
Ministry of the Armed Forces May 2019 – Jul 2019
Data Scientist (internship)
Lyon, France
  • Built an automated pipeline for classifying social media text data: collected and annotated a dataset, trained and evaluated ML classifiers.

Education

MASc. Electrical and Computer Engineering
Toronto, Canada
École Centrale de Lyon 2017 – 2021
Diplôme d’Ingénieur
Lyon, France
  • Second year project: Deep-Learning Embedding Techniques Applied to Natural Language Processing.

Publications

L. Bourtoule. Lack of Isolation in Agentic Browsers Resurfaces Old Vulnerabilities. Trail of Bits Blog, 2026.

T. Afonja, L. Bourtoule, V. Chandrasekaran, S. Oore, and N. Papernot. Generative Extraction of Audio Classifiers for Speaker Identification. arXiv:2207.12816, 2022.

L. Bourtoule. Model Extraction in the Context of Audio Classifiers. MASc thesis, University of Toronto, 2021.

L. Bourtoule, V. Chandrasekaran, C. Choquette-Choo, H. Jia, A. Travers, B. Zhang, D. Lie, and N. Papernot. Machine Unlearning. In Proceedings of the 42nd IEEE Symposium on Security and Privacy, San Francisco, CA, 2021.

Skills

ML Tools
PyTorch Jax scikit-learn Pandas Polars Dask
Programming
Python Rust JavaScript Haskell C / C++
Infrastructure
Linux Docker CI/CD SQL
Security
Threat Modeling ML Security Auditing ML Supply Chain Confidential Computing (SGX, SEV, Nitro)
AI / ML
Deep Learning NLP Computer Vision Adversarial ML Agents

Languages