What we study
Research that connects data, models, and security decisions.
Our work focuses on making security analytics more automated, adaptive, interpretable, and useful in real network environments.
Network threat detection
Machine learning systems for detecting malicious traffic, botnets, denial-of-service attacks, fast-flux networks, and scanning activity.
Device and OS fingerprinting
Passive identification of devices, hosts, and operating systems from packet-level protocol headers and encrypted traffic metadata.
Optimization and explainability
Genetic algorithms, Artificial Bee Colony optimization, feature selection, quantization, and SHAP-based model analysis.
LLMs and long-context AI
Large language models for security tasks, alongside retrieval-augmented generation and adaptive context pruning.