I build cyber defenses for real attackers. A game theory enthusiast, an artificial intelligence pragmatist, and a researcher who leverages psychological constructs against both human and AI attackers.
§ about
I study how people attack computer systems and how defenders can use their habits against them. Classical security games assume an adversary who always finds the best move. The attackers in our experiments do something messier. They skim dense tables, lean on two or three attributes, and settle for a target that looks good enough. My work measures that behavior in the lab, models it with tools from cognitive science and game theory, and folds the models back into defensive planning.
So far this has produced two threads. One asks how a defender should plan deception when the attacker responds noisily and the model of that noise may itself be wrong. The other runs behavioral experiments where people attack simulated systems, then fits cognitive process models to their choices. I collaborate with researchers at UTEP and the DEVCOM Army Research Laboratory, and my current work brings agentic AI attackers and reinforcement learning into these models.
More on the research, or see the publications.
§ contact
Email is the fastest way to reach me.