DERRYLAB

I build AI that attacks, defends and reasons about security.

I'm Derry Pratama, a principal AI engineer and researcher. I lead AI research at SmartM2M, where I'm building SmartX, an on-prem penetration-testing platform driven by an automated LLM agent. I finished my PhD at Pusan National University, where I built CIPHER, a pentesting LLM that outperforms models ten times its size.

Busan, South Korea / Indonesia

What I'm working on

SmartX combines supervised fine-tuning, retrieval and reinforcement learning into a single agent that plans, executes and reports on a penetration test, entirely on-premises. I also work on LLM guardrails and automotive and cyber-physical security, and I lead a team of AI engineers.

  • Autonomous offensive-security agents
  • LLM guardrails and red teaming
  • Automotive and cyber-physical security
  • Cryptographic engineering

Selected work

SmartX, an on-prem AI pentesting platform2026
Offensive AI and LLM red teaming at SmartM2M2025
CIPHER, a pentesting LLM that beats models 10x its size2024
Mid-flight DJI Wi-Fi hijack via passive man-in-the-middle2024
MECHA crypto API, 82.8% faster than context switching2023
COMET, tagged memory for RISC-V at under 1% overhead2021
Won the Trinity Fire-Fighting Robot Contest2014

Code

Hijacking DJI drone control mid-flight over Wi-Fi. Published at IEEE SecDev 2024, with a flight demo.

CIPHER42 stars

A fine-tuned LLM that guides ethical penetration testing, trained on real write-ups.

A custom OpenSSL engine, part of HSM protocol work spanning mbedTLS, WolfSSL and GnuTLS.

A deliberately vulnerable LLM endpoint for exercising guardrails and red-team tooling.

Shaikhlive

A real-time voice AI assistant for muroja'ah, grounded in Islamic references.

A live map of Islamic study sessions across Indonesia, built automatically from community schedules.

Publications

MECHA: Efficient Cryptographic API for Embedded SystemsKCC 2023
COMET: Tagged Memory for RISC-VSensors 2021
RIMI: Instruction-Level Memory IsolationIEEE TrustCom 2020

The full list is on Google Scholar.

Tools I reach for

AI and LLMs. Gemma, GPT-OSS, LLaMA, Mistral, Qwen, Gemini, Claude. For training and serving I use TRL, Axolotl, vLLM and TGI, with LangGraph and SGLang for agents. Comfortable with fine-tuning (SFT, DPO), quantization and RAG, including multimodal work with Whisper and ElevenLabs.

Security. Penetration testing, red teaming, LLM guardrails, CAN and ECU fuzzing, and cryptography down to OpenSSL internals, ARIA, LEA and RSA. Familiar with OWASP Gen AI and MITRE ATLAS.

Systems. Python, C/C++ and Assembly are my main languages, with ROS, STM32 and RISC-V on the hardware side, and Docker, Nginx and PostgreSQL for infrastructure.

Education

PhD, Information Convergence Engineering2023–2025 Pusan National University
MSc, Information Convergence Engineering2020–2023 Pusan National University
BASc, Computer Engineering2011–2015 Sepuluh Nopember Institute of Technology

Get in touch

If you're working on AI security, LLM evaluation or robotics and want to compare notes, reach me at derryprata@gmail.com.