Prof. Dr. habil. Marc-Oliver Pahl

Professor of Cybersecurity

Trustworthy Autonomous Cybersecurity · Critical Infrastructures · Distributed Systems

Google ScholarDBLPLinkedINYouTubeORCID

I study how complex digital infrastructures can establish trustworthy security state, understand adversarial behaviour, and respond safely under increasing autonomy. My research connects distributed systems and network management with cyber-physical and embedded security, trustworthy AI, contextual reasoning, autonomous response, and human decision-making.

I am Professor of Cybersecurity at IMT Atlantique and Chairholder of the Cybersecurity for Critical National Infrastructures (Cyber CNI) Chair, a multi-institutional research ecosystem spanning IMT Atlantique, Télécom Paris, and Télécom SudParis.

Google Scholar · DBLP · ORCID · HAL · LinkedIn · Cyber CNI

Research

From observation to self-healing cybersecurity

observe → understand → decide → act → verify → learn

Digital infrastructures increasingly combine embedded devices, networks, cloud and edge services, cyber-physical processes, AI components, organizations, and human operators. Attacks do not respect the boundaries between these layers.

My overarching question: How can complex digital infrastructures remain trustworthy when the systems they protect, the evidence they expose, the AI they employ, and the adversaries they face are all changing simultaneously?

Trustworthy Observability — What evidence can a defender trust? I investigate security observability across network telemetry, cyber-physical processes, honeynets, embedded execution, and physical side channels—from distributed anomaly detection to power-assisted security analysis.

Contextual Security Reasoning — How can heterogeneous observations become security knowledge? Building on semantic integration and distributed systems, I investigate system models, provenance, uncertainty, digital twins, and hybrid AI for contextual security reasoning.

Autonomous Resilience — Under what conditions may cybersecurity act autonomously? My work connects distributed and federated intelligence, AIOps, digital twins, consequence assessment, and graduated autonomy toward increasingly self-healing infrastructures.

Meaningful Human Control — How should cognition and authority be divided between humans and machines? Building on computer graphics, virtual reality, and immersive cybersecurity analytics, I investigate decision support that reduces rather than adds complexity.

Emerging frontier — Information Resilience — My recent work extends these questions to AI-mediated information systems: controlled generation, disinformation, provenance, human response, and operation-level observability.

Selected Research

Complete publication record (DBLP) · Google Scholar

Group & Experimental Research

I organize research around scientific questions rather than individual funding instruments. Projects provide the people, infrastructure, data, and experimental environments required to pursue these questions over time.

Current doctoral researchers — Christian Lübben · Erkin Kirdan · Alexander Loth · Mathis Durand · Mohammed Mezaouli · Hugo Bourreau · Luc Bournaud · Antonios Ntib

Research engineering — Axel Dupraz

The current team spans IMT Atlantique, TUM, Frankfurt University of Applied Sciences, and Western University, with work on distributed AI, industrial IoT, cyber deception, embedded physical observability, digital twins, decentralized incident response, and AI-enabled information resilience.

Industrial & OT Security — Miniaturized industrial factories with Siemens, Schneider, Industrial Shields, and Crouzet PLCs; PLC-controlled physical processes; smart-building IoT; and a virtualized environment reproducing major real-world OT attacks.

Embedded & Physical Security — Experimental environments for embedded execution analysis, power-assisted security observability, and side-channel research.

Digital-Twin Security — Experimental twins of water-treatment processes and IoT systems for state estimation, adversarial manipulation, attribution, and resilience.

Cyber Deception — Honeynet deployments and tooling for analysing realism, detectability, fingerprinting, and attacker interaction.

Immersive Cybersecurity Analytics — A multi-user VR environment for situational awareness, immersive analytics, risk analysis, and mitigation control.

Information Resilience — JudgeGPT/RogueGPT, CRED-1, and experimental infrastructure for controlled AI-generated information, provenance, and human-response studies.

Semantic Distributed Systems — A VSL-based testbed for semantic collaboration among distributed agents using a dynamically evolving knowledge model.

JudgeGPT experimental interface · labsystem / iLab infrastructure

Cybersecurity for Critical National Infrastructures

I lead the Cyber CNI Chair, connecting fundamental cybersecurity research with the constraints of real critical infrastructures. The programme has evolved from distributed and federated detection toward cyber-physical observability, deception, embedded and physical security evidence, digital twins, and autonomous response.

Current industrial partners — Airbus Programme Cyber · Airbus PROTECT · EDF · RTE · Astek

Public and institutional ecosystem — COMCYBER · Pôle d’Excellence Cyber · Campus Cyber · Région Bretagne · FEDER

Previous industrial partners include — SNCF · BNP Paribas · Nokia · Amossys · Orange · La Poste · Société Générale

Research at Scale

70+peer-reviewed publications1,590Google Scholar citations
~€7Mresearch funding acquired as PI20H2020 / Horizon Europe proposals
19doctoral researchers supervised/co-supervised150Bachelor’s and Master’s theses

h-index 18 · i10-index 45 · 5 Horizon consortium coordinator roles · figures updated September/October 2026.

Selected programmes include Cyber CNI, Horizon Europe CyberSecDome, AI-based embedded-security projects, DTACK, Atos Life-Cycle Based IoT Service Management, DECENT, and Building as a Service.

Three Latest Publications

RogueGPT: A Controlled Stimulus Generation Framework for News Authenticity Research

A Loth, M Kappes, MO Pahl Journal of Open Source Software 11 (125), 11219, 2026

RogueGPT is an open-source Python framework for the controlled, reproducible generation and curation of multilingual news fragments for AI authenticity research. It enables researchers to systematically produce synthetic news stimuli across a wide range of large language model (LLM) families, journalistic styles, languages, and content formats, while storing every fragment alongside complete generation provenance in…

2026

AI-Enhanced Security Tools with Virtual Reality for Ensuring Digital Resilience

S Islam, S Papastergiou, A Duzha, K Drakonakis, G Chrysos, S Ioannidis, … Technology-Enabled Resilience: Innovations in Critical Infrastructure …, 2026

The cybersecurity challenges facing today’s digital infrastructure make it critical to improve the disruption preparedness and resilience of these systems. Resilience can only be achieved through (i) having a clear and comprehensive understanding of cyber incidents and their cascading effects, including potential disruptions, and (ii) providing a system with dynamic recovery and response capabilities. The…

2026

Experts disagree on how to fight AI disinformation, but agree that health and politics need different solutions

A Loth, M Kappes, MO Pahl arXiv preprint arXiv:2608.28621, 2026

When 54 international experts assessed AI-generated disinformation threats, they revealed a surprising pattern: while video deepfakes received the highest average threat ratings in the political domain (M = 6.31/7), the pattern differed in the health domain, where AI-generated text received the highest average rating (M = 5.80). Experts also diverge on what to do: government…

2026

Teaching

I have taught continuously at universities for more than twenty years. I regard teaching as a design discipline: learning objectives, activities, assessment, feedback, technology, and the learning environment should form a coherent system.

My principal educational contribution is iLab / labsystem, developed over two decades into a methodology and open-source infrastructure for scalable hands-on computer science education. Its formats have reached thousands of learners across physical and virtual laboratories, MOOCs, hybrid teaching, and learning-by-teaching.

Representative formal evaluation — 1.4 overall · 1.2 practical relevance · 1.1 commitment to student success (1 = best).

Recognition includes the Ernst Otto Fischer Teaching Prize, three TUM Teaching Excellence Awards, and the TUM Supervisory Award. I hold TUM’s ProLehre Certificate for Professional University Teaching, Advanced Level.

I am currently extending this methodology toward hands-on OT cybersecurity education.

Education in the age of AI — when AI can generate convincing programs, explanations, and reports almost instantly, assessment must increasingly evaluate reasoning → experimentation → critique → evidence → reflection.

Future-IoT PhD School series

Academic Leadership

My academic career spans the German and French research systems. At TUM, I was the first scientific staff member of the newly established Chair of Network Architectures and Services. In Rennes, I built a research operation essentially from the ground up and subsequently revitalized and expanded Cyber CNI.

My leadership philosophy is based on progressive transfer of intellectual ownership: develop researchers who can define and lead their own science, build structures that outlast individual projects, and connect communities in ways that enable research none could achieve alone.

President · German Chapter of the ACM

Member of the Präsidium · Gesellschaft für Informatik

Cyber CNI Chairholder

Technical Program Co-Chair · IEEE/IFIP NOMS 2026

Distinguished Expert Panel Co-Chair · CNSM 2026

Additional roles include leadership in the German-French Academy for the Industry of the Future, Lab-Cyber/Campus Cyber, journal editorial boards, and guest editorships on AI/MLOps, Industrial IoT, and trustworthy Agentic AI.

Academic Background

Habilitation in Computer Science — Technical University of Munich, 2025

Dr. rer. nat., summa cum laude — Technical University of Munich, 2014

Diplom in Computer Science, grade 1.0 — University of Tübingen, 2007

My scientific foundations lie in distributed systems, computer networks, semantic integration, and computer graphics, complemented by media science. This combination continues to shape my approach to cybersecurity across technical layers and human decision-making.

Knowledge Transfer & Society

I engage in knowledge transfer where it strengthens research, education, or societal understanding. My activities include long-term collaboration with critical-infrastructure operators and cybersecurity organizations, open-source research and teaching infrastructure, MOOCs, international doctoral schools, and public discussion formats.

TALK.CYBER · Future-IoT · German Chapter of the ACM

I regard transfer and entrepreneurship as consequences of excellent research, not substitutes for it.

Latest

News archive