I use bad guys to catch math.
Principal Security Architect at NVIDIA.
Working on AI security since it was ML security.
Threat modeling and security design for ML systems at scale
Thinking about AI/ML as an attack surface
Writing, training, and frameworks that help AI security mature as a discipline
Exploiting and securing AI agents. My contributions: the AI Kill Chain for modeling attacks, and autonomy levels for scoping agent risk.
Grounding LLM security in application security fundamentals. If an attacker can get their data into your LLM, they control the output.
Multi-day adversarial ML training. Evasion, extraction, poisoning—hands-on. Self-paced version available as NVIDIA DLI course.
Helped found the cross-industry working group for signing and validating AI models before handing it off to the signing experts.
Multiple CVEs in AI/ML tooling and infrastructure, as well as other responsible disclosures.
20 million malware samples for security ML research. Still the largest public labeled malware corpus.