AI-Assisted Signal Extraction and Misuse Detection in Internet Systems
Julien Piet
EECS Department, University of California, Berkeley
Technical Report No. UCB/EECS-2026-142
May 14, 2026
http://www2.eecs.berkeley.edu/Pubs/TechRpts/2026/EECS-2026-142.pdf
Effective security depends on understanding behavior: how systems communicate, how users interact, and how malicious actors deviate from expected patterns. That understanding rests on two pillars: observability, which surfaces useful signals, and detection, which uses those signals to identify activity. Yet translating these pillars into practical defenses poses significant hurdles, from extracting meaningful structure from raw activity to building detectors that remain reliable amid noise, change, and adversarial pressure. In this dissertation, we develop AI-assisted methods that make security analysis more practical, robust, and deployable across modern internet systems. For observability, we introduce Matryoshka, a system that automatically generates deterministic, semantically-aware parsers for heterogeneous security logs, and GGFAST, a framework that automatically extracts discriminative structure from network traffic to build fast, interpretable classifiers, including in encrypted settings. For detectability, we present a behavioral detection system for identifying SSH impostors from encrypted interactive-session metadata, and we show that packet timing and length alone can support effective detection under realistic operational constraints. Finally, we extend this framework to language-model systems by studying watermarking as a mechanism for provenance and observability, temporally robust jailbreak detection under distribution shift, and prompt-injection defenses that harden LLM-integrated applications by design.
Advisors: David Wagner and Vern Paxson
BibTeX citation:
@phdthesis{Piet:EECS-2026-142,
Author= {Piet, Julien},
Title= {AI-Assisted Signal Extraction and Misuse Detection in Internet Systems},
School= {EECS Department, University of California, Berkeley},
Year= {2026},
Month= {May},
Url= {http://www2.eecs.berkeley.edu/Pubs/TechRpts/2026/EECS-2026-142.html},
Number= {UCB/EECS-2026-142},
Abstract= {Effective security depends on understanding behavior: how systems communicate, how users interact, and how malicious actors deviate from expected patterns. That understanding rests on two pillars: observability, which surfaces useful signals, and detection, which uses those signals to identify activity. Yet translating these pillars into practical defenses poses significant hurdles, from extracting meaningful structure from raw activity to building detectors that remain reliable amid noise, change, and adversarial pressure. In this dissertation, we develop AI-assisted methods that make security analysis more practical, robust, and deployable across modern internet systems. For observability, we introduce Matryoshka, a system that automatically generates deterministic, semantically-aware parsers for heterogeneous security logs, and GGFAST, a framework that automatically extracts discriminative structure from network traffic to build fast, interpretable classifiers, including in encrypted settings. For detectability, we present a behavioral detection system for identifying SSH impostors from encrypted interactive-session metadata, and we show that packet timing and length alone can support effective detection under realistic operational constraints. Finally, we extend this framework to language-model systems by studying watermarking as a mechanism for provenance and observability, temporally robust jailbreak detection under distribution shift, and prompt-injection defenses that harden LLM-integrated applications by design.},
}
EndNote citation:
%0 Thesis %A Piet, Julien %T AI-Assisted Signal Extraction and Misuse Detection in Internet Systems %I EECS Department, University of California, Berkeley %D 2026 %8 May 14 %@ UCB/EECS-2026-142 %U http://www2.eecs.berkeley.edu/Pubs/TechRpts/2026/EECS-2026-142.html %F Piet:EECS-2026-142