CogSec — Cognitive Threat Modeling
Gemini APIAI/MLPythonSecurity Research
Overview
CogSec shifts cybersecurity from system-centric to human-centric analysis. Using Gemini 3 Pro, it reconstructs and analyzes security failures caused by cognitive pressure, bias, and decision fatigue.
The system treats the human operator as the primary vulnerability vector—not the missing patch.
How It Works
- Telemetry Capture — Sandbox collects response times, click patterns, and cognitive load indicators
- Vulnerability Inference — Maps behaviors to cognitive biases (automation bias, time pressure heuristics)
- Counterfactual Reasoning — Calculates "what if" risk deltas under modified conditions
- Human-Centered Mitigations — Recommends design changes, not just technical fixes
Key Innovation
Traditional security focuses on technical controls. CogSec asks: "What cognitive state led to this failure?"
Outputs include forensic timelines, vulnerability mappings, and actionable interventions targeting alert fatigue, habituation, and decision overload.
Tech Stack
Gemini API Python Cognitive Psychology Forensic Analysis