I attribute attacks and disrupt adversaries. Now I read the ones using AI.
Counter-adversary researcher. The discipline is attribution: reading how threat actors adopt AI, and what those choices reveal about the conditions they operate under. Most are mapping the vulnerability. I read the constraint.
// two ideas I keep coming back to
01Attribution reads constraint
Attribution was never about a single indicator. Budget shows up in tooling, deadlines show up in tempo, and fear of consequence shows up in operational security. An adversary leaks their conditions through every choice they make, and the conditions are the fingerprint. AI tooling choices are a new surface for the same read.
02Structural beats statistical
Every control on an AI system either decides from a fact the adversary cannot rewrite, or from a classifier it can evade. The first holds when it matters. The second only buys cost and signal, and fails silently when beaten.
// whoami
I came to AI security from the adversary. Years running and leading counter-adversary operations against nation-state APTs, ransomware crews, and organized criminal groups, working the intelligence cycle end to end: requirements, collection, analysis, and the briefing at the other end of it. Navy first, then CTI, with a contribution to the Verizon DBIR and support on two CISA #StopRansomware advisories along the way. Today I work in AI security.
The clearest signal available right now is provider misuse reporting, finished intelligence on adversary AI tradecraft from the only parties who can see it directly. I treat it as collection: something to structure, pressure test, and build a method on while the method is still being built. I do that work in the open, because I would rather stake a claim and be corrected than wait for the field to settle.
// the work
Reach out
CISOs and security leaders, founders and CEOs, thought leaders, podcasters, and fellow practitioners: I am always up for a good rabbit-hole conversation.