AI and security
Language models and autonomous agents are arriving on both sides of security work at once: they promise to take load off analysts, and they open an attack surface that conventional controls only partly cover.
The first direction asks what AI can do for security operations. Analysts face more alerts than can be triaged by hand, spread across tools that share no common data model, and much of the effort goes into reconstructing context that already exists somewhere in the organisation. The group studies how language models and agents can support that work — enriching and correlating alerts, connecting threat intelligence to telemetry, turning intelligence into detection logic, and explaining a finding well enough for someone to act on it — while keeping the decisions that matter under human control and measuring the quality of the result rather than assuming it.
The second direction turns the question around and treats the AI system itself as the target. Prompts, retrieved documents, memory, tool descriptions and tool responses are all inputs that may carry untrusted content, and an agent able to call tools and reach other systems can be made to act on it. Work here covers the attack surface of model- and agent-based applications, injection attacks that cross from natural language into downstream systems such as databases, the telemetry needed to reconstruct what a model or an agent actually did, and systematic adversarial testing, so that defences are measured against attacks rather than against expectations.