What I'm working on
SmartX combines supervised fine-tuning, retrieval and reinforcement learning into a single agent that plans, executes and reports on a penetration test, entirely on-premises. I also work on LLM guardrails and automotive and cyber-physical security, and I lead a team of AI engineers.
- Autonomous offensive-security agents
- LLM guardrails and red teaming
- Automotive and cyber-physical security
- Cryptographic engineering
Selected work
Code
Hijacking DJI drone control mid-flight over Wi-Fi. Published at IEEE SecDev 2024, with a flight demo.
A fine-tuned LLM that guides ethical penetration testing, trained on real write-ups.
A custom OpenSSL engine, part of HSM protocol work spanning mbedTLS, WolfSSL and GnuTLS.
A deliberately vulnerable LLM endpoint for exercising guardrails and red-team tooling.
A real-time voice AI assistant for muroja'ah, grounded in Islamic references.
A live map of Islamic study sessions across Indonesia, built automatically from community schedules.
Publications
The full list is on Google Scholar.
Tools I reach for
AI and LLMs. Gemma, GPT-OSS, LLaMA, Mistral, Qwen, Gemini, Claude. For training and serving I use TRL, Axolotl, vLLM and TGI, with LangGraph and SGLang for agents. Comfortable with fine-tuning (SFT, DPO), quantization and RAG, including multimodal work with Whisper and ElevenLabs.
Security. Penetration testing, red teaming, LLM guardrails, CAN and ECU fuzzing, and cryptography down to OpenSSL internals, ARIA, LEA and RSA. Familiar with OWASP Gen AI and MITRE ATLAS.
Systems. Python, C/C++ and Assembly are my main languages, with ROS, STM32 and RISC-V on the hardware side, and Docker, Nginx and PostgreSQL for infrastructure.
Education
Get in touch
If you're working on AI security, LLM evaluation or robotics and want to compare notes, reach me at derryprata@gmail.com.