BIACKR0SE

Jaafer Rahmani · AI Security Researcher

AI red teaming // security engineering

scroll

[ 00 // thesis ]

I break models to make them harder to break.

Security engineer and PhD researcher in adversarial machine learning. I work both sides of AI security: red-teaming machine learning and LLM agents, and engineering the ML-driven detection that defends critical infrastructure against attackers who adapt.

IEEE ETFA 2026 IEEE WFCS 2026 ECML PKDD 2026 MDPI Sensors IEEE IDAACS IEEE ICEST CVE-2026-58196 MITRE ATT&CK OWASP

[ 01 // the record ]

10 peer-reviewed papers IEEE / Springer / MDPI, 2025-2026
7 accepted in 2026 alone adversarial ML, LLM agents, OT security
1 CVE in AI-agent infrastructure CVE-2026-58196, fixed upstream

[ 02 // operating domains ]

01

AI Red Teaming

Adversarial ML and LLM-agent offense. Evasion, model extraction, data poisoning, prompt injection against agent pipelines, and breaking AI-agent infrastructure, proven against the ML that defends live industrial networks.

adversarial-ml / llm-agents / evasion / prompt-injection / cve

02

Security Engineering

The build side of the same fight. ML-driven SIEM and IDS for critical infrastructure, OT/ICS protocol security across Modbus, CAN, and PROFINET, MITRE ATT&CK mapping, detection hardened against adaptive evasion, fixes disclosed upstream.

siem / ids / ot-ics / att&ck / disclosure

[ 03 // selected work ]

Proof of
damage.

[ 04 // peer-reviewed ]

Peer-reviewed
research.

featured // latest acceptance

When the Analyst Scans for the Attacker

SOC teams are wiring LLM agents into alert triage. This paper asks what the adversary gains. The answer, on a deployed agentic analyst in an OT network: expose one extra alert field to the model, and a crafted alert steers the agent into scanning the live PLC it is meant to protect. Three vulnerabilities in the agentic layer, one matched mitigation each, and the hostile scan drops from 52 of 100 runs to 0 on the patched pipeline.

SHIELD-AI @ ECML PKDD 2026 / Springer CCIS / to appear

[ 05 // transmissions ]

Field
notes.

What claude -p Trusts Headless AI coding agents run with the trust dialog off. Two behaviors I reported to Anthropic came back informative, and both rulings are right. The useful question is where the boundary sits. Watching an SSRF Walk Out of the Sandbox CVE-2026-58196: a remote MCP server steers the ToolHive host into fetching cloud instance metadata, from the one code path that runs before the container sandbox. Step through the chain. I Built a $7 App in 25 Lines of Bash Someone is selling a clipboard cleaner for terminal users. Here's the free version.

[ 06 // handshake ]

GET IN TOUCH

Research collaboration, responsible disclosure, or an interesting target model.

jaafer.rahmani@owasp.org

github linkedin orcid