Research

Trust you can verify

My work sits where cryptography meets deployed systems, and lately where both meet generative models. The question underneath all of it is the same: how do you prove something is trustworthy without having to hand over everything you know?

Security of AI systems

Large language models and the agents built on them are now exposed directly to untrusted input, which makes them an attack surface rather than just a capability. I work on defences that are cheap enough to run in the request path: dense semantic embeddings for prompt-safety guardrails, benign-anchored methods for cutting false alarms in intrusion detection, and identity mechanisms that let autonomous agents prove who they are acting for.

LLM prompt safetyguardrails agentic AISSI for AI agents explainable AIintrusion detection

Key publications

LLM and generative model architectures

Current direction — work in progress

Most of my work so far has treated large language models as something to defend. I have recently started working on building them instead: autoregressive LLM architectures, and diffusion-based generative models as an alternative to left-to-right generation. The two paradigms trade off differently on sample quality, controllability and inference cost, and those differences matter for the safety questions in my other work — a model you can steer during generation is a model you can constrain.

autoregressive modelsdiffusion models generative modellingLLM pretraining model architecture

Privacy-preserving identity

Identity verification normally works by disclosure: to prove you are eligible, you reveal the document that proves it. My doctoral research attacked that trade-off, building electronic know-your-customer systems where a user proves a claim without surrendering the underlying data — using self-sovereign identity, decentralized identifiers, verifiable credentials and zero-knowledge proofs over Merkle-tree commitments.

SSIDID verifiable credentialseKYC zk-SNARKsZK circuit design MPC

Doctoral dissertation

A Privacy-Preserving Decentralized eKYC Framework Leveraging SSI, DIDs, and Zero-Knowledge Proofs — Graduate School of Informatics, Osaka Metropolitan University, March 2026. Supervised by Prof. Tadashi Nakano and Prof. Thi Hong Tran, with Dr. Kentaroh Toyoda. Results published in IEEE Internet of Things Journal, IEEE Access and IEEE Transactions on Sustainable Computing.

Key publications

Blockchain and secure communication

Distributed ledgers are the substrate for most of this work, so I spend time on the substrate itself: consensus behaviour, smart-contract security, post-quantum-safe design, and what it takes to anchor credentials on-chain without the cost becoming absurd. Applied deployments have covered supply-chain traceability, healthcare authentication, charitable giving and on-chain governance.

consensussmart-contract security post-quantum-safe designWeb3 DeFidApps

Key publications

Software and research artefacts

  • 2026

    AgentRed — AI agent security assessment framework

    Open-source red-teaming framework for automated security evaluation of AI agents, covering prompt injection, tool misuse, sensitive-data leakage and system-prompt leakage. Developer and maintainer.

  • 2026

    LessonQ — learning management system

    Learning management platform built and operated in Bangladesh. Project lead.

  • 2023

    Customised Uniswap V2/V3 deployment

    Testnet implementation and analysis at INFONET Lab, Gwangju Institute of Science and Technology, Republic of Korea.

  • 2022

    ETH-ECC private Ethereum network on AWS

    Network deployment, mining, MetaMask integration and transfer tooling at INFONET Lab, GIST; documented at infonet.gist.ac.kr.

  • 2022

    BTCECC private Bitcoin network and block explorer

    Block parsing and processing pipeline for a customised Bitcoin network, INFONET Lab, GIST.

  • 2022

    Ethereum faucet dApp and ERC token implementations

    React, Truffle and Web3.js faucet with ERC-20, ERC-721 and ERC-1155 reference implementations, INFONET Lab, GIST.

Working on something adjacent?

I am always interested in collaborations on agent security, verifiable credentials and applied zero-knowledge systems.

Get in touch Browse publications

BibTeX