Cybersecurity and Behaviour Analysis Intern
Amplía Soluciones
Nov 2023 — Apr 2024 · Madrid, Spain
Part-time during my last months of the IB, on SecBluRed, a CDTI-funded national R&D project on industrial IoT security.

Photo by Max Petrunin on Unsplash
The problem
Amplía builds Industrial IoT platforms. The internship sat inside SecBluRed, a nationally co-funded R&D project on securing industrial IoT traffic, where the team had trained two families of anomaly detector — Isolation Forests and deep autoencoders — on live network data.
My job was the question that comes after training: should anyone trust them?
What I did
The obvious method was unavailable. There was no ground-truth label for “normal”. Nobody could hand me a set of known-clean traffic and a set of known attacks, so supervised accuracy could not be computed — there was nothing to compute it against.
So I replaced it with things that can be measured without labels:
- Detection consistency — does the model flag the same traffic on repeat exposure?
- Variance under perturbation — how far does a small input change move the score?
- Cross-condition stability — does behaviour hold when the operating condition changes?
Running alongside that was the work I found more interesting: keeping the models interpretable. A security team cannot act on an unexplained anomaly score. They need to see which features drove a detection, because their next step is to justify an intervention to somebody else.
What it taught me
This was my first encounter with the problem that has shaped everything since: deciding how much to trust data before analysing it.
It also taught me that “we cannot measure accuracy” is not the end of an evaluation. It is the start of designing one — you find the properties a good model must have and test those instead.
My contribution here was validation and explainability on models the team was building, not primary model authorship. That distinction matters and I keep it.