Research

The rise of AI has revolutionized the software landscape by augmenting and replacing traditional decision-making mechanisms with AI Agents that reason, plan, and act on behalf of the user. This metamorphosis in software design has transformed the security landscape in equal measure, introducing attack surfaces that were previously non-existent: agents that ingest untrusted content, make consequential decisions, and interact with other systems, all without the human judgment that traditional defenses were built to rely on.

My research develops both offensive and defensive security frameworks for AI systems. On the offensive side, I have developed an automated framework that discovers indirect prompt injection attacks against web-browsing agents by identifying injection surfaces along an agent's trajectory and synthesizing context-aware adversarial payloads through execution feedback. This has uncovered dozens of end-to-end attacks, including the first demonstrated cross-application prompt injections.

On the defensive side, we have proposed a scalable security architecture for governing multi-agent systems, introducing a cryptographic mechanism for formally verified access control over agent-to-agent interactions with minimal performance overhead.

Previously, I have also studied the resilience of Federated Learning systems to poisoning attacks in both decentralized and centralized environments. My findings highlighted the vulnerability of peer-to-peer network topologies to adversarial presence and analyzed the effectiveness of existing defenses against poisoning attacks. Additionally, I proposed a novel defense mechanism that utilizes knowledge distillation to mitigate the impact of poisoned updates on the global model.

Together, these works represent a holistic approach to AI security: uncovering how AI systems can be compromised, and building the foundations to prevent it.