Selected work

Hard problems. Bounded claims.

Our work starts with the operating problem, then defines what useful evidence would look like. Public descriptions stay focused on capability, evaluation, and the next question to answer.

The problem

AI-driven attackers depend on speed, adaptation, and anonymity.

Behavioral demasking

Identify the attacking model, objective, operating pattern, and origin through inline behavioral evidence.

Evidence today
Specialized models combine network behavior with active response to expose capability and intent.
Status
Prototype
Next step
Expand live-range demasking trials across adaptive actor classes.

The problem

Post-event analysis gives machine-speed attackers the initiative.

Fail-closed inline defense

Detect, decide, and enforce inline while the defender controls the terrain, tempo, and response rules.

Evidence today
Host-managed operation removes outside API dependency from the defensive path.
Status
Prototype
Next step
Continue inline performance and fail-closed recovery testing.

The problem

Passive observation leaves the attacker free to choose what the defender can see.

Active behavioral feedback

Use controlled probing and deception to make adaptive systems reveal decisions, capability, and control structure.

Evidence today
Live-range trials record reaction paths, timing, state changes, and operator-visible reasons.
Status
Evaluation ready
Next step
Broaden adversarial variation and operator-governed response trials.

The problem

Historical signatures and stale datasets do not represent adaptive AI aggression.

Continuous live-range training

Continuously train specialized models on current behavior captured within owned and controlled infrastructure.

Evidence today
Provenance, blind trials, drift tests, and rollback paths remain part of the operating cycle.
Status
Prototype
Next step
Increase campaign diversity and continuous retraining coverage.