Red teams test the distance between policy and packet.

Gavin Black

I lead AI security research and engineering at Leidos: automated red teaming, agents and the tools they connect to, and fuzzing. I still build the tests and run them myself, and I explain the results in plain English.

15+engineers and researchers led
5first-author IEEE papers
10+proposals that include the work
700+GitHub stars, iMAS library
4:57
LatestSep 2026

Jev can't see. It still won 57 of 59 games.

Five minutes on a decision-model benchmark: a text-only model that can't tell red from white, and still wins text adventures.

Work

Projects

Things I've built recently, newest first. Each card says what the project is and what came out of it.

AI evaluationSep 2026

Reading the State

A benchmark for decision models: 629 frozen positions from TextWorld, a roguelike and Minesweeper, each with an exact right answer. Every model is scored against the best fixed rule that never looks at the board. A model can't look smart by accident.

What I foundJev, a text-only model, called a solid red square "white", yet with its move history it won 57 of 59 TextWorld games, more than any other model tested. No decision model beat the board-blind rule at Minesweeper. And one of my own earlier results didn't survive: 92% of that roguelike set was a single rule. I retracted it.

PythonBenchmarksDecision models
AI agentsSep 2026

The effort dial

Claude Code, Codex CLI and Grok CLI each did the same hard job at two reasoning-effort settings: turn an MP3 into a cellular-automaton music video, then narrate an explainer of their own code.

What I foundFor two of the three, turning effort up made the run faster and cheaper: Grok 4.6 went from 82 minutes and at least $8.23 to 35 minutes and $4.27, because it made fewer calls with more reasoning in each. Claude's extra-high run cost more. There was one run per setting, so treat it as a case study.

Claude CodeCodexGrokCost
VisualsSep 2026

Math visualizers

Music visualizers where the audio changes the math itself. One is an equation evaluated at every pixel with the song's frequency bands as variables. The others are cellular automata whose rule the music picks, and a 4D solid rotated by the track. The video explains the technique in under three minutes.

PythonFFTCellular automataRaymarching
HardwareSep 2026

The Clock

A fullscreen clock made as a gift. It runs 24/7 on a small OLED panel driven by a Raspberry Pi 4, with the time, the weather, and alert icons that only appear when something at home needs attention.

The hard partEverything drifts slowly so the panel doesn't burn in. Redrawing only what changed took it from 10–35% of a CPU core to 6.6% on the Pi.

PythonPygameRaspberry Pi
ToolJul 2026

Music video generator

A headless command-line tool that renders a music visualization video from a track and a background image: radial or bar spectrum styles, overlays, titles, animated backgrounds and burned-in subtitles.

PythonFFmpegCLI
Screenshot of the daily AI/ML security brief page
AutomationJul 2026

Daily Feed

A brief on AI/ML security research, incidents, model releases and agent tooling from the last day or two. It is written and published at 7:55 every morning without anyone touching it.

How it worksIt runs headless Claude Code with web search and a strict JSON schema inside a Docker container, renders the result to a static page, and keeps a dated archive of every edition.

Claude CodeDockersystemd
Mobile security2013–2016

Encrypted Core Data (MITRE iMAS)

An iOS Core Data store that encrypts the whole database with SQLCipher, from MITRE's open-source iOS Mobile Application Security project. I was one of its two active researchers and the library's top contributor.

Why it matteredIt addresses two of the most common mobile weaknesses, missing and weak encryption of stored data (CWE-311 and CWE-326). It has more than 700 stars and 200 forks on GitHub.

Objective-CSQLCipheriOS
Research

Papers and talks

Peer-reviewed work on LLM code security, fuzzing and security datasets, plus a patent application. Each one has a plain-English version, because the finding should make sense to someone who will never read the paper.

2026SPIE Assurance and Security for AI-enabled Systems

MCP safety audit: LLMs with the Model Context Protocol allow major security exploits

Co-author, with John Halloran and Brandon Radosevich

When an LLM is connected to tools through the Model Context Protocol, it can be talked into attacking the developer's own machine: running malicious code, opening remote access, and stealing credentials. The paper shows this against leading models and introduces a scanner that audits MCP servers for these holes.

2025IEEE Data Descriptions, vol. 2

Descriptor: Firewall Attack Detections and Extractions (FADE)

A dataset for testing web firewalls and language-model detectors: 50 million HTTP requests, about half of them attacks drawn from open-source firewall rule sets and public penetration-testing collections, mixed into realistic traffic. Every attack is labeled with its category and the exact bytes where the payload sits.

2025IEEE Transactions on Emerging Topics in Computational Intelligence, vol. 9

Balancing Security and Correctness in Code Generation: An Empirical Study on Commercial Large Language Models

I gave commercial LLMs (GPT-3.5 and 4, Claude Instant and Opus, Gemini 1.0) programming tasks that tend to produce well-known security bugs, then tested what they wrote. Security-focused prompts cut the vulnerabilities, but at a cost in correctness. No prompt reliably did both. Which model you use mattered more than any prompt.

2024Dissertation, Dakota State University

RUFF: Resource Usage Fuzzing Framework

Most fuzzers only reward crashes and new code paths. RUFF also measures how much CPU and memory each input uses, and shows that these measurements are independent of each other and can tell where a set of inputs came from, including whether an LLM wrote them.

2024US patent application 2024/0248984 A1

Process for Generating Offensive and Defense Security Dataset Augmentation with Invariance and Distribution Independence

With Paul F. Roysdon, assigned to Leidos. Application, pending.

A way to grow network and software security datasets so machine-learning models can be trained on them. The models feed a tool that automates training and deploying network defenses, and they learn what attacks look like as a whole instead of matching fixed patterns.

2024IEEE ICNC

Security Dataset Augmentation Invariance and Distribution Independence

A security label depends on behavior, not statistics: a SQL injection is still an injection after you rewrite it, as long as the attack still works. That allows ways of growing a training set that go beyond the usual machine-learning rules. Every augmentation tested helped a query classifier, most of all the ones that extended the attack logic.

Talks and demos

  • 2026SPIE Assurance and Security for AI-enabled SystemsMCP safety findings
  • 2025Military Sensing SymposiumAutomated AI-assisted red teaming
  • 2025National Cyber Summit, Huntsville
  • 2025Air & Space Forces Association Warfare SymposiumLive demos of AI cyber capabilities
  • 2024IEEE ICNCSecurity dataset augmentation
Videos

Older videos

Math, automata and graphics experiments from 2009–2012. The newer explainers are with the projects above. Everything is on the channel.

Show 8 older videosHide older videos
2:12

Wolfram automata reacting to music

2009Java
0:39

Zooming into the essential singularity of e^(1/z)

2010Haskell
1:27

Collatz conjecture sequence lengths

2010Haskell
0:20

Self-modifying 2D Turing machines

2009Automata
2:31

A visual feedback loop with emergent behavior

2011Graphics
8:18

Pretty Graph: images from music

2012Haskell
3:49

HyperNova: a music-reactive exploration game

2012Java, on Chris Wellons' engine
0:42

Driving an Arduino from Haskell

2010Hardware
Background

Experience

  1. 2025 – nowLeidos · Director, Cyber AutonomyLeads 15+ engineers and researchers in AI security.
  2. 2020 – 2025Leidos · Principal Research Scientist and Solutions ArchitectLed AI security projects from proposal to prototype.
  3. 2008 – 2020MITRE · Lead Cyber Systems EngineerCVE backend, the iMAS iOS security project, and Air Force platform security.
  4. 2006 – 2008Lockheed Martin · GPS Software EngineerEncryption drivers for GPS satellite payloads.

PhD, Cyber Defense, Dakota State University (2024)MS, Mathematics, University of Massachusetts Lowell (2014)BS, Computer Science, Purdue University (2006)

Full résumé (PDF)
About

How I work

I like measuring things properly, and I like explaining them.

A lot of my job is taking what a research team finds to the people who decide what gets built, in terms they can act on, while staying hands-on enough to keep up with the researchers. I still write the tools, run them, and produce the numbers myself.

Measuring properly means running a test enough times to trust it, putting the dumb baseline next to the clever result, and saying so when a result doesn't hold up. The decision-model benchmark above retracted one of its own earlier results, and says so near the top of its README.

Explaining means the finding should survive being told to someone outside the field in a couple of sentences. If I can't do that, I don't understand it well enough yet. It's why the papers here have plain-English versions, and why I make short videos about the work.

The best way to reach me is LinkedIn.

Ask me about

  • Red teamingAutomated red teaming with frontier models, and digital twins to run it in.
  • AgentsTool-using LLMs, MCP servers, prompt injection, and what connectors pass to models.
  • FuzzingLLM-written seeds and harnesses, and fuzzing for resource usage instead of crashes.
  • Code securityHow often LLM-generated code is insecure, and which prompts actually help.
  • EvaluationBenchmarks with baselines, so a model can't look smart by accident.
  • ExplainingTurning research into terms the people deciding can act on: talks, write-ups, videos.