About Me
Behind the layers
I'm Ionuț Cernica, an application security engineer specializing in AI and LLM security research. My work focuses on emerging attack surfaces in large language models, agentic systems, and enterprise AI pipelines.
Before focusing on AI security, I spent over a decade in offensive security as a vulnerability researcher, penetration tester, and CTF competitor. My current research bridges traditional application security and machine learning systems, exploring how structural and logic-layer weaknesses in AI pipelines introduce new classes of enterprise risk.
That's what this blog is about: taking AI systems apart to understand them, one layer at a time. This is my personal blog, and everything here reflects my own views and research.
CTF highlights
Three-time DEF CON CTF finalist (2018, 2021, 2022) with PwnThyBytes, Codegate CTF finalist (2014, 2017, 2019), and 3rd place at the Trend Micro Raimund Genes Cup final in Tokyo (2018). Plus 15+ first-place finishes in application security CTFs and a 2nd place at AppSec Village CTF² at DEF CON (2023).
Research
- Paper Structural Desynchronization in Large Language Model Systems: Probabilistic Boundary Inference as a Security Failure Class · Zenodo, DOI 10.5281/zenodo.19625238
- Code github.com/cernica/structural-desynchronization
- In prepFollow-up papers extending the structural desynchronization research
- DisclosuresVulnerability reports submitted to Google AI VRP, Microsoft MSRC, OpenAI, xAI, and Anthropic; several disclosures still in progress
Conference talks
- 2026BSides Bucharest · Silent Leaks: Harvesting Secrets from Shared Linux Environments
- 2025DEF CON 33 · Silent Leaks: Harvesting Secrets from Shared Linux Environments
- 2025UiPath DevCon India · Build AI Agents with Confidence: How to Avoid Security Pitfalls in LLM-Based Agents
- 2025UiPath Meetup · Exploiting AI Agents: Common Pitfalls in LLM-Powered Applications
- 2022DEF CON 30 · Deanonymization of TOR HTTP Hidden Services
- 2021DEF CON 29 · Hack the Hackers: Leaking Data Over SSL/TLS
- 2014+DefCamp, RSTCon · Multiple talks on TOR deanonymization, SSL/TLS exploitation, bitsquatting, WAF bypass, and WordPress security
Responsible disclosure
Recognized through responsible disclosure programs by Google (Hall of Fame), Facebook WhiteHat, Microsoft, PayPal (50+ vulnerabilities), eBay, AT&T, VMware, IBM, Yahoo, Symantec, BlackBerry, Deutsche Telekom, Barracuda, Xilinx, and others.
Publications
- 2021"Detecting Indicators of Compromise in Web Applications Using Access Logs", IEEE BlackSeaCom
- 2020"Computer Vision Based Framework for Detecting Phishing Webpages", IEEE RoEduNet
- 2019"Security Evaluation of WordPress Backup Plugins", IEEE CSCS
- 2018"WordPress Honeypot Module", IEEE EUC
You can reach me at [email protected].