Kirk Abbott
Cloud, AI, and security: research, projects, and notes.
Prompt injection in a voice pipeline: the model scores, but it never decides
I built a scam-call detector on AWS where a caller's own words become input to an LLM. That makes the caller an untrusted author of model input, which is the part most write-ups skip. Here is where the injection surface actually sits, the four things I put in front of it, and why only the last one really matters.
Packet to Prompt
One request traced end to end, from a laptop’s network card to a model’s response: the header values before and after every hop, the log record each sensor emits, what that sensor cannot see, and the ATT&CK and ATLAS techniques that abuse each step.
Scam-Call Detector
An LLM security pipeline on AWS. I wrote “prompt injection: mitigated” in its threat model, then built the thing that could prove me wrong.
About
U.S. Air Force cyber defense operator with a web and cloud development background, working on cloud security, architecture, and AI/ML.
Started in web development, moved into cyber defense, now pointing at the place where cloud architecture, security, and AI/ML overlap.
Read full about →