About
I lead the COMPASS research group at the ELLIS Institute Tübingen, the Max Planck Institute for Intelligent Systems, and the Tübingen AI Center. I am an ELLIS member, a faculty member of IMPRS-IS, and an associated faculty member of the Max Planck ETH Center for Learning Systems.
Previously, I was an AI security researcher at Microsoft (Security Response Center, Microsoft Research Cambridge). I completed my PhD at CISPA Helmholtz Center for Information Security, advised by Prof. Dr. Mario Fritz.
-
Our 2023 work was the first to identify, coin, and taxonomize indirect prompt injection attacks in LLM-integrated applications — now referenced by NIST, MITRE, OWASP, and Microsoft.
-
Our work on LLM sampling heuristics received a Best Paper Award at ACL 2025.
News
Research
I work on the broad intersection of AI, AGI, and multi-agent systems with security, safety, and sociopolitical aspects:
- Understanding, probing, and evaluating the failure modes of AI models — their biases, emergent risks, and misuse scenarios.
- Designing mitigations — system defenses, white-box control methods, reasoning enhancements, and novel architectures to counter such risks.
- Leveraging AI agents for good — scientific discovery and advancing our society.