Kian Esmaeili · Research Archive

Research and systems, with the evidence attached.

An actively maintained record of publications, experiments, platforms, and applied work in AI security, benchmark integrity, and reproducible research.

BENCHMARK INTEGRITYENDPOINT SECURITYREPRODUCIBLE RESEARCHCYBERSECURITY EDUCATIONEMBEDDED SYSTEMS

Selected work

Flagship work on evaluation, autonomous defense, and reproducible evidence.

Project index

Research, systems, and applied work.

Search by topic or filter by the kind of work. Every record points to its strongest available evidence: a publication, interactive article, live system, source repository, or research record.

Complete archive

6 records shown.

ResearchUnder review

Misleading Performance in Sysmon-Based Machine Learning

Near-perfect ransomware-detection accuracy can be an artifact of event-level data representation. This work tests five models on 6,258 labeled Sysmon events and shows how temporal aggregation exposes the gap.

Signal6,258 labeled events · 5 models
  • Benchmark integrity
  • Sysmon
  • Machine learning
  • Endpoint security
Evidence
Under-review manuscript · Interactive article · Experimental results
Context
First-author research manuscript
Methods
Sysmon telemetry · Identifier-leakage analysis · Temporal aggregation
ResearchPublished

AI-Driven Update Validation in Endpoint Security

An AI-driven validation framework for the class of update-integrity failures exemplified by the 2024 CrowdStrike Falcon content-update outage.

SignalPublished on IEEE Xplore
  • AI security
  • Endpoint security
  • Update validation
Evidence
Peer-reviewed publication · IEEE Xplore · DOI
Context
IEEE SoutheastCon 2026 · First author
Methods
AI-driven validation · Update-integrity analysis
PlatformsOngoing

RAVA

A publication format that releases a manuscript, dataset, and evaluation code as one interactive object, allowing readers to audit the pipeline and test its claims.

SignalFirst implementation live
  • Reproducible research
  • Interactive articles
  • Research infrastructure
Evidence
Publication framework · Interactive implementation
Context
Reproducible, Auditable, Verifiable Articles
Methods
Interactive publishing · Evidence-linked evaluation
PlatformsPaper under review

Operation North Guard

A multi-variant dynamic flag platform that salts and hashes flags per student, making cybersecurity coursework resistant to answer-sharing while keeping verification automatic.

Signal10+ hands-on challenges
  • Cybersecurity education
  • Assessment integrity
Evidence
Live platform · Source repository · Under-review paper
Context
First-author platform and manuscript
Methods
Per-student flag variants · Salted hashes · Next.js · TypeScript · MDX
Research experienceAugust–December 2025

Embedded Systems Security Research

Side-channel and fault-injection work on password-verification firmware using ChipWhisperer-Nano, including timing, power, electromagnetic, and acoustic analysis.

SignalChipWhisperer-Nano
  • Embedded security
  • Side channels
  • Firmware
Evidence
Institutional research experience · Technical work
Context
Georgia Tech Research Institute · VIP Program
Methods
Timing analysis · Power analysis · Fault injection · Electromagnetic analysis
Applied workMay–November 2025

Cybersecurity Examination Automation

Power Apps automation for data analysis and reporting in cybersecurity examination workflows, alongside enterprise AI use cases for cybersecurity and operational work.

SignalPower Apps automation
  • Applied AI
  • Cybersecurity
  • Operational resilience
Evidence
Professional system record · Applied research experience
Context
Federal Reserve Bank of Atlanta · Supervision & Regulation
Methods
Power Apps · Data analysis · Reporting automation

Research direction

Defense that can explain itself.

The next direction combines behavioral telemetry with AI reasoning: detecting threats earlier, evaluating the detector with the same scrutiny this work argues for, and requiring the system to justify a decision when asked.