I attribute attacks and disrupt adversaries. Now I read the ones that target AI.
Counter-adversary researcher for AI systems. The discipline is attribution: reading how LLM and agent deployments are attacked, and what the method reveals about the actor behind the prompt. Most are mapping the vulnerability. I read the context.
01Attribution is convergence
Attribution was never about a single indicator. It is infrastructure, tradecraft, tooling, and history stacked until the picture is undeniable. AI hands adversaries new tradecraft, and that tradecraft becomes a new axis of the same method.
02Structural beats statistical
Every control on an AI system either decides from a fact the adversary cannot rewrite, or from a classifier it can evade. The first holds when it matters. The second only buys cost and signal, and fails silently when beaten.
Navy, then cyber threat intelligence, then years operating against real adversaries: nation-state APTs, ransomware crews, organized threat actors. Not from a distance. Running the hunts, building the intel, working the incidents.
I have led CTI teams, contributed to the Verizon DBIR, and supported two CISA #StopRansomware advisories. Attribution was always the discipline: reading infrastructure, tradecraft, and history until the actor is undeniable. AI is a new surface for that same read, and everyone else is arriving at it from application security. I am arriving from the adversary.
Reach out
CISOs and security leaders, founders and CEOs, thought leaders, podcasters, and fellow practitioners: I am always up for a good rabbit-hole conversation.