Seminar – Angelos Stavrou

We cordially invite you to the Department of Computer Science Colloquium, which will take place on Wednesday, 21 October 2026, from 10:00 to 11:00, in Room 148, Faculty of Pure and Applied Sciences (FST-01).

The speaker will be Dr Angelos Stavrou, Professor of Electrical and Computer Engineering at Virginia Tech. His talk is entitled “Enter the MATRIX: Learning and Validating Agentic Cybersecurity Strategies in Hybrid Environments.”

Abstract:

Network hardening still depends on manual, expert-driven work that is slow, error-prone, and offers no guarantee of coverage. Autonomous agents promise to scale that work, but the environments we train them in do not resemble the networks they are meant to defend. Today’s cybersecurity simulators use fixed topologies, abstract away system-level behavior, and reduce the threat model to availability alone — so agents memorize layouts instead of learning strategies. This talk introduces MATRIX, a training and evaluation infrastructure that deploys attacker, defender, and user agents into cybersecurity games spanning both fast simulation and high-fidelity emulation. A unified API makes the underlying environment indistinguishable to the agent, so the same unmodified policy can be trained in one and validated in any environment. MATRIX randomizes network topology and attacker footholds every episode, supports red-blue agent co-evolution, and extends objectives across the full confidentiality, integrity, and availability triad. I will present results from more than 6,000 games across 18 red and blue agents. Our results show that training must happen in simulation: 27 hours per agent versus an extrapolated 43,000 hours in emulation due to the real-time clock requirements and delays. However, agents that perform near-perfect in simulation degrade sharply when deployed in emulation. This exposes a realism gap for exploit chains and false positives the simulator never surfaces. The conclusion is that there is a need for both simulation and emulation for both attack and defense using trained agents in simulation which are validated in emulation to prove true positives while eliminating false positives.

Short Bio:

Dr. Angelos Stavrou is a professor in the Bradley Department of Electrical & Computer Engineering at Virginia Tech and the founder of Quokka Inc. and A2 Labs. Dr. Stavrou is a serial entrepreneur and the founder of Quokka, A2 Labs, Aether Argus, WayWave, Impedyme, and Weavian Inc. Quokka is a VC-backed mobile security company with a valuation of more than $100 M. Dr. Stavrou has also served as a principal investigator on research awards from NSF, DARPA, IARPA, DHS, AFOSR, ARO, ARL, and ONR. He has written more than 160 peer-reviewed conference and journal articles. Stavrou received his M.Sc. in Electrical Engineering, M.Phil., and Ph.D. (with distinction) in Computer Science, all from Columbia University. Stavrou is an Associate Editor of IEEE Transactions on Computers, IEEE Security & Privacy, and IEEE Internet Computing magazine, and part of the governing board of the IEEE Blockchain initiative. He is a senior member of the ACM, USENIX, and IEEE. In 2013, he received the IEEE Reliability Society Engineer of the Year award. His team was awarded the DHS Cyber Security Division’s “Significant Government Impact Award” in 2017 and the “Bang for the Buck Award” in 2019. He received the IEEE Reliability Society Lifetime Award in 2024.