A SELF-TAUGHT RESEARCH JOURNEY

We learned cybersecurity by building our way into it.

No formal roadmap. No assumption that we knew what we were doing. We started with code, two AI systems, and a willingness to be wrong repeatedly.

OpenAI + Anthropic in parallel. Evidence as the referee.

SMALL · EXPERIMENTAL AI-ASSISTED EVIDENCE-DRIVEN
Scroll to observe
01 / ORIGIN

WHY AI MATTERED

Action-error became the curriculum.

AI compressed the distance between a question and an understandable model of the problem. But the fastest lessons came from the moments when an idea looked convincing, reached real code, and failed.

OpenAI and Anthropic worked as parallel reasoning partners, not as competitors. One answer could challenge the other. Assumptions became easier to expose. Failed approaches could be re-evaluated. The human decision remained the final gate.

AI accelerated the learning curve; evidence decided what was true.
Observe→Hypothesize→Test→Fail→Understand→Refine→Repeat
02 / STRUCTURE

FROM EXPERIMENTS TO LENSES

One research space. Four different ways of looking.

Repeated experiments gradually became structured viewpoints. They are not products or autonomous engines; they are complementary lenses for asking better questions of code, devices, change and signals.

01

CODE-FIRST

CHROMIUM

Historical mapping · Normal · Mojo/IDL · Fixes

Large systems reveal different security questions through general code, interfaces and boundaries, or historical fixes.

02

DEVICE-FIRST

ANDROID / ADF1

Real Pixel · Full-stack context

Begin with the real device, then work backward toward the relevant artifact and code—a second viewpoint that reduced false leads.

03

FRESHNESS

GOOGLE OSS FRESH

Z1-D · Official inventory · Git delta

Not “what was interesting before?” but “what code has actually changed now?” Freshness became its own research perspective.

04

SIGNALS

PREDICTIVE RADAR

Event-driven · Manual · ESR · T0 · T1 · MDA

Watch signals around future code movement, then investigate only when something becomes materially interesting.

03 / MAP

INTERACTIVE CENTERPIECE

Enter the Google Scan Universe.

A compact map of the viewpoints, memory and validation stages that emerged from the learning process.

Preparing the universe…
GOOGLE SCAN UNIVERSE · v3.5 Drag to rotate · Pinch or scroll to zoom · Select a node to inspect
04 / BOUNDARY

INTENTIONALLY INCOMPLETE

The map shows the shape, not the machinery.

The universe shows the lenses, the flow and the validation stages. It does not expose the selection logic, internal scoring, thresholds, prompts, datasets or operational rules behind them.

SELECTION LOGICSCORINGTHRESHOLDSPROMPTSDATASETSOPERATIONS
05 / VALIDATION

WHEN A SIGNAL STARTS TO LOOK REAL

Automation stops. Deliberate examination begins.

  1. F

    01

    FREEZE

    Candidate preserved

    Evidence and candidate state are frozen before directed validation, preventing drift through the pipeline.

  2. V

    02

    V4

    Directed validation

    One concrete causal path must lead to a material, observable consequence.

  3. G

    03

    G6

    Originality gate

    A technically valid issue is not automatically new. Public prior art and observable originality still matter.

  4. R

    04

    REPORT

    Reportable outcome

    A reproducible PoC, defensible root cause, material impact and clearly applicable scope.

06 / OUTCOMES

RESULTS WITHOUT OVERCLAIMING

The line from exercise to evidence.

The system is small and imperfect, but the journey has already produced real outcomes: confirmed findings, closures, reports, technical results and cases that resulted in patches.

Just as important, many apparently promising ideas failed. False positives were eliminated. Methods were discarded when evidence did not support them. Those failures changed the system.

REAL CODEREPRODUCIBLE EVIDENCEHUMAN JUDGMENTRESPONSIBLE SCOPE
07 / SCOPE

RESPONSIBLE RESEARCH

Passive, inspectable and authorized surfaces.

Our work has focused on the passive side of security research: source, deltas, architecture, boundaries, validation and reproducibility. The active, offensive side of the discipline is a different craft that we have not explored to the same depth.

THE MAP LEFT BEHIND

We did not start by trying to build a security methodology.

We started by trying to understand why we were wrong.

The methodology came later. Explore Google Scan Universe

This universe is simply the map left behind by that learning process.