Talks
2026
[MLSys] CSLE: A Reinforcement Learning Platform for Autonomous Security Management; Ninth Annual Conference on Machine Learning and Systems (MLSys 2026), Seattle, WA, USA, May 19, 2026. Slides (online), slides (PDF).
[NOMS] Optimal Security Management through Learning-based Control; IEEE NOMS, Rome, Italy, May 20, 2026. Slides (online), slides (PDF).
[IEEE TCSP] Autonomous Security Management of Networked Systems through Learning-based Control; IEEE Control Systems Society (CSS) Technical Committee on Security and Privacy (TCSP) symposium, Paris, France, May 15, 2026. Slides (online), slides (PDF), Video.
[Sorbonne] Learning-based Control of Networked Systems; Paris 1 Panthéon-Sorbonne University, Paris, France, May 12, 2026. Slides (online), slides (PDF).
[University of Melbourne] Learning-based Control of Networked Systems; University of Melbourne, Melbourne, Australia, April 22, 2026. Slides (online), slides (PDF).
[NDSS] Incident Response Planning Using a Lightweight Large Language Model with Reduced Hallucination; NDSS, San Diego, USA, February 24, 2026. Slides (online), NDSS Video.
[University of Melbourne] Online Identification of IT Systems through Active Causal Learning; University of Melbourne, Melbourne, Australia, January 29, 2026. Slides (online).
[AAAI] Scalable Solutions to Zero-Sum Partially Observable Stochastic Games Through Belief Aggregation with Approximation Guarantees; AAAI, Singapore, January 22, 2026. Slides (online), slides (PDF), Video.
2025
[University of Melbourne] Incident Response Planning with a Foundation Model; University of Melbourne, Melbourne, Australia, December 5, 2025. Slides (online), slides (PDF).
[Ericsson Research] Online Identification of IT Systems through Active Causal Learning; Ericsson Research, Melbourne, Australia, November 18, 2025. Slides (online), slides (PDF), Video.
[City University of Hong Kong] Automated Security with a Foundation Model; City University of Hong Kong, Hong Kong, China, October 20, 2025. Slides (online), slides (PDF).
[ASU] Approximation in Value Space using Aggregation, with Applications to POMDPs and Cybersecurity; Arizona State University, Arizona, USA, Apr 2, 2025. Slides (online), slides (PDF), Video.
[KTH] Adaptive Security Policies via Belief Aggregation and Rollout; KTH Royal Institute of Technology, Stockholm, Sweden, Mar 3, 2025. Slides (online), slides (PDF), Video.
2024
[PhD defense] Optimal Security Response to Network Intrusions in IT Systems; KTH Royal Institute of Technology, Stockholm, Sweden, Dec 5, 2024. Slides (online), slides (PDF), Video.
[GameSec] Intrusion Tolerance as a Two-Level Game; GameSec, New York, USA, Oct 16, 2024. Slides (online), slides (PDF).
[DSN] Intrusion Tolerance for Networked Systems through Two-Level Feedback Control; DSN, Brisbane, Australia, June 27 2024. Slides (online), slides (PDF).
[University of Melbourne] Intrusion Tolerance as a Two-Level Game; University of Melbourne, Melbourne, Australia, June 20, 2024. Slides (online), slides (PDF), Video.
[CTO seminar] Automated Intrusion Response; Stockholm, Sweden, CTO seminar, May 31, 2024. Slides (PDF).
[CDIS] Automated Intrusion Response; Stockholm, Sweden, CDIS Spring Conference, May 22, 2024. Slides (online), slides (PDF), Video.
[Reading group] PID-Piper: Recovering Robotic Vehicles from Physical Attacks; Stockholm, KTH, ML+Security Reading Group NSE Apr 19 2024, Division of Network and Systems Engineering. Slides (PDF).
[NSE seminar] Automated Security Response through Online Learning with Adaptive Conjectures; NSE seminar, Division of Network and Systems Engineering, Stockholm, Sweden, April 5 2024. Slides (online), slides (PDF), Video.
[Handelsbanken] Självlärande System för Cybersäkerhet; Besök av Handelsbanken, Stockholm, Sweden, Jan 11 2024. Slides (online), slides (PDF).
2023
[Ericsson Research] Learning Automated Intrusion Response; Ericsson research, Stockholm, Sweden, Dec 8 2023. Slides (online), slides (PDF), Video.
[NSE seminar] Intrusion Tolerance for Networked Systems through Two-Level Feedback Control; NSE seminar, Division of Network and Systems Engineering, Stockholm, Sweden, Nov 10 2023. Slides (online), slides (PDF).
[GameSec] Scalable Learning of Intrusion Response through Recursive Decomposition; GameSec, Avignon, France, Oct 18 2023. Slides (online), slides (PDF).
[Reading group] 3D-IDS: Doubly Disentangled Dynamic Intrusion Detection; Stockholm, KTH, ML+Security Reading Group NSE Sep 22 2023, Division of Network and Systems Engineering. Slides (PDF).
[MIT] Learning Near-Optimal Intrusion Response for Large-Scale IT Infrastructures via Decomposition; MIT, Boston, USA, May 19 2023. Slides (online), slides (PDF).
[Siemens Research] Learning Near-Optimal Intrusion Response for Large-Scale IT Infrastructures via Decomposition; Siemens Research Princeton, USA, May 17 2023. Slides (online), slides (PDF).
[Princeton University] Learning Near-Optimal Intrusion Response for Large-Scale IT Infrastructures via Decomposition; Princeton University, USA, May 17 2023. Slides (online), slides (PDF).
[NYU] Learning Near-Optimal Intrusion Response for Large-Scale IT Infrastructures via Decomposition; New York University, USA, May 15 2023. Slides (online), slides (PDF).
[NOMS] Digital Twins for Security Automation; Miami, USA, KTH, NOMS 2023: IEEE/IFIP Network Operations and Management Symposium May 8-12. Video, slides (PDF), slides (online).
[NSE seminar] Learning Near-Optimal Intrusion Response for Large-Scale IT Infrastructures via Decomposition; Stockholm, Sweden, KTH, NSE Seminar, Mar 31 2023, Division of Network and Systems Engineering. Slides (online), slides (PDF).
[CDIS] Självlärande system för cybersäkerhet; Stockholm, Sweden, KTH, CDIS, Division of Network and Systems Engineering, Besök av försvarsdepartementet 21 Feb 2023. Slides (online), slides (PDF).
[Reading group] Optimal Patching in Clustered Malware Epidemics - Paper Review; Stockholm, KTH, ML+Security Reading Group NSE Feb 16 2023, Division of Network and Systems Engineering. Slides (PDF).
[NYU] Intrusion Response through Optimal Stopping; New York, USA, invited talk, Quanyan Zhu’s research group, Jan 30 2023. Slides (online), slides (PDF), Video.
2022
[IT-försvarsdagen] Självlärande system för cyberförsvar; Linköping, Sweden, IT-försvarsdagen 2022 Dec 6. Slides (online), slides (PDF), Video.
[CNSM] An Online Framework for Adapting Security Policies in Dynamic IT Environment; Thessaloniki, Greece, CNSM 2022: International Conference on Network and Service Management Oct 31 - Nov 4. Kim Hammar and Rolf Stadler. Slides (online), slides (PDF), Event, Video.
[CDIS] Self-learning Systems for Cyber Defense; Lidingö, Sweden, CDIS fall retreat, October 28 2022. Slides (online), slides (PDF), Video.
[NSE seminar] Self-learning Intrusion Prevention Systems; Stockholm, Sweden, KTH, NSE Seminar, October 21 2022, Division of Network and Systems Engineering. Slides (online), slides (PDF).
[Reading group] Paper Review: Developing Optimal Causal Cyber Agents; Stockholm, KTH, ML+Security Reading Group NSE Sep 23 2022, Division of Network and Systems Engineering. Slides (PDF).
[ICML] Learning Security Strategies through Game Play and Optimal Stopping; Baltimore, USA, ML4Cyber workshop at ICML 2022: International Conference on Machine Learning July 15-23. Kim Hammar and Rolf Stadler. Slides (online), slides (PDF), Video.
[NOMS] A System for Interactive Examination of Learned Security Policies; Budapest, Hungary NOMS 2022: IEEE/IFIP Network Operations and Management Symposium April 25-29. Kim Hammar and Rolf Stadler. Video.
[Alan Turing Institute] Intrusion Prevention through Optimal Stopping; London, UK, Alan Turing Institute, invited talk, Mar 25 2022. Slides (online), slides (PDF).
[Reading group] Reinforcement Learning-based Hierarchical Seed Scheduling for Greybox Fuzzing; Stockholm, Sweden, KTH, ML+Security Reading Group NSE March 18 2022, Division of Network and Systems Engineering. Slides (PDF).
[NSE seminar] Intrusion Prevention through Optimal Stopping and Self-Play; Stockholm, Sweden, KTH, NSE Seminar, March 18 2022, Division of Network and Systems Engineering. Slides (online), slides (PDF).
[KTH EP1200] Introduktion till försvar mot nätverksintrång; Stockholm, Sweden, KTH EP1200, Feb 22 2022. Slides (online), slides (PDF).
[Netcon seminar] Intrusion Prevention through Optimal Stopping; Stockholm, Sweden, KTH, Netcon Seminar, invited talk, Feb 7 2022, Division of Decision and Control Systems. Slides (online), slides (PDF).
[Digital Futures] Intrusion Prevention through Optimal Stopping; Stockholm, Sweden, KTH, Machine Learning Day Digital futures, Jan 17 2022, Division of Network and Systems Engineering. Slides (online), slides (PDF).
2021
[KTH FEP3301] A Game Theoretic Analysis of Intrusion Detection in Access Control Systems; Stockholm, Sweden, KTH, FEP3301 Computational Game Theory Course, Dec 8 2021, Division of Network and Systems Engineering. Slides (online), slides (PDF).
[CNSM] Learning Intrusion Prevention Policies through Optimal Stopping; Izmir, Turkey, CNSM 2021: International Conference on Network and Service Management October 25-29. Kim Hammar and Rolf Stadler. Slides (online), slides (PDF), Event, Video.
[Reading group] Reinforcement Learning Algorithms for Adaptive Cyber Defense against Heartbleed; Stockholm, Sweden, KTH, ML+Security Reading Group NSE October 22 2021, Division of Network and Systems Engineering. Slides (online), slides (PDF).
[CDIS] Självlärande system för cybersäkerhet; Stockholm, Sweden, KTH, CDIS, Division of Network and Systems Engineering, Besök av riksdagens försvarsutskott (S) 20 Oct 2021. Slides (online), slides (PDF).
[CDIS] Learning Intrusion Prevention Policies Through Optimal Stopping; Balingsholm, KTH, CDIS Research Workshop October 15 2021. Kim Hammar and Rolf Stadler. Slides (online), slides (PDF).
[NSE seminar] Learning Intrusion Prevention Policies Through Optimal Stopping; Stockholm, KTH, NSE Seminar October 8 2021, Division of Network and Systems Engineering. Kim Hammar and Rolf Stadler. Slides (online), slides (PDF).
[Ledningsregementet] Self-Learning Systems for Cyber Security; Enköping, Sweden, Ledningsregementet, August 18 2021. Slides (online), slides (PDF).
[Reading group] MuZero; Stockholm, Sweden, KTH, ML+Security Reading Group NSE April 23 2021, Division of Network and Systems Engineering. Slides (online), slides (PDF).
[CDIS] Self-Learning Systems for Cyber Defense; Stockholm, Sweden, Mar 24 2021. Kim Hammar, Rolf Stadler. Video.
[NSE seminar] Self-Learning Systems for Cyber Security; Stockholm, Sweden, KTH, NSE Seminar April 9 2021, Division of Network and Systems Engineering. Kim Hammar and Rolf Stadler. Slides (online), slides (PDF).
[CDIS] Self-Learning Systems for Cyber Security; Stockholm, Sweden, KTH, CDIS Spring Conference March 24 2021. Kim Hammar and Rolf Stadler. Slides (online), slides (PDF).
2020
[NSE seminar] Self-Learning Systems for Cyber Security; Stockholm, Sweden, KTH, NSE Seminar 4 Dec 2020, Division of Network and Systems Engineering. Kim Hammar and Rolf Stadler. Slides (online), slides (PDF).
[CNSM] Finding Effective Security Strategies through Reinforcement Learning and Self-Play; Izmir, Turkey, CNSM 2020: International Conference on Network and Service Management November 2-6. Kim Hammar and Rolf Stadler. Slides (online), slides (PDF), Event, Video.
[CDIS] Self-Learning Systems for Cyber Security; Stockholm, Sweden, KTH, Center for Cyber Defense and Information Security, October 15 2020. Slides (online), slides (PDF).
[NSE seminar] A Deep Journey of Playing Games with Reinforcement Learning; Stockholm, Sweden, KTH, Division of Network and Systems Engineering, January 31 2020. Slides (online), slides (PDF).
2019
[Spark+AI Summit] End-to-End ML Pipelines with Databricks Delta and Hopsworks Feature Store; Amsterdam, Netherlands, Spark+AI Summit October 2019. Event, Video, slides (online), slides (PDF).
[EIT Summer School] Distributed Deep Learning with Hopsworks; Bosön, Sweden, EIT Big Data Summer School, 10 August 2019. Event, slides (online), slides (PDF).
[CGI] Introduction to Large Scale Machine Learning; Stockholm, Sweden, CGI Trainee Lecture, May 2019. Slides (online), slides (PDF).
[Uddeholm] Machine Learning Infrastructure for the Steel Industry; Hagfors, Sweden, meeting at Uddeholm AB, May 8 2019. Slides (online), slides (PDF).
[SF ML Meetup] Distributed Deep Learning with Hopsworks; San Francisco, USA, SF machine Learning Meetup, 25 April 2019. Slides (online), Event, Video, slides (PDF).
[HopsML Meetup] Distributed Deep Learning with the Hopsworks Feature Store; Palo Alto, USA, HopsML Meetup, 23 April 2019. Slides (online), slides (PDF), Event.
[Spotify] Feature Store: the missing data layer in ML pipelines; Stockholm, Sweden, Spotify Machine Learning Guild Fika, February 26 2019. Slides (online), slides (PDF).
[FOSDEM] Feature Store: the missing data layer in ML pipelines; Brussels, Belgium, FOSDEM, January 30 2019. Event, slides (online), Video, slides (PDF).
[HopsML Meetup] Feature Store: the missing data layer in ML pipelines; Stockholm, Sweden, HopsML meetup, January 29 2019. Event, slides (online), slides (PDF).
2018
[Web Intelligence] Deep Text Mining of Instagram Data Without Strong Supervision; Santiago, Chile, International conference on Web Intelligence, December 4 2018. Event, slides (PDF), slides (online).
[HopsML Meetup] The Future of Deep Learning; Stockholm, Sweden, HopsML Meetup panel discussion. Event.
[RISE] Distributed Deep Learning; Stockholm, Sweden, RISE Machine Learning Study group. Slides (online), slides (PDF).
[Allstate] Building a Fault-Tolerant ETL Pipeline for Claims CAFé; Chicago, USA, Internship Presentation, Allstate, August 30 2018. Slides (online), slides (PDF).
[MSc defense] Deep Text Mining of Instagram Data Without Strong Supervision; Stockholm, Sweden, Master’s Thesis Defense, KTH, June 1 2018. Video, slides (online), slides (PDF).
[Hadoop User Group] Human Activity Recognition: On-Edge Inference and Distributed Deep Learning; Stockholm, Sweden, Hadoop User Group Meetup, January 9, 2018. Event, slides (online), slides (PDF).