About
Articles by Matthew
Activity
2K followers
Experience & Education
Licenses & Certifications
Publications
-
Is End Point Control Going the Way of the Dodo?
16th Annual New York State Cyber Security Conference
Patents
-
Single-packet authorization using proof of work
Issued US11831638B1
See patentMethods, systems, and computer-readable media for single-packet authorization using proof of work are disclosed. An access control service receives, from a client, a single-packet authorization (SPA) request. The (SPA) request comprises output of a proof-of-work task, wherein completion of the proof-of-work task requires computational resources or memory resources of the client. The access control service performs verification of the output of the proof-of-work task using fewer computational or…
Methods, systems, and computer-readable media for single-packet authorization using proof of work are disclosed. An access control service receives, from a client, a single-packet authorization (SPA) request. The (SPA) request comprises output of a proof-of-work task, wherein completion of the proof-of-work task requires computational resources or memory resources of the client. The access control service performs verification of the output of the proof-of-work task using fewer computational or memory resources of the access control service than were used by the client. In response to determining that verification of the output of the proof-of-work task succeeds, the access control service performs authentication of the SPA request. In response to determining that authentication of the SPA request succeeds, the access control service allows access by the client device to a service.
-
Deperimeterized access control service
Issued US011652822B2
See patentTechniques for deperimeterized access control are described. A method of deperimeterized access control may include receiving, by a controller of a deperimeterized access control service, a single packet authorization (SPA) request for a session ticket from an agent on a electronic device, wherein the agent sends the request for the session ticket in response to intercepting traffic destined for a service associated with the deperimeterized access control service and determining that the agent…
Techniques for deperimeterized access control are described. A method of deperimeterized access control may include receiving, by a controller of a deperimeterized access control service, a single packet authorization (SPA) request for a session ticket from an agent on a electronic device, wherein the agent sends the request for the session ticket in response to intercepting traffic destined for a service associated with the deperimeterized access control service and determining that the agent does not have a session ticket for the service, authorizing the SPA request, providing a session ticket to the agent based on the request, receiving, by a gateway of the deperimeterized access control service, a request to initiate a session with a service, the request including the session ticket, validating the session ticket, and providing session parameters to the agent to be used to initiate the session between the electronic device and the service.
-
Management and distribution of virtual cyber sensors
Issued US 9,866,575
See patentA system includes reception of data at a computing network, generation of alerts at the computing network based on received data and on cyber sensor data, the cyber sensor data defining data attribute, reception of alerts from the computing network at a defense engine, detection of events based on the received alerts at the defense engine, generation threat data based on the detected events, generation of first cyber sensor data based on the threat data, and initiation of deployment of the…
A system includes reception of data at a computing network, generation of alerts at the computing network based on received data and on cyber sensor data, the cyber sensor data defining data attribute, reception of alerts from the computing network at a defense engine, detection of events based on the received alerts at the defense engine, generation threat data based on the detected events, generation of first cyber sensor data based on the threat data, and initiation of deployment of the first cyber sensor data within the computing network.
-
Honeyport active network security
Issued US 9,436,652 and 9,838,426
See patentA device comprises a processor. The processor is configured to generate a first signal using a first communication protocol. The first signal corresponds to data received by the processor. The processor is configured to generate a second signal using a second communication protocol. The second signal comprises fabricated data generated by the processor. Additionally, the processor is configured to transmit the first signal. The processor is also configured to transmit the second…
A device comprises a processor. The processor is configured to generate a first signal using a first communication protocol. The first signal corresponds to data received by the processor. The processor is configured to generate a second signal using a second communication protocol. The second signal comprises fabricated data generated by the processor. Additionally, the processor is configured to transmit the first signal. The processor is also configured to transmit the second signal.
https://patentimages.storage.googleapis.com/35/eb/b9/0e6338bf783391/US9838426.pdf
https://patentimages.storage.googleapis.com/f5/dd/35/56f30c7a511464/US9436652.pdf -
Load balancing medical imaging applications across healthcare imaging devices in reference to projected load based on user type
Issued US 8,479,213
See patentSystems, methods and apparatus are provided through which in some embodiments healthcare imaging processing applications are allocated to computing resources in reference to criteria.
-
Medical imaging system and method with integrated weight sensing
Issued US 7,682,079
See patentAn integrated weight sensing system and method is disclosed for a medical imaging system. In one embodiment, the integrated weight sensing system may include a table assembly, a load cell, and a processor that are implemented in a medical imaging system. The table assembly includes a lifting mechanism used to position a patient within the medical imaging system. The load cell is mechanically coupled to the table assembly and in communication with the processor. The load cell is configured to…
An integrated weight sensing system and method is disclosed for a medical imaging system. In one embodiment, the integrated weight sensing system may include a table assembly, a load cell, and a processor that are implemented in a medical imaging system. The table assembly includes a lifting mechanism used to position a patient within the medical imaging system. The load cell is mechanically coupled to the table assembly and in communication with the processor. The load cell is configured to measure and indicate the weight of the patient and the processor may be configured to adjust imaging parameters based on the weight of the patient. The table assembly may include a device in communication with the load cell and/or processor to display the weight of the patient. Additionally, the table assembly and/or the processor may include an interface for zeroing or recalibrating the load cell.
-
Real-Time Protection Framework for AI Agent Tool Systems
Filed 19/468,695
Systems, devices, and methods are provided for, among other things, dynamic, context-aware security for artificial intelligence (AI) systems that utilize external tools. Techniques may involve receiving a user input, determining metadata for available tools, and generating potential attack vectors based on the metadata. When the user input or set of user inputs presents as a potential risk for one or more of the known attack vectors, a security model can be selected based on the relevant attack…
Systems, devices, and methods are provided for, among other things, dynamic, context-aware security for artificial intelligence (AI) systems that utilize external tools. Techniques may involve receiving a user input, determining metadata for available tools, and generating potential attack vectors based on the metadata. When the user input or set of user inputs presents as a potential risk for one or more of the known attack vectors, a security model can be selected based on the relevant attack vector(s) identified. The user input may be evaluated using the selected model to determine a proposed system component(s) to respond to the interaction, and multi-observer analysis may be applied to detect vulnerabilities. A weighted consensus from specialized observers may be used to determine a security intervention, such as restricting, modifying, or blocking execution.
-
Dynamic Multi-Level Token Management System for Large Language Models
Filed 19/204,366 36
Systems, devices, and methods are provided for multi-level tokenization in machine-learning models. Techniques described herein may relate to tokenization techniques that involve determining an input text and a label, selecting, based at least in part on the label, a first tokenizer from a plurality of tokenizers, using the first tokenizer to tokenize the input text and produce a first token sequence, analyzing the first token sequence to select a first trust level of a multi-trust level trust…
Systems, devices, and methods are provided for multi-level tokenization in machine-learning models. Techniques described herein may relate to tokenization techniques that involve determining an input text and a label, selecting, based at least in part on the label, a first tokenizer from a plurality of tokenizers, using the first tokenizer to tokenize the input text and produce a first token sequence, analyzing the first token sequence to select a first trust level of a multi-trust level trust hierarchy, and determining a trusted token sequence by at least applying the first trust level to the first token sequence.
-
Embeddings Defense (EmDef)
Filed 19/096,279 279
Systems and methods are provided to detect anomalous data obtained from and/or to be routed to a machine learning model. A system can identify a first embedding generated by a machine learning model. The system can obtain a first set of data associated with the machine learning model and can compare the first embedding generated by the machine learning model with the first set of data. Based on comparing the first embedding generated by the machine learning model with the first set of data, the…
Systems and methods are provided to detect anomalous data obtained from and/or to be routed to a machine learning model. A system can identify a first embedding generated by a machine learning model. The system can obtain a first set of data associated with the machine learning model and can compare the first embedding generated by the machine learning model with the first set of data. Based on comparing the first embedding generated by the machine learning model with the first set of data, the system can determine a manner of processing a second set of data (e.g., an input to and/or an output of the machine learning model). The system can process the second set of data according to the manner of processing the second set of data.
-
Generative AI and Honeypots
Filed 19/095,879 879
Techniques for using honeypots are described. In some examples, a method for using honeypots includes generating a honeypot having characteristics of a vulnerability as indicated in a publicly facing lure describing a vulnerable system, wherein the publicly facing lure includes one or more indications of a location of a honeypot and narratively refers to the honeypot as a vulnerable target; operating the generated honeypot to collect threat intelligence; generating one or more countermeasures…
Techniques for using honeypots are described. In some examples, a method for using honeypots includes generating a honeypot having characteristics of a vulnerability as indicated in a publicly facing lure describing a vulnerable system, wherein the publicly facing lure includes one or more indications of a location of a honeypot and narratively refers to the honeypot as a vulnerable target; operating the generated honeypot to collect threat intelligence; generating one or more countermeasures based on the collected threat intelligence; and applying the one or more countermeasures.
-
MiRAGE: Dynamic Context Adaptation in Large Language Models Through Mid-Inference RAG
Filed 19/096,274 274
Systems and methods are provided to dynamically adjust contextual data of a machine learning model during an inference process of the machine learning model. A system can identify one or more tokens generated by the machine learning model. The machine learning model may, during an inference process, generate the one or more tokens based on first contextual data. The system can determine that the one or more tokens satisfy one or more first parameters. The system can obtain second contextual…
Systems and methods are provided to dynamically adjust contextual data of a machine learning model during an inference process of the machine learning model. A system can identify one or more tokens generated by the machine learning model. The machine learning model may, during an inference process, generate the one or more tokens based on first contextual data. The system can determine that the one or more tokens satisfy one or more first parameters. The system can obtain second contextual data associated with the one or more tokens based on determining that the one or more tokens satisfy the one or more first parameters and can provide the second contextual data to the machine learning model. The machine learning model may generate an output based on the second contextual data and at least a portion of the first contextual data.
-
Privacy Preserving Mechanisms using Parameters and Tags
Filed 19/096,153 153
Systems and methods are provided to perform retrieval-augmented generation for machine learning models using filtered contextual data. A system can identify data associated with a machine learning model. The data may be associated with one or more first identifiers that may indicate a user, a user computing device, a model, etc. associated with the data. In response to determining that the data satisfies one or more parameters, the system can identify a need for contextual data. The system can…
Systems and methods are provided to perform retrieval-augmented generation for machine learning models using filtered contextual data. A system can identify data associated with a machine learning model. The data may be associated with one or more first identifiers that may indicate a user, a user computing device, a model, etc. associated with the data. In response to determining that the data satisfies one or more parameters, the system can identify a need for contextual data. The system can compare the one or more first identifiers associated with the data to one or more second identifiers associated with the contextual data. Based on the comparison, the system can filter the contextual data to obtain filtered contextual data. The system may provide the filtered contextual data to the machine learning model for generation of an output.
Projects
Recommendations received
-
LinkedIn User
8 people have recommended Matthew
Join now to viewOther similar profiles
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content