AI Security · LLM Red Team · Safety Evaluation


MARC-DONALD

I break AI systems on purpose so safer ones get built. I look for the gap between what a model claims it will never do and what it actually does when someone pushes it the right way. Then I measure the gap, write it up, and help close it.

● 3D CORE: BOOTING … · drag anywhere to spin it. it is under attack right now
0%
Peak encoding bypass I found on Nemotron Ultra 550B
0
Model configurations I benchmarked
0
LLM providers I probed
0
Network flows my IDS learned from
// 01 · Who I am

Red team by instinct.
Blue team by discipline.

I am Tonga Marc-Donald, an AI Red Team Engineer and LLM Security Researcher finishing my B.Sc. in Cybersecurity at ICT University in Yaoundé. Before the research, I spent seven years doing freelance security engineering for real clients, so everything I ship carries that habit: build it once, build it safe.

My dissertation turned into PromptShield, an automated LLM red teaming framework. I pointed it at 67 model configurations from 11 providers, and it surfaced a vulnerability pattern I named the encoding paradox. Bigger models get better at refusing direct attacks, yet they decode and follow obfuscated malicious instructions more faithfully, not less.

On the defensive side I built AI-IDS, a real time intrusion detection system trained on more than 2.8 million network flows. It classifies 14 attack classes with near perfect F1 and runs as a deployable pipeline with live packet inference, not a demo notebook.

I speak English and French, and I am open to remote roles anywhere in the world in AI red teaming, LLM security research, and blue team defense engineering.

// identity.lock

roleAI Red Team Engineer
researchLLM Security and Evaluation
degreeB.Sc. Cybersecurity, ICTU 2026
languagesEnglish and French
locationYaoundé, Cameroon
remoteWorldwide
open source@T-MARC-DONALD
status● Open to work
// 02 · Identity scan

This face is made of data

A photo of me, rebuilt from thousands of sampled points. They assemble on arrival, they drift when you hover, and every few seconds something tries to corrupt them. They always recover.

Subject · Tonga Marc-Donald
Sampling …
Scanning …
Integrity 100%

Interactive: move your pointer over the portrait to scatter the points. On a touch screen, tap and drag.

// 03 · Signature research

The Encoding Paradox

The main finding from my dissertation. It changes how we should think about model scale and safety.

Encoding attacks got more successful as models got bigger. They worked on Llama 3.3 70B about 40 percent of the time, and on Nemotron Ultra 550B about 66.7 percent. A stronger model reads Base64, ROT13, reversed text, and leetspeak more accurately, and then it follows the instruction it just decoded.

So the very capability that makes large models impressive also makes them easier to talk into doing what their guardrails forbid. Resistance and weakness grow together.
55 adversarial payloads 8 injection categories 67 model configurations 11 providers 41 page dissertation
Llama 3.3 · 70B40.0%
Nemotron Ultra · 550B66.7%

Encoding attack success rate, measured across 55 payloads and 67 model configurations

// 04 · The work

Tools that break and build

The four projects that define me. Every one is open source and reproducible, and they all live in the repo wall below.

Research · Red TeamOpen repo ↗

PromptShield

My dissertation, shipped as a tool. An automated LLM red teaming suite that fires 55 adversarial payloads across 8 injection categories at any model, and scores what comes back.

  • Tested 67 model configurations across 11 providers, which is how the encoding paradox showed up
  • A 4 strategy classifier labels responses automatically so results stay consistent
  • Comes with a live browser dashboard with 5 analysis views and a 41 page dissertation behind it
PythonAsync HTTPLLM as a JudgeOWASP LLM Top 10MITRE ATLAS
01
Tooling · Red TeamOpen repo ↗

redforge

A red teaming toolkit that runs 10 attack families against any model endpoint. It speaks to every provider through one adapter layer, and new attacks register themselves. About 1,800 lines across 31 modules, held together by four pytest suites.

PythonhttpxpytestPlugin architecture
02
Defense · ML SecurityOpen repo ↗

AI-IDS

A real time intrusion detection system trained on 2.8 million labeled flows from CIC-IDS2017. It tells 14 attack classes apart with near perfect F1, and it is built to be deployed, not admired.

  • A two stage Random Forest pipeline with 180 percent expanded attack class coverage
  • A custom flow assembler compatible with CICFlowMeter, written in Python and Scapy, processes live traffic
  • A Flask dashboard that alerts through Email, Telegram, and WhatsApp, plus a built in attack simulator for testing
PythonScapyscikit-learnFlaskSQLite
03
Open Source ToolsOpen profile ↗

Automatic-Porter · Vulnera · NMS

Three tools, one idea: you cannot defend what you cannot see. Automatic-Porter turns port management into a control layer, Vulnera scans for weaknesses, and NMS watches the network for anomalies. All three feed the same workflow of detection and alerting.

PythonJavaScriptScanningMonitoring
04
// 05 · Open source wall

Every public repository

Pulled live from the GitHub API. Click any card and it takes you straight to the code.

Loading repositories … View on GitHub ↗
Talking to the GitHub API …

If the wall above stays empty, the API could not be reached. All repositories are still available at github.com/T-MARC-DONALD.

// 06 · What I bring

RED · BLUE · DEV

Three columns, one engineer. I attack, I defend, and I ship the tooling both sides need.

◤ RED · Offensive AI Security

How I attack
LLM Red TeamingPrompt Injection Jailbreak AttacksObfuscation and Encoding Prompt ExtractionMulti-Turn Escalation Adversarial MLPayload Engineering OWASP LLM Top 10MITRE ATLAS FuzzingAI Penetration Testing

◢ BLUE · Defense and Safety

How I defend
LLM Defense and GuardrailsAI Safety Evaluation Red Team EvaluationRubric Scoring Preference RankingLLM as a Judge Intrusion DetectionNetwork Monitoring Vulnerability ScanningThreat Modeling with STRIDE Data Poisoning DefenseAI Incident Response

◆ DEV · Engineering and Cloud

How I build
PythonJavaScriptTypeScript SQLPyTorchscikit-learn Hugging Face TransformersFlaskDjango ReactNode.jsREST APIs DockerLinuxGit SplunkAWSAzureGCP
// 07 · The path so far

Experience timeline

2025 to 2026 · Remote

AI Red Team Engineer and LLM Evaluation Researcher

PromptShield · Independent research and my B.Sc. dissertation
  • Found the encoding paradox: encoding attacks landed 66.7 percent of the time on Nemotron Ultra 550B against 40 percent on Llama 3.3 70B.
  • Wrote 55 adversarial prompts across 8 injection categories and ran them against 67 configurations from 11 providers.
2026 · Remote

Red Team Tooling Engineer

redforge · Independent open source project
  • Built a toolkit that runs 10 attack families against any model endpoint you point it at.
  • Kept it honest with about 1,800 lines across 31 modules and four pytest suites, on top of a provider agnostic async adapter with self registering attacks.
2024 to 2025 · Remote

Machine Learning Security Engineer

AI-IDS · Independent research
  • Trained a detector that tells 14 network attack classes apart with near perfect F1 on 2.8 million labeled flows.
  • Built a two stage Random Forest on CIC-IDS2017 and a live flow assembler in Python and Scapy, expanding attack class coverage by 180 percent.
2024 to 2025 · Remote

Cybersecurity Tool Developer

Automatic-Porter · Vulnera · NMS · Open source
  • Shipped three open source tools covering port visibility, vulnerability scanning, and network anomaly monitoring.
  • Maintain 15 public repositories, and earned the GitHub Pull Shark and YOLO achievements along the way.
2018 to today · Remote

Freelance AI Consultant and Full Stack Developer

Self employed · International clients
  • Delivered more than 10 production web applications across seven years, with zero reported security incidents.
  • Input validation, CSRF protection, secure authentication, and API hardening went into every single build.
// 08 · Proof of study

Certifications and education

Verified programs from Coursera, Microsoft, Meta, and ISTIA. Click a certificate to open its credential page.

Coursera

AI Security: Security in the Age of Artificial Intelligence

Specialization · 13 courses · August 2026
13 course specializationView credential ↗
Microsoft · Coursera

Enterprise AI Governance, Ethics and Security

Professional Certificate · 5 courses · September 2026
Professional certificateView credential ↗
Packt

AI Security Fundamentals: LLM Threats and OWASP

2026
Certification
Meta · Coursera

Advanced MySQL Topics

March 2025
Course certificate
LearnQuest and Simmons University

Linux Fundamentals Specialization

April 2025
Specialization
ISTIA Cameroon

Web Development Certification

Honor roll, top of class three years running · 2015 to 2018
Diploma

B.Sc. in Cybersecurity

ICT University · Yaoundé, Cameroon · Expected 2026

Coursework covered machine learning, network security, cryptography and cryptanalysis, information systems security, Linux administration, and digital forensics. The dissertation became PromptShield.

Web Development Certification

ISTIA Cameroon · 2015 to 2018

On the honor roll as top of the class for three years in a row. This is where the build habit started.

// 09 · Talk to me

Hire the person who breaks AI
before the attackers do.

I am open to remote roles in AI red teaming, LLM security research, and blue team defense engineering, anywhere in the world. The fastest way in is a plain email.

Yaoundé, Cameroon · Remote, worldwide · ● Open to work