Fred Araujo

Title

Principal Research Scientist and Manager, Security Research
Fred Araujo

Bio

I am a Principal Research Scientist and Manager in Security Research at IBM Research, where I lead a team focused on securing AI agents and agentic middleware. Our work spans protocol and framework security, authorization and access control, systems security, and program analysis. I am a maintainer of CPEX, a policy-enforcement runtime for AI agents, and Praxis, a security-first proxy framework. I also contribute to open-source projects in this space, including MCP Context Forge and BeeAI.

My research explores how to make software systems more secure and resilient against cyber threats, with a particular interest in language-based techniques for enforcing security. My current technical interests include AI and agent security, protocol security, authorization and access control, secure systems, cloud and web security, cyber deception, malware defense, programming languages, compilers, and program analysis.

Previously, I contributed and maintained open-source projects in cloud-native and endpoint security, including SysFlow and CNCF’s Falco. I have also contributed research and technology to several IBM products, including IBM Security’s ReaQta and QRadar.

My work has appeared at leading academic and industry security venues and has received several best-paper awards, including the Best Applied Security Research Award at CSAW. I earned my Ph.D. in Computer Science from the University of Texas at Dallas under the supervision of Dr. Kevin Hamlen. My doctoral research on language-based cyber deception received the university’s Best Dissertation Award. A complete list of my publications is available on my Google Scholar profile.

I served as a conference champion for the Security & Privacy Professional Interest Community at IBM Research. I have also contributed to the following conference committees and peer-review activities:

  • ACM Conference on Computer and Communications Security (CCS) Program Committee, 2021 and 2026
  • USENIX Security Symposium Program Committee, 2023 and 2024
  • IEEE International Conference on Big Data Program Committee, 2019–2024
  • Industry Co-Chair, IEEE CIC/CogMI/TPS, 2023
  • HICSS reviewer, 2019–2022
  • IEEE Transactions on Dependable and Secure Computing reviewer, 2018, 2019, 2021, and 2022
  • IEEE Transactions on Industrial Informatics reviewer, 2020
  • NYU CSAW Applied Research Program Committee, 2017–2023 and 2025
  • The Web Conference external reviewer, 2018

Projects

  • sysflow3.png

    A cloud-native system telemetry framework that enables the creation of security analytics on a scalable, pluggable open-source platform.

Blog posts

Top collaborators