Publications
2026
[IEEE S&P] Multiagent LLM Systems for Security Operations; IEEE Security & Privacy. Kim Hammar. IEEE Proceedings, bibtex.
[Submitted] Recovery Control in Replicated Systems through Autonomous Multiagent Rollout; submitted. Kim Hammar and Yuchao Li. ArXiv(preprint), bibtex.
[Submitted] Causal Online Learning of Safe Regions in Cloud Radio Access Networks; submitted. Kim Hammar, Tansu Alpcan, and Emil C. Lupu. ArXiv(preprint), bibtex.
[GameSec] Multiagent Incident Response Planning with Code Models; Conference on Game Theory and AI for Security (GameSec), Ann Harbor, Michigan, USA, October 26th-28th 2026. Kim Hammar, Tansu Alpcan, and Emil C. Lupu. To appear.
[CDC] Optimal Stopping of Self-Refining Foundation Models; 65th IEEE Conference on Decision and Control, Honolulu, Hawaii, USA, Dec 15th-18th 2026. Kim Hammar, Tansu Alpcan, and Emil C. Lupu. To appear. ArXiv(preprint), bibtex.
[ESORICS] Agentic Incident Response through Digital Twin-Enhanced Multiscale Planning; 31st European Symposium on Research in Computer Security (ESORICS) 2026. Yiran Gao, Tao Li, and Kim Hammar. To appear. ArXiv(preprint), bibtex.
[MLSys] CSLE: A Reinforcement Learning Platform for Autonomous Security Management; Ninth Annual Conference on Machine Learning and Systems (MLSys 2026) 2026, Bellevue, WA, USA, May 18th-22nd 2026. Kim Hammar. Proceedings, presentation, arXiv(preprint), bibtex.
[AAAI symposium] In-Context Autonomous Network Incident Response: An End-to-End Large Language Model Agent Approach; AAAI summer symposium 2026, Seoul, South Korea, June 22-24 2026. Yiran Gao, Kim Hammar, and Tao Li. AAAI proceedings, arXiv(preprint), bibtex.
[NOMS] Hallucination-Resistant Security Planning with a Large Language Model; IEEE/IFIP Network Operations and Management Symposium (NOMS) 2026, Rome, Italy, May 18-22 2026. Kim Hammar, Tansu Alpcan, and Emil C. Lupu. ArXiv(preprint), bibtex.
[NDSS] Incident Response Planning Using a Lightweight Large Language Model with Reduced Hallucination; Network and Distributed System Security (NDSS) Symposium 2026, San Diego, USA, February 23-27 2026. Kim Hammar, Tansu Alpcan, and Emil C. Lupu. Proceedings, arXiv(preprint), NDSS Video, news article, bibtex.
[AAAI] Scalable Solutions to Zero-Sum Partially Observable Stochastic Games Through Belief Aggregation with Approximation Guarantees; 40th AAAI Conference on Artificial Intelligence 2026, Singapore, January 20-27 2026. Kim Hammar and Tansu Alpcan. AAAI Proceedings, AAAI Video, Poster, bibtex.
2025
[Submitted] Online Identification of IT Systems through Active Causal Learning; submitted. Kim Hammar and Rolf Stadler. ArXiv(preprint), bibtex.
[TIFS] Adaptive Network Security Policies via Belief Aggregation and Rollout; TIFS 2025: IEEE Transactions on Information Forensics and Security (IEEE TIFS). Kim Hammar, Yuchao Li, Tansu Alpcan, Emil C. Lupu, and Dimitri Bertsekas. IEEE Proceedings, arXiv(preprint), bibtex.
[Submitted] Feature-Based Belief Aggregation for Partially Observable Markov Decision Problems; submitted. Yuchao Li, Kim Hammar, and Dimitri Bertsekas. ArXiv(preprint), bibtex.
[TIFS] Adaptive Security Response Strategies through Conjectural Online Learning; TIFS 2025: IEEE Transactions on Information Forensics and Security (IEEE TIFS). Kim Hammar, Tao Li, Rolf Stadler, and Quanyan Zhu. IEEE Proceedings, arXiv(preprint), bibtex.
[AiSec] Online Incident Response Planning under Model Misspecification through Bayesian Learning and Belief Quantization; ACM CCS AiSec 2025: 18 th ACM Workshop on Artificial Intelligence and Security, Taipei, Taiwan, Oct 17. Kim Hammar and Tao Li. ACM Proceedings, arXiv(preprint), Poster, bibtex.
2024
[Submitted] Optimal Defender Strategies for CAGE-2 using Causal Modeling and Tree Search; submitted. Kim Hammar, Neil Dhir, and Rolf Stadler. ArXiv(preprint), bibtex.
[GameSec] Intrusion Tolerance as a Two-Level Game; GameSec 2024: International Conference on Decision and Game Theory for Security, New York, USA, Oct 16-18. Kim Hammar and Rolf Stadler. Springer book chapter, bibtex.
[CDC] Conjectural Online Learning with First-order Beliefs in Asymmetric Information Stochastic Games; 63rd IEEE Conference on Decision and Control (CDC’24), Milan, Italy, December 16-19, 2024. Tao Li, Kim Hammar, Rolf Stadler, and Quanyan Zhu. IEEE Proceedings, arXiv(preprint), bibtex.
[DSN] Intrusion Tolerance for Networked Systems through Two-Level Feedback Control; 54th IEEE/IFIP Dependable Systems and Networks Conference (DSN’24), Brisbane, Australia, June 24-27, 2024. Kim Hammar and Rolf Stadler. IEEE Proceedings, arXiv(preprint), bibtex, Poster.
[NOMS] Online Policy Adaptation for Networked Systems using Rollout; NOMS 2024: IEEE/IFIP Network Operations and Management Symposium, Seoul, South Korea May 6-10. Forough Shahab Samani, Kim Hammar and Rolf Stadler. IEEE Proceedings, PDF, bibtex.
[Poster] Intrusion Tolerance for Networked Systems through Two-Level Feedback Control; CDIS spring conference 2024, Stockholm, Sweden May 22. Kim Hammar and Rolf Stadler. PDF.
[PhD thesis] Optimal Security Response to Network Intrusions in IT Systems; Doctoral thesis in electrical engineering, KTH, School of Electrical Engineering and Computer Science (EECS). Kim Hammar. ArXiv version, publication, PDF, bibtex, ai_generated_summary.
2023
[TNSM] Learning Near-Optimal Intrusion Responses Against Dynamic Attackers; TNSM 2023: IEEE Transactions on Network and Service Management (IEEE TNSM). Kim Hammar and Rolf Stadler. IEEE Proceedings, arXiv(preprint), PDF(preprint), bibtex.
[GameSec] Scalable Learning of Intrusion Responses through Recursive Decomposition; GameSec 2023: International Conference on Decision and Game Theory for Security, Avignon, France, Oct 18-20. Kim Hammar and Rolf Stadler. Springer book chapter, arXiv(preprint), bibtex.
[NOMS] Digital Twins for Security Automation; NOMS 2023: IEEE/IFIP Network Operations and Management Symposium, Miami, USA May 8-12. Kim Hammar and Rolf Stadler. IEEE Proceedings, PDF(preprint), bibtex.
[NOMS] Demonstrating a System for Dynamically Meeting Management Objectives on a Service Mesh; NOMS 2023: IEEE/IFIP Network Operations and Management Symposium, Miami, USA May 8-12. Forough Shahab Samani, Kim Hammar and Rolf Stadler. IEEE Proceedings, PDF(preprint), bibtex, Poster.
[Technical report] Optimal Observation-Intervention Trade-Off in Optimisation Problems with Causal Structure; 2023. Kim Hammar and Neil Dhir. ArXiv(preprint), bibtex.
[Poster] Learning Near-Optimal Intrusion Responses Against Dynamic Attackers; CDIS spring conference 2023, Stockholm, Sweden May 25. Kim Hammar and Rolf Stadler. PDF.
2022
[TNSM] Intrusion Prevention through Optimal Stopping; TNSM 2022: IEEE Transactions on Network and Service Management (IEEE TNSM), special issue on recent advances in network security management. Kim Hammar and Rolf Stadler. IEEE Proceedings, arXiv(preprint), PDF(preprint), bibtex.
[CNSM] An Online Framework for Adapting Security Policies in Dynamic IT Environments; CNSM 2022: International Conference on Network and Service Management, Thessaloniki, Greece October 31 - November 4. Kim Hammar and Rolf Stadler. IEEE Proceedings, IFIP Open Library Conference Proceedings, IFIP Open Library PDF, PDF(preprint), bibtex.
[ICML] Learning Security Strategies through Game Play and Optimal Stopping; ICML ML4Cyber Workshop 2022: International Conference on Machine Learning, Baltimore, USA July 17-23. Kim Hammar and Rolf Stadler. PDF(extended version preprint), Camera ready version.
[NOMS] A System for Interactive Examination of Learned Security Policies; (Best demonstration paper award); Diploma; NOMS 2022: IEEE/IFIP Network Operations and Management Symposium, Budapest, Hungary April 25-29. Kim Hammar and Rolf Stadler. Video, IEEE Proceedings, PDF(preprint), arXiv(preprint), bibtex.
[Poster] Intrusion Prevention through Optimal Stopping; KTH EECS Summer Conference 8 June 2022. Kim Hammar and Rolf Stadler. PDF.
[Poster] Intrusion Prevention through Optimal Stopping; CDIS Spring Conference 24 May 2022. Kim Hammar and Rolf Stadler. PDF.
[Poster] Intrusion Prevention through Optimal Stopping; Digital Futures Machine Learning Day 17 Jan 2022. Kim Hammar and Rolf Stadler. PDF.
2021
[CNSM] Learning Intrusion Prevention Policies through Optimal Stopping; CNSM 2021: International Conference on Network and Service Management, Izmir, Turkey October 25-29. Kim Hammar and Rolf Stadler. IFIP Open Library Conference Proceedings, IFIP Open Library PDF, IEEE Proceedings, PDF, arXiv(preprint), PDF(preprint), bibtex.
[Poster] Learning Intrusion Prevention Policies through Optimal Stopping; CIFAR Deep Learning + Reinforcement Learning (DLRL) Summer School 2021. Kim Hammar and Rolf Stadler. PDF.
[Report] An RCE Exploit of a Remote SLD Resolver in Prolog; 18 June 2021. Kim Hammar. PDF.
2020
[Web Intelligence] Deep text classification of Instagram data using word embeddings and weak supervision; Web Intelligence 2020. Kim Hammar, Shatha Jaradat, Nima Dokoohaki and Mihhail Matskin. Journal article, PDF, bibtex.
[CNSM] Finding Effective Security Strategies through Reinforcement Learning and Self-Play; CNSM 2020: International Conference on Network and Service Management, Izmir, Turkey November 2-6. Kim Hammar and Rolf Stadler. IEEE Proceedings, IFIP Open Library Conference Proceedings, arXiv(preprint), PDF(preprint), bibtex.
[Report] Using Reinforcement Learning in Self-Driving Systems; 28 May 2020. A PoC. Forough Shahab and Kim Hammar. PDF.
2019
[COMPSAC] TALS: A Framework For Text Analysis, Fine-Grained Annotation, Localisation and Semantic Segmentation; COMPSAC 2019: Data Driven Intelligence for a Smarter World Hosted by Marquette University, Milwaukee, Wisconsin, USA July 15-19. Shatha Jaradat, Nima Dokoohaki, Ummal Wara, Mallu Goswami, Kim Hammar and Mihhail Matskin. IEEE Proceedings, bibtex.
[MLSys] Horizontally Scalable ML Pipelines with a Feature Store; Demo track, MLSys Conference, March 31 - April 2 2019, Stanford CA. Alexandru A. Ormenisan, Mahmoud Ismail, Kim Hammar, Robin Andersson, Ermias Gebremeskel, Theofilos Kakantousis, Antonios Kouzoupis, Fabio Buso, Gautier Berthou, Jim Dowling and Seif Haridi. Proceedings, PDF.
[Blog post] Guide to File Formats for Machine Learning: Columnar, Training, and Inferencing; 25 Oct 2019. Jim Dowling, Moritz Meister, and Kim Hammar. Blog post.
2018
[SocialCom] Dynamic CNN Models For Fashion Recommendation in Instagram; International Conference on Social Computing and Networking (SocialCom 2018), 11-13 Dec. 2018, Melbourne, Australia. Shatha Jaradat, Nima Dokoohaki, Kim Hammar, Ummul Wara and Mihhail Matskin. DiVA, bibtex.
[Web Intelligence] Deep Text Mining of Instagram Data Without Strong Supervision; Web Intelligence Conference 2018, Santiago Chile. Kim Hammar, Shatha Jaradat, Nima Dokoohaki and Mihhail Matskin. IEEE Proceedings, PDF, ArXiv, bibtex.
[Blog post] Feature Store: the missing data layer in ML pipelines?; 30 Dec 2018. Kim Hammar and Jim Dowling. Blog post, bibtex.
[Blog post] Goodbye Horovod, Hello CollectiveAllReduce; 22 Oct 2018. Robin Andersson, Jim Dowling, Ermias Gebremeskel and Kim Hammar. Blog post.
[MSc thesis] Deep Text Mining of Instagram Data Without Strong Supervision; Master’s Thesis, KTH School of Information and Communication Technology (ICT). Kim Hammar. Publication, PDF, bibtex.
[Tutorial] Programming the Semantic Web; 12 Jan 2018. A Tutorial. Kim Hammar. PDF.
2017
[Course project] Distributed Human Activity Recognition; Dec 2017. Scalable Deep Learning Course Project at KTH. (Best project award, awarded a graphics card). Kim Hammar and Konstantin Sozinov. Code.
[Report] Machine Learning for Failure Detection in Distributed Systems; 23 Nov 2017. A project report. Kim Hammar and Konstantin Sozinov. PDF.
[Report] Conflict free p2p replicated datatypes; 22 May 2017. A project report. Kim Hammar and Maxime Dufour. PDF.
[Report] Linearizable Key-Value Store; 12 Mar 2017. A project report. Kim Hammar and Konstantin Sozinov. PDF.
2016
[BSc thesis] Integrating Monitoring Systems - Pre-Study; Bachelor’s Thesis, KTH School of Information and Communication Technology (ICT). Kim Hammar and Marcus Blom. Publication, PDF, bibtex.