My name is Bobby Filar, and I am the Head of AI at Sublime Security. I lead a team that develops machine learning-based detection tools and the agentic systems that power our platform.

A lot of my work focuses on three main challenges that become tougher when AI runs in real-world, adversarial settings: thoroughly evaluating it, securing its architecture, and transitioning it from supervised to autonomous use based on solid evidence.

On evaluation, I co-authored the CAMLIS 2025 paper that introduced three ways to measure LLM-generated detection rules. I also lead the MQL Benchmark, an open-source evaluation suite with 30,000 examples for testing natural-language-to-DSL generation and a public model leaderboard. For security, I designed the secure-by-design architecture for our two production agents, ASA and ADÉ, based on the idea that the platform, not just the model, should enforce security. For governance, I created and manage Sublime’s AI Governance program, which follows the Trust, Then Autonomy framework. This means human oversight comes first, and autonomy is added gradually as we build trust through transparency and evidence.

Before joining Sublime, I led security machine learning teams at Elastic and Endgame. There, I built Artemis, one of the first natural language agents designed for security analysts.

My research covers adversarial machine learning, malware classification, and how humans and AI work together in security. I have published at AAAI, ACM AISec, and USENIX, and co-authored important work on the malicious use of artificial intelligence.

Current interests

  • Designing benchmarks and evals for LLM agents in adversarial production
  • Architecting agent security: platform-enforced boundaries, prompt injection mitigation, graduated autonomy
  • AI governance that scales with capability rather than chasing it