AI Security Engineer and researcher focused on securing the boundary between model decisions and real-world execution.

I'm an AI Security Engineer at Prologis and an Advisor supporting Anthropic through HireArt. My work focuses on the security challenges that emerge when AI systems move beyond generating text and begin accessing data, using tools, and taking real-world actions.

At Prologis, I lead enterprise AI security, developing controls, guardrails, and secure architecture patterns for AI-enabled systems. My work spans threat modeling, risk assessments, AI red teaming, and the secure deployment of agentic systems, with a focus on prompt injection, data exposure, excessive permissions, and insecure tool execution.

Alongside enterprise defense, I research and break AI infrastructure and agent systems. I've disclosed 20 CVEs across major AI frameworks, including approval bypasses, command injection, sandbox escapes, and remote code execution.

My research has been accepted at the ICML 2026 AIWILD workshop. My current work examines whether an approved agent action remains faithfully bound to what the system ultimately executes.

Outside of work I box. I founded USF's boxing club, the largest combat sports club in school history: 1,200 members, back-to-back Outstanding Sports Club of the Year.

I'm also pursuing an M.S. in Computer Science at Georgia Tech, specializing in artificial intelligence and machine learning. My papers, vulnerability research, and technical writing are available throughout this site.

For research collaboration, email me at ygamage3@gatech.edu.

Yeran Gamage
Yeran Gamage
AI Security Engineer & Researcher