Startups · AI

Research Engineer - Decentralized Training and Inference Verification

Pluralis · San Francisco · Remote

← All jobs
About Pluralis

Pluralis Research works on Protocol Learning — decentralized, communication-efficient model-parallel training for foundation models. Backed by USV.

About the role

Own the threat model : You enumerate what a malicious or careless worker can do across pre-training, post-training, and inference — training disruption and denial-of-service, free-riding, model poisoning and backdoors, data extraction from gradients and activations, reputation and reward manipulation — and you keep that model current as the network grows.

What they're looking for

  • Statistical depth : Deep expertise in statistics and probability, with the ability to design experiments, calibrate decision thresholds, and defend the error rates you claim
  • Technical background : You know the solution space for verifying untrusted compute, from statistical testing to re-execution, cryptographic proofs, and trusted hardware, and you can argue what fits a permissionless network and what doesn't
  • Mission alignment : You believe Protocol Learning is the viable third path for collective, trustless, and sovereign AI
More about this role

Pluralis Research works on Protocol Learning: training and serving large models in a fully decentralized way on small consumer-grade devices connected via the internet. Despite being dismissed as infeasible, we have made significant advances on this problem, most recently Agora, a permissionless run that pretrained an 8B model from scratch on consumer GPUs spread over the internet, with no single participant ever holding the full weights ( tech report ). While many of the core research problems have been solved, Protocol Learning unlocks a series of new challenges. For the mission in full, read A Third Path: Protocol Learning .

Our training and inference network is trustless, and the workers are GPUs scattered across the world. Many things can go wrong in this system. An inference worker can return tokens from a cheaper model, or a highly quantized version of the one it's supposed to run. Even with the right model, it can sample with the wrong parameters. Training faces its own attacks, and Agora showed what a permissionless run deals with in practice: participants who disrupt training by dropping updates or flooding the system, free-riders who submit trivial work and collect the...

Read the full posting on Pluralis's site ↗

Research

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.