Skip to content
View NehaKhann's full-sized avatar
💭
Learning..
💭
Learning..

Block or report NehaKhann

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
NehaKhann/README.md

Neha Khan Banner


👋 About Me

🌐 Portfolio: neha-khan-portfolio-gamma.vercel.app

AI Engineer | Full Stack Software Engineer · Karachi, Pakistan

Full-stack software engineer with 4+ years of experience building production systems in Java, JavaScript, and Python — across banking and product-based environments.

Currently focused on LLM engineering and AI security — applying the same engineering discipline I use in production systems to how I build and evaluate AI.

Open to full-stack & AI engineering roles.


🚀 What I'm Building

  • 🤖 LLM applications & AI agents
  • 🔎 RAG & prompt engineering
  • 🎛️ Fine-tuning (LoRA / QLoRA / DoRA) & model evaluation
  • 🛡️ AI security & LLM red-teaming (prompt injection, jailbreaks, garak scans)
  • 🛠️ Full-stack apps in Python/FastAPI, Java/Spring Boot, and React/Next.js

📝 Latest Articles

  • I Compared LoRA vs DoRA — DoRA Was Slower and Less Accurate. Here's Why.
  • LoRA Explained With Spreadsheets — How to Train a Model Without Touching Its Weights.
  • How I Fit a Model That Shouldn't Fit on a 6GB Laptop GPU.
  • From Gandalf to Garak — Automating the AI Attacks I Used to Type by Hand.

➡️ More articles on Medium


⭐ Featured Projects

Project Description Link
🛡️ MCP Trust Registry Live registry that scans and scores MCP tools for trustworthiness — rule engine + AI grading, verified in a network-blocked Docker sandbox LiveGitHub
🔍 SpringGuard Spring Boot/Java security auditor that grades code A–F with 100% deterministic scoring; AI only adds a labeled second opinion, never the grade LiveGitHub
💰 Ledger — SME Cash-Flow Underwriting Turns raw bank transaction CSVs into audit-ready credit risk memos, with every risk metric computed deterministically and an LLM that only explains the numbers LiveGitHub
🧠 AI Engineering Journey Hands-on curriculum covering LLM foundations, fine-tuning (LoRA/QLoRA/DoRA), quantization, RAG, and RLHF Repository
🧙 AI Security Labs Red-teaming LLMs with NVIDIA garak and a from-scratch Gandalf-style prompt injection challenge GarakGandalf

🧰 Engineering Toolbox


🎯 Focus Areas

  • AI Engineering & LLM Fine-tuning (LoRA / QLoRA / DoRA)
  • Retrieval-Augmented Generation (RAG)
  • AI Security & Red-Teaming
  • Full-Stack Development (Java/Spring Boot, Python/FastAPI, React/Next.js)
  • Open Source

📈 GitHub Activity

Neha's GitHub contribution graph


Building practical software • Learning in public • Always improving

Pinned Loading

  1. ai-engineering-journey ai-engineering-journey Public

    Structured, hands-on AI engineering repository covering LLMs, fine-tuning, LoRA/QLoRA, RLHF, RAG, AI agents, and real-world projects

    Jupyter Notebook 1

  2. mcp-trust-registry mcp-trust-registry Public

    Runtime + semantic trust registry for MCP servers - catches tool poisoning and scope creep, $0 infra (local LLM via Ollama)

    TypeScript 2

  3. sme-cashflow-explainer sme-cashflow-explainer Public

    Turn raw bank transaction CSVs into audit-ready risk memos in seconds. Deterministic cash-flow metrics, rule-based risk scoring, LLM-assisted narrative, PDF export, report comparison, and a Q&A cha…

    Python 1

  4. ai-security-garak ai-security-garak Public

    A beginner-friendly guide to NVIDIA Garak for LLM security testing with hands-on examples using Hugging Face, Spring Boot REST APIs, and Ollama.

    HTML 1

  5. springguard springguard Public

    Spring Boot security auditor: 21-rule engine + AI review pass (backend), React/TS UI (frontend). Monorepo.

    Java 1

  6. ai-security-gandalf ai-security-gandalf Public

    Hands-on exploration of prompt injection using Lakera's Gandalf game, plus my own Spring Boot chatbot demonstrating escalating LLM defenses (system prompts, input filters, output filters). Part of …

    HTML 1