I designed the two-pass architecture (Understand first, Secure second), modular Python CLI toolkit for token-optimized autonomous agent authoring, deterministic web ingestion, and static documentation site deployed with Astro and Starlight. Covers trust boundaries, tool authorization, prompt injection, and secure reference architectures.
Open to view full write-up and README details
agentic AIAI securitythreat modelMCP securityreference architectureAstroPython CLI
I worked on the context-routing, VitaeGraph structured memory, and native MCP server integration for a portable framework with eight focused skills and adapters for 11 agent environments. The zero-external-dependency MCP server exposes four resources, three tools, and four reusable prompts while preserving evidence boundaries and deterministic context retrieval.
Open to view full write-up and README details
agent skillscontext engineeringMCP serverVitaeGraphClaude CodeCodexGemini CLIOpenCodenpm
I developed a fraud-detection agent stack with LangChain and Langfuse, then tuned recursion depth, token use, and sampling settings to balance accuracy, cost, and latency under a tight contest budget.
Open to view full write-up and README details
LangChainLangGraphLangfuseReActmulti-agentfraud detectiontoken budget
I trained and evaluated a multi-model detection pipeline across network flows, malware API traces, unseen attacks, and shell-command tactic attribution. Selected results include 0.82 test macro F1 for the strongest malware models and 92% anomaly recall, alongside shortcut-learning and minority-class analyses.
Open to view full write-up and README details
MLPyTorchBERTUniXcoderGNNanomaly detectionmalware detection
I built evidence chains across source, bytecode, verifier logs, translated instructions, and runtime traces. The analysis confirmed one taint-tracking bypass and one bounded 54-byte intra-packet overflow; neither established kernel RCE or privilege escalation.
Open to view full write-up and README details
kerneleBPFexploitLinuxverifier internalsXDPkernel hardening
I built an investigation workflow where players inspect five evidence types and assess supported and hallucinated AI claims against chain-of-custody ground truth. An evidence-review gate prevents verdicts before raw artifacts are inspected.
Open to view full write-up and README details
AIforensicsadversarialgamehallucination defenseevidence validation
I designed a multithreaded Python CLI that integrates Hybrid Analysis, VirusTotal, and ANY.RUN, then mapped 12 Equivocal Software Behaviours from 60 MITRE ATT&CK Enterprise techniques. The thesis analyzed 36 SourceForge goodware binaries and was published on Zenodo.
Open to view full write-up and README details
malware analysissupply chain securityMITRE ATT&CKsandboxingVirusTotalANY.RUNPython
I built preprocessing and evaluation pipelines for seven intent categories using classical ML, clustering, and BERT representations. Supervised and frozen-BERT classifiers reached about 0.99 weighted F1 on the dataset while remaining weaker on rare behavior.
Open to view full write-up and README details
MLNLPhoneypotMITRE ATT&CKthreat intelligencesequence modeling
I implemented core cryptographic primitives and protocol exercises in C and Python, then stress-tested them through cryptanalysis and CTF-style break/fix challenges. It bridges formal concepts with hands-on attacker thinking.
Open to view full write-up and README details
CPythonOpenSSLCTFcryptanalysisapplied crypto
I implemented custom QEMU initialization for memory, clocks, NVIC, LPUART, and PIT timers, then ported FreeRTOS and built event, monitoring, and alert tasks. The MPU study documents an adaptation route rather than claiming a completed MPU port.
Open to view full write-up and README details
embeddedCNXPhardware securityFreeRTOSwatchdogQEMU
I designed and compared IPSec and TLS VPN topologies in GNS3 using Cisco routers and Dockerized endpoints, then verified IKE/ESP security associations, TLS handshakes, NAT traversal, SecureNAT assignment, and protocol trade-offs with Wireshark and SoftEther logs.
Open to view full write-up and README details
VPNGNS3WiresharkIPSecTLSDockernetwork forensics
I processed Android GNSS measurements for pseudorange and spoofing analysis, then ran WiFi goodput experiments with iperf, tcpdump, and Wireshark across Ethernet, WiFi, and mixed scenarios with repeated min/max/average/std-dev reporting.
Open to view full write-up and README details
wireless securityGNSSspoofing detectionMATLABWiresharkiperfAndroid
I developed a security-first full-stack forum with server-enforced role and ownership checks, session-based authentication, TOTP-gated admin moderation, salted scrypt password verification, parameterized SQLite queries, and anonymous comments.
Open to view full write-up and README details
ReactNode.jsTOTPOWASPRBACsessionsSQLite
I co-built Budget HQ, a fintech-focused web platform created during the IEEE-HKN Global Hackathon where we secured 1st place worldwide. The delivery balanced rapid product iteration with secure full-stack engineering.
Open to view full write-up and README details
CTFhackathon1st placefull-stackfintechDocker