About me

Ph.D. Researcher Applied ML Engineer Software Engineer DevOps Engineer

I build systems at the intersection of applied machine learning, LLMs, and web security. As a Ph.D. researcher at Florida International University, I design autonomous browser-agent experiments, evaluation pipelines, behavioral models, and web-scale measurement studies. Before and alongside research, I spent years building software, cloud platforms, and data infrastructure for production environments. That combination lets me take an idea from experimental design and model evaluation through implementation, deployment, and observability.

What I'm doing

  • Security Research

    Studying commercial bot defenses, phishing ecosystems, Captcha security, and software vulnerabilities through reproducible measurement.

  • Applied ML

    Building LLM agents, automated evaluation harnesses, time-series models, and open-set systems with measurable real-world outcomes.

  • Site Reliability

    Designing Kubernetes platforms, CI/CD workflows, streaming systems, and observability for reliable production operations.

  • Software Engineering

    Developing Python and Node.js services, internal tooling, APIs, and distributed data pipelines across research and industry.

Resume

Education

  1. Ph.D. Computer Science

    Florida International University 01/2022 — 12/2026
  2. M.Sc. Computer Engineering

    Sharif University of Technology 2018 — 2021
  3. B.Sc. Computer Engineering

    University of Tehran 2014 — 2018

Experience

Graduate Research Assistant

Florida International University
Present
  • Evaluated LLM browser agents across model backends, orchestration strategies, browser profiles, and automation layers, observing over 95% bypass rates against four commercial bot services.
  • Crawled 30K vulnerability reports across 10+ software ecosystems and built an LLM evaluation pipeline to compare prompting strategies on patched and vulnerable packages.
  • Trained LSTM and Transformer models in PyTorch on browser-interaction time series, reaching 95% classification accuracy and isolating the contribution of each input modality.
  • Operated collection pipelines for 1.6B+ DOM, screenshot, and event-stream artifacts, turning web-scale measurements into datasets for model development.
  • Measured Captcha deployment across 1M+ websites and developed an object-detection pipeline that solved 12 Captcha schemes at 80%+ accuracy.

Platform Technical Team Lead

Tapsi
  • Created Python and Bash tooling that connected locally running microservices to shared Kubernetes staging environments, reducing developer resource requirements by 80%.
  • Built Node.js and Python messaging libraries over gRPC and RabbitMQ that sustained 10K events per second, with Prometheus metrics and Grafana dashboards.

DevOps Consultant

  • Built a scalable application platform on Google Cloud, combining a Java App Engine runtime and deployment pipeline with PostgreSQL and Kafka data infrastructure.

Machine Learning Engineer Intern

Fraunhofer IDMT
  • Trained a CNN-based face-recognition model with OpenCV and built a Python annotation tool to label hundreds of hours of news video by anchor identity and scene type.

Senior Infrastructure Engineer

Tapsi
  • Migrated 60+ microservices to Kubernetes and established repeatable Dockerization and cluster processes across backend teams.
  • Built Kafka and Apache Spark pipelines that fed Python ML services and analytics workflows.
  • Implemented Bash and Ansible CI/CD across staging, canary, and production environments, using A/B testing to reduce release risk.

Co-Founder and Full Stack Developer

Lambede
  • Co-founded and developed a home-services platform with Express.js APIs for users, payments, and request matching, a jQuery submission flow, and Telegram notifications for service agents.

Honors and Services

  • Dissertation Year Fellowship Award

    Florida International University

    2026
  • SGA Graduate Scholarship

    Florida International University

    2025
  • Teaching Assistant

    Software Vulnerability; Data Structures & Python Programming, FIU

    2022–Present
  • Graduate Mentor

    Research methodology, coding practices, and project planning

    2022–2025
  • Journal Reviewer

    IEEE Transactions on Information Forensics & Security (TIFS, IF 8.0)

    2024
  • Conference Reviewer

    RAID, DIMVA, MadWeb

    2024, 2025

Projects

  • LLM Browser Agent Evaluation of Commercial Bot Services

    Designed controlled experiments across model backends, agent orchestration, browser profiles, and automation stacks to study how commercial bot-management systems respond to autonomous web agents.

    View Publication
  • Analyzing Adversarial Payloads via Large Language Models

    Collected and analyzed a corpus of 90K+ payloads from publicly exposed online forms. Performed comprehensive analysis using Open-source Large Language Models for payload classification.

  • Investigating Security Challenges in Open-Source Software

    Analyzed vulnerability trends across 10+ ecosystems using GitHub Advisory and Snyk.io data. Identified common vulnerability types and compared distribution patterns, with detailed analysis of malicious packages in the NPM ecosystem.

  • Real-Time Browser Interaction Modeling

    Developed a scalable pipeline for Multi-Modal browser interaction data collection and classification of 1.6B+ artifacts. Published research demonstrating advanced bot detection capabilities.

    View Publication
  • Evaluating Resilience of Behavioral Bot Detection

    Evaluated deep learning bot detectors with adversarial ML (FGSM, Genetic Algorithm) to quantify model robustness in practical scenarios.

    View Publication
  • Adversarial Assessment of Text Captchas

    Developed Object Detection module using Tensorflow to solve real-world text-based Captchas, achieving 80%+ success rate on samples from 1M+ top websites.

    View Publication
  • Phishing Websites Detection

    Investigated code reuse patterns in 300K+ phishing websites using Semi-Supervised Clustering, enabling scalable detection of malicious websites with similar origins.

  • Deep Open Set Analysis for Network Traffic

    Built Feature Engineering pipelines for terabytes of PCAP data and implemented Open Set Recognition models in TensorFlow to detect zero-day anomalies in encrypted flows.

    View Publication
  • Cloud Application Platform for Image Analysis

    Built a Google Cloud application platform for Image Analysis Group, integrating a Java App Engine deployment pipeline with PostgreSQL and Kafka data infrastructure.

Publications

From Puzzles to Profiles: A Cross-Stack Study of Solver Services and LLM Browser Agents Against Bot Management Systems

B. Ousat, N. Turkmen, L. Rampersaud, D. Bailey, S. Uluagac, A. Kharraz

Beyond Valid Commands: Security Limits of Command Mediation in ROS2-PX4 UAVs

A. Espinoza, B. Ousat, R. Rangaswami, A. Kharraz

An Analysis of Architectural and Operational Dynamics of Phishkits in the Wild

B. Ousat, M. A. Tofighi, E. Schafir, A. Kharraz

Broken Gates: Re-evaluating Web Bot Defenses in the Age of LLM Agents

B. Ousat, L. Rampersaud, D. Bailey, N. Turkmen, A. Kharraz

Vulnerability Evolution and the Promise of Automated Gatekeeping in Open-Source Software

S.A. Akhavani*, B. Ousat*, A. Kharraz

International Symposium on Research in Attacks, Intrusions and Defenses (RAID), 2026

RAID, 2026 View on arXiv

In-Application Defense Against Evasive Web Scans through Behavioral Analysis

B. Ousat, M. Shariatnasab, E. Schafir, F. Shirani, A. Kharraz

The Matter of Captchas: An Analysis of a Brittle Security Feature on the Modern Web

B. Ousat, E. Schafir, D. C. Hoang, M. Ali Tofighi, S. Arshad, C. Nguyen, S. Uluagac, A. Kharraz

Constructs of Deceit: Exploring Nuances in Modern Social Engineering Attacks

M. A. Tofighi, B. Ousat, J. Zandi, E. Schafir, A. Kharraz

Evaluating Security Checks Against Malicious Payloads with Forged Signatures

L. Rampersaud, B. Ousat, S. A. Akhavani, J. Zandi, S. Uluagac, A. Kharraz

On the Effectiveness of End-Users' Data Backup Practices Against Data Corruption

L. Rampersaud, B. Ousat, C. Brown, S. Uluagac, A. Kharraz

Skills

Technical Skills

ML & Research

PyTorch TensorFlow Transformers Scikit-Learn OpenCV Adversarial ML Open Set Recognition Time Series Analysis

Generative AI & LLMs

LLM Agents Prompt Engineering RAG Prompt Chaining LLM Evaluation OpenAI API Vertex AI Hugging Face

Data & Streaming

PostgreSQL MongoDB Redis Kafka RabbitMQ Pinecone PySpark Elasticsearch

Engineering & Observability

Linux Ansible GitHub Actions CI/CD gRPC Prometheus Grafana Datadog

Languages

Python Node.js TypeScript Bash C++

Cloud & Platform

AWS Google Cloud Platform Kubernetes Docker Terraform

Cloud Expertise

Amazon Web Services

EC2, Beanstalk, S3, RDS, DocumentDB, VPC, IAM, CloudWatch, AWS Sagemaker

Google Cloud Platform

Compute Engine, GKE, Vertex AI, MLflow, AutoML

Google Cloud Machine Learning Engineer Learning Path In Progress, 100+ Hours
Data & Feature Engineering
BigQuery ML SQL-based ML Data Preprocessing Feature Engineering
Model Development
TensorFlow Keras Vertex AI Workbench Model Training Hyperparameter Tuning
MLOps
Vertex AI Pipelines Feature Store Model Registry Model Deployment Model Monitoring CI/CD for ML
Generative AI & LLMs
Large Language Models Generative AI on GCP Prompt Engineering Fine-tuning GenAI Generative AI Studio
Responsible AI
Fairness & Bias Mitigation Explainable AI Model Interpretability AI Privacy & Safety
Cloud & Infrastructure
Vertex AI Lifecycle Cloud ML Pipelines Scalable ML Design