Security researcher — IoT · mobile · appsec · Consumer Reports
Most of my work isn't public. The throughline that is: I look for the gap between what a system is supposed to do and what it can be made to do.
Now building → an agentic-AI CTF featuring hands-on challenges for breaking and hardening LLM agents: prompt injection, tool abuse, and the failure modes that only show up once a model can act. Repo goes public once it's ready.
Recently wrote → How Much Does a Local LLM Actually Cost to Run? in Towards Data Science — the real, wall-calibrated electricity cost of running LLMs locally on Apple Silicon.
Views are my own.