Diane Lin is a machine-learning researcher, cybersecurity entrepreneur, and co-founder of Culminate, the security-operations startup acquired by Datadog. As its chief technology officer, she developed agents that investigate security alerts, incorporate analysts’ decisions, and adapt to individual organizations.
Lin earned a doctorate at Imperial College London studying continual learning, then worked with Josh Tenenbaum at MIT on one-shot learning. She was among the first three applied scientists on Alexa’s question-answering team and subsequently researched zero-shot transfer learning at Vicarious. At Zscaler, she became director of machine learning, applying these techniques to cybersecurity; her team’s work contributed to efforts against the Qakbot malware network.
In 2023, Lin and Rex Guo founded Culminate to address a persistent security-operations problem: analysts receive more alerts than they can investigate. Its agent automated investigations across tools including Amazon GuardDuty while learning customers’ operational preferences. Following Culminate’s acquisition, Lin joined Datadog, where her work centered on agents that improve through experience.
How Lin makes security agents more reliable
- Disagreement reveals ambiguity. Contradictory verdicts on identical inputs often expose unclear labels, missing context, or customer-specific policies. An attempted login from a suspicious address, for example, demands different action depending on whether the attacker actually entered the account.
- Active learning directs human attention. Lin uses disagreement between repeated runs or different models to identify difficult cases, concentrating expert review where it can most improve decisions. She considers these disagreements more informative than a language model’s self-reported confidence.
- Semantic and episodic memory serve different purposes. Semantic memory encodes explicit organizational rules; episodic memory retrieves comparable incidents and previous analyst decisions. Together, they automate recurring cases and escalate unfamiliar situations without requiring immediate fine-tuning.
In her AI Engineer World’s Fair session, Lin described testing 93 security alerts three times each. Approximately one-quarter initially produced inconsistent verdicts; incorporating comparable past cases resolved inconsistencies for roughly 15 percent of all alerts, leaving approximately 10 percent for human review.