Home / AI & ML

AI & Machine Learning

Applying deep learning and AI to security problems — and validating the results honestly, even when that means reporting a model is worse than it looks.

PythonTensorFlowAmazon SageMakerAzure AI FoundryGRU / Deep Learning
§ 01Capstone projects

AI-assisted defence.

Two full AI-SOC systems, from data pipeline through to analyst-ready output.

01 Threat Intelligence · NLP · Knowledge Graphs

ThreatFusion AI — CTI Fusion Pipeline

An end-to-end defensive threat-intelligence pipeline: ingests CTI reporting, extracts indicators of compromise, proposes MITRE ATT&CK mappings with a supervised classifier, scores risk, builds a knowledge graph, and exports STIX 2.1 bundles.

Honest evaluationA "perfect" 0.90 F1 turned out to be a data-leakage artefact — held-out template testing collapsed it to 0.27. I rebuilt the detection backlog on analyst-validated labels rather than shipping a misleading metric.
60Reports processed
362STIX objects
85·302Graph nodes·edges
PythonScikit-LearnSTIX 2.1MISP / OpenCTIKnowledge Graphs
02 Deep Learning · Network Detection

ThreatNet — AI-Assisted SOC Detector

A supervised deep-learning detector classifying network flows into benign traffic plus five attack behaviours — reconnaissance, brute force, web attack, exfiltration, and botnet C2. Covers the full lifecycle: leakage-controlled preprocessing, class-imbalance handling, explainability, and a streaming live-detection demo.

Endpoint coverageA complementary GRU host-log model extends detection from network flows to Linux authentication sessions — flagging brute force, privilege misuse, and persistence.
0.9994Macro-F1
30KFlows classified
43Incidents auto-raised
PythonTensorFlowGRUColab GPU
§ 02Hands-on labs

Cloud ML & generative AI.

AWS ML — Amazon SageMaker

AWS

An end-to-end ML workflow on Amazon SageMaker: notebook instances, data ingestion and exploratory analysis, feature encoding, model training and deployment, performance metrics, and hyperparameter tuning — culminating in an airplane-delay prediction challenge.

SageMakerJupyterLabPandasEDAHyperparameter Tuning

Azure AI — AI Foundry

Azure

Built a generative-AI project in Microsoft Azure AI Foundry: deployed and tested a GPT-4.1 model, worked with project and model endpoints, and integrated the AI Foundry toolkit into Visual Studio Code.

Azure AI FoundryGPT-4.1GenAIModel DeploymentVS Code
§ 03Language

Built in Python.

Python PRIMARY LANGUAGE

Every model, pipeline, and experiment on this page is written in Python — from TensorFlow deep-learning detectors and Scikit-Learn classifiers to Qiskit quantum circuits and the data engineering that feeds them.

TensorFlowScikit-LearnPandasNumPyMatplotlibQiskitNLTK
§ 04Credentials

AI & Python certifications.

Click a certificate name to view it.

IBM · Coursera · Dec 18, 2025
Cisco Networking Academy · Python Institute · Completed 11 Apr 2026
Cisco Networking Academy · Python Institute · Completed 26 Apr 2026
AVAILABLE FOR SOC · RED TEAM · NETWORK ROLES

Interested in AI for security?

Available for ML engineering, AI security research, and detection-engineering roles.