Timothy R. McIntosh

dblp:231/1041 · DBLP profile ↗
← Back
11ranked-venue papers
8as first author
9since 2021 · last 2026
0000-0003-0836-4266ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 4 · 3 first-author · 2 since 2021Security and privacy · 4 · 4 first-author · 4 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Over the Edge of Chaos? Excess Complexity as a Roadblock to Artificial General Intelligence
abstract
This study explores the progression of artificial intelligence (AI) systems through the lens of complexity theory, challenging conventional linear projections of advancement toward artificial general intelligence (AGI). We posit the existence of critical points, akin to phase transitions, where increasing system complexity may not lead to greater capability, but rather to performance plateaus or instability. To investigate this hypothesis, we used agent-based modelling (ABM) to simulate the evolution of AI systems, using evaluation benchmark performances as a proxy for complexity. Our simulations modeled the possible characteristics that systems could exhibit when crossing a critical threshold, transitioning from predictable improvement to a regime of erratic, volatile behavior. Practically, we introduced and validated a methodology for detecting these simulated critical transitions algorithmically. We proposed a heuristic Stochastic Gradient Descent-based approach and compared it with established CUmulative SUM (CUSUM) and Lyapunov exponent techniques, to show that different signatures of instability-from abrupt shifts to gradual volatility ramps-can be identified. We contextualized these findings with real-world phenomena, arguing that the empirically observed -"Jagged Capability Frontier" in large language models (LLMs) illustrates the kind of nonlinear performance boundaries that could be sharply accentuated by the onset of criticality. This research contributes not only a novel theoretical framework for understanding potential limits to AI scaling but also a practical, validated methodology for monitoring the systemic stability of AI systems, offering a new dimension to AGI evaluation and safety.
Teo Susnjak, Timothy R. McIntosh, Andre L. C. Barczak, Napoleon H. Reyes, Tong Liu 0016, Paul A. Watters, Malka N. Halgamuge
IEEE Trans. Cybern.2
2025 Modeling the Chaotic Semantic States of Generative Artificial Intelligence (AI): A Quantum Mechanics Analogy Approach
abstract
Generative AI models have revolutionized intelligent systems by enabling machines to produce human-like content across diverse domains. However, their outputs often exhibit unpredictability due to complex and opaque internal semantic states, posing challenges for reliability in real-world applications. In this article, we introduce the AI Uncertainty Principle , a novel theoretical framework inspired by quantum mechanics, to model and quantify the inherent unpredictability in generative AI outputs. By drawing parallels with the uncertainty principle and superposition, we formalize the tradeoff between the precision of internal semantic states and output variability. Through comprehensive experiments involving state-of-the-art models and a variety of prompt designs, we analyze how factors such as specificity, complexity, tone, and style influence model behavior. Our results demonstrate that carefully engineered prompts can significantly enhance output predictability and consistency, while excessive complexity or irrelevant information can increase uncertainty. We also show that ensemble techniques, such as Sigma-weighted aggregation across models and prompt variations, effectively improve reliability. Our findings have profound implications for the development of intelligent systems, emphasizing the critical role of prompt engineering and theoretical modeling in creating AI technologies that perceive, reason, and act predictably in the real world.
Tong Liu 0016, Timothy R. McIntosh, Teo Susnjak, Paul A. Watters, Malka N. Halgamuge
ACM Trans. Intell. Syst. Technol.2
2025 Automating Research Synthesis with Domain-Specific Large Language Model Fine-Tuning
abstract
This research pioneers the use of fine-tuned Large Language Models (LLMs) to automate Systematic Literature Reviews (SLRs), presenting a significant and novel contribution in integrating AI to enhance academic research methodologies. Our study employed advanced fine-tuning methodologies on open sourced LLMs, applying textual data mining techniques to automate the knowledge discovery and synthesis phases of an SLR process, thus demonstrating a practical and efficient approach for extracting and analyzing high-quality information from large academic datasets. The results maintained high fidelity in factual accuracy in LLM responses, and were validated through the replication of an existing PRISMA-conforming SLR. Our research proposed solutions for mitigating LLM hallucination and proposed mechanisms for tracking LLM responses to their sources of information, thus demonstrating how this approach can meet the rigorous demands of scholarly research. The findings ultimately confirmed the potential of fine-tuned LLMs in streamlining various labor-intensive processes of conducting literature reviews. As a scalable proof-of-concept, this study highlights the broad applicability of our approach across multiple research domains. The potential demonstrated here advocates for updates to PRISMA reporting guidelines, incorporating AI-driven processes to ensure methodological transparency and reliability in future SLRs. This study broadens the appeal of AI-enhanced tools across various academic and research fields, demonstrating how to conduct comprehensive and accurate literature reviews with more efficiency in the face of ever-increasing volumes of academic studies while maintaining high standards.
Teo Susnjak, Peter Hwang, Napoleon H. Reyes, Andre L. C. Barczak, Timothy R. McIntosh, Surangika Ranathunga
ACM Trans. Knowl. Discov. Data5
2024 From COBIT to ISO 42001: Evaluating cybersecurity frameworks for opportunities, risks, and regulatory compliance in commercializing large language models
abstract
This study investigated the integration readiness of four predominant cybersecurity Governance, Risk and Compliance (GRC) frameworks - NIST CSF 2.0, COBIT 2019, ISO 27001:2022, and the latest ISO 42001:2023 - for the opportunities, risks, and regulatory compliance when adopting Large Language Models (LLMs), using qualitative content analysis and expert validation. Our analysis, with both LLMs and human experts in the loop, uncovered potential for LLM integration together with inadequacies in LLM risk oversight of those frameworks. Comparative gap analysis has highlighted that the new ISO 42001:2023, specifically designed for Artificial Intelligence (AI) management systems, provided most comprehensive facilitation for LLM opportunities, whereas COBIT 2019 aligned most closely with the European Union AI Act. Nonetheless, our findings suggested that all evaluated frameworks would benefit from enhancements to more effectively and more comprehensively address the multifaceted risks associated with LLMs, indicating a critical and time-sensitive need for their continuous evolution. We propose integrating human-expert-in-the-loop validation processes as crucial for enhancing cybersecurity frameworks to support secure and compliant LLM integration, and discuss implications for the continuous evolution of cybersecurity GRC frameworks to support the secure integration of LLMs.
Timothy R. McIntosh, Teo Susnjak, Tong Liu 0016, Paul A. Watters, Dan Xu 0021, Raza Nowrozy, Malka N. Halgamuge
Comput. Secur.1
2024 A Reasoning and Value Alignment Test to Assess Advanced GPT Reasoning
abstract
In response to diverse perspectives on artificial general intelligence (AGI), ranging from potential safety and ethical concerns to more extreme views about the threats it poses to humanity, this research presents a generic method to gauge the reasoning capabilities of artificial intelligence (AI) models as a foundational step in evaluating safety measures. Recognizing that AI reasoning measures cannot be wholly automated, due to factors such as cultural complexity, we conducted an extensive examination of five commercial generative pre-trained transformers (GPTs), focusing on their comprehension and interpretation of culturally intricate contexts. Utilizing our novel “Reasoning and Value Alignment Test,” we assessed the GPT models’ ability to reason in complex situations and grasp local cultural subtleties. Our findings have indicated that, although the models have exhibited high levels of human-like reasoning, significant limitations remained, especially concerning the interpretation of cultural contexts. This article also explored potential applications and use-cases of our Test, underlining its significance in AI training, ethics compliance, sensitivity auditing, and AI-driven cultural consultation. We concluded by emphasizing its broader implications in the AGI domain, highlighting the necessity for interdisciplinary approaches, wider accessibility to various GPT models, and a profound understanding of the interplay between GPT reasoning and cultural sensitivity.
Timothy R. McIntosh, Tong Liu 0016, Teo Susnjak, Paul A. Watters, Malka N. Halgamuge
ACM Trans. Interact. Intell. Syst.1
2023 Applying staged event-driven access control to combat ransomware
abstract
The advancement of modern Operating Systems (OSs), and the popularity of personal computing devices with Internet connectivity, have facilitated the proliferation of ransomware attacks. Ransomware has evolved from executable programs encrypting user files, to novel attack vectors including fileless command scripts, information exfiltration and human-operated ransomware. Many anti-ransomware studies have been published, but many of them assumed newer ransomware variants only performed file encryption, were similar to existing variants, and often did not consider those novel attack vectors. We have defined an updated ransomware threat model to include those novel attack vectors, and redefined false positives and false negatives in the context of ransomware mitigation. We proposed to apply both program-centric and user-centric access control to combat ransomware, but only delegate access control decisions that users are capable of making to users, while enforcing non-negotiable access control decisions by OS and software developers. We have designed a Staged Event-Driven Access Control (SEDAC) approach to incorporate both program-centric and user-centric access control measures, and demonstrated a prototype on Windows OS. Our prototype was able to intercept more types of ransomware attack vectors than existing proposals. We hope to convince OS and software architects to incorporate our design to better combat ransomware.
Timothy R. McIntosh, A. S. M. Kayes, Yi-Ping Phoebe Chen, Alex Ng, Paul A. Watters
Comput. Secur.1
2023 Harnessing GPT-4 for generation of cybersecurity GRC policies: A focus on ransomware attack mitigation
abstract
This study investigated the potential of Generative Pre-trained Transformers (GPTs), a state-of-the-art large language model, in generating cybersecurity policies to deter and mitigate ransomware attacks that perform data exfiltration. We compared the effectiveness, efficiency, completeness, and ethical compliance of GPT-generated Governance, Risk and Compliance (GRC) policies, with those from established security vendors and government cybersecurity agencies, using game theory, cost-benefit analysis, coverage ratio, and multi-objective optimization. Our findings demonstrated that GPT-generated policies could outperform human-generated policies in certain contexts, particularly when provided with tailored input prompts. To address the limitations of our study, we conducted our analysis with thorough human moderation, tailored input prompts, and the inclusion of legal and ethical experts. Based on these results, we made recommendations for corporates considering the incorporation of GPT in their GRC policy making.
Timothy R. McIntosh, Tong Liu 0016, Teo Susnjak, Hooman Alavizadeh, Alex Ng, Raza Nowrozy, Paul A. Watters
Comput. Secur.1
2021 Dynamic user-centric access control for detection of ransomware attacks
Timothy R. McIntosh, A. S. M. Kayes, Yi-Ping Phoebe Chen, Alex Ng, Paul A. Watters
Comput. Secur.1
2021 Enforcing situation-aware access control to build malware-resilient file systems
Timothy R. McIntosh, Paul A. Watters, A. S. M. Kayes, Alex Ng, Yi-Ping Phoebe Chen
Future Gener. Comput. Syst.1
2019 The Inadequacy of Entropy-Based Ransomware Detection
Timothy R. McIntosh, Julian Jang, Paul A. Watters, Teo Susnjak
ICONIP (5)1
2018 Large Scale Behavioral Analysis of Ransomware Attacks
Timothy R. McIntosh, Julian Jang, Paul A. Watters
ICONIP (6)1