Pratyay Kumar
Final-year Ph.D. candidate in Computer Science at New Mexico State University
Ph.D. expected Dec 2026 · Open to full-time Research Scientist and Applied Scientist roles in industry
I study AI agent security and adversarial machine learning. My work covers the tool servers agents use and the robustness of network intrusion detectors.
During my applied scientist and research scientist internships at Fincore, I built production AI agents for finance workflows. My research also examines the security risks that arise when agents use tools and access sensitive data. I am advised by Dr. Huiping Cao and co-advised by Dr. Satyajayant Misra.

News
- Jul 2026
MCP-in-SOS was accepted at AgentNet 2026, co-located with IEEE ICNP 2026. The presentation is on Oct 5. The study examined 1,186 open-source MCP server repositories. Manual validation of the highest-risk findings confirmed 68 vulnerabilities in 32 repositories. arXiv v1
- Jul 2026
A survey of generative AI and federated learning for intrusion detection is available as a preprint. arXiv v1
- May 2026
Following my internship, Fincore sponsored a one-year research project on agentic AI for finance at New Mexico State University.
Research
My dissertation examines how AI systems fail under attack and how to improve their resilience. I focus on three areas:
AI agent security
I study security weaknesses in open-source Model Context Protocol (MCP) servers, which connect AI agents to tools and data. My current work focuses on agent memory.
- MCP-in-SOS
- Agent memoryIn progress
LLM evaluation and adversarial robustness
I evaluate large language models (LLMs) for network intrusion detection using prompting alone. I also use adversarial flow features to test the robustness of deep-learning detectors.
Intrusion detection data
I build datasets for federated intrusion detection that preserve the uneven mix of traffic classes across sites. I also test whether detectors trained on synthetic flows perform well on real traffic.
Experience
All experience- May 2026 – Present
Graduate Research Assistant Current
Studying AI agent security, with work on open-source Model Context Protocol (MCP) servers (MCP-in-SOS, AgentNet 2026) and ongoing research on agent memory.
- Jan 2026 – May 2026
Research Scientist Intern
Built production multi-agent systems for financial close, cash forecasting, and revenue recognition. Their harness supports MCP tool orchestration, per-agent data scoping, persistent memory, and citations that trace each figure to its source transactions.
- Jul 2025 – Dec 2025
Applied Scientist Intern
Built production AI agents for real-time financial analysis of ERP, CRM, and HRIS data, with natural-language querying using LangChain and MCP.
Selected publications
All publications- 2026
MCP-in-SOS: Measuring the Security Posture of Open-Source MCP Servers Accepted
Manual review of the highest-risk findings from 1,186 MCP server repositories confirmed 68 vulnerabilities in 32 repositories. Of these vulnerabilities, 72% involved server-side request forgery. Disclosure to maintainers is ongoing.
- 2026
NetDiffuser: Deceiving DNN-Based Network Attack Detection Systems with Diffusion-Generated Adversarial Traffic Preprint
In benchmark experiments, NetDiffuser increased attack success rates by up to 29.93 percentage points compared with baseline attacks and reduced the AUC-ROC of adversarial-example detectors by up to 0.534.
- 2025
NetPrompt: Evaluation of LLMs as Network Intrusion Detection System
Using prompting without fine-tuning, the strongest of three LLMs outperformed a multilayer perceptron (MLP) baseline on CICDDoS2019 but performed worse on CICIDS2017.
- 2023
FLNET2023: Realistic Network Intrusion Detection Dataset for Federated Learning
The dataset preserves the uneven mix of traffic classes at ten emulated routers, revealing accuracy and convergence problems in federated intrusion detection.
Skills
- Security evaluation
- Static and dynamic security testing
- Risk prioritization
- Adversarial examples
- Intrusion detection benchmarks
- Agent systems
- Agent harness and context engineering
- Model Context Protocol (MCP)
- Multi-agent workflows and agent memory
- Retrieval-augmented generation
- LangGraph and LangChain
- Machine learning
- Diffusion models
- LLM fine-tuning (PEFT, LoRA)
- Federated learning
- PyTorch and Hugging Face
- Engineering
- Python, C/C++, SQL
- Network emulation (CORE)
- Full-stack web development
Talks and service
All talks and service- Jan 2026
- Oct 2025
- 2024 – 2026
Journal reviewer
- IEEE/ACM Transactions on Networking
- IEEE Internet of Things Journal
- IEEE Transactions on Mobile Computing
Education
- 2022 – Present
- 2016 – 2021