Chirag Dewan

I'm an AI security researcher. I work on the security of LLMs and agentic systems: red teaming them, and building the runtime detection that catches abuse when it happens.

Lately that has meant a few things. I built MCP-Poison-Bench, a de-circularized benchmark for tool-poisoning across six models and three vendors, and the result was a negative one: the client-side defense everyone recommends is structurally blind to the one attack that reliably lands. I write about why prompt injection isn't a bug you patch and how I'd build a red team that never stops. And I build behavioral detectors, PARALLAX for model-extraction abuse and KESTREL for cloud-workload attacks, that classify from the shape of traffic alone, never the content.

Before AI security I did offensive security research. There's more on the background, or you can read the writing, see the code, or reach out.

Selected research