Application domain

AI and cybersecurity

Security is a game: attackers adapt to the defence. I have spent more than a decade applying game theory and machine learning to security problems, in academic projects and inside companies that protect hundreds of millions of users.

Game-theoretic defence

  • Honeypots and deception: where to place decoys so that a rational attacker is most likely to reveal themselves (GameSec 2012; Advances in Information Security 2015). Recently: mapping the deception surface of MITRE ATT&CK, i.e. which attacker techniques decoys can and cannot cover (2026).
  • Attack-graph games for optimal network hardening against strategic attackers (IJCAI 2015, AAMAS 2015, IEEE Intelligent Systems 2016, Computers & Security 2019).
  • Intrusion detection against a rational adversary, a project funded by the Office of Naval Research Global where I was PI. Also: detecting data exfiltration and randomised operating points for adversarial classification.

Machine learning for detection

  • Malware detection under concept drift: learning with predictions of future malware (2024).
  • Robust malware classifiers trained with adversarial strings generated from perturbed latent representations (2021).
  • Avast-CTU Public CAPE Dataset (2022), a public dataset of malware behaviour reports for research.
  • Learning from raw structured data: hierarchical multiple-instance learning (Mill.jl, JsonGrinder.jl) and explaining such classifiers.

Agents and security

NASimEmu (ESORICS 2023 workshop) is a network attack simulator and emulator for training RL agents that generalise to network scenarios they have not seen. This is a step toward autonomous agents for penetration testing and defence. With the rise of LLM agents, the field is moving in two directions at once:

  • agents for security, which triage alerts, investigate incidents and emulate attackers;
  • security of agents, which must resist prompt injection, manipulation and poisoned memories.

Both directions call for the adversarial reasoning our group is known for.

Industry experience

I have worked on security problems with Cisco and Trend Micro, and inside Avast and Gen (Norton, Avast, AVG, Avira, LifeLock) as Principal AI Scientist and AI Architect (2019–2024). There I led the move of a malware detector used by 350 million people from hand-written rules to deep learning, and the AI architecture of an LLM-based scam analysis assistant. I also co-authored three US patents.

Building a security product or a consortium on AI for cybersecurity? Let's talk.

Papers

Key papers: security

  • 2026
    Decoys Cannot Go Everywhere: Mapping the Deception Surface in MITRE ATT&CK
    Veronica Valeros, Carlos Catania, Viliam Lisý, Harm Griffioen
    arXiv preprint
  • 2024
    Counteracting Concept Drift by Learning with Future Malware Predictions
    Branislav Bošanský, Lada Hospodkova, Michal Najman, María Rigaki, Elnaz Babayeva, Viliam Lisý
    arXiv preprint
  • 2023
    NASimEmu: Network Attack Simulator & Emulator for Training Agents Generalizing to Novel Scenarios
    Jaromír Janisch, Tomáš Pevný, Viliam Lisý
    Workshop at ESORICS 2023 (LNCS)
  • 2022
    Avast-CTU Public CAPE Dataset
    Branislav Bošanský, Dominik Kouba, Ondrej Manhal, Thorsten Sick, Viliam Lisý, Jakub Křoustek, Petr Somol
    arXiv preprint
  • 2019
    Hardening networks against strategic attackers using attack graph games
    Karel Durkota, Viliam Lisý, Branislav Bošanský, Christopher Kiekintveld, Michal Pěchouček
    Computers & Security
  • 2015
    Optimal network security hardening using attack graph games
    Karel Durkota, Viliam Lisý, Branislav Bošanský, Christopher Kiekintveld
    IJCAI 2015
  • 2012
    Game Theoretic Model of Strategic Honeypot Selection in Computer Networks
    Radek Píbil, Viliam Lisý, Christopher Kiekintveld, Branislav Bošanský, Michal Pěchouček
    LNCS
All publications on Google Scholar →
Student theses

Security

Master's and bachelor's theses I supervised at CTU.