Cyber Security Research Topics & Ideas
Here are 50 research question ideas in cybersecurity, each paired with a real dissertation or thesis on something similar.
By Derek Jansen (MBA) · Reviewed by Eunice Rautenbach (DTech)
Updated
- 01
Which adversarial attacks still work on a large language model that has been aligned?
- 02
How does a deep network fail once it leaves the benchmark it was tested on?
- 03
Could a signal classifier be made robust without losing the accuracy it was built for?
- 04
Should a security team trust a model whose decisions nobody can interpret?
- 05
How much compute does privacy cost when several parties train one network together?
- 06
How ready is a power utility for ransomware, measured rather than self-reported?
- 07
Can overlapping cybersecurity standards be reconciled automatically rather than by committee?
- 08
How did the internet become a place where states fight one another?
- 09
How does a state claim sovereignty over a domain it cannot physically hold?
- 10
What regulation actually changes a firm's security spending rather than its paperwork?
- 11
How much leakage does an encrypted database give up through the queries run against it?
- 12
What can an attacker infer from order-preserving encryption, and can that be closed off?
- 13
Could a quantum scheme lease out a decryption key and reliably take it back?
A sample dissertation
Collusion-Resistant Quantum Key Leasing Nikhil Pappu · Portland State University · 2026 - 14
Does the charging-line side channel on a smartphone survive an attempt to reproduce it?
- 15
What does an attacker gain by trading memory for time against a cryptographic primitive?
A sample dissertation
Time-Space Trade-Offs in Cryptographic Primitives Akshima · University of Chicago · 2022
- 16
How would you detect a trojan in a sensor your organization did not manufacture?
- 17
What would a computer look like if it were designed to make a backdoor impossible?
- 18
Which countermeasures against power side channels introduce vulnerabilities of their own?
- 19
Will a vehicle ever run its own intrusion detection on the hardware already inside it?
- 20
How much location privacy can an app give a user that the platform underneath does not?
- 21
How do you find malware that exists only in memory, on a platform the usual tools cannot image?
- 22
How fast does an Android malware classifier go stale, and can it notice on its own?
- 23
Can you tell an attack from ordinary administration when both use the same built-in binaries?
- 24
Can a small language model run a useful penetration test on consumer hardware?
- 25
What does internet-wide scanning tell a defender that their own logs cannot?
- 26
Is zero trust network access measurably safer than a VPN, or only newer?
- 27
Can a detector trained on known attacks classify one it has never seen on a medical device?
- 28
Can synthetic network traffic stand in for the real thing when the real thing cannot be shared?
- 29
What forensic trace does an attack on a software-defined control plane leave behind?
- 30
Can an agent learn to defend a network by repeatedly attacking itself?
- 31
Will a phishing detector's explanation ever be good enough for an analyst to act on?
- 32
Which nudge actually stops someone tapping a link in a text message?
- 33
What should an organization do in the hour after a phishing email is detected?
- 34
Can anomalies in a voter registration file be told apart from ordinary data entry error?
- 35
Is the way you move a mouse distinctive enough to authenticate you?
- 36
Does a differentially private system leak through how long it takes to answer?
- 37
Do people judge the same data collection differently in a room and on a screen?
- 38
Why do students say they care about privacy and then hand it over anyway?
- 39
How would you estimate what a system gives away when you cannot model it exactly?
- 40
What does a privacy-preserving pipeline cost a language model in accuracy?
- 41
Which cybersecurity model actually fits a school district with no budget for one?
- 42
Do staff-facing policies say the same thing across the campuses of one university?
- 43
What would actually close the cybersecurity workforce gap, and who has to move first?
- 44
Does the way cybersecurity education is delivered explain who ends up in the field?
- 45
How should an organization govern the risk of an AI system it did not build?
- 46
Where are the real gaps in a software supply chain, as opposed to the ones tools check?
- 47
Does a multiparty computation stay fair when one participant walks away halfway through?
- 48
How do you let a voter spoil a ballot without making the choice traceable?
- 49
Could a person carry a device that defends their privacy from the sensors around them?
A sample dissertation
Machine-Augmented Humans As a Privacy Armor Yuxin Chen · University of Chicago · 2022 - 50
Which privacy attacks become practical only once the attacker has a model to work with?
Need a helping hand?
Book a free 15-minute chat and talk it through with a doctoral-qualified Grad Coach® who’s been through the topic ideation process hundreds of times.
15-minute chat. No cost. No pressure.







