E. Ologunde Case file

Scene 04 of 06The AI threadCase file: E. Ologunde

Scene 04

The AI thread

Starts in 2023 on the route. Research in progress; praxis began fall 2026.

In plain English: AI can speed up security work, but it can be wrong or be tricked. I let it suggest, never decide, and I protect AI systems themselves from attack.

Where AI helps, where it gets attacked, and where it is not allowed to decide.

Exhibit DAI security

AI proposes, evidence decides

Sources: the Breakwater paper and phase work (doctoral coursework), and the design notes of two systems I runStatus: research in progress; praxis began fall 2026

7
AI-assisted techniques, each tied to the evidence that must exist before its output counts
3
defenses on one federated model: poisoning filter, differential privacy, drift correction
5
stages before an automated fix runs: simulate, verify, approve, execute, health-check

D.1 Threat model: letting a language model near systems I run

In plain English: a map of how an AI assistant connected to my own systems could be misused, and the safeguard I put in place at each step.

Two of my own systems use a language model: my operations platform, HoWz, has a question pane where a model may suggest changes, and the lab runs a small local model on a CPU. Pick any part of the flow to see what can go wrong there and the control in the design.

Illustrative Written for this page from the design notes of HoWz and the lab. It is not an audit.

Threats at this step

Hover, tap or tab to a step in the flow. Each shows the threats that enter there and the control in the design, with its source.

The threat model as a table
Threat model for a language model that can suggest changes to systems the subject runs, with the control from each design and its source
No.ThreatEnters throughControl in the designSource
T-1Prompt injection steers the model toward a harmful changeText the model readsThe model can only propose. Code validates every proposal, and nothing is written until I approve it.HoWz
T-2Excessive agency: the model acts instead of suggestingModel outputProposals are data, not actions: nothing is written until a separate human step approves it.HoWz
T-3Tampered model runtimeInstallationInstalled only after its release checksum was verified.Lab
T-4Model endpoint reachable from outsideNetworkThe local model listens on the lab network only.Lab
T-5Stolen session on the approval screenBrowserPassword gate, Content Security Policy, and HttpOnly, SameSite=Strict cookies.HoWz

D.2 The rule, in the research

In plain English: in my research an AI tool may point at a possible problem, but the problem only counts once a real test confirms it.

Language models are fast and confidently wrong often enough that I do not let one close a finding. In the Breakwater paper every AI-assisted technique gets the same treatment: it may propose candidates and rank them, but a finding closes only when a measured or scoped, simulated witness exists. AutoML ranks known CVE features; it does not discover vulnerabilities. An LLM proposes fuzzing inputs; the proof is the crash, not the model’s description of one.

AI-assisted techniques and the witness each needs. From the Breakwater paper, doctoral coursework.
TechniqueWhat it may doWitness required
AutoML triage rankingrank candidatesmeasured CVE and EPSS features
Nuclei templatestargeted checksmeasured template match
OpenVAS / GVMscanner evidencemeasured plugin result
Default-credential checkscoped proofsimulated loopback login
Firmware entropysupply-chain signalmeasured file evidence
Protocol grammar from capturesstructure inferencemeasured wire capture
LLM mutation and RL fuzzingpropose test inputsmeasured crash or response

D.3 AI as the target: defending the models themselves

In plain English: AI models can be attacked too, for example by feeding them bad training data. These are defenses I built and tested in my doctoral project.

A federated intrusion detector that expects some of its clients to lie. In Breakwater’s collaborative phase I trained a Transformer-based intrusion-detection model across simulated sites without pooling their raw traffic. Multi-Krum aggregation drops poisoned updates from malicious clients, differential privacy (Gaussian mechanism with Rényi accounting) bounds what any one site’s data can leak, and SCAFFOLD corrects client drift.

Autonomous agents on a short leash. A reinforcement-learning agent (PPO) plans offensive tests inside a decision model, but only behind a tiered safety controller that moves from simulation or shadow mode to controlled to autonomous, with every step written to a SHA-256 evidence chain. The remediation phase asks before it acts: simulate, verify, approve, execute, health-check, with rollback checkpoints.

Also on file: the App Academy certificate in AI-powered software development and generative AI engineering, Introduction to Generative AI (Google Cloud), the SANS AI Cybersecurity Forum, the Agentic AI Bootcamp at the Howard AI Network, a 2026 preprint on adversarial machine learning against automotive attack surfaces, and AI security risk and governance advisory at Cyntraix.