You're pledging to donate if the project hits its minimum goal and gets approved. If not, your funds will be returned.
I work on SCADA and IEC-104 security. I want to test a practical problem in AI-assisted vulnerability research: when a model produces a convincing finding, can somebody else reproduce it, and does the same method work on a different project?
This is a new 12-week pilot, at about three days per week. I am requesting $25,000. I will use open-source industrial-protocol code in isolated test environments. The outputs will be a reproducible evaluation harness, reviewed cases and a report covering failures as well as successes.
Goals and method
In weeks 1-2, I will select three buildable codebases and preregister the scoring rules. The target is 15-24 cases using historical vulnerable/patched versions and clearly labelled synthetic controls. In weeks 3-5, I will build version-pinned replay environments. In weeks 6-9, I will compare two model configurations with three runs per case and a fixed resource cap. I will freeze the workflow before testing held-out projects. In weeks 10-12, I will arrange independent review of a subset and release the permitted artifacts and results.
I will measure confirmed-finding precision, detection on known cases, false positives on patched controls, replay success, cross-run agreement, transfer to held-out projects and reviewer time. Synthetic mutations will be labelled separately from real historical vulnerabilities. If I cannot validate enough cases, I will report the smaller set and its limits.
The AI safety motivation is that cyber-capability evaluations and defensive deployments need verified evidence. Plausible reports and narrow benchmark scores can give a misleading impression of capability. This project could improve those evaluations, but its effect on catastrophic risk is indirect and depends on uptake by other researchers.
Use of funding
$18,000 gross researcher compensation: 36 days at $500/day, including provision for applicable personal taxes.
$3,000 compute/API budget: capped at $250/week.
$1,500 independent review: 15 hours at $100/hour; reviewer to be recruited.
$2,500 contingency: 10% of the total.
No travel or hardware purchase is budgeted. API credits received would reduce compute costs paid from the grant. The indicative work period is January-April 2027; the actual start follows funding and coordination with current commitments.
Team and track record
I am Heinrihs Kristians Skrodelis, an RTU doctoral researcher, research assistant and lecturer working on SCADA/ICS, IEC-104 threat scenarios and explainable intrusion detection. I am credited as reporter of CVE-2026-62972 in BACnet Stack: https://github.com/bacnet-stack/bacnet-stack/security/advisories/GHSA-9hq3-w3pc-8385 . Relevant publications and CV: https://heinrihs.org/ . My initial public artifact is https://github.com/heinrihs-s/Scada-Agent-SafetyBench . It demonstrates implementation experience, but I am not claiming established adoption or a completed version of this new study. This is an individual project; no collaborator or reviewer has committed.
What could fail
Historical cases may be hard to rebuild or too contaminated to tell us much. Ground truth may be ambiguous, reviewer recruitment may fail, or the workflow may not transfer. I will use an early feasibility check, pinned environments, patched controls, explicit exclusions and independent review. A negative result with replayable evidence is still useful. The study will not establish that a frontier model is safe. Newly discovered flaws will be coordinated with maintainers before details are released. There is no NATO affiliation or endorsement.
Other funding
I am also applying to the Transformative AI Fund for this same $25,000 pilot. These are alternative funding requests. If either funds the full pilot, I will withdraw or reduce the other before accepting an award. No cost or work will be funded twice. Separate NLnet proposals concern non-AI infrastructure work with separate milestones and time accounting.
I have not received grant or project funding in the past 12 months. No funding has yet been received for this pilot.
Drafting assistance
AI tools helped structure this proposal from my research profile and my choices of topic, budget and time commitment.
Contact: mail@heinrihs.org
There are no bids on this project.