Cross-Model Agentic-Commerce Attack/Defense Evaluation · designed, built & ran end-to-end
attempted-unauthorized-action rate
I build LLM security systems where a deterministic SHA-256 oracle — never an LLM judge — is the sole authority on success. Findings are byte-reproducible and false-positive-free — security evaluation at scale, with no LLM in the verdict path.
I build LLM security systems where a deterministic SHA-256 oracle — never an LLM judge — is the sole authority on success. Findings are byte-reproducible and false-positive-free — security evaluation at scale, with no LLM in the verdict path.
I build LLM security systems where a deterministic SHA-256 oracle — never an LLM judge — is the sole authority on success. Findings are byte-reproducible and false-positive-free — security evaluation at scale, with no LLM in the verdict path.
attempted-unauthorized-action rate
ReAct agent loop scored by a SHA-256 oracle as sole authority — byte-identical, farm-resistant grading with no LLM in the verdict path. Leak-proof toolbox (no-filesystem / no-shell) + network scope-gate isolating the model from the live environment.
5 candidate vulnerabilities submitted to MITRE (CNA-LR) across agent / MCP-server / LLM-server attack surfaces
Coordinated vulnerability disclosures to Chile's national CSIRT / ANCI
Direct, build, evaluate, and ship LLM-orchestration security systems end-to-end: agentic red-team harnesses, deterministic evaluation frameworks, authorization gates, and coordinated-disclosure pipelines.
Founded and ran the venture before moving into full-time AI-security research.
Independent researcher with sole-authored, peer-reviewable cs.CR publications (arXiv + Zenodo DOI) and public reproducible artifacts — offered as the MSc-or-equivalent the role asks for.