Marwan Naili

RESEARCHER — AGENTIC SYSTEMS / APPLIED ML / SECURITY

ALGIERS, DZ · UTC+01:00

I build systems that run unattended, and I measure what they inherit. Three areas: agent platforms where a model calls tools and can break its own environment, applied ML where the hard part is knowing when a system is wrong, and security measurement — exposure, malware, and the surface area between them.

Everything runs on-device. A phone, a laptop, no rented GPUs, no cloud dependency. That constraint is not a limitation I work around; it is the reason the systems still function when the network doesn't.

on-deviceNO CLOUD RUNTIME
non-intrusiveDEFAULT METHOD
90 daysDISCLOSURE WINDOW
method + resultALWAYS PUBLISHED TOGETHER
[A]

Agentic systems

Platforms where a model calls tools, executes code, and runs for hours without supervision. I work on the parts that only fail under real load: sandbox containment, plugin permission models, network allowlisting enforced below the application layer, loop detection, and the CI discipline to ship a fork for years without upstream drift.

ANDROID · LINUX · PYTHON · CAPABILITY SECURITY · CI

[B]

Applied ML & evaluation

Retrieval that is allowed to say I don't know, and evaluations that don't flatter me. Supervised fine-tuning on constrained hardware, routing across small specialist models, adversarial needle-retrieval against long context, and building a gold set by hand so a benchmark means something.

RAG · ABSTENTION · SFT · ROUTING · ADVERSARIAL EVALS

[C]

Security measurement

Exposure enumeration, malware and exfiltration analysis, attack-surface review of real applications. Passive indexes, protocol identification, static and dynamic analysis on samples already in hand. No exploitation, no credential testing, no state-affecting action — the line is cheaper to hold before you cross it.

EXPOSURE · RE · OSINT · APPSEC · DISCLOSURE

Minis X

SHIPPED

verified 2026-10-01

A complete agent runtime for Android: on-device model routing, tool execution, a Linux sandbox for untrusted code, plugins with declared permissions and a network allowlist, scheduled tasks, an encrypted vault, and run telemetry. Ships through CI as a signed build and is verified on-device after every release — because a green build is a claim, not a test.

AGENTS ANDROID SANDBOX PLUGIN PERMISSIONS SIGNED CI
architecture diagram — add later

ARGUS

SHIPPED

verified 2026-09-28

Entity intelligence that runs entirely from a phone. Content-addressed evidence in SQLite, a resolver that returns SAME / DIFFERENT / UNKNOWN with the evidence attached, per-source coverage states so "not checked" can never be mistaken for "nothing found", and report generation behind a citation validator that fails closed.

OSINT RESOLUTION PROVENANCE CITATION VALIDATION
entity graph — add later

DarkTortilla RAT

SHIPPED

verified 2026-09-29

Reverse engineering of a commodity Android RAT's Telegram exfiltration channel: payload extraction, protocol reconstruction from recovered code, derived indicators of compromise. Samples handled in isolation; no live infrastructure contacted.

RE THREAT ANALYSIS IOC DERIVATION
protocol reconstruction — add later

PANOPTES

ACTIVE

updated 2026-09-28

A cron-snapshot geospatial feed on edge workers — earthquakes, military and civil flights, satellites, fires, hazards, news — collected on schedule into a historical store. Deliberately inverted from per-request fan-out: the observation is the record, not a query. A national Algerian-scoped variant runs alongside it.

EDGE WORKERS SCHEDULED COLLECTION HISTORICAL STORE

CyberRAG

ACTIVE

updated 2026-09-29

A retrieval arsenal over WSTG, ATT&CK, exploitation references and my own field notes, rebuilt around one rule: abstention is a valid output. Keyed lookup data and conceptual corpora live in separate indexes so a 1,900-record CVE catalogue cannot poison concept queries, and a query term absent from the corpus is treated as evidence the corpus lacks the topic.

RAG IDF WEIGHTING CALIBRATION EVAL HARNESS

Wormlab

RESEARCH

started 2026-09-28

An unanswered question: what is the real capability floor of small open-weight models used as autonomous cyber tooling? Existing public claims test one deliberately undisclosed model size and call it a result. I'm building the sweep — size against task fitness, below single-GPU scale, micro-policies versus language models, payload execution versus rhetoric.

RESEARCH LITERATURE REVIEW EXPERIMENTAL DESIGN

Algeria wilayas & communes

SHIPPED

verified 2026-09-28

All 69 wilayas and their communes, updated for the 2026 administrative reform, bilingual naming, with a documented generation procedure — a reproducible build rather than a one-off export.

DATASET REPRODUCIBLE BUILD PUBLIC
Verify the target
A passing command proves the mechanism worked. It never proves the objective was met. After anything that matters, I inspect the resulting state instead of trusting the exit code.
Keep layers apart
Observed, reported, inferred, unknown. A subagent's claim is evidence to check, not evidence. A report does not become a fact because it would be convenient.
Smallest change
Incremental beats elegant. A verified rough system is worth more than a clean one that was never deployed. Rewrite only when evidence demands it, not because it would read better.
Method travels with result
Procedure, timestamp, source and reproduction steps are published alongside the finding. Without them it is a screenshot, not research.
Refuse early
No written authorization, no work. Most of what keeps a project alive is refusing one job on day one instead of managing the consequences on day ninety.

Critical infrastructure exposure census

ACTIVE

started 2026-09-30

Passive-first measurement of Algerian critical-sector exposure — energy, water, ports, rail, telecom edge. The deliverable is a chain, not a port number: observation → attribution → technology → known vulnerability → how long it has been observable. Rules of engagement published before collection; disclosure to the responsible party and the regulator first.

NON-INTRUSIVE REPRODUCIBLE METHOD CERT-CC / ARPCE

Small-model capability floor

RESEARCH

started 2026-09-28

Model size swept against autonomous cyber-task fitness below single-GPU scale, establishing the quantitative floor that current public claims only gesture at.

EXPERIMENTAL DESIGN PUBLICATION PLAN ATTACHED

SECURITY — security@marwan-naili.me

CODE — github.com/hellbound2307

RESEARCH RECORD — /.well-known/security.txt

Security acknowledged within 3 business days. Publication after 90 days of silence, unless fixed.

  • Contactsecurity@marwan-naili.me — machine-readable at /.well-known/security.txt
  • ScopeReports accepted in any infrastructure. Findings concerning Algerian critical infrastructure are routed through CERT-CC / ARPCE rather than published first.
  • TimingAcknowledgement within 3 business days. Publication after 90 days of vendor silence, unless a fix or mitigation exists.
  • MethodNon-intrusive by default — no exploitation, no authentication attempts, no denial of service, no state-affecting action.
  • PromiseNo legal action against researchers acting in good faith within this policy, and no attribution without consent.