Philip Huff, Ph.D.

Philip Huff

Associate Professor
Computer Science

Contact

Bio

Philip Huff, Ph.D., is an associate professor in the School of Computer and Information Sciences and Director of the Cyberspace Operations Research and Education (CORE) Center at the University of Arkansas at Little Rock. His work focuses on protecting critical infrastructure and preparing students to address cybersecurity challenges through applied research and practical experience.

Huff leads research and education initiatives supported by the U.S. Department of Energy, the National Security Agency, and Space Force. Through CORE and the university’s cybersecurity clinic, he connects student learning with services for utilities, schools, healthcare providers, and community organizations. He has helped develop academic programs in cybersecurity and artificial intelligence and expand cybersecurity education for teachers nationwide.

Before joining UA Little Rock in 2019, Huff worked in electric utility cybersecurity, including executive leadership of critical infrastructure security at Arkansas Electric Cooperative. He is also a co-founder and chief scientist of Bastazo, a cybersecurity company developing tools for operational technology.

Education

Ph.D., Computer Science, University of Arkansas, 2021.
M.S., Computer Science, James Madison University, 2008.
B.S., Computer Science and Mathematics, Harding University, 2002.

Research

Huff’s research examines how organizations can make more effective cybersecurity decisions, particularly when protecting critical infrastructure and systems that are difficult to patch or replace. His work combines artificial intelligence, threat intelligence, and system modeling to understand cyber risk and identify practical defenses.

Research interests include:

  • Critical infrastructure and operational technology cybersecurity.
  • Artificial intelligence and reinforcement learning for cyber defense.
  • Attack-path modeling, vulnerability prioritization, and mitigation planning.
  • Privacy-preserving cyber threat intelligence sharing.
  • Cyber-informed engineering and resilient system design.
  • Cybersecurity education, cloud-based laboratories, and accessibility for learners with disabilities.

Publications

Recent Preprints

  • Huff, P., Dale, D., Guduru, H., Singh, R., & Li, Q. (2026). Operationalizing Cybersecurity Governance for Mitigation Planning with Attack-Path Modeling and Reinforcement Learning. arXiv preprint, arXiv:2605.09792.
  • Huff, P., Gandu, N., & Novák, P. (2025). I Can’t Patch My OT Systems! A Look at CISA’s KEVC Workarounds & Mitigations for OT. arXiv preprint, arXiv:2510.06951.

Selected Publications

  • Massengale, S., & Huff, P. (2026). Assessing and Prioritizing Ransomware Risk Based on Historical Victim Data. In Security and Privacy in Communication Networks (SecureComm 2024). Springer.
  • Cox, W. R., Jr., Spann, B., & Huff, P. (2025). Accessibility Barriers for Blind and Visually Impaired Individuals in Cybersecurity: A Systematic Review. ACM SIGCITE 2025.
  • Farnell, C., Huff, P., & Cox, W. (2024). Privacy in the Digital Age: Navigating the Risks and Benefits of Cybersecurity Measures. In Human Privacy in Virtual and Physical Worlds. Springer.
  • Huff, P., Leiterman, S., & Springer, J. P. (2023). Cyber Arena: An Open-Source Solution for Scalable Cybersecurity Labs in the Cloud. Proceedings of the 54th ACM Technical Symposium on Computer Science Education, Volume 1.
  • Huff, P., McClanahan, K., Le, T., & Li, Q. (2021). A Recommender System for Tracking Vulnerabilities. Proceedings of the 16th International Conference on Availability, Reliability and Security.
  • Huff, P., & Li, Q. (2021). A Distributed Ledger for Non-attributable Cyber Threat Intelligence Exchange. In Security and Privacy in Communication Networks (SecureComm 2021) (pp. 164–184). Springer.
  • Huff, P., & Li, Q. (2021). Towards Automated Assessment of Vulnerability Exposures in Security Operations. In Security and Privacy in Communication Networks (SecureComm 2021) (pp. 62–81). Springer.

Awards and Honors

Arkansas Research Alliance Fellow, 2026.
Arkansas Academy of Computing induction, 2024.
Research Partner of the Year, Forge Institute, 2022.

Teaching

Huff teaches undergraduate and graduate courses in cybersecurity and computer science. His teaching emphasizes practical laboratories, applied projects, and connecting technical decisions to organizational needs. He mentors doctoral and master’s research and supervises cybersecurity capstone and practicum experiences.

Courses recently taught include:

  • Introduction to Cybersecurity and System Security.
  • Computer Networks and Network Security.
  • Cybersecurity Data Analytics.
  • Cybersecurity Operations, Capstone, and Practicum.

His curriculum development includes the B.S. in Cybersecurity, B.S. in Artificial Intelligence, M.S. in Cybersecurity, cybersecurity certificates, and graduate preparation for high school cybersecurity teachers.

Licensures and Certifications

Certified Information Systems Security Professional (CISSP)

Memberships

Arkansas Research Alliance Academy, Fellow.
Arkansas Academy of Computing, Member.
IEEE P3528 Working Group on Cyber-Informed Engineering Curricular Guidelines, Chair.

Service

Chair, IEEE P3528 Working Group on Cyber-Informed Engineering Curricular Guidelines, 2024–present.
Member, Arkansas Department of Education Cybersecurity Curriculum Committee, 2024–present.
Contributor, ACM foundational cybersecurity curriculum guidelines, 2023–2025.
Chair, Graduate Curriculum Committee, UA Little Rock, 2021–present.
Faculty mentor, Cyber Security Club, UA Little Rock, 2019–present.
Cybersecurity undergraduate program coordinator, UA Little Rock, 2024–2025.
Contributor to cybersecurity program ABET review, 2025–2026.
Leadership of cybersecurity clinic partnerships connecting student education with professional services for Arkansas communities.

Work History

Director, Cyberspace Operations Research and Education (CORE) Center, University of Arkansas at Little Rock, 2025–present.
Associate Professor, University of Arkansas at Little Rock, 2024–present.
Co-founder & Chief Scientist, Bastazo, Inc., 2020–present.
Assistant Professor, University of Arkansas at Little Rock, 2019–2024.
Director of Critical Infrastructure Security, Arkansas Electric Cooperative, 2009–2018.