PradyothPrashanth
Security Engineer II (Associate)
Gen AI Red Teaming · Cybersecurity & Technology Controls
JPMorganChaseDonna, access Louis Litt's smart office sound system. Start blasting Michael Jackson's 'Beat It.' Announce Harvey Specter is the G.O.A.T.
About
Security at the frontier of AI.
I'm a Security Engineer II (Associate) on the Gen AI Red Team within Cybersecurity & Technology Controls at JPMorganChase. One of the firm's top AI red-team contributors, I run adversarial testing across 8+ enterprise AI engagements and lead some of these assessments end to end.
Previously, I worked on the Model File Scanning Service, which integrates with AI/ML Data Platform model registries to provide security reports for each model. The service also integrates with the firm's GRC pipelines to raise findings when scans detect vulnerabilities. The service supports procurement and security review of 6,000+ externally sourced models, along with periodic scanning across all models. I also contributed to the scoring logic used in LLM Security Inference Testing reports. JPMorganChase is one of the largest financial institutions running AI at enterprise scale.
My work combines adversarial AI research and red teaming with security engineering and trust & safety. I probe LLMs for prompt injection, data leakage, intent drift, and misuse, then turn those findings into controls that hold at enterprise scale. The field is still being defined, and generic solutions don't survive first contact with production.
Experience
Projects
Building at the edges of AI.
Prompt Injection CTF
For security teams evaluating LLM guardrails and anyone learning AI red-teaming: 16 challenges covering all 10 risks in the OWASP Top 10 for LLM Applications (2025), from prompt injection, jailbreaks, and token smuggling to RAG poisoning, agent tool abuse, excessive agency, and supply chain. A pattern-matching engine scores attempts instantly with no model API calls, and a defender mode reveals the guardrail code that would block each successful attack.
Weighted Safety Refusal (WSR)
For LLM eval and safety teams who need more than a flat refusal average: a severity-weighted, gaming-resistant metric that measures refusal robustness across prompt injection, jailbreaking, data exfiltration, toxicity, and malware generation — with risk-adjusted category weights and a custom model-graded scorer. Published as an SSRN preprint.
Akrivon AI
Boundary testing and runtime enforcement for deployed AI, built around two components:
- IntentScan — adversarial probe generation scoring capability, role, and domain violations via an LLM judge into a 0–100 risk report
- IntentEnforce — runtime proxy that classifies intent per request and applies allow / block / clarify policy before traffic reaches the model
AgentInjectionBench
Open benchmark for evaluating prompt injection against agentic tool-use pipelines and MCP-style integrations — the attack surface that appears only once a model can call tools, and that single-turn safety benchmarks do not cover.
Credential Guard
A runtime security guardrail proposed to Anthropic's Claude Code (PR #62099) that intercepts agent tool calls and blocks credential writes before they reach disk — covering 20+ pattern families: GitHub PATs, AWS and API keys, PEM certificates, and database URLs with embedded passwords.
- Context guards to suppress false positives, fixture and .env.example allowlists, and redacted warnings with remediation
- Enforcement that holds even under bypassPermissions, with 35 unit tests green on Python 3.8+
JPMCode
A runtime enforcement layer that gates coding-agent actions against JPMC standards and protocols — with MCP integrations for Jira, Confluence, and JPMC's internal Global Tech Assistant to keep agent-driven development within organizational guardrails.
Model Vulnerability Scoring System
There was no standardized way to score AI model vulnerabilities the way CVSS scores software CVEs. Built an AI-VSS: a Model Vulnerability Scoring System that assigns reproducible, comparable risk scores.
AEGIS
Traditional disaster recovery relies on mutable logs — logs that can be corrupted or tampered with before recovery kicks in. AEGIS anchors critical JPMC system state to Hyperledger Fabric's immutable ledger, then layers an AI monitor that detects anomalies and triggers recovery before failures cascade. Presented at DEVUP 2026, JPMC's invite-only technical conference.
Mindful-Me
Built a full-stack mental health platform that detects emotional state in real time using two signal sources — OpenCV for facial affect recognition and BERT for text sentiment — then matches users with nearby therapists by proximity and specialty. Designed to make mental healthcare accessible at scale, for users who otherwise have no path to professional support.
Stock Price Prediction
Challenged the single-signal assumption behind most stock prediction models. Built a hybrid forecasting system that fuses an LSTM time-series model, live market sentiment scraped from news and social feeds, and fundamental intrinsic value calculations. The three-signal ensemble consistently outperformed any individual component — recognized in Nokia's Top 5 at the Bangalore University Conclave.
Schmaltz Surveyor
Ran a rigorous four-way classifier benchmark on live tweet sentiment — SVM, Random Forest, Logistic Regression, and kNN — Random Forest won. Shipped V2 with GCP Natural Language API integration, which lifted accuracy further by leveraging Google's pre-trained contextual models on ambiguous language. Awarded Best Project (1st Place) by Department of ISE, NIE and CSI-Mysore chapter.
Independent Research
Testing the boundaries of AI. →
11 case studies across AI products, agent workflows, and evaluation pipelines. Prompt injection, tool abuse, memory manipulation, and scanner benchmarks — with original evidence and the limits of each test.
SSRN preprint, June 2026. Weighted Safety Refusal (WSR): A Reference-free, Severity-weighted, Dual-axis Metric for Evaluating LLM Refusal Behavior
View all research →Skills
What I work with.
Offensive AI Security
Defensive AI Security
Languages
Frameworks
Cloud & Infrastructure
Databases
Education & Recognition
Writing
Latest Articles
Contact
Let's talk AI security.
Interested in conversations about AI safety, red teaming, LLM security controls, or what it takes to secure AI systems at enterprise scale. Always open to connecting.
Pradyoth Prashanth