LLM Firewall & RAG Security Lab
A defensive gateway for prompt injection, canary DLP, output inspection, structured-response validation, and bounded tool authorization.
View repository ↗Cybersecurity systems · AI/ML security · cloud
I’m Niket, a cybersecurity postgraduate building practical defenses across SOC detection, LLM security, cloud privilege paths, software supply chains, and identity analytics.
01 / PROFILE
My work lives at the intersection of defensive engineering, machine learning, and the systems that make security decisions trustworthy.
I’m currently pursuing an M.Tech in Cyber Security Systems and Networks at Amrita School of Engineering. I like taking a difficult security question, turning it into a testable model, and making the result useful to the person who has to act on it.
Good security tooling should explain what it saw, why it matters, what it cannot know, and what a human should do next.
— working principle02 / SELECTED WORK
Every project is defensive, reproducible, and explicit about its limits. The goal is not to make a louder alert—it is to make a better decision.
A defensive gateway for prompt injection, canary DLP, output inspection, structured-response validation, and bounded tool authorization.
View repository ↗Hybrid detection using transparent telemetry rules, Isolation Forest anomaly scoring, evidence explanations, ATT&CK tags, and incident correlation.
View repository ↗Read-only graph analysis that connects public exposure, trust relationships, privilege transitions, and sensitive assets into explainable remediation paths.
View repository ↗Dependency and vulnerability analysis with direct/transitive context, provenance, policy decisions, and SARIF output for developer workflows.
View repository ↗Privacy-conscious anomaly detection for suspicious login behavior with behavioral signals, analyst explanations, and pseudonymous reporting.
View repository ↗RESEARCH IN PROGRESS
Three current builds pushing beyond the portfolio labs.
PyMuPDF, DistilBERT, XGBoost, SHAP, and PyTorch fused to detect hidden PDF instructions and semantic injection in enterprise RAG pipelines.
Research repository ↗Cloud-native healthcare security with FastAPI, PostgreSQL RLS, Keycloak, OPA, mutual TLS, behavioral analytics, and post-quantum identity research.
More on GitHub ↗NetworkX-based AWS IAM and Kubernetes RBAC analysis modeling IRSA attack paths from a compromised pod toward administrator access.
Research repository ↗03 / TOOLKIT
Detection engineering, SOC triage, incident correlation, ATT&CK mapping, threat modeling, digital forensics, and secure API design.
Isolation Forest, feature engineering, explainability, prompt-injection defense, RAG trust boundaries, DLP, SHAP, and model evaluation.
AWS IAM, Kubernetes RBAC, IRSA, NetworkX graph modeling, Docker, PostgreSQL, Redis, JWT, OPA, and Keycloak.
Reproducible fixtures, policy-as-code thinking, incremental testing, privacy-aware analytics, clear limitations, and human-readable evidence.
04 / BACKGROUND
Amrita School of Engineering, Amritapuri
CGPA 8.38 / 10Government Engineering College Barton Hill, Thiruvananthapuram
77.1%English · Malayalam · Tamil · Hindi
05 / NEXT CONVERSATION
I’m open to conversations about cybersecurity engineering, AI security, cloud security, research opportunities, and roles where careful systems thinking matters.