Rahul Singh — Jersey City, NJ

AI Engineer AI Security & Adversarial Evaluation

6+ years building — and breaking — production ML systems. I red-team LLMs, benchmark multi-agent attribution, and ship secured RAG and agentic AI in regulated environments.

Rahul Singh — AI Engineer specializing in AI security and adversarial evaluation
Open to AI security roles
Currently — Senior AI Engineer @ Syneos Health Research — AEGIS-AT · attribution integrity
6+Years in AI / ML
95Passing tests — AEGIS-AT
61Adversarial tests — LLM Auditor
60%SOC reporting reduced
0.86Macro-F1 — clinical NLP
100+Enterprise customers served
01 — Selected Work

Case Studies

Research · Benchmarks · Production
Flagship · Independent Research

AEGIS-AT

Attribution Integrity Benchmark for Multi-Agent AI

Year2026 LicenseApache-2.0 Tests95 passing Defense gradientB1–B9 Statusv3 measured
View repo ↗
“Does attribution survive an adversary impersonating a sibling agent?

A pre-registered red-team benchmark measuring whether you can still prove which agent did what in a multi-agent AI system once one agent starts impersonating another. Defenses are arranged on a B1–B9 gradient — from shared credentials to sender-constrained tokens and 2026 agent-identity specs — and each version of the benchmark asks where attribution actually holds.

Defense gradient B1 → B9Where attribution holds
v1 — RFC 8693 baselineToken exchange, tamper-evident logs
B1
B2
B3
B4
B5
B6
B7
B8
B9
v2 — + DPoP sender-constraintRFC 9449, key-bound tokens
B1
B2
B3
B4
B5
B6
B7
B8
B9
v3 — 2026 identity specsAIP / PEDIGREE / HDP self-report
B1
B2
B3
B4
B5
B6
B7
B8✕
B9
Attribution holds Attribution lost Collapses under collusion
v1

The gap — token exchange has no executor field

OAuth 2.0 Token Exchange (RFC 8693) carries no field naming who actually executes a request. Attribution regresses from B2 to B3, and tamper-evident logs (B4) do not recover it — logs faithfully record the wrong agent.

v2

The fix — sender-constrained tokens

DPoP (RFC 9449) binds each token to the executor's cryptographic key. Attribution recovers at B5, validated against independent OS-process ground truth rather than anything an agent self-reports.

v3

The 2026 finding — self-report collapses under collusion

The new agent-identity drafts (AIP / PEDIGREE / HDP) trust the executor's self-report. B8 collapses when agents collude — while the sender-constrained baselines from v2 keep attribution intact.

  • SHA-256-locked pre-registration — committed before measurement code existed
  • Mechanical CI gate · 95 passing tests
  • 4-agent adversarial self-review with anti-fabrication controls
  • Every spec claim source-verified against RFC 8693 / 9449 / 8705 / 8707, MCP, AIP / PEDIGREE / HDP
  • Published validity-threats analysis — measured vs. by-construction

Status // v1 + v2 papers written · v3 measured · v3.1 (real-LLM attacker tier) in pre-registration

02 // Research2022–2024

MITRE-Core

Self-supervised GNN alert correlation

A heterogeneous graph neural network that correlates raw SIEM / IDS / EDR alerts into multi-stage attack campaigns with zero labels at inference — encoding alerts via MITRE ATT&CK tactic dimensions across 8+ node types and 29 edge relations, evaluated zero-shot on 6 public datasets with frozen result manifests and deterministic seeding.

The integrity story: a systematic self-audit surfaced label leakage in my own input features. I quantified the impact, retracted the inflated claims, and published the invalidated results in a public honest-assessment log.

Heterogeneous GNNMITRE ATT&CKZero-shotFrozen manifestsCI benchmark
GitHub ↗
03 // Tooling2025

Enterprise LLM Security Auditor

Adversarial evaluation harness

A systematic 61-test harness across 6 vulnerability classes — prompt injection, jailbreaks, PII leakage, data exfiltration, RAG poisoning, and system-prompt extraction — using an LLM as a semantic evaluator to catch soft-compliance failures that keyword matching misses.

Full-stack delivery: FastAPI + React + WebSockets + Docker, streaming live audit results as they run.

Prompt InjectionJailbreaksPII LeakageRAG PoisoningLLM-as-Judge
GitHub ↗
More experiments, papers & tooling github.com/rahulsingh1397 →
02 — Experience

Where I've Shipped

2018 → Present
Jan 2024 — PresentJersey City, NJ

Senior AI Engineer

Syneos Health — regulated clinical AI (HIPAA / SOC-2)
  • LLM security controls — prompt-injection defenses, role-based access, audit trails, and model-behavior monitoring for enterprise agent workflows in regulated clinical deployments.
  • Architected and own the end-to-end production RAG pipeline — semantic chunking, hybrid retrieval (BM25 + dense embeddings fused via RRF), and cross-encoder re-ranking; hybrid retrieval was required because dense embeddings alone missed exact trial IDs.
  • Fine-tuned Llama-3.1-70B with QLoRA for clinical summarization; built a multi-tool LangChain ReAct agent unifying retrieval, SQL, and API access.
  • AI governance — double-layer PII masking (Presidio + regex), OPA-based RBAC, immutable audit logging; vector index treated as a PHI store.
  • RAGAS + LangSmith evaluation with confidence scoring and an evidence-backed “I don't know” fallback; FastAPI + Docker deployment holding a sub-2.5s latency SLA; BERT/RoBERTa clinical NLP at 0.86 macro-F1.
Mar 2022 — Jan 2024Percept Cloud Security

Senior Machine Learning Engineer

Sequretek — ML threat detection for 100+ enterprise customers
  • Built MITRE-Core — self-supervised heterogeneous GNN correlating raw alerts into multi-stage attack campaigns (see case study above).
  • RL-based logon anomaly detection in Percept EDR/XDR — adaptive per-user behavioral profiles, dynamic thresholds, and an analyst feedback loop; reduced manual SOC reporting by 60%.
  • MalJPEG — LightGBM pipeline detecting malicious JPEGs from structural features (markers, segment sizes, DHT/DQT counts), deployed for endpoint threat detection.
  • Behavioral anomaly scoring at 88% prediction accuracy; led a Snowflake migration improving query performance by 40%.
Sep 2018 — Aug 2021Mumbai, IN

Data Analyst

Clover Infotech — financial reporting & analytics
  • Automated data processing pipelines, reducing report generation time by 65%.
  • Built Tableau and Power BI dashboards improving forecasting accuracy by 20%, partnering with 7+ stakeholders.
03 — Skills

The Stack

No bars. No percentages. Just tools.

A.AI Safety & Adversarial Evaluation

Pre-Registered BenchmarksDeterministic EvaluationMulti-Agent AttributionDPoP / mTLSThreat ModelingRFC 8693 / 9449 / 8705 / 8707MCPPrompt Injection DefenseRAGASLangSmithOWASP LLM Top 10MITRE ATT&CK / ATLAS

B.Machine Learning

LLM Fine-tuning (QLoRA)RAG PipelinesLangChainReAct AgentsFAISS / PineconeEmbeddingsGraph Neural NetworksHDBSCANAnomaly DetectionNLPPyTorchScikit-learn

C.Security & Threat Detection

SIEM (Splunk, Wazuh)EDR TelemetryAlert CorrelationIntrusion DetectionPII Detection & MaskingPresidioOPA RBAC

D.MLOps & Deployment

FastAPIDockerKubernetesCI/CDModel MonitoringDrift DetectionAudit Logging

E.Data & Cloud

PythonSQLAzureAWSDatabricksSnowflakeApache SparkPower BITableau

F.Education

Sep 2021 — May 2023

M.S. Information Systems

Stevens Institute of Technology — Hoboken, NJ
04 — Writing

Field Notes

05 — GitHub

Live Telemetry

api.github.com/users/rahulsingh1397
Public repos
Followers
Public gists
GitHub contribution chart for rahulsingh1397