Research
I study how security changes when intelligent systems are allowed to act, persist, and interact.
My PhD studies the security of LLM-based systems under constrained external interaction. My broader interests span models, agents, and systems in which multiple participants interact.
Research interests
Model boundary
Security and privacy in language models.
Stateful agents
Security and reliability in AI agents.
Multi-principal systems
Security in systems with multiple interacting participants.
I am interested in how security questions change as intelligent systems become more capable and interconnected.
Published work
When Forgetting Reveals: Black-Box Inversion Attacks on Unlearning in Large Language Models
STMUS 2025 · ESORICS 2025 International Workshops
Published online 1 May 2026 · Springer LNCS
Can model behaviour reveal what was meant to be forgotten? I developed and evaluated a probe-based pipeline comparing original and unlearned LLMs to infer removed subjects.
Read the paper (opens in a new tab)