Blake Buchert
About

Security engineer,
adversarial mindset.

I test machine learning systems the way an attacker would, then stay long enough to help fix what I find. Most of my work sits in three places: the prompt and tool boundary of agentic systems, the data and weights supply chain behind a model, and the detection layer that has to notice when either one is being abused.

Before AI security, I spent my time in ordinary application security — web, cloud, identity — and that grounding still shapes how I work. A model is a component in a system, and most incidents involving one are still failures of trust boundaries, logging, and least privilege. I write findings so an engineer can act on them the same week, and I build the test that keeps the bug from returning.

Discipline
AI & cyber security
Focus
Adversarial ML, detection
Engagements
Research, consulting, speaking
Based
United States — remote

What I do

Assessment

AI red team engagements

Two to six weeks against a live system: prompt and tool-boundary abuse, retrieval poisoning, agent privilege escalation, model and prompt extraction. You get reproducible cases, severity with reasoning, and a regression suite that runs in your CI.

Architecture

Threat modeling for ML systems

A structured review of where a model touches untrusted data, who can influence training, and what an attacker gets for compromising each component. Delivered as a diagram your team argues over, not a PDF nobody reopens.

Engineering

Detection and telemetry

Instrumenting inference paths and training pipelines so abuse is visible: extraction-shaped query patterns, anomalous tool use, unsigned artifacts reaching deploy. Rules land in the tooling your on-call already watches.

Enablement

Workshops for engineering teams

A working session that turns the research into habits — what to log, which boundaries to distrust, how to review a feature that puts a model in front of user data. Run for product, platform, and security teams together.

Track record

2026 Independent practice — AI security research and consulting Red team engagements and threat modeling for teams shipping agentic products, plus published research on tool-boundary injection.
2025 Security engineer, Corvid AI — inference platform Built the extraction-detection telemetry on the inference gateway and led the rollout of signed model artifacts across training and deploy.
2024 Application security, Halden Systems Cloud and identity security for a multi-tenant platform; ran the internal red team exercise program and the first ML-specific threat review.
2023 Published: poisoning small fine-tune sets Measured the number of corrupted examples required to install a durable backdoor in a domain-tuned model, with an audit method that catches it.
2022 Started in offensive security Web and cloud penetration testing, bug bounty work, and the CTF habit that still supplies most of my ideas.

Toolkit

Offensive Prompt and tool-boundary testing, retrieval poisoning, model extraction, Burp, custom harnesses
Defensive Detection engineering, Sigma, eBPF tracing, Sigstore and SLSA provenance, policy gates in CI
Build Python, Go, PyTorch, Terraform, Kubernetes, GitHub Actions

Read what people
say about the work.