Felix Waschke

PhD Student · Department of Software Science
Tallinn University of Technology (TalTech), Estonia

felix.waschke{at}taltech.ee

Research

My doctoral research is titled Using Machine Learning for Supporting Cyber Threat Handling in Security Operation Centers. Security Operations Centres (SOCs) receive far more alerts than analysts can investigate. I study how machine learning can help them prioritise and triage those alerts and detect threats. The methods have to work under real SOC constraints: little labelled data, heavy class imbalance and the need for analyst trust.

Publications

2026

  1. Semi-supervised learning in Security Operations Centers: Performance, trade-offs and practical implications F. Waschke, A. Guerra-Manzanares, R. Vaarandi Computer Networks, vol. 289, 112697, 2026
  2. ML4SOC: A Comprehensive Review on Machine Learning for Security Operations Centres F. Waschke, R. Vaarandi, A. Guerra-Manzanares ACM Computing Surveys, vol. 58, no. 14, pp. 1–48, 2026

Teaching

Computer Forensics Lab → Interactive case studies for students: disk and file-system forensics in the browser, a network and SIEM investigation, and the hands-on "Learn" modules. AI Attack Lab → Hands-on LLM security: attack an AI assistant across scenarios on prompt injection, indirect and image injection, data exfiltration, and encoding bypasses, mapped to MITRE ATLAS.