Pratyay Kumar

Final-year Ph.D. candidate in Computer Science at New Mexico State University

Ph.D. expected Dec 2026 · Open to full-time Research Scientist and Applied Scientist roles in industry

I study AI agent security and adversarial machine learning. My work covers the tool servers agents use and the robustness of network intrusion detectors.

During my applied scientist and research scientist internships at Fincore, I built production AI agents for finance workflows. My research also examines the security risks that arise when agents use tools and access sensitive data. I am advised by Dr. Huiping Cao and co-advised by Dr. Satyajayant Misra.

Pratyay Kumar

News

  • Jul 2026

    MCP-in-SOS was accepted at AgentNet 2026, co-located with IEEE ICNP 2026. The presentation is on Oct 5. The study examined 1,186 open-source MCP server repositories. Manual validation of the highest-risk findings confirmed 68 vulnerabilities in 32 repositories. arXiv v1

  • Jul 2026

    A survey of generative AI and federated learning for intrusion detection is available as a preprint. arXiv v1

  • May 2026

    Following my internship, Fincore sponsored a one-year research project on agentic AI for finance at New Mexico State University.

Research

My dissertation examines how AI systems fail under attack and how to improve their resilience. I focus on three areas:

  • AI agent security

    I study security weaknesses in open-source Model Context Protocol (MCP) servers, which connect AI agents to tools and data. My current work focuses on agent memory.

  • LLM evaluation and adversarial robustness

    I evaluate large language models (LLMs) for network intrusion detection using prompting alone. I also use adversarial flow features to test the robustness of deep-learning detectors.

  • Intrusion detection data

    I build datasets for federated intrusion detection that preserve the uneven mix of traffic classes across sites. I also test whether detectors trained on synthetic flows perform well on real traffic.

Experience

All experience
  • May 2026 – Present

    Graduate Research Assistant Current

    New Mexico State University · Las Cruces, New Mexico

    Studying AI agent security, with work on open-source Model Context Protocol (MCP) servers (MCP-in-SOS, AgentNet 2026) and ongoing research on agent memory.

  • Jan 2026 – May 2026

    Research Scientist Intern

    Fincore Inc. · Seattle, Washington · Remote

    Built production multi-agent systems for financial close, cash forecasting, and revenue recognition. Their harness supports MCP tool orchestration, per-agent data scoping, persistent memory, and citations that trace each figure to its source transactions.

  • Jul 2025 – Dec 2025

    Applied Scientist Intern

    Fincore Inc. · Seattle, Washington · Remote

    Built production AI agents for real-time financial analysis of ERP, CRM, and HRIS data, with natural-language querying using LangChain and MCP.

Selected publications

All publications

6 published or accepted (3 as first author) · 2 preprints

  • 2026

    MCP-in-SOS: Measuring the Security Posture of Open-Source MCP Servers Accepted

    Pratyay Kumar*, Miguel Antonio Guirao Aguilera*, Srikathyayani Srikanteswara, Abu Saleh Md Tayeen, Satyajayant Misra

    IEEE ICNP 2026 Workshop on Networking Foundations for Autonomous Agents (AgentNet) · * Equal contribution

    arXiv v1 is an earlier version with a different title and author order.

    Manual review of the highest-risk findings from 1,186 MCP server repositories confirmed 68 vulnerabilities in 32 repositories. Of these vulnerabilities, 72% involved server-side request forgery. Disclosure to maintainers is ongoing.

    arXiv v1Code and data
  • 2026

    NetDiffuser: Deceiving DNN-Based Network Attack Detection Systems with Diffusion-Generated Adversarial Traffic Preprint

    Pratyay Kumar, Abu Saleh Md Tayeen, Satyajayant Misra, Huiping Cao, Jiefei Liu, Qixu Gong, Jayashree Harikumar

    arXiv:2603.08901 [cs.CR]

    In benchmark experiments, NetDiffuser increased attack success rates by up to 29.93 percentage points compared with baseline attacks and reduced the AUC-ROC of adversarial-example detectors by up to 0.534.

    arXiv v1
  • 2025

    NetPrompt: Evaluation of LLMs as Network Intrusion Detection System

    Pratyay Kumar, Abu Saleh Md Tayeen, Qixu Gong, Jiefei Liu, Satyajayant Misra, Huiping Cao, Jayashree Harikumar

    IEEE Military Communications Conference (MILCOM 2025)

    Using prompting without fine-tuning, the strongest of three LLMs outperformed a multilayer perceptron (MLP) baseline on CICDDoS2019 but performed worse on CICIDS2017.

    PaperCode
  • 2023

    FLNET2023: Realistic Network Intrusion Detection Dataset for Federated Learning

    Pratyay Kumar, Jiefei Liu, Abu Saleh Md Tayeen, Satyajayant Misra, Huiping Cao, Jayashree Harikumar, Oscar Perez

    IEEE Military Communications Conference (MILCOM 2023)

    The dataset preserves the uneven mix of traffic classes at ten emulated routers, revealing accuracy and convergence problems in federated intrusion detection.

    PaperDataset

Skills

  • Security evaluation
    • Static and dynamic security testing
    • Risk prioritization
    • Adversarial examples
    • Intrusion detection benchmarks
  • Agent systems
    • Agent harness and context engineering
    • Model Context Protocol (MCP)
    • Multi-agent workflows and agent memory
    • Retrieval-augmented generation
    • LangGraph and LangChain
  • Machine learning
    • Diffusion models
    • LLM fine-tuning (PEFT, LoRA)
    • Federated learning
    • PyTorch and Hugging Face
  • Engineering
    • Python, C/C++, SQL
    • Network emulation (CORE)
    • Full-stack web development

Talks and service

All talks and service

Education