AI Security · LLM Evaluation · Security Automation · Offensive Security
Final-year BS Cybersecurity student at GIKI (Class of 2027) focused on evaluating and securing LLM and agentic systems, building practical security automation, and applying offensive-security thinking to emerging AI systems.
- LLM & Agent Security — prompt injection, adversarial evaluation, tool-use security, attack/defense evaluation
- Security Automation — AI-assisted triage, workflow automation, policy enforcement, alerting
- Applied AI for Security — model evaluation, classification, explainability, multilingual LLM analysis
- Offensive Security — VAPT, web/network security, CTFs, vulnerability analysis
LLM Security · Cross-Lingual Evaluation · Reproducible Research
Reproducible evaluation of cross-lingual prompt-injection and protected-context leakage in aligned large language models.
Python · NVIDIA garak · Mistral-7B · Adversarial Evaluation
Evaluated an instruction-tuned LLM across 64 adversarial attempts, establishing a 35.94% attack-success baseline and extending the evaluation to English–Urdu prompt-injection behaviour.
n8n · Security Automation · Webhooks · Slack
Policy-governed AI-security workflow for structured alert ingestion, payload validation, risk/severity routing, logging, and automated incident-response notifications.
Python · XGBoost · TF-IDF · SHAP
Machine-learning pipeline for detecting sensitive information using character-level features, metadata, and explainable classification, achieving 94% classification accuracy in project evaluation.
JavaScript · Browser Privacy · Fingerprinting
Browser-extension project exploring resistance to browser-fingerprinting and behavioural profiling through controlled modification of browser-identifying attributes.
Web · Cryptography · Reverse Engineering · Forensics · OSINT
Curated technical writeups from an ongoing offensive-security journey spanning 80+ CTF challenges across multiple security domains.
Final-year project exploring adaptive attacker and defender agents, shared-state coordination, prompt injection, tool-use security, and measurable attack/defense evaluation for enterprise LLM systems.
Development repository is currently private while the project is in active development.
Dammam, Saudi Arabia · Jun–Aug 2025
Conducted enterprise VAPT across 150+ hosts, identified and prioritized high-risk exposures, contributed to ISO 27001:2022 compliance work, and translated technical findings into remediation guidance for technical and management stakeholders.
Remote · Dec 2025–Present
Support AI-focused campus engagement and serve as a liaison between Confinality and the GIKI community around LLM systems, AI assistants, and emerging AI technologies.
Languages: Python · C++ · JavaScript · SQL · Bash
AI / ML: NVIDIA garak · scikit-learn · XGBoost · Hugging Face · SHAP · LLM Evaluation
Security: Nmap · Nessus · OWASP ZAP · Nikto · Burp Suite · VAPT · OWASP Top 10
Automation & Engineering: n8n · Webhooks · APIs · Git/GitHub · Linux · Docker
Governance: ISO 27001:2022 · Security Policy Development · Risk Assessment
- Top 8% globally on TryHackMe
- Founder & President of The Ansars, leading multi-team humanitarian and community initiatives
- Technical writer covering cybersecurity, AI security, research, and practical learning
- Research interests: LLM security, agent security, adversarial evaluation, multilingual AI safety
I'm interested in opportunities and collaborations involving AI security, LLM evaluation, security automation, offensive security, applied AI engineering, and technical AI/security products.
Email: mahad.aqeel7@gmail.com
LinkedIn: linkedin.com/in/mahad-aqeel