Reading

Published work I am reading for each of my research interests. None of it is mine. Every entry is the peer-reviewed version, from a conference or a journal.

AI-augmented adversarial attack and defense

How automated offense changes attacker cost, and what detection has to do once reconnaissance and evasion are cheap.

Most of the attention here goes to attack demonstrations. I think the benchmarks matter more. Cybench, NYU CTF Bench, and AgentDojo turn "could an agent do this" into a number, and a number is what lets a defender argue about coverage instead of intuition. I am more optimistic than most about which side gains from this. The same automation that produces an exploit also produces the detection for it, and the defender gets to run it against their own environment first.

SOC optimization

Where AI assistance lowers analyst load, and where it moves the bottleneck instead of removing it.

Both surveys reach the conclusion I reached in production: alert volume, not detection logic, is the binding constraint. That is where I think AI earns its place first, filtering noise rather than trying to replace the analyst. Rule generation is the other half of the problem. If writing a detection gets cheap, coverage expands, and the filtering has to improve at the same rate or the analyst ends up worse off than before.

Threat hunting and adversary intelligence

Hunting, OPSEC, and tracking adversary infrastructure over time, including what that tradecraft costs to sustain.

Provenance-based detection answers the attribution question and creates a volume question. HOLMES, UNICORN, and MAGIC each produce a graph that an analyst still has to read. The Tea Leaves result is the uncomfortable one, because threat intelligence feeds agree with each other less than most teams assume. Given the choice, I would rather expand rule coverage and filter hard than trust any single feed’s precision.

Back to research interests