A security AI model maturity checklist and Sublime's four pillars of AI safety for agents that operate directly on attacker-authored content.
Media & Writing
Selected public talks, writing, and news.
Analysis of an in-the-wild credential phishing campaign carrying a second, adversarial payload designed to manipulate AI-based email security into returning a benign verdict.
A two-tier router architecture — fine-tuned open-weight model with uncertainty-based escalation to a frontier model — that cut ASA's median latency 16x and inference cost ~70% with no accuracy loss.
Guest segment on evaluating agentic AI in security, and how organizations are cutting through 'AI fatigue' to make real decisions about deployment.
Talk introducing the five-level autonomy framework, evidence ladder, and three architectural foundations for evaluating earned autonomy in deployed AI systems.
Architectural deep-dive on tool scoping, platform-enforced authorization, prompt injection mitigation, and graduated oversight for production LLM agents.
A three-pillar framework — detection accuracy, robustness, and economic cost of coverage — for evaluating LLM-generated detection rules, applied to Sublime's ADÉ agent.
Sponsor interview on the rising use of spam bombing and email bombing as initial-access techniques in modern intrusion campaigns.
Introducing Attack Score, an explainable AI feature that summarizes threats and provides a transparent verdict, built on privacy-preserving feature engineering and MQL.
How Sublime combines Natural Language Understanding with Message Query Language to detect Business Email Compromise, an attack style with no malicious links or attachments to key on.
How Sublime's LinkAnalysis function uses Siamese neural networks and computer vision on rendered link screenshots to catch brand-impersonating credential phishing pages.