Honggfuzz
Feedback-guided fuzzer used across Google. Handles multi-core workloads, hardware tracing, and corpus minimization to keep bug finds steady.
github.com/google/honggfuzzAgent Security Architecture · Google DeepMind
I lead technical architecture for Agent Security at Google DeepMind. I have spent 25+ years in systems security, from vulnerability research to building the defenses that run in production.
Hardened sandboxing and execution-isolation infrastructure to safely run untrusted code and frontier AI agents at scale, paired with automated red-teaming and automated fix-verification loops.
Runtime guardrails, data-exfiltration controls, and prompt-injection defenses across Gemini's agentic products.
Architecting multi-layered containment and syscall mediation to safely run autonomous frontier agents and untrusted code execution environments at scale, integrating automated red-teaming with closed-loop fix verification.
Designed and deployed runtime safety boundaries, indirect prompt-injection defenses, and data-exfiltration controls across Gemini's agentic ecosystem.
Led Google's AI/ML Systems Security group, directing security architecture for core foundation models and training infrastructure via confidential compute, model supply chain integrity, and proactive red teaming.
Grew engineering teams across Zurich, Mountain View, and Warsaw, pairing systems specialists with ML experts and holding them to clear threat reduction targets.
Launched sandboxing, syscall mediation, and hardening layers that protect major Google workloads, including Sandboxed API for running risky code with least privilege.
Pushed fuzzing and review programs that uncovered critical flaws in OpenSSL, the Linux kernel, browsers, and internal stacks before they shipped.
Feedback-guided fuzzer used across Google. Handles multi-core workloads, hardware tracing, and corpus minimization to keep bug finds steady.
github.com/google/honggfuzzLinux namespace-based jail for running untrusted code, CTF tasks, and production prototypes. Ships with flexible seccomp policies through the kafel DSL.
github.com/google/nsjailComposable runtime that lets teams execute high-risk code inside hardened compartments with low integration effort. Runs in latency-sensitive services and ML pipelines.
github.com/google/sandboxed-apiRecognized in 2016 and 2017 for AMD microcode privilege escalation work and for uncovering the first OpenSSL flaw rated 'critical'.
Co-founded and mentor Dragon Sector, a long-running competitive security team focused on new exploitation techniques and tooling.
Co-authored the Polish edition of 'Practical Reverse Engineering', turning advanced reversing techniques into practical guidance.