Research Group
I work with a group of PhD students, undergraduate researchers, and collaborators on the security of cyber-physical systems, robotic and embodied AI systems, critical infrastructures, and security education.
PhD Students
Luis is a PhD student in Computer Science and Engineering. He is interested in developing security and privacy-preserving strategies for cyber-physical systems and embodied AI, using control-theoretic techniques.
Diego works on the security of robotic vehicles and drones, with a focus on falsification, testing, and attacks on embodied AI systems.
Sebastian works on AI agents for cyber operations, including how agents can be used to automate offensive and defensive security tasks.
Juanita works on open source software and supply-chain security, studying how vulnerabilities and malicious changes propagate through software ecosystems.
Eya focuses on the security of drones and drone swarms, including attack models and defenses for multi-drone systems.
David is a PhD student in Computer Science and Engineering, co-advised by David Lee and a recipient of the NSF CSGrad4US Fellowship. His research focuses on improving the accessibility of research opportunities for undergraduate students.
Nancy is a PhD student in Computer Science and Engineering. She is interested in the security of AI agents, building on her prior work in firmware security and competitive CTF participation.
Roberto is a PhD student in Computer Science and Engineering and a recipient of the DoD NDSEG Fellowship. He is interested in the security of embodied AI systems and autonomous drones, with a focus on physical-world attacks and robust, safety-aware autonomy.
Sergio is a PhD student in Computer Science and Engineering. He is interested in the security of AI agents, focusing on how they behave in adversarial environments and how to harden them against subtle manipulations.
Undergraduate Students
We have an amazing group of undergraduate students who are interested in security. They have participated in multiple security competitions, most recently obtaining 2nd place in the eCTF competition in 2023.
Group leadership has included Ex (Iakov) Taranenko, Nancy Lau, Brian Mak, Steven Mak, Jeffrey Zhang, Jackson Kohls, Victor Ho, Stephen Lu, and others.
Amy is interested in using large language models (LLMs) for software security, including program analysis, vulnerability discovery, and secure coding assistance. She is supported by an REU for her research.
Taya is interested in AI agent security, studying how autonomous agents can be attacked and how to design safer decision-making pipelines. She is supported by an REU for her research.
Iakov is a core leader in Slug Security and works on binary exploitation, offensive security, and competition strategy, while mentoring newer members of the team.
Astra is interested in reverse engineering and has been the fastest student to complete the NSA Codebreaker Challenge for three years in a row. She is supported by an REU for her research.
Graham is interested in AI agent security and works on tools and experiments for evaluating how agents behave under adversarial conditions.
Alumni
Postdocs
Kunal was a postdoctoral scholar jointly with Prof. Ricardo Sanfelice. His research spans robust multi-agent path planning, hybrid systems, and control synthesis for spatiotemporal specifications. After UCSC he took a postdoctoral position at MIT.
Jairo is a Research Assistant Professor at the University of Utah. He works on security and privacy in control theory, including physics-aware intrusion detection and differential privacy mechanisms for cyber-physical systems.
Mohamed was a postdoctoral fellow at UCSC and now holds a research position at CNRS in France. His interests include dynamical systems, safety and robustness, and control theory with applications to power systems and cyber-physical systems.
Junia led efforts to create a general framework to understand the risks of IoT devices and web cameras. Her work was covered by Newsweek, IEEE Spectrum, Threatpost, and Forbes articles on IoT security and drone security.
Luis worked on security and penetration testing for IoT devices, automated vehicles, and software-defined networks.
Keerthi focused on network security, deep-packet inspection, and the security of smart devices in the Internet of Things.
Juan worked on the security of industrial control networks, including analysis of SCADA communication and industrial protocols.
Neil is an expert on SCADA systems in the power grid and other critical infrastructures, publishing comprehensive analyses of real-world SCADA networks and protocols.
Xi is a Principal Scientist at Amazon. Her dissertation focused on deep-packet inspection for industrial control systems and anomaly detection in industrial networks.
Raul is a software engineer at CoreLogic. He worked on operating system security and the security of embedded and IoT devices, including unmanned aerial and ground vehicles.
Kelvin is a security researcher with the U.S. Department of Defense and has worked on network security and deep-packet inspection for industrial control systems.
Junia is a security researcher whose work includes physics-based attestation for remote CPS and visual challenges for verifying video integrity. Her research has received multiple awards.
Carlos is a postdoctoral scholar at Vanderbilt University. His research combines control theory, game theory, and mechanism design to improve the security of control systems and the smart grid.
Mustafa is a data scientist at Procter & Gamble. He worked on machine learning, privacy, and security in industrial control systems and smart grids, including deep packet inspection for ICS.
David is a security researcher at Intel, working on secure design and operation of IoT hardware and software, ICS security, and secure architectures.
David’s MS thesis (co-advised with Prof. Su-hua Wang) examined security and privacy issues in IoT devices for children, with a focus on human factors and parental decision making.
Matthew is a security engineer at BetterHelp. His work has focused on the security of IoT hubs and the safety and privacy of intimate devices.
Brian, Steven and Jeffrey led a team of undergraduate students to obtain the 2nd place (among 80 participants) in the eCTF competition in 2023, and one of the only two teams that was not compromised.
Waylon worked on firmware security and was part of the UCSC team that earned 2nd place in the 2021 DOE CyberForce competition.
Aviv’s interests span theoretical computer science and information security. His work on industrial malware won a Chancellor's Undergraduate Research Award at UCSC.
Dominic collaborated on reverse engineering industrial malware with Aviv Brook, work that also received a Chancellor's Undergraduate Research Award at UCSC.
This team built an extensible autonomous vehicle platform and received 3rd place (out of 43 teams) for their senior design project, co-advised by Dr. Tyler Summers.
Sonia worked on mandatory security policies for industrial control systems and received multiple undergraduate research awards for her work.
Vanessa worked on privacy issues in Internet of Things devices, focusing on risks for consumers.
Elena investigated privacy challenges in IoT devices, with an emphasis on data collection and user consent.
Kelly worked on privacy and security for IoT devices and co-authored work on improving the security of visual challenges.
Cathryn received multiple undergraduate research awards and worked on human–machine interfaces and visualization for data and security analysts.
Michael studied intrusion detection for process control systems and co-authored award-winning work on encrypted AMI network traffic patterns.
Michael participated in a summer REU and worked on human-centered computing and network security.
Carlos joined a summer REU at UT Dallas and worked on human-centered interaction and data visualization for security.
Grace worked at the intersection of big data analytics and information security and contributed to reports on big data analytics for security.
Laurel studied network security, intrusion detection, and analytic tools to detect anomalies in computer networks.
These students participated in the Young Women In Science and Engineering (YWISE) program, analyzing how IoT devices collect data from consumers and studying privacy implications.
Hampei is an Assistant Professor at the Tokyo Institute of Technology. During his visit, he worked on cyber-physical systems security and decision processes.
Efren Lopez Morales is now an Assistant Professor at New Mexico State University. He was a PhD student at Texas A&M Corpus Christi, where he was advised by Carlos Rubio-Medrano. Efren is interested in the security of industrial control systems.
John was a PhD student at SUTD who visited to work on industrial control systems security, co-advised with Jianying Zhou and Martin Ochoa.
Andres was a PhD student at Universidad de los Andes whose research focuses on SDN and NFV security, CPS security, and smart grids. He was adviced by Sandra Rueda.
Luis Francisco is a professor at Universidad Distrital and PhD student at Universidad de los Andes. He works on adapting fault-detection algorithms to adversarial settings in control systems. He was adviced by Nicanor Quijano.
Jairo also visited as an international collaborator while completing his PhD at Universidad de los Andes, working on control theory and microgrid synchronization. He was adviced by Nicanor Quijano.
Marina is a researcher in process control systems security and industrial testbeds, and visited to collaborate on ICS security.