Back to search
Listing unavailableEngineeringRemote

Research Engineer - Decentralized Training and Inference Verification

Pluralis Research · Remote

This listing is no longer verified as available.

MeritLog keeps this source-backed description for reference. Availability is not verified, and there is no application link here.

Last seen by MeritLog September 10, 2026Source: AshbySource version: ashby-public-job-posting-v1

Source: the employer's Ashby job board. Open the original listing for current details. Availability is not verified for this retained page.

Job details

Work model
Remote
Salary
Not listed by source
Location
USA or Australia

What the role asks for

What you'd do

  • Own the threat model: You enumerate what a malicious or careless worker can do across pre-training, post-training, and inference - training disruption and denial-of-service, free-riding, model poisoning and backdoors, data extraction from gradients and activations, reputation and reward manipulation - and you keep that model current as the network grows.
  • Design and calibrate the tests: You build statistical verification methods with stated error rates, tune them with rigorous benchmarks, and keep false positives and false negatives controlled across heterogeneous hardware, including different GPUs and Macs.
  • Ship the verifier: You build and run the verification service in the inference path, and you live with its mistakes.
  • Verification systems, shipped or published: You've built a calibrated statistical decision system with stated error rates and lived with its mistakes. Publications in inference and training verification count; fraud detection, anti-cheat, and experimentation platforms count as much as papers do.
  • Statistical depth: Deep expertise in statistics and probability, with the ability to design experiments, calibrate decision thresholds, and defend the error rates you claim.
  • Technical background: You know the solution space for verifying untrusted compute, from statistical testing to re-execution, cryptographic proofs, and trusted hardware, and you can argue what fits a permissionless network and what doesn't.
  • Mission alignment: You believe Protocol Learning is the viable third path for collective, trustless, and sovereign AI.

What they're asking for

  • Familiarity with large scale Pre-training and RL post-training.SkillPreferred
  • Familiarity with decentralized ML security and adversarial threat models, such as poisoning, Sybil, collusion, and replay.SkillPreferred
  • Experience at proprietary, open-weight and open-source AI labsSkillPreferred

Parsed by MeritLog from the employer’s own posting. The full description follows below.

Job description

Pluralis Research works on Protocol Learning: training and serving large models in a fully decentralized way on small consumer-grade devices connected via the internet. Despite being dismissed as infeasible, we have made significant advances on this problem, most recently Agora, a permissionless run that pretrained an 8B model from scratch on consumer GPUs spread over the internet, with no single participant ever holding the full weights (tech report https://arxiv.org/abs/2607.13332). While many of the core research problems have been solved, Protocol Learning unlocks a series of new challenges. For the mission in full, read A Third Path: Protocol Learning https://pluralis.ai/blog/a-third-path-protocol-learning/. Our training and inference network is trustless, and the workers are GPUs scattered across the world. Many things can go wrong in this system. An inference worker can return tokens from a cheaper model, or a highly quantized version of the one it's supposed to run. Even with the right model, it can sample with the wrong parameters. Training faces its own attacks, and Agora showed what a permissionless run deals with in practice: participants who disrupt training by dropping updates or flooding the system, free-riders who submit trivial work and collect the rewards, poisoned updates that plant backdoors, attempts to extract private data from gradients and activations, and contributors who inflate their reported work to claim rewards they didn't earn. Sentinel https://arxiv.org/abs/2603.03592 is our first published answer on the training side. Your primary role is to come up with efficient algorithms and systems that verify the work: that tokens came from the claimed model and sampling parameters, and that training contributions are what they claim to be. KEY RESPONSIBILITIES - Own the threat model: You enumerate what a malicious or careless worker can do across pre-training, post-training, and inference - training disruption and denial-of-service, free-riding, model poisoning and backdoors, data extraction from gradients and activations, reputation and reward manipulation - and you keep that model current as the network grows. - Design and calibrate the tests: You build statistical verification methods with stated error rates, tune them with rigorous benchmarks, and keep false positives and false negatives controlled across heterogeneous hardware, including different GPUs and Macs. - Ship the verifier: You build and run the verification service in the inference path, and you live with its mistakes. WHAT WE'RE LOOKING FOR - Verification systems, shipped or published: You've built a calibrated statistical decision system with stated error rates and lived with its mistakes. Publications in inference and training verification count; fraud detection, anti-cheat, and experimentation platforms count as much as papers do. - Statistical depth: Deep expertise in statistics and probability, with the ability to design experiments, calibrate decision thresholds, and defend the error rates you claim. - Technical background: You know the solution space for verifying untrusted compute, from statistical testing to re-execution, cryptographic proofs, and trusted hardware, and you can argue what fits a permissionless network and what doesn't. - Mission alignment: You believe Protocol Learning is the viable third path for collective, trustless, and sovereign AI. NICE TO HAVE - Familiarity with large scale Pre-training and RL post-training. - Familiarity with decentralized ML security and adversarial threat models, such as poisoning, Sybil, collusion, and replay. - Experience at proprietary, open-weight and open-source AI labs COMPENSATION & BENEFITS - Equity-Heavy Package: We offer significant ownership for key technical contributors in addition to a high base salary. - Remote-First Culture: Flexible work environment with team members distributed globally. - Visa Sponsorship: Optional full visa sponsorship and relocation support to either Australia or the US. - Open Problems: Training and serving frontier models on hardware you don't control, over networks you don't own, mostly has no published answers yet. You'll write some of the first ones. FYI'S - We work remotely across the world, with the main teams in Australia and North America. You'll need to be comfortable working across timezones. - Applicants must have professional-level English proficiency (written and spoken). - Recruiters: we aren't looking for agency support at this time. We'll reach out if we need help. We are backed by Union Square Ventures https://www.usv.com/ and other tier-1 investors, and we are a world-class, deeply technical team of ML researchers. Pluralis is unapologetically ideological. We believe AI, and the world, end up on a better path if we succeed in implementing the protocol for intelligence. If this resonates, please apply.

Keep exploring

Available Engineering roles

These current listings are available to explore now.

Search all jobs

Privacy choices

Analytics and advertising stay off unless you allow them. Private data stays out.

Read the privacy notice