Qian Cui

Anomaly detection & agent systems for security · Senior Applied Scientist, Amazon

prof_pic.jpg

Anomaly detection

Agent systems for security

Seattle, WA, USA

I work where anomaly detection meets agent systems for security — building AI that finds what shouldn’t be there, and then reasons about it the way a good analyst would.

At AWS I was a core designer of the Amazon GuardDuty Investigation Agent, a multi-agent system that turns a raw security finding into a structured, evidence-backed assessment and cuts investigation from hours to minutes.

Before that I spent years on the machine learning behind GuardDuty’s threat detection itself — continuous, ML-based detection across an entire cloud footprint: API activity, network flows, DNS, containers, serverless, databases, and storage. The problem is learning what normal looks like for each account and surfacing only the deviations that matter — compromised credentials, cryptomining, privilege escalation, data exfiltration — in near real time, mapped to MITRE ATT&CK, across millions of API calls and network events. It is research-to-production in its least forgiving form: the model has to be fast, cheap, and right, on data that never stops moving, for customers who feel every false positive.

What I care about most is the part nobody demos: making these systems honest about what they don’t know. Detection that reports its uncertainty. Agents that verify before they claim. Evaluation that measures the thing you actually care about instead of the thing that is easy to score.

I explore the same questions in the open — FlowCrew, a multi-agent orchestrator built so that “it didn’t work” is a first-class outcome, and open-data studies on how far a small local model can go on private-domain retrieval once you measure the frontier honestly. I write up what I learn, including the experiments that failed, in notes.

latest posts

selected publications

  1. TMLR
    Contextual Learning for Anomaly Detection in Tabular Data
    Spencer King, Zhilu Zhang, Ruofan Yu, and 3 more authors
    Transactions on Machine Learning Research (TMLR), 2025
  2. WWW
    Tracking Phishing Attacks Over Time
    Qian Cui, Guy-Vincent Jourdan, Gregor V. Bochmann, and 1 more author
    In 26th International World Wide Web Conference (WWW), 2017