Forensic Scientist & AI Systems Engineer
Nine years of criminal casework, distinction-grade research in deepfake detection, and sovereign AI, cyber and forensic systems engineered for government — where the output has to survive a courtroom.
عالِم أدلة جنائية ومهندس أنظمة ذكاء اصطناعي
تسع سنوات من العمل الجنائي الميداني، وبحث بتقدير امتياز في كشف التزييف العميق، وأنظمة سيادية وسيبرانية وجنائية مهندَسة للجهات الحكومية — حيث يجب أن تصمد النتيجة أمام القضاء.
Engineer officer at Kuwait's Ministry of Interior with over nine years across criminal casework and AI systems. Specializes in the forensic examination and authentication of audio, video and digital evidence, and in deep-learning detection of deepfakes. INTERPOL-certified Digital Evidence First Responder, court-recognized expert witness, and technical subject-matter expert to senior police leadership. Architects enterprise AI systems for government — from requirements and data governance through sovereign deployment: multi-agent architecture, retrieval-augmented generation, air-gapped operation, human-in-the-loop decision design. Builds complete systems rather than isolated AI demonstrations — requirements and architecture through databases, APIs, agents, security, testing, deployment and observability. Works provider-independently across eleven AI engineering ecosystems, selecting the model that fits each task. Independently builds across the Google AI ecosystem — over 278 applications, agents and prototypes in Google AI Studio and the Gemini API, alongside 30+ projects developed in enterprise Google Cloud and Vertex AI environments.
Government-grade suite for deepfake detection and digital-evidence analysis, supporting technical examination of audio and video referred by investigative authorities.
Offline-first laboratory information management environment architected for secure, potentially air-gapped deployment — case and exhibit management, sample lifecycle, chain of custody, hash-based evidence integrity, audit logging, role-based access, bilingual Arabic/English OCR and interfaces, encrypted backups, and locally operated AI assistance with human confirmation before any AI-assisted action.
Evidence-first platform for detecting and localizing both AI-generated media and conventional manipulation — moving past binary “real versus fake” to identify what changed, where the suspicious signal sits, and what supports the conclusion. Covers splicing, copy-move, inpainting, voice cloning, partial spoofing, recompression and metadata analysis, with pixel-level masks, provenance and C2PA, confidence calibration and explicit insufficient-evidence reporting.
First-of-its-kind interactive platform for the 11th INTERPOL Digital Forensics Expert Group Meeting at the National Forensic Sciences University, India. Attendees followed the session live from their phones: slides that speak in real time, an AI agent answering audience questions, multilingual support, and linked deepfake-detection tools. Presented with the keynote “United Against Crime — A Global AI Forensic Alliance.” The work was subsequently generalized into a private multiscreen AI presentation architecture — main screen, presenter remote and audience devices synchronized in real time, with polls, reactions, AI-assisted Q&A, offline/PWA resilience and live-translation architecture.
A family of nationally controlled AI agents for forensic casework — built so that sensitive evidence never leaves sovereign infrastructure.
Multi-agent architecture with retrieval-augmented generation over approved forensic sources only; every finding routes through human-in-the-loop review before it reaches an examiner's report. Designed for air-gapped deployment.
A voice-driven encyclopedia that explains deepfakes, synthetic media and detection to the Arabic-speaking public — it talks, listens and answers.
Conversational agent grounded in vetted sources, with spoken Arabic as the primary interface. Built to translate nine years of forensic deepfake expertise into public understanding.
A multimodal generation and editing suite — image and video creation pipelines built on Google's generative stack.
Production pipelines for image generation, video synthesis and editing workflows, exercising the full breadth of the Gemini multimodal API surface.
Architects systems that select a different model for each task rather than committing an institution to one provider — the deliberate opposite of single-vendor AI adoption.
Model selection is treated as an engineering decision driven by data sensitivity, security classification, capability, accuracy, context length, vision and voice requirements, coding strength, latency, cost, infrastructure location and sovereignty constraints. The architecture stays stable as individual models are replaced.
Ecosystems in active engineering use: Claude (architecture, code review, long-context reasoning, agentic workflows) · Kimi (long-context and large-project analysis) · Manus (autonomous multi-step execution) · OpenAI Codex (repository-level engineering) · Gemini and Google AI Studio (multimodal, vision, voice, prototyping) · Vertex AI (enterprise deployment) · Replit (full-stack prototyping) · GitHub Copilot · Hugging Face (open models, evaluation, local deployment) · local and open models where sovereignty or offline operation is required.
Private enterprise AI environments that coordinate multiple models, specialist agents, tools and organizational workflows through a governed control layer — so an institution can run an internal AI workforce without surrendering control to a single external provider.
Multi-agent orchestration and agent-to-agent coordination, model routing and intent classification, task delegation and agent councils, tool calling with controlled web interaction, local and cloud model integration, retrieval-augmented organizational knowledge, long-term operational memory, persistent agents on autonomous scheduled workflows, computer-use and browser agents, agent observability and provenance, audit trails, human escalation and approval workflows, security policies, cost-aware routing and agent performance evaluation.
The design objective: individual models can be replaced as the technology moves, while governance, knowledge and operational architecture stay under institutional control.
Agent-assisted software engineering across the full development lifecycle, structured as a governed engineering organization rather than isolated code generation.
Coordinated specialist agents spanning requirements analysis and PRDs, architecture and UX planning, code generation and review, testing, security review, documentation, CI/CD, deployment, monitoring, bug triage and improvement cycles — with human oversight and technical traceability maintained throughout.
Enterprise security assessment platform combining automated passive checks, threat intelligence and AI-assisted remediation guidance — intentionally defensive, with no intrusive exploitation.
Assesses HTTP security headers, TLS and HTTPS configuration, cookie security, CORS and exposed-file exposure, and email-security posture. Adds subdomain intelligence and certificate-transparency analysis, CVE and known-exploited-vulnerability references, and remediation mapped to NIST- and ISO-aligned guidance, with full auditability.
Agents that reverse-engineer cybercrime attacks in order to prevent them — built on a clinical and epidemiological model rather than a purely technical one.
An attack is treated the way a physician treats a case and an epidemiologist treats an outbreak: diagnose the incident, reconstruct the chain of transmission, identify the vector, contain it, then immunise the wider environment against recurrence. The agents move from post-incident forensics toward predictive prevention.
An agentic platform for the forensic analysis of network and digital video recorder logs — reconstructing surveillance timelines from raw recorder data.
Automates the parsing, correlation and timeline reconstruction of NVR and DVR logs across heterogeneous recorder formats, surfacing gaps, tampering indicators and event sequences for examiner review under chain-of-custody controls.
Every system is architected with its own security layer rather than a bolted-on review: adversarial testing, monitoring, and a hardening loop that reconciles both into improvements.
Applied principles include least privilege, role-based access control, human authorization, agent permission boundaries, sensitive-data separation and secret protection, audit logging and provenance, AI-output verification, model evaluation and reproducibility, rollback capability, and local or sovereign deployment. Red-team probing, blue-team monitoring and purple-team improvement loops run as a continuing discipline across the portfolio.
ضابط مهندس بوزارة الداخلية بدولة الكويت، بخبرة تتجاوز تسع سنوات في التحقيقات الجنائية وأنظمة الذكاء الاصطناعي. متخصص في فحص الأدلة الصوتية والمرئية والرقمية والتحقق من أصالتها، وفي كشف التزييف العميق بتقنيات التعلم العميق. معتمد من الإنتربول بصفة مستجيب أول للأدلة الرقمية، وخبير فني معتمد أمام الجهات القضائية ولدى القيادات الأمنية. يصمم ويهندس أنظمة ذكاء اصطناعي مؤسسية للجهات الحكومية — من تحديد المتطلبات وحوكمة البيانات وصولاً إلى النشر السيادي: بنية الوكلاء المتعددين، والاسترجاع المعزز، والتشغيل المعزول عن الشبكات، ومبدأ الإنسان في حلقة القرار. يبني أنظمة متكاملة لا نماذج عرض معزولة — من المتطلبات والمعمارية إلى قواعد البيانات والواجهات البرمجية والوكلاء والأمن والاختبار والنشر والمراقبة. ويعمل باستقلال عن المزوّدين عبر إحدى عشرة منظومة هندسية للذكاء الاصطناعي، مختاراً النموذج الأنسب لكل مهمة. يطوّر بشكل مستقل ضمن منظومة Google AI — أكثر من ٢٧٨ تطبيقاً ووكيلاً ونموذجاً أولياً في Google AI Studio وGemini API، إلى جانب أكثر من ٣٠ مشروعاً طُوِّرت في بيئات Google Cloud وVertex AI المؤسسية.
منظومة حكومية متخصصة لكشف التزييف العميق والتحليل الفني للأدلة الرقمية، تدعم الفحص الفني للأدلة الصوتية والمرئية المحالة من جهات التحقيق.
بيئة إدارة معلومات مختبرية تعمل دون اتصال أولاً، مصممة للنشر الآمن والمعزول — إدارة القضايا والأحراز ودورة حياة العينات، وسلسلة حفظ الأدلة، وسلامة الأدلة بالبصمة الرقمية، وسجلات التدقيق، وصلاحيات المستخدمين، والتعرف الضوئي على النصوص بالعربية والإنجليزية، والنسخ الاحتياطية المشفّرة، ومساعدة ذكاء اصطناعي محلية تتطلب تأكيداً بشرياً قبل أي إجراء.
منصة قائمة على الأدلة لكشف الوسائط المولّدة بالذكاء الاصطناعي والتلاعب التقليدي وتحديد مواضعه — تتجاوز التصنيف الثنائي «حقيقي أم مزيف» إلى تحديد ما تغيّر، وأين، وما الدليل الداعم. تشمل الدمج والنسخ والطمس واستنساخ الصوت والتزييف الجزئي وإعادة الضغط وفحص البيانات الوصفية، مع أقنعة على مستوى البكسل، وإثبات المصدر وC2PA، ومعايرة الثقة، والإفصاح الصريح عن عدم كفاية الأدلة.
منصة تفاعلية هي الأولى من نوعها، بُنيت للاجتماع الحادي عشر لمجموعة خبراء الطب الشرعي الرقمي التابعة للإنتربول في جامعة العلوم الجنائية الوطنية بالهند. تابع الحضور العرض مباشرة من هواتفهم: شرائح تتحدث بالوقت الحقيقي، ووكيل ذكاء اصطناعي يرد على الأسئلة، ودعم متعدد اللغات، وأدوات مرتبطة بكشف التزييف العميق. قُدِّمت مع العرض الرئيسي «متحدون ضد الجريمة — تحالف عالمي للذكاء الجنائي».
منظومة وكلاء ذكاء اصطناعي وطنية للعمل الجنائي — مصممة بحيث لا تغادر الأدلة الحساسة البنية التحتية السيادية.
بنية وكلاء متعددين مع استرجاع معزز يقتصر على المصادر الجنائية المعتمدة؛ وتمر كل نتيجة عبر مراجعة بشرية قبل وصولها إلى تقرير الفاحص. مصممة للنشر المعزول عن الشبكات.
موسوعة صوتية تفاعلية تشرح التزييف العميق والوسائط الاصطناعية وطرق كشفها للجمهور الناطق بالعربية — تتحدث وتستمع وتجيب.
وكيل حواري مستند إلى مصادر موثوقة، بالعربية المنطوقة واجهةً أساسية — لتحويل تسع سنوات من الخبرة الجنائية في كشف التزييف العميق إلى وعي عام.
منظومة توليد وتحرير متعددة الوسائط — خطوط إنتاج للصور والفيديو مبنية على منظومة Google التوليدية.
خطوط إنتاج لتوليد الصور وتركيب الفيديو وسير عمل التحرير، بالاستفادة الكاملة من قدرات Gemini متعددة الوسائط.
تصميم أنظمة تختار نموذجاً مختلفاً لكل مهمة بدل ربط المؤسسة بمزوّد واحد — نقيض مقصود لتبنّي الذكاء الاصطناعي من مصدر وحيد.
يُعامَل اختيار النموذج قراراً هندسياً تحكمه حساسية البيانات، والتصنيف الأمني، والقدرة، والدقة، وطول السياق، ومتطلبات الرؤية والصوت، وقوة البرمجة، وزمن الاستجابة، والتكلفة، وموقع البنية التحتية، ومتطلبات السيادة. وتبقى المعمارية مستقرة مع استبدال النماذج.
المنظومات المستخدمة هندسياً: Claude (المعمارية ومراجعة الشيفرة والسياق الطويل وسير عمل الوكلاء) · Kimi (تحليل السياق الطويل والمشاريع الكبيرة) · Manus (التنفيذ الذاتي متعدد الخطوات) · OpenAI Codex (هندسة على مستوى المستودع) · Gemini وGoogle AI Studio (متعدد الوسائط والرؤية والصوت والنماذج الأولية) · Vertex AI (النشر المؤسسي) · Replit (النماذج الأولية المتكاملة) · GitHub Copilot · Hugging Face (النماذج المفتوحة والتقييم والنشر المحلي) · النماذج المحلية والمفتوحة حيث تُشترط السيادة أو العمل دون اتصال.
بيئات ذكاء اصطناعي مؤسسية خاصة تنسّق بين نماذج متعددة ووكلاء متخصصين وأدوات وسير عمل تنظيمي عبر طبقة تحكم محوكمة — لتشغّل المؤسسة قوة عمل ذكية داخلية دون تسليم السيطرة لمزوّد خارجي واحد.
تنسيق الوكلاء المتعددين والتنسيق فيما بينهم، وتوجيه النماذج وتصنيف النوايا، وتفويض المهام ومجالس الوكلاء، واستدعاء الأدوات مع تفاعل شبكي محكوم، ودمج النماذج المحلية والسحابية، والاسترجاع المعزز للمعرفة المؤسسية، والذاكرة التشغيلية طويلة المدى، ووكلاء دائمون بسير عمل مجدول ذاتياً، ووكلاء استخدام الحاسوب والمتصفح، ومراقبة الوكلاء وإثبات المصدر، وسجلات التدقيق، والتصعيد البشري وسير الموافقات، والسياسات الأمنية، والتوجيه المراعي للتكلفة، وتقييم أداء الوكلاء.
الهدف التصميمي: إمكانية استبدال النماذج مع تطور التقنية، مع بقاء الحوكمة والمعرفة والبنية التشغيلية تحت سيطرة المؤسسة.
هندسة برمجيات بمساعدة الوكلاء تغطي دورة التطوير الكاملة، ببنية منظمة هندسية محوكمة لا مجرد توليد شيفرة.
وكلاء متخصصون منسّقون يغطون تحليل المتطلبات ووثائق المنتج، والمعمارية وتخطيط تجربة المستخدم، وتوليد الشيفرة ومراجعتها، والاختبار، والمراجعة الأمنية، والتوثيق، والتكامل والنشر المستمر، والمراقبة، وفرز الأخطاء، ودورات التحسين — مع الحفاظ على الإشراف البشري وقابلية التتبع التقني.
منصة تقييم أمني للمؤسسات تجمع الفحوصات الآلية غير التدخلية واستخبارات التهديدات وإرشادات المعالجة المدعومة بالذكاء الاصطناعي — دفاعية بالتصميم دون أي استغلال تدخّلي.
تفحص ترويسات الأمان وإعدادات TLS وHTTPS وأمن الكوكيز وسياسات CORS والملفات المكشوفة ووضع أمن البريد الإلكتروني. وتضيف استخبارات النطاقات الفرعية وتحليل شفافية الشهادات، ومراجع الثغرات CVE والثغرات المستغلّة المعروفة، ومعالجة مرتبطة بإرشادات NIST وISO مع قابلية تدقيق كاملة.
وكلاء يعيدون هندسة الهجمات السيبرانية عكسياً بهدف منعها — بمنهج طبي ووبائي لا تقني بحت.
يُعامَل الهجوم كما يعامل الطبيب الحالة ويعامل عالم الأوبئة تفشي المرض: تشخيص الحادثة، وإعادة بناء سلسلة الانتقال، وتحديد ناقل العدوى، واحتواؤه، ثم تحصين البيئة الأوسع ضد تكراره. تنتقل هذه الوكلاء من التحليل الجنائي بعد الحادثة إلى المنع الاستباقي.
منصة قائمة على الوكلاء للتحليل الجنائي لسجلات أجهزة التسجيل الشبكية والرقمية — لإعادة بناء التسلسل الزمني لأنظمة المراقبة من بيانات المسجّل الخام.
تُؤتمت قراءة سجلات NVR وDVR وربطها وإعادة بناء تسلسلها الزمني عبر صيغ مسجّلات متباينة، مع إبراز الفجوات ومؤشرات العبث وتسلسل الأحداث لمراجعة الفاحص وفق ضوابط سلسلة حفظ الأدلة.
كل نظام يُصمَّم بطبقة أمنية خاصة به لا بمراجعة لاحقة: اختبار عدائي، ومراقبة، وحلقة تحصين توفّق بينهما لاستخلاص التحسينات.
تشمل المبادئ المطبَّقة أقل الامتيازات، والتحكم بالصلاحيات حسب الدور، والتفويض البشري، وحدود صلاحيات الوكلاء، وفصل البيانات الحساسة وحماية الأسرار، وسجلات التدقيق وإثبات المصدر، والتحقق من مخرجات النماذج، وتقييم النماذج وقابلية إعادة الإنتاج، وإمكانية التراجع، والنشر المحلي أو السيادي. وتجري حلقات الاختبار الأحمر والمراقبة الزرقاء والتحسين البنفسجي بوصفها ممارسة مستمرة عبر المنظومة.