Statement of purpose
As a result of the numerous requests for advice I've received for grad apps, I've decided to share my annotated statement of purpose (SoP) for PhD applications. Besides the general definition of a statement of purpose (see: this) an SoP involves showing
- that you can do (and like to do!) research in the first place.
- what your research-focused goals are.
- why a PhD is the best fit for you.
- Learnings from my projects: Specifically the part of my profile that just cannot be explained through my CV, transcripts, or publications.
- Initiative: Specifically, where I took charge, or started a research initiative, such as starting a team for the Amazon Challenge, or taking my Microsoft project forward at CMU with my own ideas.
- How (some of) my past projects inform me of my future goals: There's a reason why I believe AI security is important; I incorporate some elements of what brought in this belief.
My SoP reads very "matter-of-fact"-ly and doesn't have the so-called personal touch to it. It's quite boring and it looks as though I'm tired of life in general - but this was a conscious choice on my part. I didn't want the admissions committee to be enamoured by my life story, but to simply see that I can conduct research and am a good fit for their program. I can think of at least one other person who shares a similar opinion on this.
My annotated statement of purpose
Below is my annotated statement of purpose for graduate school applications. I've added comments to explain my internal thought process and reasoning behind each section. The goal here is to simply provide a window into how I structured my SoP, and why I chose to do what I did. After the annotation, I've also included some tips and alternate strategies I tried, and why I chose not to include them in the end. Some of these strategies may actually work for you, however, so I encourage you to read through them and decide for yourself.
Begin annotation!I aim to pursue a Ph.D. at the intersection of Natural Language Processing (NLP), Safety, and Security. I am keen on going beyond chat-based interactions and exploring systems that are granted forms of agency. This interest stems from my realization that generative harms are not limited to chat interfaces or user-system interactions alone; when models can take actions, the potential for unintended consequences increases significantly. Below, I highlight my experiences surrounding AI safety, security and ethics that have shaped my research interests and led me to consider pursuing this problem.The aim of the first paragraph of my Statement was to clearly and concisely state my research topic, and the subproblems in which I'm looking to research on. I segue into the actual motivation behind considering this topic through my final lines ("I highlight my experiences"). I did not dwell a lot on my topics, as (1) my research experiences and future work sections would explain my motivations in more detail, and (2) the admissions committee is likely not to spend more than 10 minutes on my application, and I could make it easier for them to judge my interests' relevance to the professors I wanted to work with.
Jailbreaking and LLM Safety: As large language models get increasingly powerful in terms of their capabilities, they are also increasingly prone to causing harm to their users. This is something I quickly realized as a Research Fellow at Microsoft Turing - around late 2022, I discovered early on in a bug bash for our product, Bing Chat, that it exhibited surprisingly toxic generations when cleverly prompted to do so. While such prompts are established as jailbreaks, there was little analysis at the time that understood the extent and applicability of these harms. Hence, I initiated a project studying jailbreaks with my mentors, Prof. Monojit Choudhury and Prof. Somak Aditya, curating an ontology of jailbreak types, lexical categories, and their attacker’s intentions. Through this work, I uncovered that jailbreaks were further exacerbated when different alignment techniques were applied and upon scaling model parameters To better capture attack success I further proposed a two-subject evaluation paradigm: whether model outputs are misaligned from the original task, and if attacker intents are satisfied. This work was published at LREC-CoLING 2024[1].I decided to clearly demarcate my different research experiences and add in my future plans on each of these directions. This is rather common in computer science SoPs, especially in empirical AI research, where people tend to work on several not-so-very chronologically connected research projects.
I would recommend structuring your SoP in this way if you have multiple research experiences that you wish to highlight, and if they don't necessarily build on each other. The admissions committee primarily looks for:
- What research problems have you worked on and how did they inform your goals? (advisor fit)
- What was your role in the project and your key contributions? (Evidence for independence and initiative, and other soft-skills)
- What did you learn from the project? (your technical and research proficiency and in some cases, personal growth)
This was a great learning experience for me; I learned how to formalize an unfamiliar and understudied problem by defining a jailbreak ontology, curating a dataset and evaluating models on multiple axes.When I mention that I specified what I learned from projects, I don't necessarily mean the technical learnings from my results alone! That would be simply a summary of the paper, or a rehash of my CV. What's more important is deduplication. My personal learnings and reflections cannot be specified in a paper or CV, so I decided to include them over here.
Realizing that most jailbreak methods focused solely on chat-based systems led me to explore broader threat models - I formed a team and secured a $250,000 grant to work on the Amazon Trusted AI Challenge - an attack-defense competition to develop and red-team Code LLMs. Advised by Prof. Carolyn Rose from the Language technologies institute (LTI) and Prof. Michael Hilton from Software and Societal System Department (S3D), CMU, I’m working on minimizing code-vulnerabilities, such as those from the Common Weakness Enumeration (CWEs) by leveraging code-vulnerability datasets such as the MITRE ATT&CK Python CWEs to develop strong attack vectors in a black-boxed setup.This paragraph is what caught the eye of most of my interviewers, as it mentioned two things - (1) I was able to secure funding for a project, and (2) I was able to mobilize a team to work on a problem I cared about. Both of these are very important skills for an academic researcher, as you will invariably need to write grants and lead teams in your future career.
A sidenote: while I was very authoritative in this paragraph, I eventually didn't lead this project for reasons beyond the scope of this blogpost. I made sure to clarify this change explicitly with my interviewers. However, it would have been better if I had worded this paragraph more carefully in anticipation of such changes.
Future directions: During my graduate studies, I wish to study threat models that aren’t restricted to toxic/harmful generation. While reviewing existing work for the Amazon Challenge, I noticed that singular defenses like circuit breakers [4] may not handle insecure code generation. Hence, it is necessary to have comprehensive security frameworks that can anticipate and mitigate unintended harmful actions by AI systems. Additionally, developing robust monitoring and evaluation systems [5] when multiple actors/agents are involved can add multiple layers of complexity to the problem.There are many ways to write about your future directions. I personally preferred to structure my future directions in a separate paragraph at the end of each of my research experience sections, as they were fairly disconnected and non-chronological. I've seen some of my friends bundle all of their ideas towards the end of their essay, with a "future work" section header, as their research experiences were far more cohesive.
My research directions are rather generic - I don't even specify concrete examples of the "threat models" I was mentioning! However, they're specific enough to show that I have a clear idea of what I want to research on. This kind of balance is rather crucial in an SoP; a super generic direction (e.g. I want to work on AI alignment) is not very convincing and doesn't give you an edge, while a super specific direction (e.g. I want to study the effect of insecure code generation on industrial package development) may box you in to a very limited scope, pushing you away from potential advisors.
When you're confused about specificity, a good tip is to optimize for recall - though I wanted to work on AI Security, I considered applying to professors who were studying LLMs' dual use from the angle of social biases to as far as software development. Consequently, I kept my future directions rather broad to appeal to a wider set of professors.
AI-Ethics; cultural representation harms, and generalizability: AI systems have been known to misrepresent certain sections of society by directly undermining or failing to recognize their core values: I studied the detrimental nature of alignment methodologies on LLM’s ethical reasoning abilities in a position paper I led on value pluralism. I designed a framework, developing a systematic evaluation paradigm to evaluate the ethical reasoning capabilities of a language model, encompassing moral dilemmas over multiple granularities (EMNLP Findings, WiNLP Keynote 2023 [2]). This work advocated that LLMs should be value-neutral, and that value-alignment should occur at the application level. This project was my first introduction to interdisciplinary research, and it required that I studied moral frameworks surrounding the ethical triple theory, and to effectively communicate their subjective ideas amongst team members. The results from this effort proved particularly interesting: LLMs hinted a western centric bias in their reasoning, and they were unable to adapt their outputs to user-provided policies. I wished to translate this philosophical position into a practically usable resource to measure this adaptability further.I really did not wish to explore this direction during my PhD - however, I still wanted to include it in my SoP to show that I had a breadth of research experiences, and that I was able to take initiative in different environments. In hindsight, my learnings are rather underwhelming here; this was a position paper on a topic I barely spent a year on, and for a contribution I had a very hard time appreciating. This paragraph served more as a motivation into my next research experience.
When I entered CMU, I noticed work surrounding NLP and cultural studies borrowed frameworks that directly evaluated humans’ intrinsic moral values. However, an LLM deployed worldwide should largely be value neutral and should also be able to adapt to users from different backgrounds. Hence, in a project supervised by Prof. Maarten Sap, I designed a dataset, NormAd-Eti [3], to evaluate cultural adaptability of language models by contextualizing social situations, with coarse grained geographical information, and finer grained social norms. Through this framework, we encountered several key insights (1) language models indeed have a western-centric bias when contextualized with social norms, (2) this bias is amplified through value-alignment strategies. (C3NLP workshop @ ACL 2024; in review at NAACL 2025).This paragraph's main intent was to show that I translated my (well, tough-to-appreciate) framework into something more usable and concrete, and was able to publish it at a top-tier venue (NormAd eventually was accepted into NAACL-main as an oral session after two resubmissions). Here I show best my independence as a researcher - I was able to maintain a consistent research direction even when I switched institutions, advisors, and research groups. I believe that while some projects may not directly inform you of your future goals, they can still be useful in showing your research skills to the adminssions committee.
Future Directions: The findings uncovered by NormAd makes me more curious about other biases related to non-chat setups that are exacerbated during the value alignment stage. Furthermore, I believe multi-agent setups can offer a different perspective on biases which chat based setups may not cover. I am interested in conducting simulation studies [6] to explore how phenomena surrounding bias-propagation such as information cascades may show up in multi-agent systems and their resultant effects on decision-making.While my research experiences on biases and ethics were not directly related to my main research interest surrounding AI security, I was still able to tie them in through my future directions; the goal here was recall optimization again; I wanted to appeal to professors who started exploring AI-safety and risks from the angle of social biases.
Vision for graduate school: Pursuing a Ph.D. at X will equip me to address these challenges and contribute meaningfully to AI safety and security, and prepare me for a research-focussed career. I'm interested to work with Y; her focus on ABC aligns strongly with my current interests around the problem. Given my background in AI ethics and safety, I believe I am well-positioned to examine both representational and generational harms that AI systems can produce. To this end, Prof. Z's research vision of DEF aligns deeply with my research goals during my graduate studies. Notably, her projects on GHI overlap with a broad set of problems I wish to pursue. Overall, X is a great place for me to pursue my research aspirations, as I can learn from its diverse student group and esteemed faculty.This final paragraph is rather standard in most SoPs - you need to specify why you're applying to this specific institution, why it's a good fit, and who you wish to work with. I made sure to clearly specify how my research interests aligned with the professors I was applying to work with, and how their research aligned with my goals. Note that I was intentionally vague about what I wanted to do with my PhD - this was in part because I wasn't too sure of it myself. But I was leaning towards heading back to the industry. I would recommend being more open and specific about this; as all of my interviewers (I had 10!) asked me about my future career plans.
Some Tips on Structuring your SoP
- I had mentioned earlier in the annotation that I recommend demarcating each of your research projects if they don't necessarily build on each other. However, some of you may have a more coherent story to sell, i.e. you can see a clear progression in all of your research experiences, and a story might actually just seem more appropriate. If so, I would recommend against using my structure, a more narrative structure may be more appropriate. The SOP I've linked is from a student studying in UC Berkeley, and it ties each project to a single overarching "range" of threats.
- You do not need to explain your life's story and how you transformed over the course of a few years. Steven Kolawole has explicitly mentioned this in his "Road to PhD" series. It doesn't explain your research and how it's relevant to your future goals, and appears as plain fluff.
Alternate strategies and why I chose to remove them.
Research Experience #3 - Multilingual NLP
One key thing to note in an SoP is that you do not need to include every single research experience you've had. For instance, I also have some minor research experience on multilingual NLP; but I chose to exclude it as it didn't add much value to my overall narrative.I was inclined to pursue my bachelor's dissertation in NLP on Automation Punctuation Restoration at Nanyang Technological University (NTU), working with Prof. Chng Eng Siong. Most current approaches deal with a single language at a time. I developed a single model and pipeline capable of adding punctuation to Automatic Speech Recognition (ASR) Transcripts for multiple languages, beating the performance of the SOTA Chinese-only punctuation model with a multilingual variant. The dissertation taught me to work with large transformer-based models such as BERT and to package and ship these models to end-users using tools such as Docker. This work has been accepted and recently presented at APSIPA ‘22[¹]. Additionally, interacting with NTU students during my thesis gave me a different perspective on my education: many students tried a variety of fields, making me realize the importance of open-mindedness and willingness to try new things. I believe I can put these skills to good use in my graduate program by solving problems in various fields and subfields.This paragraph is from my Statement of Purpose during my masters applications. I chose not to include it, as it was very old news, and I never intended to pursue this direction of research again. It didn't add much value otherwise either; nothing I really learned from it that I could include in my SoP.
Adding future directions towards the end of my essay
Some applicants prefer adding in their future directions towards the end of their essay, with a "future work" section header. I had tried this approach as well; here's my attempt from the version history of one of my drafts:Through my work on jailbreaking, I realized that a language model may output toxic or obscene content, but true harm is delivered to its users only when it's granted a form of agency, such as through the ability to execute code. While reading up existing work for the Amazon Challenge, I noticed that singular defenses such as circuit breaking [7] cannot handle threats that can arise outside of an intent to cause harm. For instance, robustly training an LLM from leaking confidential data, be it their training data or a system prompt, is still unsolved.There were several issues with this structure; it seemed like a word salad of ideas ("action-space", "multiple-actors"), and while I did mention that I developed these after my work on jailbreaking, it was not super clear why I would want to pursue multi-agent setups and the flow appeared rather abrupt. Also, I wasn't doing a good job of linking my future directions to my research experiences -- I've instead chosen to study different threat models from what I had already worked on! Also, everyone I asked for feedback on my SoP was confused about the "information cascade"; it felt rather out of place and sounded like I was trying to sell a formulation of an existing problem instead of answering a particular research question.
Hence, during my graduate studies, I wish to study similar threat models that aren’t <1> solely dependent on a model’s internal representation of harm and <2> involve a model’s interaction with a system, i.e. agents. Currently, code generation LLMs have been to produce secure code through constrained decoding or adversarial training. However, a software development process involves multiple actors and multiple processes, such as code execution, review and repair. The broad action space in this setup can yield harms beyond vulnerable / malicious outputs. It is especially unclear on how to develop robust monitoring/evaluation systems when multiple actors are involved - an LLM or a classifier may never act as a perfect detector of harm when provided with model outputs alone, combining this with identifying a failure mode in an entire system adds multiple layers of complexities to the problem [8].
Finally, I believe multi-agent setups can offer a different perspective on biases which singular LLMs / chat based setups may not cover. Behavioral economics shows that humans are influenced by their environment despite possessing information otherwise, a phenomenon known as an information cascade. One such instance reported by [10] shows that information cascades from a user with a low number of twitter followers can result in a large follow/retweet chain. Given that language models exhibit human-like biases [11], I’m interested in studying the effect of similar biases in multi-agent systems and its resultant decision bias/multi-agent cascades.
Writing a motivating paragraph at the start of my essay
Sometimes, people write a motivating paragraph at the start of their essay. I had tried this as well, by stating how important AI security is in the world today:The rapid mainstream adoption of AI systems—ranging from user-facing chat services to developer-facing coding agents—highlights the urgent need to develop not only faster and more reliable but, more importantly, secure, ethical, and safer systems. Given the increasing capabilities of such systems in the past couple of years, threats such as adversarial attacks, data poisoning, and the misuse of AI for generating disinformation, once only proposed as theoretical thought experiments [9], now pose direct physical implications to humans and software systems [4]. For instance, large language models (LLMs) can be manipulated to output sensitive information or execute malicious code, leading to security breaches and privacy violations. However, no reasonably reliable defense mechanisms, mitigation strategies, or guidelines [8, 10] are currently available to prevent these emerging threats effectively.The idea behind this paragraph was to essentially show "AI security is a big problem, and hence I'm interested in it." However, I've never really answered why I was interested in this problem, and what my specific research goals were! I fell into the trap of writing my statement as thought it were an introduction to a research paper, instead of a reflection of myself and my purpose.
Pursuing a Ph.D. at the intersection of Generative AI, Safety, and Security would provide me with the opportunity to formalize and mitigate these risks within a diverse set of threat models. I am particularly keen on going beyond chat-based interactions and exploring modalities where language models are granted forms of agency, such as the ability to execute code or interact with external systems. This interest stems from my realization that harms are not limited to chat interfaces alone; when models can take actions, the potential for unintended consequences increases significantly. Below, I highlight my experiences that have shaped my research interests and led me to consider pursuing this critical problem.
Make no mistake, it is very important to have the skills needed to write a research paper, but this essay isn't where you need to show that -- instead, it should be centered around YOU, YOUR PURPOSE, and YOUR RESEARCH GOALS. I eventually chose not to explicitly motivate why I was interested in this problem, and instead let my research experiences and future directions speak for the motivation themselves. However, it may not hurt to have 2-3 sentences to be more explicit - for instance - "I'm interested in AI security because my prior research experiences have shown that this is a major problem that needs to be addressed..."