Writing
Field notes on building and measuring detections — for classic logs and for attacks against AI systems.
2026-07-12
My detection models score 100% on everything. That's a red flag, not a feature.
A weekend detection lab, sixteen trained models, perfect metrics on almost every row — and why the most honest number on the dashboard was a 0.0%. On synthetic fixtures, dataset naivety masquerades as model quality.
2026-07-07
Backtesting detection rules — including the ones for AI attacks
A lottery-prediction backtester, stripped of its models and repointed at Sigma rules. Two findings from real public data: a rule that was right and still blind, and keyword rules that catch under 9% of real jailbreaks.