LIVE · CYPHER LAB · UNIVERSITY OF RHODE ISLAND · KINGSTON, RI
Philip Akekudaga
OT/ICS & network security researcher. PhD student in Electrical Engineering.
I spent eight years running a national utility's SCADA and IT infrastructure.
Now I build defenses for the power grid inside the network itself: P4 programs on
Intel Tofino switches that detect, deceive, and protect before traffic ever
reaches the control room.
I am a PhD student in Electrical Engineering at the University of Rhode Island,
working in the CYPHER Lab under Dr. Hui Lin on ONR- and NSF-funded research.
My work sits at the intersection of programmable data planes and critical
infrastructure security: I write P4 programs for Intel Tofino ASICs that
detect threats, impersonate industrial devices, and control what the network
measures, without waiting for the control plane to catch up.
Before the PhD I spent years in the trenches: eight years assessing, securing,
and operating OT and IT infrastructure across five sites of Ghana's national
water utility, hands-on with PLCs, HMIs, RTUs, and telemetry over Modbus and DNP3.
Then security automation for a regulated FinTech, and enterprise security in the
CISO's office at the New York State Department of Health, monitoring 5,000+ assets.
That operational background shapes how I approach research: if it can't survive
a production network, it's not done.
the hardware in my world
RTUremote telemetry
PLCcontrol logic
P4 switchTofino data plane
SmartNICprogrammable NIC
Transformersubstation
Transmissionthe grid itself
02 · research
Research focus
Four connected threads, all on real hardware: what a network can see about
industrial devices, how to hide it, how to fake it, and how to decide where to look.
Traffic obfuscation for SCADA links
Encrypted SCADA traffic still leaks operational state through packet size and
timing. GridCloak reshapes what a WAN observer sees, padding, chaff, and
calendar scheduling at line rate on Tofino, verified end-to-end with real
OpenDNP3 traffic.
A Tofino switch that impersonates DNP3 outstations: virtual RTUs with realistic
MAC addresses, OS fingerprints, open ports, and substation measurements that
don't physically exist. Includes methodology for quantifying honeypot detectability.
Deciding in the packet path what gets through: firmware rollout admission for
battery storage sites (OTA-Shield), and per-command authorization for DNP3
control traffic on bandwidth-limited serial links (SDNP, in memory-safe Rust).
Networks can't measure everything at once. MCP is a control-plane subsystem
that decides, every epoch, which measurement tasks run on which P4 switches
under hard resource budgets, using a constrained contextual bandit.
HW verifiedfig — the wire before and after obfuscation
SCADA WAN traffic-obfuscation gateway on P4/Tofino. Defeats a passive observer
who fingerprints encrypted SCADA links through packet size, timing, and volume:
fixed-size padding states, chaff, and calendar scheduling so the wire shows
gateway-controlled timing, not device timing. Round-trips real OpenDNP3
master–outstation traffic through the obfuscator on hardware.
A programmable data-plane decoy that impersonates DNP3 outstations (RTUs) on a
Tofino switch. Attackers scanning the network see virtual devices with realistic
MAC addresses, OS fingerprints, open TCP ports, and substation measurements,
none of which physically exist.
Hardware-measured reference architecture for in-network OTA firmware-rollout
admission and bounded firmware-attack detection on battery energy storage (BESS)
site networks: the switch parses the OTA channel and a two-stage arbiter admits
only authorized rollouts and rollbacks.
A DNP3-compatible security profile for the bandwidth-limited serial links
(1200–9600 bd) where TLS does not fit: session encryption plus per-command
authorization inside a strict serial byte budget. Reference implementation in
memory-safe Rust with formal verification models.
Under reviewfig — scenario × baseline evaluation heatmap
Decides every epoch which measurement tasks (sketches, sampling, watchlists,
polling) run on which P4 switches under hard resource budgets, using a
constrained contextual bandit with shadow prices. Ranked first against six
baselines on five of nine evaluation scenarios.
Cryptographic admission control against external corpus poisoning in
retrieval-augmented generation: an enforcement layer that blocks unauthorized
sources from entering a RAG corpus, matching the attack-success reduction of
heavier defenses on that subproblem. ACM submission with full evaluation code.
Closed-loop network defense pipeline: attack generation, real-time detection,
agent-based controller orchestration, and P4 data-plane enforcement. Classifies
threats at 10,000+ events per second with 97% accuracy and automated remediation
under 50 ms.
P4-based adaptive load balancing that distributes traffic across equal-cost paths
using real-time link utilization counters, a data-plane feedback loop with no
per-packet controller involvement.
Functional Dependency Network Analysis for power-grid cascading failure:
multi-layer dependency modeling (physical, cyber, mission), failure propagation
simulation, and risk metrics on IEEE 14- and 30-bus test systems. Won the
SIRAcon '25 research competition.
Quantitative cyber-risk assessment with Factor Analysis of Information Risk:
threat scenario modeling, annualized loss expectancy, Monte Carlo simulation,
and threat event frequency analysis.
Interactive tool that quantifies the potential business impact of phishing
attacks from company profile, user access patterns, and industry benchmarks,
with risk breakdowns across financial, operational, and reputational dimensions.
React
Risk
Visualization
Cloud Honeypot Threat Mapping
Deployed an Azure Windows honeypot, captured 75,000+ brute-force attempts in
24 hours, and built a KQL-driven Microsoft Sentinel dashboard mapping attacker
IPs and key indicators in real time.
Azure
Sentinel / KQL
Honeypot
04 · experience
Experience
Jan 2026 – Present
Research Assistant, OT/ICS Security
CYPHER Lab, University of Rhode Island · Kingston, RI
Research programmable-network (P4) defenses for power-grid and industrial control systems, including DNP3 and IEC 61850 traffic; ONR and NSF funded, advised by Dr. Hui Lin
Built OT anomaly detection and industrial asset discovery classifying threats at 10,000+ events per second with 97% accuracy and automated remediation under 50 ms
Design and deploy network topologies with BGP, OSPF, ECMP, and VLAN segmentation on P4 switches targeting BMv2 and Intel Tofino ASICs; automate provisioning and metrics collection with Python and Bash
Assess OT/ICS network architectures for risk and design ISA/IEC 62443- and NIST 800-82-aligned segmentation
Aug 2024 – Dec 2025
Cybersecurity Analyst, Office of the CISO
New York State Department of Health · Albany, NY
Monitored and investigated security alerts across 5,000+ assets with Splunk (SPL) and Microsoft Sentinel (KQL); cut manual review effort 60% through detection tuning and Python automation over REST APIs
Conducted Nessus-driven vulnerability assessments against NIST CSF and NIST 800-53 baselines; identified 200+ vulnerabilities and misconfigurations
Authored 15+ security policies and 5 incident response playbooks; prepared assessment reports and executive summaries for technical and operational stakeholders
Supported evaluation of AI/LLM tools for agency adoption, assessing data protection risks and HIPAA/HITECH compliance
Aug 2025 – Dec 2025
Graduate Assistant
University at Albany, College of Emergency Preparedness, Homeland Security & Cybersecurity
Curated and analyzed PhD program data to support assessment, accreditation, and curriculum decisions
Oct 2024 – May 2025
Senior Research Aide
Research Foundation for SUNY / UAlbany Innovation Center · Albany, NY
Built ML time-series anomaly detection pipelines; trained a GRU model to 94% accuracy on 500,000+ records
Conducted 37+ third-party security assessments against ISO 27001 and CIS controls; documented findings, tracked remediation, and implemented network segmentation across production environments
Sep 2014 – Jan 2022
IT / MIS Officer
Ghana Water Company Ltd. (national utility, OT/SCADA environment) · Kumasi, Ghana
Assessed, secured, and operated OT and IT infrastructure across 5 utility sites (600+ endpoints, 50+ servers) in a SCADA and industrial control environment for eight years
Operated, hardened, and troubleshot SCADA field equipment (PLCs, HMIs, RTUs) with telemetry over Modbus and DNP3, hands-on at the protocol level; maintained SCADA data historians
Designed Purdue Model OT/IT segmentation with Layer 2/3 switch configurations over industrial Ethernet, isolating control traffic from office networks
Managed patching baselines at 98% compliance; handled 120+ incidents per week; authored the SOP and topology documentation library and trained 15+ operations staff
Earlier: business analyst roles at Voltic (Coca-Cola) and Wilmar Africa.
05 · publications
Publications
Where Should the Network Look Next? Multi-Objective Measurement Control for Programmable Network Monitoring
NSDI Frontiers Track Under review
MemProof: Cryptographic Admission Control Against External Corpus Poisoning in RAG
ACM (TAISAP) Under review
Quantifying Systemic Risk in Critical Power Infrastructure Using FDNA: From Single-Node Failure to Grid-Wide Cascades
SIRAcon '25, Boston, MA Research competition winner · extended version under review at SmartNets 2026
Navigating Multi-Jurisdictional Privacy Compliance in AI: An Empirical Analysis of Regulatory Gaps
IEEE UEMCON 2025, New York, NY Accepted
Enhancing Critical Infrastructure Security: Addressing Cybersecurity Risks and Regulatory Gaps in AI-Enabled IoT Systems
IEEE UEMCON 2025, New York, NY Accepted
A Framework for Financial Markets Impact Assessment of Data Breaches Using Interpretable Machine Learning and Event Study Methods
ASIA '25, Albany, NY Published
Resilient IoT Security: Early Flood Attack Detection in IoT Networks Using GRU Deep Learning Model
World Journal of Advanced Research and Reviews, 27(2), 871–886 Published
When the Ground Shakes: Social Media Responses to the 2024 Northeast Earthquake