Co-Founder & Head of AI/ML · Vezran

Applied AI/ML, from detection to proof.

I build production ML and agentic security systems that don't stop at spotting the threat — they close it, with a human in command and evidence you can hand a regulator. Twelve years shipping real systems; now building the SOC that acts, not just alerts.

Currently: building Zyberpol — an agentic SOC that reasons, acts, and proves.
Imran Ahamed
12+
years shipping
production ML
44+
merged pull requests
to core OSS libraries
1
agentic SOC platform
in production
3
companies —
2 senior roles, 1 founded
Building

The part everyone skips: closing the threat, and proving it.

Most AI security stops at "we found something." At Vezran I lead the AI/ML behind Zyberpol — an agentic security-operations layer that takes an incident all the way to resolved, with a human approving the consequential moves and a tamper-proof record at the end.

ZYBERPOL · AGENTIC SOC

Detection got cheap. Trusted closure didn't.

Zyberpol sits on top of the security tools a team already runs — identity, endpoint, cloud, SIEM — correlates the noise into a handful of real incidents, recommends the safest containment, routes consequential actions through a human, then verifies the fix and exports proof an auditor accepts. The model is rented and swappable; the control layer and its governance are the moat.

01
Detect
Correlate alert noise into a few high-priority incidents.
02
Decide
Auto-gather evidence; recommend the safest containment.
03
Approve
Route consequential actions through a human in command.
04
Act & verify
Execute, then confirm the fix actually worked.
05
Prove
Export a tamper-proof record for audits and insurers.

Selected work

Systems shipped, and risks found.

From agentic security platforms to production ML at enterprise scale, to coordinated vulnerability disclosures in the tools everyone builds on.

Vezran · in production

Zyberpol — agentic security operations

An agentic SOC that investigates across every console and executes human-approved fixes from one screen — moving teams from monitoring to mitigation. Identity-first, human-approved, proof-native.

agentic AImulti-agentgovernanceSOC
Security research

Adversarial AI & disclosure

Coordinated disclosures in HuggingFace Transformers, and benchmarks probing prompt-injection robustness with DSPy and AgentDojo.

red-teamingPyRITevals
Starbucks · Sr. Data Scientist

Contact-center NLP at scale

Production natural-language systems for a global contact-center operation — routing, understanding, and surfacing signal from millions of customer interactions.

NLPproduction MLscale
FedEx · Sr. Data Scientist

Package-risk modeling

Risk models across a logistics network at national scale — predicting and flagging shipment risk to protect operations and cost.

risk modelinglogisticsMLOps


Writing & notes

Field notes on applied AI.

Long-form on the problems that actually bite in production — and short notes from the bench.

LATEST · JUL 14, 2026 · fraud detection / evals

My fraud detector scored 100% in every language. It wasn't reading any of them.

Defanging the dataset handed the model a shortcut that made it look multilingual. Strip the placeholder and non-Latin scripts collapse — Chinese 1.00 → 0.09, Arabic 0.98 → 0.04. The failure wasn't in the model. It was in the measurement.

Read the essay →
JUL 13, 2026 · LLM SECURITY

Upgrading your AI model can silently break its security

A more capable model started following attackers' orders. Across eight models, nothing — size, vendor, or capability — predicted which would break.

Read →
JUL 6, 2026 · FRAUD / BENCHMARKS

I built a benchmark for AI-written fraud — and the first result was too good to be true

LureBench. Control for the dataset confound and telling AI-written fraud from human is close to a coin flip. The defensive problem is still open.

Read →
JUL 2, 2026 · LLM SECURITY / EVALS

When does prompt optimization stop helping and start hurting security?

Three regimes by base-model strength, with a practitioner decision rule — DSPy optimizers vs AgentDojo prompt-injection attacks.

Read →
JUN 25, 2026 · DIFFERENTIAL PRIVACY

The DP-LoRA silent corruption: 5 months of broken fine-tuning, hidden in plain sight

A device-placement ordering quirk between opacus, PEFT, and HuggingFace zeroed gradients while noise kept accumulating. What to check in your own setup.

Read →
JUN 24, 2026 · LLM SECURITY

Does DSPy prompt optimization weaken adversarial robustness?

Optimizing prompts for accuracy tightens them to the training distribution — and can cost ~20 points of security on the harder attacks.

Read →
Contact

Building something at the edge of
AI and security?

I'm always up for a sharp conversation — agentic systems, LLM security, or turning a security team from monitoring into mitigation.