Background Pattern

Behind the PhD: Nemania Borovits on privacy engineering

Posted on

Most organizations tell you they take privacy seriously, but demonstrating it is much harder. That gap between intention and proof became the focus of Nemania Borovits’ PhD research. As data systems grow more complex and AI becomes part of everyday operations, organizations need ways to show that personal data is collected, used, and protected as intended.

His research covers topics ranging from data minimization and synthetic data to federated learning and decentralized data governance. The common thread is privacy engineering: turning privacy from a principle into something that can be built, measured, and audited.

Ahead of his PhD defense, we spoke with Nemania about finding societal value in technical research, working at the intersection of academia and industry, and why communication and collaboration proved as important to his PhD as the technology itself.

Why did you choose this research subject and what makes it so fascinating?

The most fascinating aspects of my PhD are its domain and setup. With a background in Computer Science (BSc), Data Science (MSc) and 5 years of experience in the industry as a software engineer, if I were to pursue a PhD degree, I wanted it to have societal relevance. In the era of AI, I wanted my research to contribute to an aspect where its societal utility was evident. So, the domain of privacy and its engineering within contemporary software systems with the goal of societal utility, was one of the reasons.

An equally important factor for choosing the subject was the application setup, namely the collaboration between JADS and KPN materialized within the ICAI responsible AI Lab:
1. Contributing to the research domain with high popularity (AI in contemporary software systems),
2. Having societal relevance by design (Privacy being the heart of the research),
3. Creating tangible impact with software solutions validated under a contemporary industrial environment (KPN).
This combination of academic novelty and real-world value is what I found most compelling.

Which challenges did you meet along the way and how did you overcome them?

The challenges I faced fell into two main categories. The first was privacy itself. Though not new as a field, it remains an emerging one, and it has drawn growing attention with the introduction of legal frameworks such as the GDPR. Finding novelty in an emerging domain is not easy, since there are few prior results to build on. I navigated this by combining the structure these frameworks provide with the established methods of software engineering and AI. That pairing produced new theory and tools for privacy engineering.

The second was the collaboration between academia and industry. A research setting and an operational approach work through different processes, so on paper, aligning them seemed not straightforward. In practice, it proved otherwise. Both sides were committed to the success of the research, and with that established, the only remaining question was how to achieve it, which we resolved together.

In both cases, the difference came down to two principles: communication and collaboration, which I consider important for any challenge. Here, I credit my supervisors and my colleagues at KPN. Whatever came up was readily worked out by discussing it with them directly, and their experience consistently led us to a solution. A PhD may seem solitary, but its success fundamentally depends on communication and collaboration. I am deeply indebted to my supervisors and colleagues at KPN for keeping the goal in focus and working through the means with me.

What is the impact of your work in the real world?

The impact of my work is twofold, regarding both scholars and practitioners. From a theoretical perspective, my work contributes to a better understanding of the privacy engineering domain and its dimensions, highlighting gaps and underrepresented areas. Two novel contributions concern the introduction of privacy into decentralized data governance paradigms and the evaluation of two fundamental GDPR principles within contemporary software systems. From a practical perspective, my work delivers three software solutions, two of which stem directly from the collaboration with KPN, grounding them in genuine real-world operational conditions. One of these, a novel solution for synthetic data validation and evaluation, goes beyond novelty to offer real relevance and an architecture that is extensible to fast-growing areas of interest such as Agentic systems.

These outputs address real-world challenges faced by the scholarly software community and by practitioners in the industry alike, showing how privacy can be effectively engineered in contemporary software systems under real operational conditions.

What are your plans after your PhD?

I would like to continue building software solutions with both societal relevance and industrial impact. There are several follow-ups to my research already in motion. In particular, I am excited that our collaboration with KPN continues through the project LUCID, which focuses on text anonymization. In addition, a recently accepted EU-funded project MIDAS, in which our lab at JADS participates, has a significant part of its motivation and goals directly related to follow-up work from my research.

Group 5
Group 6
Group 7
JADS