Freelancers using Hugging Face in Nairobi
Freelancers using Hugging Face in Nairobi
Sign Up
Post a job
Sign Up
Log In
Filters
2
Projects
People
Stephen Kisong'e
Nairobi, Kenya
Cyber Security Analyst
Follow
Message
Cyber Security Analyst
0
Performed a manual, black-box security assessment of a locally-hosted large language model served through LM Studio, using Burp Suite as the primary testing tool. The engagement began with no prior knowledge beyond a single IP address, mirroring how an external attacker would approach an exposed AI server discovered on a network. Worked through a full discovery-first methodology: confirming the target was live, enumerating the server's exposed endpoints by probing and reading response codes, extracting the loaded model name directly from the API, and proving the expected request format through the server's own error responses rather than assuming it. This reconnaissance phase converted an unknown target into a complete map of its attack surface. With the attack surface established, executed a series of manual techniques through Burp's Repeater and Intruder tools, including prompt injection, system prompt extraction, role and system-message injection, parameter manipulation, error-message disclosure, and authentication testing. Demonstrated additional Burp capabilities relevant to AI systems, including response comparison to prove behavioral changes under attack, randomness testing of server-generated identifiers, and live request tampering to illustrate a man-in-the-middle scenario against AI traffic. Organized all findings into a structured vulnerability map aligned to OWASP LLM risk categories, recording each technique's result, severity, and supporting evidence. Delivered the work as a complete, reproducible, beginner-accessible walkthrough covering environment setup, discovery, exploitation, and reporting.
0
87
0
Conducted an automated security assessment of a locally-hosted large language model, Dolphin 3.0 (Llama 3.1 8B), using Garak, NVIDIA's open-source LLM vulnerability scanner. The model was served through LM Studio's OpenAI-compatible REST API and tested from a Parrot OS environment running in VirtualBox. Configured Garak to target the model via a custom REST generator configuration, handling endpoint routing, Bearer token authentication, JSON response parsing, and extended timeouts for local inference. Executed nine distinct probe categories against the model, covering DAN jailbreaks, prompt injection, encoding-based bypass, malware generation, latent injection, real toxicity prompts, continuation attacks, grandma exploits, and package hallucination. The assessment identified that Dolphin 3.0, an uncensored model with no built-in safety guardrails, was vulnerable across the majority of probe categories. Findings were documented per probe, distinguishing where the model resisted versus complied, and translated into a clear, layered explanation of each attack type and its real-world security implications. Delivered the work as a complete, reproducible walkthrough, including environment setup, tool configuration, probe execution, and results interpretation, suitable for both technical practitioners and stakeholders newer to AI security.
0
104
0
AI security research project focused on prompt injection risks in LLM-powered applications. The work involved testing how AI systems handle malicious or hidden instructions inside user inputs, documents, webpages, and other untrusted content. The assessment explored risks such as instruction bypass, guardrail failure, data leakage, unsafe tool use, and AI output manipulation. It demonstrated the importance of testing the full AI application, not only the model, especially when connected to files, APIs, RAG systems, browsers, or autonomous agents. Skills demonstrated: AI red teaming, LLM security testing, prompt injection analysis, guardrail evaluation, threat modeling, and secure AI deployment. Tool: Spike
0
94
1
I conducted an authorized AI security assessment of Lily Cybersecurity 7B to evaluate how effectively a hardened system prompt could resist jailbreak and prompt injection attacks. Using Prompt Fuzzer, I ran 15 attack techniques against the model. The system prompt successfully blocked 8 attempts, including most roleplay and social engineering attacks. The successful bypasses mainly used translated or altered wording to disguise the intent of the request. This project demonstrates why system prompts should be supported by input validation, moderation, output filtering, and continuous AI red team testing.
1
47
Hugging Face
(3)
Follow
Message
Emmanuel Kiriinya
Nairobi, Kenya
Full-Stack Solutions & AI Integrations Expert
Follow
Message
Full-Stack Solutions & AI Integrations Expert
0
AI-Powered Travel Recommendation App
0
4
0
Cross-Border Money Transfer & Payment App
0
7
0
Multi-tenant E-commerce Order Management Platform
0
8
View more →
Hugging Face
(1)
Follow
Message
Explore people