Research
Security through measurability, making abuse of legitimate functionality observable at scale.
Adversaries frequently repurpose legitimate features rather than exploit implementation flaws, attacks known as abuse of functionality. Because these features work as intended, vulnerability disclosure alone cannot reveal how they are misused. For each technology I study, I ask which legitimate capability is being exploited, what instrument makes that abuse observable at scale, and how the resulting evidence can inform defenses that deter abuse without disrupting legitimate use.
My work is organized around three recurring barriers to observing abuse: it is hidden by design, obscured by complexity, or expensive by convention.
Hidden by Design
01Obscured by Complexity
02Expensive by Convention
03Future Directions
As new web features become part of everyday browsing, I plan to extend this agenda in three directions:
- Web features that signal trustsuch as age-verification flows
- AI-mediated interactionssuch as embedded chatbots and browser agents
- AI-generated websitesand their misuse for phishing and malware