Hung X Nguyen
Professor and Academic Lead, Cybersecurity and Networking
Adelaide University · Cyber-AI Research Group
Our research currently focuses on security and safety issues related to AI, which are becoming central to cybersecurity as both a tool for defence and a new source of risk. They hold identities and permissions, read the documents and memories other agents wrote, call tools, use skills and act. We map where an organisation that runs them can be attacked, watch how misbehaviour spreads across a fleet before it does damage, and test whether what a model's internals appear to say can be trusted. Our starting point is years of algorithmic network defence, guided by one question: what can an attacker reach, and how do we stop them? We answer it with models, algorithms and tools for organisations that run AI agents.
Research
AI agent security and safety
Map. An organisation's agents inherit its identity and permission graph and add their own: delegated credentials, tool access, shared memories, and the metadata that systems write on their behalf. We generate realistic graphs of this kind, find the few weak links an attacker needs, and fine-tune language models to help operators close them.
Watch. Misbehaviour spreads through what agents share. We build fleet-level monitors with calibrated guarantees that tell a shared channel apart from a shared flaw in the model, and we collect incident data from real agent activity on the open web.
Trust. Some failures need no attacker: misalignment that emerges from narrow fine-tuning, or internal features that interpretability tools read incorrectly. We test when tools such as sparse autoencoders and transcoders can be trusted, and we keep a systematic map of the field's evidence.
Robust multi-agent systems
Teams of autonomous agents, from drones to data-collecting robots, must keep working when members fail or are lost. We design decentralised planning and coordination that survives attrition and changing environments.
Algorithmic defence of enterprise networks
Active Directory controls identity in most large organisations and is a prime target in ransomware attacks. We model it as an attack graph and compute defences with guarantees: which edges to block, where to place honeypots, which choke points matter. Our open generator ADSynth produces the graphs this work runs on, and is the base we extend to agent identities.
Selected recent publications
Full list on Google Scholar-
NeurIPS 2026CORE A*
-
ICAPS 2026CORE A*
-
IJCAI 2026CORE A*
-
IEEE TMC 2025CORE A*
-
RAID 2025CORE A
-
AAAI 2024CORE A*
-
IJCAI 2024CORE A*
-
INFOCOM 2024CORE A*
-
IEEE TVT 2024CORE A*
-
AAAI 2023CORE A*
-
IEEE TMC 2023CORE A*
-
AAAI 2022CORE A*
Recent
- Paper at NeurIPS 2026 on when interpretability protections for sparse autoencoders fail to carry over to transcoders.
- Papers at IJCAI 2026 and ICAPS 2026.
- CS-Guard, a benchmark of LLM guardrails for secure code generation, released.
- Completed the Cisco and Defence Trailblazer project Resilient Platform Interfaces.
Join the group
I supervise PhD students on AI agent security and safety, and on algorithmic defence of enterprise networks. Strong candidates have an exceptional academic record and a background in machine learning, algorithms or optimisation, and are self-motivated. They want to work on problems that deployed systems face now.
Email me a CV and one paragraph on a problem you would like to work on. Meet the current group.