Research
Recent publications
Publications
Google ScholarGraphQLer: Enhancing GraphQL Security with Context-Aware API Testing
arXiv preprint arXiv:2504.13358
PrediQL: Automated Testing of GraphQL APIs with LLMs
arXiv preprint arXiv:2510.10407
XploitSQL: Advancing Adversarial SQL Injection Attack Generation with Language Models and Reinforcement Learning
Proceedings of the 33rd ACM International Conference on Information and Knowledge Management
Areas I'm actively thinking about. If any of these overlap with your work, I'd love to compare notes.
API Security & Fuzzing
Automated vulnerability discovery in GraphQL and REST APIs — dependency-aware fuzzing, IDOR detection, and the limits of static vs. dynamic analysis.
LLM-Assisted Security Testing
Using large language models to improve test coverage, classify endpoints, and reason about access-control chains. Where does the model help, and where does it hallucinate?
AI-Powered Cyber Defence
Using AI systems to detect, respond to, and anticipate attacks in real time — from anomaly detection to autonomous incident response and adaptive threat modelling.
Hardware & Embedded Security
Attack surfaces in embedded and IoT devices — firmware analysis, side-channel attacks, and the gap between software security assumptions and hardware reality.
Data-Driven Threat Intelligence
Applying data science and ML to security telemetry — anomaly detection, attribution, and building pipelines that surface signal from noise at scale.
Social Economics
Incentives, information asymmetry, and social dynamics — with intersections in security (bug bounties, ransomware markets) and AI (labour displacement, governance).