Profile Image

Grigoris Ntousakis

My name is Grigoris Ntousakis, born and raised in Chania, Crete. I hold a Master of Science in Computer Science from Brown University, where I conducted research under the guidance of Professor Nikos Vasilakis and Professor Vasileios Kemerlis. My research interests include computer security—with a particular focus on AI agent security—programming languages, dynamic program analysis, and techniques for improving software development workflows.
Interests. Dynamic Analysis, Security, Programming Languages

Education

  • Brown University MSc in Computer Science (May 2026) Providence, USA Thesis: Securing MCP-based Agent Workflows
  • Technical University of Crete (TUC) MSc in Computer Science and Engineering (Sept. 2024) Chania, Greece Thesis: Applying Dynamic Coarse-Grained Library Interposition to Security
  • Technical University of Crete (TUC) BSc in Electrical and Computer Engineering (Sept. 2020) Chania, Greece Thesis: Coarse-Grained Dynamic Analysis of Software Libraries

Experience

  • IBM Research Security Research Intern (May 2025 - Aug. 2025) Yorktown Heights, NY
    • Conducted security research on LLM agents, focusing on threat modeling and data leakage prevention.
    • Designed and built systems that analyze agent behavior to infer and enforce runtime security policies, mitigating data leakage and other agent-specific risks.
    Python, TypeScript, MCP, A2A, LLMs, Docker, Dynamic Analysis, Static Analysis
  • Telecommunication Systems Research Institute (TSI) Research Scientist (Mar. 2021 - Sept. 2024) Chania, Greece
    • Led development of PRINCIPALS, a novel architecture for safe programmability and adaptability in 5G networks, strengthening security through primitives such as DGA analysis and TLS fingerprinting.
    • Automated Kubernetes cluster deployment with Ansible and Vagrant for rapid R&D provisioning across multiple VMs, significantly reducing setup time for large-scale testing.
    • Containerized cybersecurity primitives with Docker, streamlining their deployment and management across 5G infrastructure.
    Go, Python, Docker, Kubernetes, Ansible, Vagrant, Git, CI/CD
  • Brown University Visiting Research Fellow (Mar. 2023 - Nov. 2023) Providence, USA
    • Designed and implemented a novel system combining dynamic and static analysis for enforcing more expressive and fine-grained security policies.
    • Developed a language-level system-call filtering mechanism to strengthen syscall safety guarantees for untrusted code.
    • Co-led development of BinWrap, a hybrid protection framework against native Node.js add-ons.
    Node.js, Shell Scripts, LLMs, Npm, Latex
  • Aegis Technologies Ltd. Cyber Security Engineer (Jan. 2022 - Jan. 2023) Remote, Singapore
    • Implemented a high-performance deep packet inspection (DPI) engine, improving threat detection accuracy for the network monitoring and threat intelligence product.
    • Collaborated with a 15-person engineering team to optimize packet processing and build protocol-specific parsing modules.
    C, Python, Git, CI/CD

Projects

  • BinWrap paper code blog Hybrid sandbox that isolates native Node.js add-ons from the host process, containing memory-unsafe C/C++ code without requiring changes to existing application APIs. Node.js, Native Add-ons (N-API), Sandboxing Distinguished Paper Award, ASIA CCS 2023
  • MIR paper code arxiv Runtime privilege-reduction system that strips write access from executable memory pages to block dynamic library compromise in Node.js applications. Node.js, Dynamic Linking, Memory Protection (RWX)
  • Lya paper code Module-level dynamic analysis framework for dynamic languages that instruments third-party dependencies via module recontextualization, with no changes to application code. JavaScript, Dynamic Program Analysis, Module Systems Distinguished Paper Award, ESEC/FSE 2021
  • HoneyChart paper code Automated deployment and lifecycle management for honeypots on Kubernetes, letting small security teams run threat-intelligence infrastructure with minimal operational overhead. Kubernetes, Honeypots
  • PRINCIPALS Architecture for safe programmability and adaptability in 5G networks, strengthening security through primitives such as DGA analysis and TLS fingerprinting, containerized and deployed across multi-VM research clusters. Go, Python, Docker, Kubernetes, Ansible, Vagrant

Publications

Talks / Demos

Awards

Service