Scott Freitas

I’m a Principal Applied Scientist at Microsoft working at the intersection of applied and theoretical machine learning, with a focus on graph mining and deep learning. My goal is to develop explainable, robust, and efficient next-generation cybersecurity systems.

I completed my Machine Learning PhD at Georgia Tech where I worked with Polo Chau. I co-authored several winning research proposals, including a multi-million dollar DARPA grant; was awarded PhD fellowships from IBM Research, NSF GRFP and Raytheon; and was fortunate to work with amazing engineers and scientists at IBM Research, Amazon, Microsoft Advanced Threat Protection, Microsoft Research, Intel and the Naval Air Warfare Center.

News

2024Check out our 2 new Microsoft Tech Community blogs on Copilot for Security Guided Response, and incident correltion in Defender XDR

2024Our ML for cybersecurity research led to 5 patent filings this last year

2024Our work GraphWeaver, billion-scale cybersecurity incident correlation, was invited for a keynote talk at CIKM Industry Day 2024

2024I was promoted to Principal Applied Scientist at Microsoft!

2024Our work on Microsoft Copilot for Security Guided Response is now available on arXiv to read!

2024Our work on GraphWeaver, billion-scale cybersecurity incident correlation, was accepted into CIKM

2023I was promoted to the second level of Senior Applied Scientist at Microsoft!

Research Highlights

Education

Dec. 2021Aug. 2018Ph.D. in Machine Learning
Aug. 2018Georgia Institute of Technology, Atlanta, GA
Advisor: Duen Horng (Polo) Chau
Thesis: Developing Robust Models, Algorithms, Databases and Tools with Applications to Cybersecurity and Healthcare
Committee: Duen Horng (Polo) Chau, Srijan Kumar, Diyi Yang, B. Aditya Prakash, Hanghang Tong
Thesis Thesis Recording (Proposal) Thesis Slides

May 2018 —May 2017M.S. in Computer Science
May 2017Arizona State University, Tempe, AZ
Advisor: Hanghang Tong
Thesis: Mining Marked Nodes in Large Graphs
Committee: Hanghang Tong, Ross Maciejewski, Yezhou Yang
GPA: 4.00/4.00
Thesis

May 2017 —Aug. 2015B.S. in Computer Science
Aug. 2015Arizona State University, Tempe, AZ
Advisor: Ross Maciejewski
Thesis: Guided Augmented Reality Tours using Landmarks and Social Media
GPA: 3.98/4.00
Thesis Thesis Recording

May 2014 —Aug. 2010B.S.E. in Electrical Engineering
Aug. 2010Arizona State University, Tempe, AZ
Advisor: James Aberle
Thesis: Multi-Stage Linear Electromagnetic Accelerator Using Optical Triggering
GPA: 3.64/4.00
Thesis Thesis Recording

Awards (selected)

2021IBM PhD Fellowship
One of sixteen fellows; awarded for my work in developing next-generation explainable defenses

2021Nvidia Data Science Teaching Kit
Helped develop one of five Nvidia teaching kits used by educators around the world

2019Raytheon Research Fellowship
Awarded for my PhD work in adversarial machine learning

2018 — 2021NSF Graduate Research Fellowship
National Science Foundation recognizes and supports outstanding graduate students in STEM fields

2018Outstanding Computer Science Masters Student (ASU)
Awarded to single master student demonstrating exemplary performance

2017Best Demo Award, Runner Up at CIKM '17
For "Rapid Analysis of Network Connectivity"

Industry Research Experience

Present —Sep. 2024Microsoft, Redmond, WA
Sep. 2024Principal Applied Scientist (level 65), Microsoft Security Research
• Leading research into LLM-based agents to automatically identify detection and disruption rule gaps.
• Created an ML-driven threat intelligence platform that fuels key detection and disruption capabilities for Microsoft Defender XDR.
• Developed an adaptive incident prioritization score to assist in prioritizing security incidents for investigation.

Aug. 2024Sep. 2023Microsoft, Redmond, WA
Sep. 2023Senior Applied Scientist (level 64), Microsoft Security Research
• Led an ML research team in architecting and delivering key capabilities for our flagship AI product, Copilot for Security, including recommendations for similar incidents, triaging, and remediation. Collaborated across teams to launch the product on a tight timeline.
Paper Blog Dataset

• Created an incident correlation architecture responsible for correlating billions of alerts across hundreds of thousands of Microsoft Defender XDR enterprises. Reduced our singleton incident rate by 7%, translating into millions of investigation hours saved annually by SOCs.
Paper Blog

Aug. 2023Jan. 2022Microsoft, Redmond, WA
Jan. 2022Senior Applied Scientist (level 63), Microsoft Security Research
• Developed graph-based algorithms to identify alert correlation gaps, enabling the correlation of millions of alerts into comprehensive incident stories, saving customers millions in investigation time.
• Led the development and execution of a comprehensive research integration plan, successfully help merge two billion-dollar security products, M365D and Sentinel, into Microsoft Defender XDR.
Blog

Dec. 2021 —Sep. 2021IBM Research, Yorktown Heights, NY
Sep. 2021Research Intern, Cyber Security Intelligence (CSI) Team
Mentor: Teryl Taylor, Frederico Araujo, Jiyong Jang
Developed unsupervised graph representation learning techniques to detect suspicious activity in cloud platforms

Aug. 2021 —May 2021Amazon, Seattle, WA
May 2021Applied Scientist Intern, Fraud Detection and Risk Transaction (CTPS)
Mentor: Hao Zheng, Yanni Lai
Created unsupervised and semi-supervised approaches to prevent fraudulent transactions across the Amazon marketplace

May 2020 —Aug. 2020Microsoft, Redmond, WA
Aug. 2020Research Intern, Microsoft ATP + Microsoft Research
Mentor: Karishma Sanghvi, Yuxiao Dong
Designed semi-supervised graph neural network approach to detect malicious software

Aug. 2019 —May 2019Microsoft, Redmond, WA
May 2019Research Intern, Microsoft Advanced Threat Protection (ATP)
Mentor: Andrew Wicker, Joshua Neil
• Created first framework to model lateral attacks on enterprise networks, enabling IT admins to quantify and mitigate network vulnerability to lateral attacks
Paper

March 2015 —Dec. 2014General Dynamics, Scottsdale, AZ
Dec. 2014Systems Engineer, Mission Systems
Worked on the Integrated Threat Force team to develop and refine the communication technology systems.

Aug. 2013 —May 2013Naval Air Warfare Center, Point Mugu, CA
May 2013Research Intern, Naval Research Entperprise Internship Program (NREIP)
Mentor: Balaji Iyer
Explored methods of preventing electromagentic interference from coupling into superconducting receivers

Publications

AI-Driven Guided Response for Security Operation Centers with Microsoft Copilot for Security
Scott Freitas, Jovan Kalajdjieski, Amir Gharib, Rob McCann
arXiv (arXiv). 2024.
Project PDF Blog Dataset BibTeX Deployed in Microsoft Copilot for Security product

GraphWeaver: Billion-Scale Cybersecurity Incident Correlation
Scott Freitas, Amir Gharib
ACM International Conference on Information and Knowledge Management (CIKM). Boise, Idaho, 2024.
Project PDF Blog BibTeX Deployed in Microsoft Defender XDR product Keynote Talk at CIKM Industry Day

Graph Vulnerability and Robustness: A Survey
Scott Freitas, Diyi Yang, Srijan Kumar, Hanghang Tong, Duen Horng (Polo) Chau
IEEE Transactions on Knowledge and Data Engineering (TKDE). 2022.
PDF BibTeX

MalNet: A Large-Scale Image Database of Malicious Software
Scott Freitas, Rahul Duggal, Duen Horng (Polo) Chau
ACM International Conference on Information and Knowledge Management (CIKM). Atlanta, GA, 2022.
Demo PDF Dataset Code BibTeX

A Large-Scale Database for Graph Representation Learning
Scott Freitas, Yuxiao Dong, Joshua Neil, Duen Horng (Polo) Chau
Neural Information Processing Systems Datasets and Benchmarks (NeurIPS). Virtual, 2021.
Project Demo PDF Blog Dataset Code BibTeX

Evaluating Graph Vulnerability and Robustness using TIGER
Scott Freitas, Diyi Yang, Srijan Kumar, Hanghang Tong, Duen Horng (Polo) Chau
ACM International Conference on Information and Knowledge Management (CIKM). Virtual, 2021.
PDF Blog Video Code BibTeX Featured in Nvidia Data Science Toolkit

EnergyVis: Interactively Tracking and Exploring Energy Consumption for ML Models
Omar Shaikh, Jon Saad-Falcon, Austin P Wright, Nilaksh Das, Scott Freitas, Omar Asensio, Duen Horng Chau
ACM Conference on Human Factors in Computing Systems (CHI). Virtual, 2021.
Demo PDF Video Code BibTeX

UnMask: Adversarial Detection and Defense Through Robust Feature Alignment
Scott Freitas, Shang-Tse Chen, Zijie J. Wang, Duen Horng (Polo) Chau
IEEE International Conference on Big Data (Big Data). Atlanta, GA, 2020.
Project PDF Blog Video Code BibTeX

HAR: Hardness Aware Reweighting for Imbalanced Datasets
Rahul Duggal, Scott Freitas, Sunny Dhamnani, Duen Horng (Polo) Chau, Jimeng Sun
IEEE Conference on Big Data (Big Data). Orlando, USA, 2021.
PDF Video BibTeX

Argo Lite: Open-Source Interactive Graph Exploration and Visualization in Browsers
Siwei Li, Zhiyan Zhou, Anish Upadhayay, Omar Shaikh, Scott Freitas, Haekyu Park, Zijie J. Wang, Susanta Routray, Matthew Hull, Duen Horng (Polo) Chau
ACM International Conference on Information and Knowledge Management (CIKM). Virtual, 2020.
Demo PDF Code BibTeX

REST: Robust and Efficient Neural Networks for Sleep Monitoring in the Wild
Rahul Duggal*, Scott Freitas*, Cao Xiao, Duen Horng (Polo) Chau, Jimeng Sun
The Web Conference (WWW). Taipei, Taiwan, 2020.
Project PDF Blog Video Code BibTeX * Authors contributed equally

D2M: Dynamic Defense and Modeling of Adversarial Movement in Networks
Scott Freitas, Andrew Wicker, Duen Horng (Polo) Chau, Joshua Neil
SIAM International Conference on Data Mining (SDM). Cincinnati, Ohio, 2020.
Project PDF Blog BibTeX

Extracting Knowledge For Adversarial Detection and Defense in Deep Learning
Scott Freitas, Shang-Tse Chen, Duen Horng (Polo) Chau
KDD Workshop: Learning and Mining for Cybersecurity (LEMINCS). Anchorage, Alaska, 2019.
PDF BibTeX

Local Partition in Rich Graphs
Scott Freitas, Nan Cao, Yinglong Xia, Duen Horng (Polo) Chau, Hanghang Tong
IEEE International Conference on Big Data (Big Data). Seattle, Washington, 2018.
Project PDF BibTeX

X-Rank: Explainable Ranking in Complex Multi-Layered Networks
Jian Kang*, Scott Freitas*, Haichao Yu, Yinglong Xia, Hanghang Tong
ACM International Conference on Information and Knowledge Management (CIKM). Turin, Italy, 2018.
Project PDF BibTeX * Authors contributed equally

Rapid Analysis of Network Connectivity
Scott Freitas, Hanghang Tong, Nan Cao, Yinglong Xia
ACM International Conference on Information and Knowledge Management (CIKM). Singapore, 2017.
Project PDF Video Code BibTeX Best Demo Paper, Runner up