About

Jaafer Rahmani. Security engineer and PhD researcher. AI red teaming, and the security engineering that defends critical infrastructure.

whoami

Jaafer Rahmani. Security engineer and PhD researcher in adversarial machine learning. I work both sides of AI security: red-teaming ML models, LLM agents, and RAG pipelines, and engineering the ML-driven detection that defends enterprise and industrial networks against a moving target. Ten peer-reviewed papers, a CVE, and a preference for attacks that reproduce.

current

  • Doctoral research in adversarial ML: evaluating and hardening intrusion detection systems against adaptive evasion
  • Security analysis of agentic LLM SOC assistants: prompt injection against tool-wielding analysts that act on live OT networks
  • Engineering AI-supported SIEM for critical infrastructure (IT/OT networks)
  • Vulnerability research on AI-agent infrastructure (MCP servers, agent runtimes, coding assistants)

arsenal

  • AI red teaming: evasion, model extraction, data poisoning, prompt injection, robustness evaluation
  • Security engineering: ML-driven detection, SIEM, IDS (Suricata, Zeek), MITRE ATT&CK mapping
  • Critical infrastructure: OT/ICS protocols (Modbus, CAN, PROFINET), SCADA, fieldbus security
  • Vulnerability research: AI-agent infrastructure, MCP servers, exploitation, responsible disclosure

disclosures

[+] CVE-2026-58196 - ToolHive: host-side SSRF bypassing container
    isolation. Fixed in v0.31.0. Advisory GHSA-pr64-jmmf-jp54.

More reports are in vendor queues. They land here when they go public.

certs & affiliations

Affiliations: OWASP member.

publications

Ten peer-reviewed papers across IEEE, Springer, and MDPI venues (2025-2026), spanning SIEM frameworks for OT anomaly detection, MITRE-mapped attack emulation testbeds, PROFINET intrusion detection, agentic LLM security analysts and the prompt-injection attacks that subvert them, and adversarial campaign evaluation of ML-based IDS. Full list with venues and status on the work page.

contact

Email is the fastest path for vulnerability reports and research collaboration.