CERIAS Weekly Security Seminar - Purdue University

CERIAS

CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.

  1. 3d ago ·  Video

    Romila Pradhan, Reasoning About Interventions in Data and Machine Learning Systems

    Modern machine learning systems are only as reliable as the data and pipelines that support them, yet improving their behavior often requires navigating enormous spaces of possible data and system configurations. These systems are complex enough that improving them by changing everything at once is both inefficient and unreliable. This talk explores a simple principle for building smarter data and machine learning systems: identify which intervention is most likely to change the outcome, and act there.  I will first introduce DataSift that applies this principle to model behavior, identifying the most influential data to expand the training data when the goal is to improve fairness without sacrificing predictive performance. By combining data valuation, influence functions, and multi-armed bandits, DataSift identifies small, high-impact subsets of candidate data rather than indiscriminately adding data to the training set. Next, I will present PipeLens that applies the same principle to data science pipelines, identifying the components and parameters whose intervention is most likely to repair a malfunctioning pipeline. By learning from successful and failed pipeline executions, PipeLens identifies causally relevant root causes and efficiently searches for interventions that restore pipeline utility. Despite addressing different problems, both systems replace brute-force search with targeted intervention using principled reasoning about influence and causality to determine what to change, why it matters, and how to change it efficiently. About the speaker: Romila Pradhan is an Assistant Professor in the School of Applied & Creative Computing at Purdue University and leads the Responsible DataScience Lab, where she and her students build trustworthy and responsible data-driven decision-making systems. Her research is in the broader areas of databases and data management and is driven by the need to design algorithms and develop solutions that enable system explainability, fairness, and robustness.  Her research is supported by NSF, Google, and Underwriters Laboratories. She is a recipient of a Google Research Scholar award and an NSF CAREER award. Romila earned her Ph.D. in Computer Science from Purdue University and graduated with M.S. and B.S. in Mathematics and Computing from the Indian Institute of Technology (IIT) Kharagpur, India.

  2. Sep 2 ·  Video

    Armin Moin, TianoShield: Improving the Security Posture of the TianoCore Ecosystem

    In this talk, I will provide an overview of our NSF-sponsored award, TianoShield, focused on enhancing the security posture and the software maintenance process of the open-source core of the UEFI Firmware, called EDK II, and maintained by the TianoCore community. The talk will highlight our ongoing collaborations with our industrial partners, including Intel Corporation, Arm, AMI, Insyde Software, GitHub, Phoenix Technologies, Binarly, etc. First, we will discuss our methods and techniques for rapid triaging of existing bug reports that have remained open for a long time due to a lack of resources in the community. Second, we will introduce our security analysis tools and their enhancements for static and dynamic analysis of the UEFI firmware, thus discovering many new vulnerabilities. Finally, we will present our suggestions and improvements for software maintenance, specifically bug handling, and DevOps/DevSecOps practices in TianoCore. A key pillar of TianoShield is leveraging the state of the art in Artificial Intelligence (AI), including Large Language Models (LLMs) for software security and software maintenance. As part of the dissemination practices in TianoShield, we have organized/will organize a full-day workshop, called FirmVuln26, at VulnCon26 in Scottsdale, AZ, in April 2026, and another full-day workshop, called FTA 2026, at ISSTA 2026 in Oakland, CA, in October 2026. The TianoShield project started in October 2025 and is expected to run until September 2027. About the speaker: Dr. Armin Moin is a Tenure-Track Assistant Professor and Director of the Purdue Quantum-Classical AI and Software Engineering (QCASE) Lab at the School of Applied and Creative Computing (ACC) in the Polytechnic Institute at Purdue University in West Lafayette and Indianapolis, Indiana, USA. He previously (2023-2026) held a Tenure-Track Assistant Professor position in the Computer Science (CS) department of the University of Colorado Colorado Springs (UCCS). Before starting his faculty position, he worked as a Postdoctoral Scholar-Employee in the CS Department of the University of California, Santa Barbara (UCSB) in the U.S. and as a Postdoctoral Scholar in the CS Department of the University of Antwerp and FlandersMake in Belgium. Dr. Moin obtained his Ph.D. in CS from the Technical University of Munich (TUM), Germany, one of the world's top universities, in 2022. He also has a Master's in CS and an Executive MBA in Innovation and Business Creation. His research focuses on the intersection of Artificial Intelligence (AI) and Software Engineering (SE), particularly AI4SE and SE4AI, with an emphasis on hybrid quantum-classical computing and software security. Grants from various sources, including the U.S. National Science Foundation (NSF) and the Colorado Office of Economic Development and International Trade (OEDIT), have funded his lab. Besides conducting research and teaching at Purdue University, Dr. Moin reviews top academic conferences and journals. He is passionate about encouraging and empowering students to start their ventures based on what they learn at the university. Please refer to his academic homepage at https://web.ics.purdue.edu/~moin/index.html or his professional profile at https://polytechnic.purdue.edu/profile/moin for more information.

  3. Aug 26 ·  Video

    Matt Scheurer, Lies, Telephony, and Hacking History

    You may find yourself attending a CERIAS Security Seminar, and you may ask yourself "Well, how did we get here?" Once upon a time, not long ago, there was no cybersecurity industry or careers. This talk transports attendees on a retrospective journey through time to highlight the advancements which paved the way here. We further explore historic attack vectors to understand how they relate to the cyberattacks of today. Topics include when Social Engineering first intertwined with technology following previous milestones in telecommunications. Our expedition highlights the technological origins of Phone Phreaking, Computer Hacking, Social Engineering, and how these activities relate to modern attacks. The speaker pulls out numerous hardware relics from the past to show attendees and demo them throughout this presentation. Come learn about what the underground phone phreak and early computer hacker scenes were like, and get ready for some "Show & Telecom"! About the speaker: Matt Scheurer is the show host of the ThreatReel Podcast, and Vice President of Computer Security and Incident Response in a large enterprise environment. He has many years of hands-on technical experience. Matt is an official "Hacking is NOT a Crime" Advocate, serves on the Advisory Board for the Warren County (Ohio) Career Center "Information Technology and Cybersecurity" program, and also volunteers as a technical mentor for the Women's Security Alliance (WomSA). He has presented numerous Information Security topics at countless technology meetup groups, and prominent Information Security conferences, including keynotes at the Cybersecurity Collaboration Forum Cincinnati Leadership Exchange, the Information Security Summit in Cleveland, Queen City Con (0x1, 0x2, and 0x3) in Cincinnati, and SecureWV in Charleston. He is awarded with delivering lifetime conference Keynote Addresses at Queen City Con. Matt is also a 2019 comSpark "Rising Tech Stars Award" winner, named a "Top 12 Hacking Influencer" by Bishop Fox in 2023, and awarded a "Black Badge" for continuous community engagement at Queen City Con in 2024.

  4. Apr 29 ·  Video

    Pragathi Jha, Modeling Cyber Adversaries: A Critical Survey of Methods and Assumptions

    Cybersecurity practitioners face a persistent methodological problem: how should we reason about intelligent adversaries who observe our defenses, adapt their tactics, and choose targets based on our vulnerabilities? The field has responded with a fragmented toolkit. Quantitative risk assessment borrowed from safety engineering treats threat, vulnerability, and consequence as independent terms. Threat modeling frameworks such as STRIDE and attack trees emphasize structure but rarely quantify uncertainty. Game-theoretic models assume rationality and common knowledge that real attackers do not exhibit. Qualitative heat maps compress uncertainty into colored cells that cannot support budget optimization.This talk surveys these approaches critically, examining what each method commits you to and what it quietly sets aside. A common thread emerges: the alternatives can be understood as approximations to a Bayesian decision-theoretic ideal, each relaxing one or more assumptions for tractability. Modeling an adversary requires addressing four dimensions of uncertainty (what they want, what they know, what they can do, and how they decide) and the standard critiques of probabilistic cyber risk analysis (information asymmetry, correlated inputs, adaptation, the absence of objective base rates) turn out to be errors of naive practice rather than indictments of the methodology itself. Threat intelligence feeds, indicator matches, and shifts in attacker tradecraft fit naturally as Bayesian updates rather than as awkward inputs to frequentist frameworks. The survey closes not with a prescription but with a diagnostic question for practitioners and researchers alike: are the assumptions embedded in your chosen method appropriate for the decision you are trying to support? About the speaker: Pragathi Jha is a doctoral researcher in Industrial Engineering at Purdue University, where her work focuses on optimization, stochastic modeling, and game-theoretic approaches to decision-making under uncertainty. Her research lies at the intersection of operations research, applied probability, and strategic interaction, with an emphasis on developing rigorous mathematical frameworks for complex, adversarial systems.Her academic interests include multi-stage stochastic optimization, game theory, and the modeling of strategic behavior in dynamic environments. In the context of cybersecurity, she is particularly interested in adversarial decision-making, risk-aware resource allocation, and the design of resilient systems that account for uncertainty and strategic threats. Her work aims to bridge theoretical advances in optimization and game theory with practical applications in security, infrastructure protection, and data-driven decision support.Pragathi brings a strong foundation in quantitative methods and is committed to advancing research that is both mathematically rigorous and operationally impactful. Through her work, she seeks to contribute to the development of robust, scalable frameworks for analyzing and mitigating risks in complex, high-stakes environments.

  5. Apr 22 ·  Video

    Smriti Bhatt, Evolving Security Landscape in the Agentic AI-Enabled IoT Era

    The rapid evolution of connected devices and technologies has transformed the Internet of Things (IoT) into increasingly intelligent and autonomous systems. This talk focuses on the progression from traditional IoT to the Artificial Intelligence of Things (AIoT), and further toward Agent-Based IoT (AB-IoT), also referred to as Agentic AI-enabled IoT. As intelligent agents become embedded within IoT ecosystems, they introduce new capabilities for autonomy and decision-making, but also significantly reshape the security landscape. In this talk, I first outline the technological evolution from IoT to AIoT and Agentic AI-enabled IoT systems. I then discuss how the adoption of agentic intelligence in IoT environments introduces emerging security risks and threats with particular emphasis on challenges related to authentication, access control, and trust management in highly distributed and autonomous environments. I also present potential approaches to address these challenges, including zero-trust security frameworks and context-aware machine learning–based access control mechanisms. Finally, this talk highlights current research challenges and open problems in securing Agentic AI-enabled IoT systems, outlining future directions for building resilient, trustworthy, and secure next-generation Agentic AI-enabled IoT infrastructures. About the speaker: Dr. Smriti Bhatt is an Assistant Professor of Cybersecurity in the School of Applied and Creative Computing at Purdue University. She has received her Ph.D. and M.S. in Computer Science from the University of Texas at San Antonio and did her doctoral research at the Institute for Cyber Security (ICS) and NSF CREST Center for Security and Privacy Enhanced Cloud Computing (C-SPECC). Dr. Bhatt's research focuses on security and privacy in the Internet of Things (IoT) and Cyber-Physical Systems (CPS) leveraging Cloud and Edge Computing. Her research interests also include the application of AI and Machine Learning to secure IoT and CPS infrastructures in various application domains, such as Smart Health, Smart Home, and Wearable IoT. Some of her current research work includes access control models, secure data communication, and anomaly detection for different domains in Cloud-Enabled IoT. She has several conference and journal publications, and also continually serves as an expert reviewer for various journals and technical program committees for several conferences and workshops.

  6. Apr 15 ·  Video

    Gary Hayslip, The AI Arms Race

    Ransomware has evolved from basic digital extortion into a sophisticated, AI-powered threat that's faster,smarter, and more devastating than ever before. In this session, we'll explore how threat actors are weaponizing artificial intelligence to supercharge their operations—from automated reconnaissance and hyper-realistic phishing to malware that adapts in real-time to evade detection. We'll also examine how AI-driven ransomware exploits supply chain vulnerabilities to create cascading disruptions across entire industries.More importantly, we'll discuss practical strategies for fighting back: leveraging AI-powered behavior alanalytics and autonomous response tools, implementing zero-trust architecture,and building true organizational resilience through tested backup and recovery procedures. Whether you're in security operations, incident response, or infrastructure protection, this session will equip you with actionable insights to shift from a prevention-only mindset to one focused on preparedness and rapid recovery in today's evolving threat landscape. About the speaker: Gary Hayslip is an experienced Global Security Executive with a proven track record of delivering innovative security programs that protect billion-dollar enterprises at every touchpoint. He is intensely focused on driving continuous improvement to maximize the efficiency of security programs while minimizing costs. As an insightful thought leader, he possesses strong business acumen and a commitment to organizational mission, values, and goals. He has demonstrated the ability to collaborate with all levels of an organization to champion new ideas, gain buy-in, and build consensus. Hayslip brings extensive experience in information technology, security leadership, physical security, and risk management to his role as the Senior Security Advisor | CISO in Residence for Halcyon.ai. His previous executive positions include multiple roles as Chief Information Security Officer, Chief Information Officer, Deputy Director of IT, and Chief Privacy Officer for the U.S. Navy (Active Duty), the U.S. Navy (Federal Government employee), the City of San Diego, California, Webroot Software, and SoftBank Investments (Vision Fund & Vision Fund II).Hayslip is a proven cybersecurity expert with excellent communication and public speaking skills. He is skilled at explaining complex security and risk concepts to audiences with different levels of knowledge. Hayslip has earned a reputation as a highly effective communicator, author, and keynote speaker. He co-authored the "CISO Desk Reference Guide: A Practical Guide for CISOs – Volumes 1 & 2," "The Executive Primer: An Executive's Guide to Security Programs," "Developing Your Cybersecurity Career Path," and the "The Essential Guide to Cybersecurity for SMBs." He recently coauthored andpublished "Mastering Third Party Risk," a guide aimed specifically for security practitioners to help them manage the risk exposure to organizations from vendors and supply chains. These books are among the top resources for helping CISOs improve their leadership and business skills. Hayslip currently serves as an independent director on several boards and advises various other security and technology firms. He is an active member of the cybersecurity community and belongs to professional organizations such asISC2, NACD, ISACA, and Infragard. Hayslip holds several professional certifications, including CISSP, CISA, and CRISC, and has earned a BS in Information Systems Management from the University of Maryland,University College, and an MBA from San Diego State University.

  7. Apr 8 ·  Video

    Brian Peretti, Symposium Closing Keynote: AI, Cybersecurity, and the Path Forward

    Annual Security Symposium. Visit: https://ceri.as/2026 Artificial intelligence is rapidly transforming both the opportunities and risks within cybersecurity, creating a new landscape that today's students and researchers will soon inherit and shape. This keynote explores how AI is evolving from a supporting tool to a decision-making system, fundamentally changing how cyber threats are created, detected, and managed. It will examine emerging risks such as deepfakes, model manipulation, and systemic dependencies on shared technologies, while also addressing the growing role of regulation and the challenges of governing systems that are powerful yet often opaque. Most importantly, the session will highlight where the greatest opportunities lie—at the intersection of AI, cybersecurity, and policy—and how the next generation of professionals can play a defining role in building secure, resilient, and trustworthy systems for the future.  About the speaker: Brian J. Peretti is a career member of the Senior Executive Service at the United States Department of the Treasury. In his final position, he served as Treasury's Chief Technology Officer and Deputy Chief Artificial Intelligence (AI) Officer in the Office of Chief Information Officer.As Treasury's Chief Technology Officer, Mr. Peretti establishes, leads, and manages a comprehensive, multi-year strategic and long-range planning process that promotes the vision for IT and ensures consistent progress toward accomplishing the CIO's vision, while identifying and leveraging common technology solutions to support business processes and work methods and/or to improve effectiveness of current technologies while also developing appropriate policy for emerging technology such as Artificial Intelligence, Machine Learning, Biometrics and Quantum Computing. As Treasury's Deputy Chief AI Officer, Mr. Peretti supported Treasury's Chief AI Officer in advancing the Department's deployment of this emerging technology. In this capacity, he oversaw the publication of Treasury's report, Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector, and directed the subsequent lines of effort. Additionally, serving in this position has seen him designated as the Executive Officer for the Department's AI Governance Board as well as the Department's representative to the Office of the Director of National Intelligence's CAIO Council. In addition, Mr. Peretti leads the development of domestic and international operational resilience policy, including cyber, as part of Treasury's Sector Risk Management Agency responsibility for the financial services sector. In this role, he spearheads Treasury's efforts to increase multi-directional sharing of cyber threat and vulnerability information. He also serves as the United States's designated subject matter expert at the Group of 7 Cyber Expert Group (G-7 CEG). Mr. Peretti has served at the Treasury for over 22 years with increasing levels of responsibility, including being named the Senior Career Official Executing the Duties of the Assistant Secretary for Financial Institutions during the transition from the Obama to the Trump Administration. Based on his expertise in critical infrastructure protection and operational resilience, he was detailed to the Department of Homeland Security, Cybersecurity and Infrastructure Security Agency's National Risk Management Center during the intial response to the COVID-19 pandemic and served as the first Senior Advisor for Security and the Economy. He also speadheaded DHS response to the SolarWinds cyber incident. A sought-after speaker and presenter, Mr. Peretti has been the recipient of numerous awards and honors throughout his career. Most recently, he received the 12th Annual Billington CyberSecurity Leadership Award at the 2023 Annual Billington CyberSecurity Summit. Prior to joining the Treasury, Mr. Peretti was an associate in Shook, Hardy & Bacon's Corporate Banking and Finance Section in Washington, D.C., and was the General Counsel for the Wright Patman Congressional Federal Credit Union. He has authored numerous publications related to financial sector operations, including payment systems. Mr. Peretti received his bachelor's degree from Rider University (cum laude) in 1989, and his law degree from American University's Washington College of Law (cum laude) in 1992.

  8. Apr 1 ·  Video

    Jen Sims, Analyzing Supply Chain Risk in Mobile Applications for Home Energy Storage Systems

    The rapid adoption of mobile applications for managing consumer whole-house battery and energy systems has introduced new questions about software supply chain security. While these applications are not currently integrated with critical infrastructure, their growing role in connected energy environments highlights the importance of understanding the dependencies,permissions, and external services that support their operation. Many of these applications rely on shared third-party libraries, analytics frameworks, and messaging services, creating overlapping software ecosystems across vendors.In this talk, I will present an analysis of several battery-management mobile applications using static and dynamic analysis techniques. The study examines third-party dependencies, Android permission usage, and outbound network activity to identify common software components and shared external infrastructure. The results reveal significant overlap in libraries and permissions across applications, suggesting that vulnerabilities in widely used components could introduce shared risk pathways across multiple vendors. This work highlights the need for stronger dependency governance,permission minimization, and ongoing monitoring as mobile energy applications continue to evolve. About the speaker: Jen Sims is a cybersecurity technical professional in the Cyber Resilience and Intelligence Division at Oak Ridge National Laboratory (ORNL). Her research focuses on resilient cyber-physical systems and vulnerability assessment of technologies used within the electric grid, with particular emphasis on supply chain risk. She also conducts research in cybersecurity for manufacturing and is actively involved in cyber education outreach, engaging students from grade school through graduate programs.Jen earned a Master of Software Engineering and a Bachelor of Computer Science with a concentration in Secure Cyber Systems from the University of Texas at El Paso (UTEP). During her time at UTEP, she founded the Women in Cybersecurity (WiCyS) student chapter and helped launch the university's summer cybersecurity camps.Outside of her research, Jen is passionate about workforce development and cybersecurity education, volunteering with Oak Ridge Computer Science Girls (ORCsGirls) and creating hands-on cybersecurity activities to inspire the next generation of students.

Ratings & Reviews

4.1
out of 5
7 Ratings

About

CERIAS -- the Nation's top-ranked interdisciplinary academic education and research institute -- hosts a weekly cyber security, privacy, resiliency or autonomy speaker, highlighting technical discovery, a case studies or exploring cyber operational approaches; they are not product demonstrations, service sales pitches, or company recruitment presentations. Join us weekly...or explore 25 years of archives for the who's-who in cybersecurity.