AI Safety Engineering Lead on the AI Red Team at Microsoft

November 2023 - present · Remote (WA)
October 2026

MLCommons Jailbreak Benchmark v1.0

I contributed to MLCommons Jailbreak Benchmark v1.0, collaborating with Chris Knotz on implementations for leaf nodes in the jailbreak taxonomy. PyRIT provided the foundation for this work.
September 2026

PyRIT v1 release

At the end of July, we released v1 of PyRIT, Microsoft's AI red teaming toolkit. Our new blog post and white paper, co-written with Rich Lundeen and Eugenia Kim, trace its evolution from a research prototype into a production-grade platform used to red team hundreds of generative AI products and services. PyRIT now supports repeatable, measurable, and collaborative red teaming through the Python framework, scanner CLI, CoPyRIT graphical user interface, and RAMPART. The publications also show how Volkan Kutal uses PyRIT for reproducible, auditable enterprise assessments and how MLCommons uses its attack libraries and prompt converters to power a jailbreak benchmark organized around the MLCommons Jailbreak Taxonomy. Huge kudos to my fellow PyRIT maintainers Rich Lundeen, Behnam Ousat, Hannah Westra, Justin Song, Varun Joginpalli, Toby Kohlenberg, Adrian Gavrila, Bolor-Erdene Jagdagdorj, Victor Valbuena, Spencer Schoenberg, Bashir Partovi, and Nina Chikanov.
November 2025

PyData Seattle talk

I spoke about Red Teaming AI: Getting Started with PyRIT for Safer Generative AI Systems at PyData Seattle!
October 2025

Blind Goal-Directedness paper accepted at ICLR 2026

Overview graphic of the pre-print including examples of blind goal-directedness in computer-use agents, the benchmark design, as well as evaluation and findings
Our paper "Just Do It!? Computer-Use Agents Exhibit Blind Goal-Directedness" has been accepted at ICLR 2026! This was a collaboration between the AI Red Team and our friends at Microsoft Research AI Frontiers, based on Erfan Shayegani's summer internship. The work was also covered by 404 Media.
September 2025

Talk Python To Me podcast

Tori Westerhoff and I joined Michael Kennedy on the Talk Python To Me podcast to talk about red teaming LLMs and generative AI with PyRIT.
July 2025

Mentored UMass Amherst students on PyRIT

The UMass Open Source Apprenticeship Program logo
I had the pleasure of mentoring Sarayu Poddutoori, Amanda Sherman, Varshini Balaji, and Yen Do from UMass Amherst as they extended PyRIT. Amanda built a cross-prompt injection (XPIA) example with a website target, Sarayu built out result reporting in the pyrit.analytics module, Varshini contributed to the GCG adversarial suffix attack, and Yen extended Tree of Attacks with Pruning to support image targets.
May 2025

Build 2025 Lab

The crew supporting our lab at the Microsoft Build conference 2025 called AI security testing with PyRIT
After attending //Build for the first time last year, I co-presented the same lab on "AI security testing with PyRIT" twice, once with Rich Lundeen and once with Nina Chikanov. It was fun to see people try out PyRIT, learn about this new area, and get feedback. Shoutout to Sarah Young, Sydney Lister, Joylynn Kirui, Justin Song, and JP Hernandez for supporting the sessions.
April 2025

Taxonomy of Failure Modes in Agentic AI

Our new whitepaper "Taxonomy of Failure Modes in Agentic AI Systems" is out! For a high-level idea, check out this Microsoft blog.
January 2025

Lessons from Red Teaming 100 GenAI Products

The header image of the Microsoft blog post saying 8 lessons from the front lines of AI red teaming
We published a new whitepaper titled "Lessons Learned from Red Teaming 100 Generative AI Products" as described in this Microsoft blog.
August 2024

Mentored Stanford ICME students on PyRIT

I mentored Naijing Guo and Salma Zainana from the Stanford ICME program (together with Eric Darve and Kari Hanson) as they brought state-of-the-art jailbreaks to PyRIT. Salma implemented Tree of Attacks with Pruning and Naijing contributed the GCG (Greedy Coordinate Gradient) adversarial suffix attack — a far more involved, optimization-based jailbreak than a simple converter — expanding PyRIT's automated attack toolkit for probing generative AI systems.
August 2024

Mentored Microsoft intern Safwan Ahmed

I mentored Safwan Ahmed during his Microsoft internship, where he implemented two well-known jailbreaks in PyRIT. He added the single-turn Skeleton Key attack, disclosed by Mark Russinovich, and the multi-turn Crescendo orchestrator, giving red teamers reusable implementations of both.
July 2024

Phi-3 Safety Post-Training

PyRIT was a key part of Phi-3 Safety Post-Training which is highlighted in the associated paper Phi-3 Safety Post-Training: Aligning Language Models with a "Break-Fix" Cycle
May 2024

Microsoft //Build 2024

One of the highlights from my perspective was going to the Microsoft //Build conference in May to talk to customers about PyRIT. After just about eight (!) years at Microsoft this was my first //Build conference. My colleagues Tori Westerhoff and Pete Bryan did an amazing job talking about the work of the AI Red Team in their session.
February 2024

PyRIT release

The PyRIT project mascot, a raccoon named Roakey, in pirate clothes with a parrot on her shoulder.
We released PyRIT! Since then, we have been expanding its capabilities to allow for probing multimodal generative AI systems (rather than just text-based ones). Another focus area has been state-of-the-art attack techniques. This space moves pretty fast, but we have added (or are in the process of adding) PAIR, Tree of attacks with pruning, GCG, Crescendo, Skeleton Key, and several others. Some of these are our own contributions, some of them happened via collaborations or contributions facilitated via the open source repository.
November 2023

Joined the AI Red Team

I have joined the AI Red Team. See these articles for some background [1], [2], and [3].

Responsible AI Engineer on the Azure AI team at Microsoft

December 2021 - November 2023 · Remote (MA)
October 2023

LLM Evaluation Framework paper

A screenshot from the JMLR website showing the new Fairlearn paper title with authors.
Our new paper is on ArXiv! Titled A Framework for Automated Measurement of Responsible AI Harms in Generative AI Applications, it talks about some of the ways we have been evaluating LLMs. This was a joint effort of many teams at Microsoft and Microsoft Research. I am particularly happy with the emphasis on input from domain experts. This is merely a tool to help speed up evaluations, but the actual decisions about mitigations and whether a system is deployed remains (and should remain) with humans.
August 2023

Fairlearn JMLR paper

A screenshot from the JMLR website showing the new Fairlearn paper title with authors.
The new Fairlearn paper is now in the Journal for Machine Learning Research (Open Source Software section)! It captures our change from being a project under Microsoft governance to being a true open source project with open governance. As of today, half the maintainers are employed by Microsoft (including myself). Also, the focus of the project has shifted significantly since the original whitepaper. Back then, the Python toolkit was the main focus whereas now the educational materials are being prioritized. This aims to acknowledge the sociotechnical nature of fairness.
January 2022

Mentored MIT students on Fairlearn

I mentored Kevin Spiekermann and Britney Ting from MIT on Fairlearn. They documented the modern folktables benchmarks from Ding et al. as replacements for the dated UCI Adult dataset — Kevin added documentation and a fetch function for ACSIncome and Britney added documentation for the sibling ACSPublicCoverage dataset.
December 2021

Responsible AI Dashboard release

RAI dashboard view of error analysis tool
We released the Responsible AI dashboard. As one of the key contributors on the engineering side I am really proud of this milestone. Of course, this is only where it really starts as we can now iterate on the first version. Make sure to try it and leave some feedback! The functionality is better captured by the blog and website, but something not mentioned there that I am really excited about is that we pulled this off in the open on GitHub. That means anyone can see what goes into this, ask for features, or even contribute bugfixes. Doing impactful work is awesome, but seeing the recognition in the entire company takes this to a whole different level. For example, I have seen tweets about this by Microsoft CTO Kevin Scott and Chief Scientific Officer Eric Horvitz.

Graduate student at the Max Planck Institute for Intelligent Systems

September 2021 - November 2021 · Tübingen, Germany

Responsible AI Engineer on the Azure ML team at Microsoft

July 2017 - August 2021 · Cambridge, MA (until 2020), Bellevue, WA (2020-2021)
May 2021

Mentored Stanford ICME students on chest X-ray fairness

I mentored Lilian Kourti and Xiaoye Yuan from the Stanford ICME program (together with Matt Lungren, Kari Hanson, and Trevor Hastie) on fairness in chest X-ray classification, studying how deep-learning diagnostic models perform across patient subgroups.
August 2020

Mentored Stanford ICME students on Fairlearn

I mentored Davide Giovanardi, Lauren Pendo, and Andra Fehmiu from the Stanford ICME program (together with Kari Hanson and Mary Wootters) on Fairlearn. Together they implemented bounded group loss via exponentiated gradient, extending Fairlearn's fairness reductions to regression problems.
April 2020

Mentored UMass Amherst students on Fairlearn

I mentored Parul Gupta and Abdul from UMass Amherst (together with Miro Dudík) on Fairlearn. Abdul added the Equal Opportunity constraint while Parul contributed additional reduction constraints and grid-search improvements to the fairness algorithms.
April 2020

The Good AI fairness keynote

I gave a keynote on fairness in algorithms for The Good AI, covering how to assess and mitigate unfairness in machine learning systems with Fairlearn.
November 2019

Fairlearn announced at Ignite

fairlearn repository
For a little while now I have been working on Responsible AI at Microsoft. Now that Sarah Bird announced our tools at Ignite I can finally point to our tools publicly. A lot of my time over the past months went into Fairlearn, our open source toolkit for fairness assessment and unfairness mitigation. We just released v0.3.0, so there is a lot more to come in the next months. I will be in Vancouver for NeurIPS in December to demo our tools around fairness and interpretability. Talk to me if you will be there!
November 2019

Responsible AI reading group

Abstraction in Fairness-aware Machine Learning
Since fairness is tricky to get right we have been meeting bi-weekly as a Responsible AI reading group. Today I had the honor to lead the discussion about "Fairness and Abstraction in Sociotechnical Systems" by Andrew D. Selbst, danah boyd, Sorelle A. Friedler, Suresh Venkatasubramanian, and Janet Vertesi. I highly encourage everyone to read this paper to avoid the mentioned abstraction traps when building machine learning systems. Maybe this should be part of a mandatory checklist before releasing models... If you are interested in my slides you may download them here.
August 2018

Mentored ITAM student on Azure ML

I mentored Emilio Alfonso Venancio from the Instituto Tecnológico Autónomo de México on Azure Machine Learning.
March 2018

MIT Breaking the Mold Hackathon

Participating at MIT`s Breaking the Mold Hackathon for Inclusion was truly a blessing. With so many truly difficult problems to tackle, it is fantastic to see all the ideas people came up with. Big shoutout to MIT for organizing this, Microsoft for the venue (and encouraging me to go!), and Amazon for sending two inspiring mentors for my team all the way from Seattle! Thanks also to my team for creating a creative environment where everybody could express their ideas. I learned a ton from all of you, and winning 3rd prize tops it all off. I hope everybody takes some time to think about Machine Learning Bias. With ML becoming increasingly prevalent, it is more important than ever to take bias into account.
July 2017

Joined Azure Machine Learning team

After a year on the Office team, I moved to the Azure Machine Learning team. We are building the infrastructure and services from scratch using lots of open source (e.g., Kubernetes, Linux, .NET core).

Software Engineer at Microsoft Office (Docs)

June 2016 - June 2017 · Cambridge, MA
May 2017

Hacking Bias in ML workshop

I participated in the Hacking Bias in ML workshop at Microsoft`s New England Research and Development Center (which happens to be my office, too). My group specifically looked at gender bias in text through word embeddings. We found lots of evidence of gender bias, e.g., some words are generally more used in connection with men ("smart"), some more with women ("lovely"). You can play around with the tool resulting from the workshop here.
June 2016

Joined Microsoft Office Docs

I have joined the Docs team within Microsoft Office. We enhance collaboration capabilities through the Share feature in all Office apps.

MS in Computer Science, Focus on Distributed Systems and ML

Fall 2015 - Spring 2016 · Amherst, MA
Fall 2015 - Spring 2016

Cache Networks research

Cache Networks Simulation Results
I had the pleasure of working as a Research Assistant in the Computer Networking Lab with Professor Don Towsley and Professor Antonio Rocha on the Simulation of Cache Networks. The results still remain to be published, so I will write about it if that happens. Separately, I conducted experiments with cache networks for a graduate seminar on distributed systems. You can download my project report here.
January 2016

Content-Centric Networking paper

Content Centric Networking
There are several NSF-funded Future Internet Architecture research projects in the US. Their focus is mostly on improving the scalability and efficiency. I am interested in how the different approaches affect (or do not affect) the privacy of users in comparison to the current Internet. My main focus was the feasibility of censorship circumvention. As an example, I picked Content-oriented Networking. See the full paper at arxiv.org/abs/1601.01278.
January 2016

NFL play prediction paper

Pete Carroll - coach
Based on NFL game data we try to predict the outcome of a play in multiple different ways including Decision and Classification Trees, Nearest Neighbors, Naive Bayes, Linear Discriminant Analysis, Support Vector Machines and Regression, and Artificial Neural Networks. An application of this is the following: by plugging in various play options one could determine the best play for a given situation in real time. While the outcome of a play can be described in many ways we had the most promising results with a newly defined measure that we call "progress". We see this work as a first step to include predictive analysis into NFL playcalling. See the full paper at arxiv.org/abs/1601.00574; in collaboration with Brendan Teich and Valentin Kassarnig.

Systems Engineering Intern

June 2015 - August 2015 · Eschborn, Germany

Graduate Exchange Student

Fall 2014 - Spring 2015 · Amherst, MA
Fall 2014 - Spring 2015

Baden-Württemberg Exchange

I took part in Baden-Württemberg Exchange between University of Ulm and University of Massachusetts Amherst.
May 2015

Fantasy Football prediction paper

Thomas Rawls - player
New paper! The ubiquity of professional sports and specifically the NFL have lead to an increase in popularity for Fantasy Football. Users have many tools at their disposal: statistics, predictions, rankings of experts and even recommendations of peers. There are issues with all of these, though. Especially since many people pay money to play, the prediction tools should be enhanced as they provide unbiased and easy-to-use assistance for users. This paper provides and discusses approaches to predict Fantasy Football scores of Quarterbacks with relatively limited data. See the full paper at arxiv.org/abs/1505.06918.

University of Ulm

Fall 2011 - Summer 2014 · Ulm, Germany
Fall 2011 - Summer 2014

BSc in Computer Science

After a year of studying in the Mathematics Bachelor`s program with a minor in Computer Science I decided to swap major and minor. I still graduated with a BSc in Computer Science with honors. The courses covered basics in Systems, AI, and Theory.
2014

Bachelor`s thesis: Adaptive Large Neighborhood Search

Adaptive Large Neighborhood Search - Destroy and Repair
The goal of my Bachelor`s thesis was to implement the Adaptive Large Neighborhood Search (ALNS) heuristic and possibly come up with improvements. ALNS was described first by S. Ropke and D. Pisinger and is based on P. Shaw`s Large Neighborhood Search. The idea is that some problems are difficult to solve with basic local search algorithms because of a tightly constrained search space. Small changes to a solution will rarely bring improvements. As a consequence, LNS and ALNS change larger parts based on different heuristics. For this thesis, I received the innoWake Award 2015. innoWake was a software modernization company based in Austin, TX and had a number of branch offices including one in Germany. They have since been acquired by Deloitte.
2013

Teaching Assistant for Algorithms and Data Structures

Graph from http://commons.wikimedia.org/wiki/File:Dinic_algorithm_Gf2.svg, public domain
As a teaching assistant for Prof. Jacobo Toran, Gunnar Völkel and Dominikus Krüger, I explained the solutions to weekly assignments to a group of 20 students whose work I also graded. In addition to that, I often gave a review of the material presented in class. It made me very happy to see the attendance rate constantly high throughout the semester and especially the positive feedback at the end of the course.
2013

Nature-Inspired Metaheuristics: Artificial Bee Colony

Bees from https://pixabay.com/en/queen-cup-honeycomb-honey-bee-337695/, CC0 Public Domain
As part of a seminar at Uni Ulm, I implemented and evaluated the Artificial Bee Colony (ABC) meta-heuristic by D. Karaboga. ABC is a nature-inspired metaheuristic that projects the foraging behavior of bees on an algorithm in order to solve optimization problems. The idea behind such approaches is that many kinds of behavior of animals, bacteria etc. in nature have adapted to their specific environment due to evolution — in a way, an optimization process has taken place.
2012

Concurrent Programming in Java seminar

Traffic from https://pixabay.com/en/traffic-highway-lights-night-road-332857/, CC0 Public Domain
Under the guidance of Christian Spann, I read up on different ways to implement concurrent programs in Java, from Threads, Runnables and Executors to thread-safe versions of data structures. Finally, I presented the different approaches and techniques in a seminar talk.

Map of the US states I have visited

flag = visited, dark gray = not visited



Map of the countries I have visited

Miscellaneous

The 5 stages of git, from Navin Narra's tweet.

from Navin Narra's tweet