My name is Bobby Filar, and I am the Head of AI at Sublime Security. I lead a team that develops machine learning-based detection tools and the agentic systems that power our platform.

Much of my work addresses three primary challenges that intensify when AI operates in real-world, adversarial environments: comprehensive evaluation, robust architectural security, and evidence-based transition from supervised to autonomous deployment.

Regarding evaluation, I co-authored the CAMLIS 2025 paper, which introduced three methodologies for assessing LLM-generated detection rules. I also lead the MQL Benchmark, an open-source evaluation suite containing 30,000 examples for testing natural-language-to-DSL generation, accompanied by a public model leaderboard. In terms of security, I designed the secure-by-design architecture for our two production agents, ASA and ADÉ, emphasizing that the platform, rather than solely the model, should enforce security. For governance, I established and manage Sublime’s AI Governance program, which adheres to the Trust, Then Autonomy framework. Under this approach, human oversight is prioritized, and autonomy is incrementally introduced as trust is established through transparency and evidence.

Before joining Sublime, I led security machine learning teams at Elastic and Endgame, where I developed Artemis, one of the earliest natural language agents designed for security analysts.

My research encompasses adversarial machine learning, malware classification, and human-AI collaboration in security contexts. I have published at AAAI, ACM AISec, and USENIX, and have co-authored significant work on the malicious use of artificial intelligence.

Current research interests

  • Designing benchmarks and evaluation methodologies for LLM agents deployed in adversarial production environments
  • Architecting agent security, including platform-enforced boundaries, prompt injection mitigation, and the implementation of graduated autonomy
  • Developing AI governance frameworks that scale proactively with system capabilities rather than reactively adapting to advancements