Welcome
Navigate About Research Focus Experience CTF Wins Achievements Projects Certifications Recognition Contact

Yeran Gamage

AI Security Researcher • Incoming Cloud Security Engineer @ Wells Fargo • CTF Competitor

$whoami

Yeran Gamage headshot

I'm a cybersecurity researcher transitioning into AI security research, with professional experience in cloud security, offensive security, and application security. Currently studying at the Judy Genshaft Honors College at the University of South Florida in the Bellini College of Cybersecurity and AI.

Research Focus: Offensive evaluation of AI systems, LLM security vulnerabilities, adversarial robustness, and composite attack chains that bridge traditional security and AI-specific weaknesses.

I actively compete in national CTFs with USF CyberHerd (Top 5 nationally) and founded the USF Boxing Club, which scaled to over 1,300 members-the largest combat-sports organization on campus.

AI Security Research

My transition into AI security is motivated by bringing traditional penetration testing methodology to AI systems-systematically probing where vulnerabilities hide in interactions between ML components and infrastructure.

Current Research Areas:

  • Offensive AI System Evaluation: Applying pentesting techniques (session manipulation, API fuzzing, privilege escalation) to discover vulnerabilities in model APIs, agent frameworks, and ML infrastructure
  • Composite Attack Chains: Researching how traditional security vulnerabilities chain with AI-specific weaknesses (e.g., rate limiting + prompt injection to infer model architecture)
  • LLM Jailbreak Analysis: Systematic testing of open-source models (Llama 3, Mistral) with telemetry capture to identify predictable failure patterns
  • Adversarial ML Security: Exploring robustness of computer vision models against adversarial attacks (FGSM) in malware detection contexts

Experience

Wells Fargo Honeywell JPMorgan Accenture

Notable CTF Wins

Key Achievements

Projects

Jailbreak Telemetry & Attack Surface Mapping

Python framework automating jailbreak testing on open-source LLMs (Llama 3, Mistral) with granular telemetry capture-token distributions, latency patterns, resource metrics. Developing interactive visualizations of attack surfaces to identify predictable failure modes in smaller fine-tuned models vs. large base models.

View on GitHub →

Composite Attack Chain Research (Ongoing)

Investigating how traditional security vulnerabilities chain with AI-specific weaknesses to create novel attack vectors. Examples: exploiting rate limiting + prompt injection to infer model architecture; chaining authentication bypass + agent tool poisoning to compromise multi-agent systems. Researching whether composite attacks follow predictable patterns that can be systematically enumerated and defended against.

AI Malware Vision Classifier

End-to-end deep learning pipeline converting malware binaries into grayscale images for classification. Lightweight CNN achieving 98.90% test accuracy on Malimg dataset. Integrated GradCAM explainability for model interpretation and FGSM adversarial robustness analysis to study failure modes under attack.

View on GitHub →

Anbu Full-Stack CSPM

Cloud Security Posture Manager detecting and remediating misconfigurations across AWS/GCP with focus on identity misconfiguration detection and visualization. Built for at-scale security posture management in multi-cloud environments.

View on GitHub →

Secure Cloud CI/CD Pipeline

Production-grade DevSecOps reference implementation with automated build, scan, deploy, and self-healing for containerized workloads on AWS (cloud-agnostic configurable). Integrates Trivy scanning, policy-as-code enforcement, and automated rollback.

View on GitHub →

Azure SIEM for RDP Attack Detection

Dynamic detection system using Azure Sentinel and KQL to monitor global RDP brute-force attempts with automated remediation workflows. Real-time threat intelligence integration and geolocation-based alerting.

View on GitHub →

Explore more projects on GitHub →

Certifications

CPTS Badge
CPTS
Security+ Badge
Security+

In Progress: OSCP, AWS Security Specialty, Terraform Associate

Media & Recognition