< 086fbc8c75 />
< 02db495216 />
< bf62e56bac />
< c8db44eac5 />
< 1b274ad93d />
< b0c91ac66a />
< b4a73a3e92 />
< f52ebfe281 />
< e171d941f0 />
< fb6d9bde65 />
< 1a385c0048 />
< b58e04a9b7 />
< 83fa785898 />
< 543696c485 />
< f25c4a4b21 />
< 0afd19592f />
< 347e4599be />
< 279b143230 />
< d3f5138020 />
< 198cafdbc5 />
< 775ccd7a4a />
< e59c3f1698 />
< 28b50f74eb />
< 9b59d6ace1 />
< c6644ceb11 />
< a8660beab7 />
< 65c0081784 />
< a6c7eed6c3 />
< 131c93a036 />
< 216acd2963 />
< 46848ee9e5 />
< ab14cb99f5 />
< b2fb3cbed6 />
< e9c197e05c />
< f6cb295be3 />
< be94d7433c />
< 98a21e0f4f />
< 4d07a3393b />
< cf098c3558 />
< 74831bed1a />

ALL PROJECTS

FEATURED

Vibe Coding Security Benchmark

Honors Thesis · AI-Generated Code Security

securityresearchai

Benchmarked 12 LLM-generated web applications across 5 attack scenarios using a custom Playwright-based exploit verification pipeline and CAF metric. Key finding: security failures concentrate at integration boundaries, not isolated logic bugs.

PythonPlaywrightFlaskExpressReact

> 12 apps · 5 attack types · published

FEATURED

YC API Penetration Test

Production Security Audit

security

Cold-emailed a YC founder, got pre-authorized API access, and confirmed a cross-tenant cache isolation vulnerability (CWE-200/208) reproducible 10/10 times. Full writeup published.

PythonBurp SuiteREST APIsCWE-200

> 10/10 confirmed · $300 bounty

FEATURED

SpectralQuant Security Benchmark

Original Research · KV Cache Attack Surface

securityresearchai

Identified that the static calibrated eigenbasis in SpectralQuant creates a predictable attack surface. Targeted eigenbasis perturbations outperformed random noise in 91.7% of cases across 28 layers of Qwen2.5-1.5B.

PythonPyTorchQwen2.5NumPy

> 91.7% attack success rate

ZkLoRA

Applied Cryptography · Verifiable AI Fine-Tuning

securityresearchai

Zero-knowledge proof system for verifiable LoRA fine-tuning -- cryptographic proof that AI model adaptation occurred correctly without revealing weights. Built 8 ZK backward pass gadgets at distilGPT2 scale.

C++emp-zkmlPythonPyTorch

> 8 ZK gadgets · distilGPT2 scale

gittuf

Open Source · Supply Chain Security

securityresearch

Active contributor to gittuf, a Git supply chain security framework built on TUF, incubating under the Linux Foundation OpenSSF. Fixed RSL synchronization bugs, annotation entry logic, and silent error swallowing in commit operations.

GoTUFGitOpenSSF

> Linux Foundation · OpenSSF

PratGPT

Multi-Agent Telegram Orchestrator

ai

Multi-agent Telegram orchestrator with specialized agents for PhD application tracking (Gmail polling, Claude-drafted replies), content drafting, and budget management via Plaid. Event bus architecture with SQLite state.

PythonTelegramClaude APIPlaidSQLite

> Always-on · Railway deployed

CarbonCompass

HackHarvard 2024 Winner · Climate Analytics

ai

Climate-impact analytics application using Cloudflare Workers and D1, integrating LLM-powered data extraction through Gemini and Amazon Q to deliver real-time carbon-footprint estimates for consumer products.

Cloudflare WorkersD1GeminiAmazon QPython

> HackHarvard 2024 Winner · <150ms

SecureChat

Encrypted Messaging & Exploit Simulation

security

Built and reverse-engineered a full-stack messaging platform using Flask, SQLite, and AES-ECB, simulating encrypted DHE-AES conversations. Launched XSS, ECB replay, and Diffie-Hellman key manipulation attacks using Selenium automation.

FlaskSQLiteAES-ECBSeleniumPython

> Full security simulation

Sherpa

Autonomous Vehicle Collaboration Platform

ai

Data-sharing platform for autonomous vehicles enhancing traffic flow and reducing congestion using real-time communication and traffic APIs.

Next.jsTomTom APIYOLOVector SearchFlask

> 83.4% accuracy · 15% congestion reduction