Research
My research is on agentic security — both attacks against and defenses for LLM-based agents. I focus in particular on prompt leaking, prompt injection, and indirect prompt injection, as well as the domain-specific security problems that arise once these agents are deployed in real systems.
