Publications
Showing 22 results for Author: T S. Oesch
Jul, 2026
Conference Paper
FATHOMS-RAG: A Framework for the Assessment of Thinking and Observation in Multimodal Systems that use Retrieval Augmented Generation
Retrieval-augmented generation (RAG) has emerged as a promising paradigm for improving factual accuracy in large language models (LLMs). We introduce a benchmark designed to evaluate RAG pipelines as a whole, evaluating a pipelines ability to ingest several modalities of information. We present (1) a curated dataset of 93 questions designed to evaluate a pipeline's ability…
Mar, 2026
Conference Paper
Towards a High Fidelity Training Environment for Autonomous Cyber Defense Agents
Cyber defenders are overwhelmed by the frequency and scale of attacks against their networks. This problem will only be exacerbated as attackers leverage AI to automate their workflows. Autonomous cyber defense capabilities could aid defenders by automating operations and adapting dynamically to novel threats. However, existing training environments fall short in areas suc…
Mar, 2026
Conference Paper
On the Abuse and Detection of Polyglot Files
A polyglot is a file that is valid in two or more formats. Polyglot files pose a problem for file-upload and generative AI web interfaces that rely on format identification to determine how to securely handle incoming files. In this work we found that existing file-format and embedded-file detection tools, even those developed specifically for polyglot files, fail to relia…
Mar, 2026
Conference Paper
Toward the Detection of Polyglot Files
Standardized file types play a key role in the development and use of computer software. However, it is possible to confound standardized file type processing by creating a file that is valid in multiple file types. The resulting polyglot (many languages) file can confuse file type identification, allowing elements of the file to evade analysis. This is especially problema…
Mar, 2026
ORNL Report
ORNL AI Capabilities Summary
ORNL AI-powered capabilities in cybersecurity: CESER sponsor is cataloging AI-powered lab capabilities in cybersecurity and has asked us to complete this one-page template for each capability. These can be CESER-funded work, LDRD efforts, even projects or efforts funded by other agencies.) Note the request is for capability, not project.
Oct, 2025
Journal
The Path to Autonomous Cyberdefense
Defenders are overwhelmed by attacks against their networks, which will only be exacerbated as attackers leverage artificial intelligence to automate workflows. We propose a path to autonomous cyberagents able to augment defenders by automating critical steps in the cyberdefense lifecycle.
Oct, 2025
Journal
Agentic AI and the Cyber Arms Race
In this article, we examine the implications for cyberwarfare and global politics as agentic artificial intelligence becomes more powerful and enables the broad proliferation of capabilities only available to the most well-resourced actors today.
May, 2025
Conference Paper
Estimating vehicle fuel economy from overhead camera imagery and application for traffic control
In this work, we explore the ability to estimate vehicle fuel consumption using imagery from overhead fisheye lens cameras deployed as traffic sensors. We utilize this information to simulate vision-based control of a traffic intersection, with a goal of improving fuel economy with minimal impact to mobility. We introduce the ORNL Overhead Vehicle Dataset (OOVD), consistin…
Feb, 2024
Conference Paper
AI ATAC 1: An Evaluation of Prominent Commercial Malware Detectors
This work presents an evaluation of six prominent commercial endpoint malware detectors, a network malware detector, and a file-conviction algorithm from a cyber technology vendor. The evaluation was administered as the first of the Artificial I ntelligence Applications t o Autonomous Cybersecurity (AI ATAC) prize challenges, funded by / completed in service of the US Navy…
Dec, 2023
Journal
Testing SOAR Tools in Use
Investigations within Security Operation Centers (SOCs) are tedious as they rely on manual efforts to query diverse data sources, overlay related logs, correlate the data into information, and then document results in a ticketing system. Security Orchestration, Automation, and Response (SOAR) tools are a relatively new technology that promise, with appropriate configuratio…