- About
- Admissions
- Study at AUS
- Prospective Students
- Bachelor's Degrees
- Master's Degrees
- Doctoral Degrees
- Admission Publications
- International Students
- Contact Admissions
- Grants and Scholarships
- Sponsorship Liaison Services
- Testing Center
- Sharakah Program
- New Undergraduate Student Guide
- Undergraduate Orientation
- New Graduate Student Guide
- Graduate Orientation
- File Completion
- Payment Guide
- Students with Disabilities
- Academics
- Life at AUS
- Virtual Campus Tour
- Around Campus
- One Stop Solution Center
- Residential Halls
- Commercial Outlets
- Athletics and Recreation
- Career Services
- Celebrating our Graduates
- Health and Wellness
- Student Life
- Sustainability
- Merchandise
- Alumni
- On-Campus Services
- Students with Disabilities
- Fazaa
- Complaint Hotline
- Engage Arts
- Ethics Culture
- Research
- Contact Us
- Apply Now
- .

AUS students build AI prototype that learns from patients’ data while protecting privacy
Around the world, healthcare organizations gather patient information that could help improve AI models, yet bringing sensitive records together creates privacy concerns. Four American University of Sharjah (AUS) students have developed UAE Privacy Mesh, a working prototype that allows organizations to train a shared AI model while keeping their records on their own servers.
The project earned the team, AUSec, second place at the School of Cyber Defense Championship 2026, held at GISEC Global. The competition was organized by the Dubai Electronic Security Center in collaboration with Tech Firm Technology LLC.
A way to learn together
UAE Privacy Mesh uses federated learning, an approach that allows each organization to use its own data to train an AI model. It shares protected updates that help improve a common model, rather than sending the underlying records to a central location. The team also incorporated differential privacy, which adds carefully calibrated noise to limit the influence of any one person’s data and make it harder to trace information in the model back to an individual.
“We wanted to address a problem that many organizations face: they have information that could be more useful if they worked together, but they have a responsibility to protect it,” said team lead Alizar Farhan, a master’s student in computer engineering. “Our goal was to find a way to support that collaboration without moving the original records.”
Alizar worked with Mustafa Ashraf, also a master’s student in computer engineering; Austin Thomas, a senior undergraduate double majoring in computer science and mathematics; and Alikhan Sirgaliyev, a sophomore studying computer science.
The students built a working training system, privacy safeguards, tests and an interactive dashboard. They demonstrated the prototype using simulated data representing three healthcare authorities. No real patient information was used.
“Building a complete system in a few days meant making many parts work together,” said Ashraf. “We had to move quickly, but we also needed results we could check and explain.”
Putting the protections to the test
Keeping records on local servers does not automatically prevent an AI model from revealing information about the people whose data helped train it. Without using real patient data, AUSec tested that risk by trying to determine whether a particular person had been included in the training data and whether sensitive details about that person could be inferred from the model.
The students repeated their experiments three times and compared different levels of protection. With the full UAE Privacy Mesh safeguards applied, an attacker’s ability to identify a training participant fell to approximately the level of random guessing in the team’s tests. The protected model achieved about 78.5 percent accuracy. These findings are limited to the prototype’s experiments with simulated data.
“The most important question for us was what someone could still learn from the model after it had been trained,” said Thomas. “Testing it from an attacker’s perspective helped us measure whether the safeguards made a meaningful difference.”
The team’s technical submission and prototype scored 98 out of 100, securing a place in the in-person final. During the final, the students used a five-slide presentation to explain the challenge, their proposed system and their findings to a nontechnical audience.
“A good technical idea also has to be understandable,” said Sirgaliyev. “We wanted the judges to see why this challenge matters and what our prototype showed, without getting lost in the mechanics of the system.”
Looking beyond the prototype
The team was advised by Dr. Fadi Aloul, Dean of the AUS College of Engineering.
“For AI to deliver meaningful benefits in healthcare, institutions must be able to learn from data while earning and maintaining public trust,” said Dr. Aloul. “That challenge requires engineers and computer scientists who understand privacy as part of the design from the outset. At AUS, we prepare students to bring that thinking to problems of real consequence, and AUSec’s work shows the value of giving them the space to build and test their ideas.”
The students hope to test UAE Privacy Mesh with larger datasets, strengthen the protection of shared model updates and explore how it could perform in a realistic setting with the necessary data approvals. The approach could also be explored in other fields where sensitive information is held by separate organizations.
Through its academic programs and faculty mentorship, the AUS College of Engineering gives students opportunities to develop their technical skills and apply them to challenges beyond the classroom.
For more information about the AUS College of Engineering, visit www.aus.edu/cen.

