His research asks whether the metrics defensive AI reports about itself can be trusted — and builds the endpoint telemetry, evaluation methods, and embedded-security tooling to find out.
First-author, IEEE SoutheastCon 2026 · Incoming M.S. Cybersecurity, Georgia Institute of Technology
Sysmon telemetry, evaluated the way an attacker experiences it — over time, not one event at a time.
Side-channel and fault-injection attacks against firmware, where security has a physical signal, not just a log line.
Models built to be checked, not just trusted — where the evaluation is as rigorous as the architecture.
Building automation for cybersecurity examinations showed how much of enterprise risk assessment depends on data most people never see directly. It set the question that still drives this work: how do you build a system that improves a decision before a human is asked to make it?
Studying the 2024 CrowdStrike Falcon outage led to a first-author paper on AI-driven update validation — and to a harder problem underneath it: most ML-security results report accuracy numbers that don't survive contact with real-world behavior.
Benchmarking ransomware detection on 6,200+ labeled Sysmon events, event-level models looked almost perfect while behavioral aggregation told the truth — 75–82%, not 99%. That gap now has a name, "temporal collapse," and a paper under review at EAI Endorsed Transactions.
Side-channel and fault-injection work on embedded firmware, using the ChipWhisperer-Nano platform, showed that the same discipline — question the signal, not the summary — holds below the operating system, not just above it.
Static PDFs hide the most interesting part of research: how a result was reached. A capture-the-flag platform built to teach that reasoning became the basis of the next paper.
That idea became a real project: turning published papers into interactive investigations, where the reader tests the hypothesis and watches the evidence collapse or hold. The first Living Paper — built on the Sysmon-ML temporal-collapse result — is live.
Explore Living Papers →The direction: systems that combine behavioral telemetry with AI reasoning to detect threats earlier — and hold up when someone asks why the system made that call.
The Sysmon-ML paper below is now also a Living Paper — an interactive investigation instead of a static PDF, built on its own findings.
Why AI-driven validation could have caught the failure mode behind the 2024 CrowdStrike Falcon outage before it shipped.
Read on IEEE Xplore →A per-student, salted-hash flag architecture that makes cybersecurity coursework resistant to answer-sharing without adding grading overhead.
Why near-perfect ransomware-detection accuracy is usually a measurement artifact of event-level representation, not a real result — and how temporal structure exposes it.
Explore the Living Paper →Not a list of technologies — the problem, the constraint, and the decisions that followed.
M.S. Cybersecurity (Information Technologies), Atlanta, GA · starting August 2026
B.S. Cybersecurity, Minor in Entrepreneurship · GPA 3.82/4.00 · Honors Thesis on AI-driven endpoint security
Open to research collaboration, cybersecurity and AI/ML security roles, and conversations about problems worth solving.