AI Infrastructure
Model serving, inference systems, AI SDKs, agents, remote resources, model loading, cloud integrations, and isolation boundaries.
// research archive
Case studies show the affected boundary, root cause, validation method, practical impact, disclosure status, and remediation. Working exploit material stays out of the public record until coordinated disclosure is complete.
Research domains
Model serving, inference systems, AI SDKs, agents, remote resources, model loading, cloud integrations, and isolation boundaries.
Workload orchestration, distributed control, authorization boundaries, messaging infrastructure, robotics middleware, and component-to-component trust.
Embedded and connected devices, industrial software, firmware, device-management tools, network services, management interfaces, certificate validation, device communication, edge infrastructure, and supporting protocols.
Security-sensitive libraries, container systems, parsers, protocols, package handling, cryptographic validation, and other upstream infrastructure.
IoT & Industrial Research
Current work examines security boundaries in connected and industrial systems, including management applications, firmware, embedded software, network-facing services, certificate validation, device protocols, and cloud-connected edge components.
Published industrial research includes two Lantronix G520 vulnerabilities disclosed through CISA, with researcher credit in ICS Advisory ICSA-26-272-01 and vendor remediation.
Only publicly disclosed vulnerabilities appear as individual case studies. Findings still under vendor or coordinator review remain private until disclosure is complete.
A Critical SSRF flaw let an unauthenticated caller cross the MLflow server network boundary through webhook redirects and DNS rebinding.
Read case studyTwo vulnerabilities in the Lantronix G520 update and package-handling mechanisms could allow arbitrary code execution under the conditions described by CISA. The disclosure resulted in two CVEs, a public CISA ICS advisory, and vendor remediation.
Read case studyA flaw in the agent-side Control Interface authorizer allowed a scoped workload to access or modify cluster state outside its authorized subtree.
Read case studyA model-specific multimodal processor bypassed centralized media-retrieval protections, exposing network and local-file trust boundaries.
Read case studySSRF, API-key exposure, and response forgery were validated in an AI SDK integration that accepted a caller-influenced provider endpoint.
Read case studyLMDeploy enabled Hugging Face remote code by default during model loading, removing the operator decision that peer inference systems expose as an explicit opt-in.
Read case study