This project focused on building and testing a practical AI security assessment lab for evaluating LLM defenses against prompt injection and jailbreak attacks.
I integrated Spikee by Reversec with a locally hosted cybersecurity model running through LM Studio, then added NVIDIA NeMo Guardrails to compare model behavior under three conditions: no guardrails, input filtering, and combined input/output protection.
The work included configuring the local model environment, building a custom FastAPI gateway, integrating NeMo Guardrails, troubleshooting model latency and timeout issues, creating a reusable Spikee target, and analyzing attack results using Spikee’s built-in reporting tools.
The project also explored different adversarial testing approaches, including prompt injection datasets, obfuscation, encoded attacks, Best-of-N testing, synthetic canary leakage tests, and structured benchmark comparisons.
The objective was to measure how much the guardrails reduced successful attacks while keeping the model, dataset, and testing conditions consistent.
This project demonstrates a hands-on approach to LLM red teaming, AI safety testing, prompt-injection assessment, and guardrail validation for organizations deploying generative AI systems.
𝐌𝐲 𝐫𝐨𝐥𝐞: Python Backend Engineer focused on AWS serverless architecture
𝐏𝐫𝐨𝐣𝐞𝐜𝐭 𝐝𝐞𝐬𝐜𝐫𝐢𝐩𝐭𝐢𝐨𝐧:
I built a serverless backend for an AI-driven trading platform handling real-time market data and analytics. I used AWS services like Lambda, API Gateway, RDS, and S3 to create a system that scales without manual infrastructure management. I designed pipelines for ingesting and processing live data to support trading signals and sentiment analysis. My focus was on keeping latency low, handling high concurrency, and ensuring the platform remained stable for global users.
𝐏𝐫𝐨𝐣𝐞𝐜𝐭 𝐝𝐞𝐬𝐜𝐫𝐢𝐩𝐭𝐢𝐨𝐧:
I integrated Single Sign-On (SSO) using OpenID Connect into an existing Flask application. I implemented a secure authentication flow with a standard identity provider, enabling seamless and centralized login. I handled token validation, session management, and secure user identity processing. This reduced login friction while maintaining strong security standards, and I delivered a stable, production-ready authentication system within a tight deadline.