Questions tested in practice

Applied Research

Explore the question. Test the assumptions.

This is the home for research initiatives, from thesis work to focused technical investigations. Each initiative connects a question to its assumptions, experiments, and evidence. The aim is to understand what works, under which conditions, and what remains unresolved.

Explore the research
  • Dendroaspis
  • Behavioral modeling
  • Efficient inference
  • Agent trust
  • Experimental evaluation
01

Questions driving the work

Can a system learn an entity's behavior?

Investigate how endpoint telemetry can represent the activity of a particular user or device, and whether deviations can become useful detection signals.

What can run at the edge?

Study detection quality together with compute, memory, and latency constraints on general-purpose hardware.

How should agents establish trust?

Investigate identity, authorization, task integrity, and tool verification across agent systems, including post-quantum approaches.

02

Research directions

01

Dendroaspis · behavioral modeling

The thesis program studies entity-specific behavior using endpoint telemetry. Model architectures are hypotheses to compare; the central question is whether behavior can be learned well enough to support effective, practical anomaly detection.

Methods & tools

  • Endpoint telemetry
  • Event representation
  • Sequence modeling
  • Anomaly detection

Intended outputs

  • Telemetry and representation design
  • Controlled experiments
  • Detection and efficiency evaluation
02

Efficient learning & inference

Investigate the tradeoff between useful context, detection performance, and operating cost. Comparisons need equivalent data, realistic workloads, and explicit hardware conditions.

Methods & tools

  • Architecture comparisons
  • Profiling
  • Edge inference
  • Ablation studies

Intended outputs

  • Benchmark protocol
  • Resource measurements
  • Documented limitations
03

Trust in agent systems

A research direction exploring how agent identity, mission context, permissions, and tool integrity can be verified across system boundaries. Protocol and benchmark work must distinguish proposed mechanisms from validated findings.

Methods & tools

  • Agent identity
  • Mission integrity
  • Tool verification
  • Post-quantum cryptography

Intended outputs

  • Adversary and security models
  • Protocol design
  • Prototype evaluation
04

Reproducible investigation

Make the relationship between a research question, an experiment, and a conclusion inspectable. Record decisions and negative results alongside successful runs.

Methods & tools

  • Experiment registries
  • Versioned configurations
  • Progress reports
  • Evidence tracking

Intended outputs

  • Methods and assumptions
  • Experiment records
  • Results and next questions
03

How an investigation takes shape

  1. 01

    Define the question

    State the problem, assumptions, scope, and what evidence would change the conclusion.

  2. 02

    Design the experiment

    Choose baselines, data, metrics, and constraints before interpreting results.

  3. 03

    Collect and evaluate

    Record conditions and outcomes, inspect failures, and distinguish observation from explanation.

  4. 04

    Share and refine

    Publish methods, progress, findings, and limitations; use them to frame the next question.

Have a related question or a useful challenge?

Get in touch about research collaboration, relevant datasets, evaluation ideas, or technical feedback.

Discuss research