A 9th grader stopped AI agents from leaking secrets, accepted at an IEEE conference
AI agents that read emails, documents and websites can be tricked by hidden instructions into leaking private data, an attack called indirect prompt injection. Rishik built a lightweight defense that separates trusted instructions from untrusted content, detects instruction-like attacks, gates sensitive outputs and tracks risk across a conversation. Across 150 test cases and seven attack categories, active detection cut observed leakage of protected secrets to zero, while passive measures like warnings alone did nothing. He also documented a flaw in his own evaluation openly rather than hiding it, exactly the rigor reviewers look for.
A 9th grader at Wake Early College of Information and Biotechnologies in North Carolina with Python and cybersecurity certifications and a third-degree black belt.
First author of a defense framework against prompt injection attacks on AI agents, accepted at an IEEE conference as a 9th grader.