Independent Security Researcher
I identify and validate vulnerabilities across AI infrastructure, robotics, IoT and industrial systems, and security-sensitive open-source software. My work focuses on trust boundaries, authorization failures, device and service communication, unsafe resource handling, and reproducible vulnerability validation.
Google Cloud VRP Recognition
Coordinated Vulnerability Disclosure
Upstream Security Contributions
Security boundaries tested in code.
Each case is a trust boundary crossed by untrusted input, reproduced and validated before disclosure.
Unauthenticated full-read SSRF in webhook delivery
A Critical SSRF flaw let an unauthenticated caller cross the MLflow server network boundary through webhook redirects and DNS rebinding.
Authorization bypass in workload control rules
A flaw in the agent-side Control Interface authorizer allowed a scoped workload to use an empty field mask and access cluster state outside its authorized subtree.
Multimodal media path bypassed hardened retrieval controls
A model-specific processor fetched user-controlled image and audio references outside vLLM’s hardened MediaConnector path, enabling SSRF and local-file access.
Provider endpoint trust-boundary failure
SSRF, API-key exposure, and response forgery were validated in an AI SDK integration that accepted a caller-influenced provider endpoint.
Unsafe remote-code trust during model initialization
LMDeploy enabled Hugging Face remote code by default during model loading, removing the operator decision that peer inference systems expose as an explicit opt-in.
Research that also produces tools.
Not every security problem ends as a vulnerability report. I also build systems for detection, reproducible analysis, and security evaluation.
Deterministic ML-assisted network anomaly detection
An open-source network-flow detector that turns CICFlowMeter-compatible traffic into deterministic analyst-facing security incidents. The project includes a frozen model, causal feature pipeline, versioned incident output, CLI, Docker distribution, and end-to-end regression testing.
View project →Detection-as-Code with measurable evidence
KQL detections for Microsoft Sentinel and Defender mapped to MITRE ATT&CK, tested through controlled triggers, incident generation, investigation evidence, false-positive measurement, and PR-gated deployment.
View project →Security reference for model-serving infrastructure
A security reference covering vulnerability classes, attack surfaces, and hardening patterns across major LLM-serving platforms and inference infrastructure.
View project →Selected upstream work.
Security and hardening work where the boundary is visible in code.
gVisor
Isolation boundaries, networking, race conditions, checkpoint security, and protocol validation.
View evidence →vLLM
Security controls around multimodal media retrieval and shared connector policy.
View evidence →Swift Package Manager
Archive extraction and symbolic-link boundary protection in package registries.
View evidence →Tink
Strict JWK parsing and validation at a public cryptography-library boundary.
View evidence →Google Bumble
Bluetooth protocol parsing and denial-of-service protections.
View evidence →Microsoft Sentinel
Detection content for suspicious network, identity, endpoint, and control-plane activity.
View evidence →Reproducible work, not a scanner result.
My research starts with architecture, source code, firmware, protocol behavior, or a clearly defined trust boundary.
I trace how untrusted input, identity, commands, network destinations, certificates, files, or state move through the system, reproduce the behavior in a controlled environment, test alternative explanations, and establish whether the result crosses a meaningful security boundary.
The same process is used across AI infrastructure, robotics, IoT devices, industrial software, and open-source systems. Automation and AI accelerate triage and hypothesis generation. Reproduction and evidence determine the result.
- 01Target and trust-boundary analysistrace
- 02Source review and data-flow tracingtrace
- 03Reproducible test environmenttrace
- 04Proof-of-concept validationtrace
- 05Impact and exploitability assessmenttrace
- 06Vendor / coordinator disclosuretrace
- 07Remediation verificationverified
Where trust crosses a system boundary.
- 01AI inference and model-serving systems
- 02Robotics and distributed control systems
- 03IoT and embedded device security
- 04Industrial and edge infrastructure
- 05Firmware and device-management software
- 06Device-to-cloud and device-to-device trust boundaries
- 07Network services, management interfaces, and protocols
- 08Cloud and container isolation
- 09Authorization, identity, and trust boundaries
- 10SSRF and untrusted resource retrieval
- 11Parser and protocol security
- 12Source-code auditing and reverse engineering
Security research across connected and industrial systems.
Connected systems extend software trust into physical devices, management interfaces, edge infrastructure, cloud services, and operational networks.
My current research examines how these components authenticate each other, exchange commands and telemetry, retrieve configuration, validate certificates, expose management services, and cross network or privilege boundaries.
The work spans IoT devices, industrial software, embedded systems, edge platforms, device-management applications, firmware, network services, and supporting protocols.
- Device-management interfaces
- Firmware and embedded software
- Industrial and edge systems
- Device-to-cloud communication
- Device-to-device trust
- Authentication and authorization
- TLS and certificate validation
- Management protocols and network services
- Unsafe update and configuration paths
- Protocol parsing and input validation
Operations experience behind the research.
My security research is grounded in hands-on work across cloud security, detection engineering, incident response, enterprise infrastructure, identity, network security, and compliance-sensitive environments.
That operational background matters because a vulnerability is rarely only a code defect. Its real impact depends on the identity, network position, privileges, data, and surrounding systems that the affected component can reach.
Read the background →Security reviews built around evidence.
I review software and infrastructure where untrusted input crosses a privileged boundary, from model-serving systems and distributed control planes to open-source and connected-device software.
AI infrastructure security review
Remote model loading, multimodal resource retrieval, provider credentials, agent tools, inference APIs, cloud access, and container boundaries.
Distributed and connected systems review
Authorization boundaries, control-plane behavior, message and protocol handling, service identity, device communication, and trust between distributed components.
Open-source component audit
Source-led review of parsers, protocols, package handling, authentication and authorization logic, isolation controls, dependencies, and security-sensitive data flows.
Bring me the boundary that needs testing.
Open to security research roles, product-security work, expert technical evaluation, open-source security engineering, and selective security research engagements.