Can a system learn an entity's behavior?
Investigate how endpoint telemetry can represent the activity of a particular user or device, and whether deviations can become useful detection signals.
Questions tested in practice
Explore the question. Test the assumptions.
This is the home for research initiatives, from thesis work to focused technical investigations. Each initiative connects a question to its assumptions, experiments, and evidence. The aim is to understand what works, under which conditions, and what remains unresolved.
Explore the researchInvestigate how endpoint telemetry can represent the activity of a particular user or device, and whether deviations can become useful detection signals.
Study detection quality together with compute, memory, and latency constraints on general-purpose hardware.
Investigate identity, authorization, task integrity, and tool verification across agent systems, including post-quantum approaches.
The thesis program studies entity-specific behavior using endpoint telemetry. Model architectures are hypotheses to compare; the central question is whether behavior can be learned well enough to support effective, practical anomaly detection.
Investigate the tradeoff between useful context, detection performance, and operating cost. Comparisons need equivalent data, realistic workloads, and explicit hardware conditions.
A research direction exploring how agent identity, mission context, permissions, and tool integrity can be verified across system boundaries. Protocol and benchmark work must distinguish proposed mechanisms from validated findings.
Make the relationship between a research question, an experiment, and a conclusion inspectable. Record decisions and negative results alongside successful runs.
State the problem, assumptions, scope, and what evidence would change the conclusion.
Choose baselines, data, metrics, and constraints before interpreting results.
Record conditions and outcomes, inspect failures, and distinguish observation from explanation.
Publish methods, progress, findings, and limitations; use them to frame the next question.
Get in touch about research collaboration, relevant datasets, evaluation ideas, or technical feedback.