Skip to content
View VinayK88's full-sized avatar
🎯
Focusing
🎯
Focusing
  • TMUS
  • Austin, Texas
  • 16:21 (UTC -05:00)

Block or report VinayK88

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
VinayK88/README.md

Cybersecurity and AI security portfolio banner

Security, thoughtfully engineered

AgentShield  ·  VulnSignal  ·  LLM Security Eval Lab  ·  DetectionForge  ·  RiskOS  ·  Frontier Agent Evals


Python   SQL   XGBoost   scikit-learn   Streamlit   FastAPI   NetworkX   Docker



What I build

Applied data science and AI for security systems where the model is only one part of the decision.


Detect

Abuse patterns
Security anomalies
Attack behavior
Emerging campaigns
Understand

Graph relationships
Behavioral context
Threat provenance
Attack paths
Decide

Risk calibration
Policy thresholds
Intervention ranking
Operational tradeoffs
Measure

False positives
Experiment impact
Model drift
Safety guardrails

The projects below focus on the full analytical lifecycle: telemetry → features → models → explanations → decisions → measurement. Many combine supervised ML, anomaly detection, graph analytics, NLP, causal analysis, and analyst-facing dashboards rather than treating prediction as the final output.



Flagship systems

Six portfolio anchors across agent security, AI evaluation, detection engineering, and risk decisioning.


🛡️ AgentShield

AI Agent Runtime Security

Deterministic tool authorization, learned trajectory-risk evidence, human approval, redaction, and measurable risk-versus-friction controls.

Runtime policy · MCP-aware governance · Sequence ML · Control evaluation

AI Security Finding Intelligence

End-to-end finding quality, model routing, deduplication, triage experiments, remediation outcomes, and verified resolution.

Model routing · Finding quality · Experimentation · Security outcomes

Adversarial AI Evaluation

Prompt-injection, secret-leakage, hallucination, tool-authorization, approval-control, and response-trace evaluation.

Adversarial evals · Tool safety · Human approval · Trace grading

Detection Engineering as Code

Versioned detections, KQL compilation, malicious/benign replay, deterministic release gates, ML alert ranking, and active learning.

Detection as code · MITRE ATT&CK · Replay · Security ML

RiskOS

Calibrated Security Decisioning

Risk decisions separated from prediction so thresholds and interventions can reflect exposure, capacity, false-positive cost, and policy constraints.

Calibration · Exposure modeling · Policy optimization · Decision science

Long-Horizon Agent Evaluation

Outcome quality, process safety, intervention behavior, efficiency, and calibration for agents that reason and act over multiple steps.

Long-horizon evals · Process safety · Calibration · Agent reliability



Research labs & supporting systems

Domain-focused systems that extend the flagship work across trust and safety, SOC operations, cloud, identity, and threat intelligence.


Evaluation & Decision Infrastructure

Production-style systems for keeping models, signals, benchmarks, and human-review policies trustworthy over time.


Project Focus
GoldenSet Factory Production feedback → governed, deduplicated, versioned evaluation sets
EvalDrift Offline-to-production divergence, confidence intervals, sustained alerts, investigation ranking
ReviewerIQ Capacity-constrained human-review optimization with clean policy comparisons
FeatureDecay Lab Signal decay, uncertainty, change points, replacement discovery, time-aware evaluation
DecisionStream Leakage-safe event-time features, policy actions, replay, and champion/challenger evidence

Shared engineering baseline: synthetic-data boundaries · Python 3.10–3.12 CI · reproducible manifests · benchmark artifacts · MIT licensing · security reporting.



Trust & Safety · Fraud · Abuse

Consumer protection, abuse detection, content integrity, and risk decisioning.


These projects explore a recurring product question: how do you stop harmful behavior while minimizing friction for legitimate users? The emphasis is therefore not only recall, but precision, calibration, false-positive cost, exposure, intervention design, and ecosystem-level measurement.

Project Focus
MessageShield RCS/RBM spam, phishing, impersonation, graph abuse signals, experiments, counterfactual analysis
CallShield AI Scam calls, robocalls, voice impersonation, behavioral ML, anomaly detection, explainability
DeepTrace Content authenticity, provenance, semantic similarity, coordinated narrative clustering
RiskOS Calibrated Trust & Safety decisioning, exposure modeling, policy optimization
SignalForge Fraud, abuse, and operational-risk ML with graph signals and cost-aware decisions
PhishGraph AI Phishing/BEC detection using identity, URL, behavioral, and campaign-graph signals

Methods represented: classification · gradient boosting · anomaly detection · graph features · clustering · calibration · SHAP-style explainability · A/B testing · counterfactual analysis.



AI · Agent · LLM Security

Security and evaluation for systems that reason, act, and use tools.


This portfolio area treats AI systems as active security principals. The core questions include what an agent can access, what tools it can invoke, whether its trajectory remains policy-compliant, how safeguards fail under adversarial pressure, and how model behavior can be evaluated beyond single-turn accuracy.

Project Focus
AgentShield Runtime AI-agent security, tool policy, trajectory risk, safeguard measurement
AegisMesh Multi-agent security orchestration with policy-gated tools
AgentAtlas AI-agent inventory, effective access, permission drift, anomaly prioritization
LLM Security Evaluation Lab Prompt injection, leakage, misuse, tool authorization, intervention evaluation
Frontier Agent Evals Long-horizon agent outcomes, process safety, efficiency, and calibration
Model Containment Eval Lab Shutdown compliance, containment, tripwires, trace-risk monitoring
Oversight Integrity Lab Counterfactual testing for compromised oversight and monitor effectiveness
VulnSignal AI vulnerability-finding quality, model routing, validation, remediation outcomes

Themes: agent authorization · prompt-injection resilience · containment · long-horizon evaluation · oversight integrity · model routing · tool-use policy · trajectory monitoring.



Security Operations · Detection · Endpoint

From raw telemetry to investigation, prioritization, and explainable detections.


These systems focus on the operational path from high-volume security telemetry to an analyst decision: normalization, feature generation, detection logic, replay/testing, prioritization, investigation context, ATT&CK mapping, and measurable false-positive reduction.

Project Focus
DetectionForge Detection-as-code, replay metrics, release gates, ML alert prioritization
Agentic SOC Investigator Evidence-grounded SOC investigation, enrichment, ATT&CK mapping
InsiderGuard UEBA, DLP, peer baselines, insider risk, exfiltration-sequence detection
Security Telemetry Lakehouse Event normalization, dedupe, watermarking, feature windows, explainable detections
BrowserGuard Browser-extension risk, session exposure, permission drift, hybrid anomaly detection
MacSentinel macOS threat analytics, provenance graphs, streaming ML, robustness testing
Cybersecurity Analytics & AI Identity, endpoint, network, SIEM, AI-safety, OSINT, and purple-team analytics

Operational patterns: detection-as-code · UEBA · peer baselines · streaming features · SIEM analytics · evidence enrichment · ATT&CK mapping · analyst prioritization.



Application · Web Security

Secure code, application behavior, and adversarial web activity.


Project Focus
CodeSentinel AI AI-native secure code review, CWE mapping, finding validation, remediation tracking
AdversarialWeb Bots, scraping, credential stuffing, account takeover, detection-gap analysis

This category connects application-layer evidence with ML-assisted prioritization: code findings, attack behavior, account-abuse patterns, validation, and remediation outcomes.



Cloud · Identity · Infrastructure · Attack Paths

Identity exposure, blast radius, recovery, infrastructure trust, and attack-path reasoning.


Rather than score cloud findings independently, these projects model relationships and reachability: which identities connect to which resources, how permissions create paths, what compromise can reach next, and which defensive intervention most efficiently reduces blast radius.

Project Focus
AttackPath AI Cross-source identity and agentic attack-path detection
SaaSGraph OAuth/SaaS exposure, token behavior, anomaly detection, blast radius
Counterfactual Security Engine Attack-path simulation and defensive intervention ranking
CloudRescue Cloud ransomware recovery assurance, recoverability gates, restore forecasting
InfraGuard AI Critical-infrastructure AI assurance, provenance, safety envelopes, degraded-safe operation
GPU Trust Guardian GPU trust, attestation, workload behavior, attack paths, analyst-agent guardrails
AI Data Center Security Digital Twin Cyber-physical attack paths, blast radius, multivariate infrastructure telemetry ML

Methods represented: graph traversal · attack-path ranking · anomaly detection · counterfactual intervention · recovery forecasting · attestation · digital twins · multivariate telemetry analysis.



Threat Intelligence · OSINT · Supply Chain

Evidence, provenance, graph context, and software-supply-chain risk.


These projects emphasize evidence quality and provenance. The goal is to preserve where an assertion came from, connect indicators and behaviors into usable context, expose contradictions, and make machine-generated recommendations inspectable by an analyst.

Project Focus
Threat Intelligence Knowledge Graph CTI evidence paths, graph retrieval, analyst-gated link prediction
OSINT Threat Intelligence Agent IOC investigation, provenance, contradictions, ATT&CK context
SupplyChain Guardian AI SBOM, CI/CD, build provenance, dependency risk, policy release gates

Themes: knowledge graphs · IOC enrichment · provenance · ATT&CK context · SBOM analysis · build integrity · dependency risk · analyst-in-the-loop reasoning.



ML & analytical patterns across the portfolio

Different security domains. A reusable decision-science toolkit.


Layer Techniques
Supervised ML Logistic regression, gradient boosting, XGBoost, multiclass classification, ensemble scoring
Unsupervised ML Isolation Forest, clustering, behavioral baselines, novelty detection
NLP Text classification, TF-IDF, semantic similarity, transcript analysis, threat-text enrichment
Graph analytics Attack paths, knowledge graphs, campaign graphs, blast radius, centrality, reachability
Model evaluation PR-AUC, ROC-AUC, precision/recall, calibration, false-positive guardrails, challenger/champion comparison
Explainability Feature importance, local risk explanations, evidence paths, analyst-readable reasoning
Experimentation A/B testing, guardrail metrics, counterfactual analysis, intervention measurement
Decision science Threshold optimization, exposure modeling, cost-aware decisions, capacity-aware policy


How I think about security ML


Raw telemetry
     │
     ▼
Normalization & quality
     │
     ▼
Behavioral / graph / text features
     │
     ▼
Rules + ML + anomaly detection
     │
     ▼
Calibrated risk
     │
     ├────────► Explanation / evidence
     │
     ▼
Policy or analyst decision
     │
     ▼
Outcome measurement
     │
     ▼
Feedback, tuning & monitoring

The common design principle across the portfolio is that a model score is not the end product. Useful security systems also need evidence, thresholds, guardrails, operational context, and a way to measure whether the intervention actually improved the outcome.



Engineering stack


Data & ML

Python
SQL
pandas
scikit-learn
XGBoost
PySpark
Security analytics

Splunk / SIEM
MITRE ATT&CK
Identity telemetry
Endpoint telemetry
Threat intelligence
Detection engineering
AI systems

LLMs
RAG
Agent workflows
Evaluation harnesses
Tool policy
Knowledge graphs
Productization

Streamlit
FastAPI
Docker
Dashboards
Model monitoring
Experimentation


Legacy & earlier analytics work


Earlier data-science and coursework repositories remain available for historical context. The six projects above represent the current cybersecurity and AI-security focus.

Data Science Projects · Python Proficiency Test · Social Media Mining · NLP Projects · Customer Marketing Analytics · Electronic Arts Data Science Test



Portfolio principles


Security-first — optimize for adversarial behavior, uncertainty, false-positive cost, and evidence quality.

Explainable by design — pair risk scores with features, graph paths, provenance, or analyst-readable evidence.

Product-aware — connect model outputs to interventions, user friction, capacity constraints, and measurable outcomes.

Evaluation-driven — use holdouts, replay, guardrails, calibration, experiments, and counterfactuals instead of relying on headline accuracy.

Systems-oriented — build the surrounding data, decision, and monitoring layers rather than presenting isolated notebooks.



Build the signal. Understand the risk. Improve the decision.

AI Security · Security ML · Detection Engineering · Application Security · Threat Intelligence · Cloud Security · Identity Security · Trust & Safety


Pinned Loading

  1. AgentShield AgentShield Public

    Runtime security gateway for AI agents and MCP—enforcing intent-aware tool policies, least privilege, prompt-injection defenses, sensitive-data controls, human approval, and multi-step trajectory r…

    Python

  2. VulnSignal VulnSignal Public

    VulnSignal is an AI security evaluation platform that measures finding accuracy, severity, actionability, duplication, developer acceptance, remediation, and verified resolution.

    Python

  3. LLM-Security-Evaluation-Lab LLM-Security-Evaluation-Lab Public

    It includes prompt-injection testing, synthetic secret-leakage detection, hallucination checks, authorized-vs-unauthorized tool-use grading, human-approval enforcement, response-trace evaluation, p…

    Python

  4. DetectionForge DetectionForge Public

    Production-grade Detection Engineering & Detection-as-Code platform for Sigma/KQL rule validation, attack replay, precision/recall testing, ATT&CK coverage, CI/CD quality gates, and analyst-driven …

    Python

  5. riskos riskos Public

    RiskOS — Trust & Safety decisioning platform for fraud detection, entity-link analysis, temporal risk scoring, policy enforcement, model evaluation, drift monitoring, and analyst investigations.

    Python

  6. frontier-agent-evals frontier-agent-evals Public

    Long-horizon agent environments with perturbations, process graders, safety checks, and deterministic replay.

    Python