Hi, I'm Andrew Fasano — a senior cyber researcher leading the cyber workstream at NIST's Center for AI Standards and Innovation (CAISI), where I assess the hacking capabilities of frontier AI models.

In practice, my research is less about running benchmarks and more about figuring out what to measure in the first place, and what the results actually mean. That can mean designing new benchmarks grounded in realistic threat models, or spending weeks with a single model deployed as a coding agent, pushing past automated scores to find real vulnerabilities and to build working exploits. The other half of my time is spent briefing these findings to senior USG stakeholders, including the White House — and convening the TRAINS interagency taskforce I lead to debate them with experts across government.

This work builds on a decade I spent at MIT Lincoln Laboratory's Cyber System Assessments Group, where I worked on vulnerability discovery, firmware rehosting, and dynamic program analysis — and built systems for rigorously evaluating the tools that do this kind of work. I led MIT-LL's Lab RATs to a top-10 finish at DEF CON CTF finals. My roots in the cyber community go back to RPISEC at RPI.

Recently

2026.02
Found and disclosed vulnerabilities in the Linux kernel, Exim, and Open5GS.
2025.09
OpenAI publicly described my finding in ChatGPT Agent as a "sophisticated exploit chain combining traditional software vulnerabilities with AI vulnerabilities."
2024.08
Presented "A Reverse Engineer's Guide to Mechanistic Interpretability" at DEF CON, on understanding the internals of large language models.

Projects

Talks

Awards

R&D100 Award
2020.09
LAVA was awarded an R&D100 award for its impact advancing the state of the art in vulnerability discovery and enabling rigorous, large-scale evaluation of automated security tools.
MIT Lincoln Scholar Award
2019.09
Selected to receive special funding through a competitive process to pursue advanced research in cybersecurity and dynamic program analysis.
MIT Lincoln Laboratory Team Award
2017.06
Recognized for outstanding technical achievement in advancing cybersecurity research and tooling development.

Disclaimer

This is a personal website. The views expressed here are my own and do not represent the views of my employer or any other organization.