Skip to content
View Raoof128's full-sized avatar
👋
Hello
👋
Hello

Highlights

  • Pro

Block or report Raoof128

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Raoof128/README.md
Raouf Abedini — AI Security Researcher

Typing SVG

LinkedIn Portfolio ORCID Email Profile Views


Terminal Animation


> ./about_me --verbose

╔══════════════════════════════════════════════════════════════════════════╗
║  🔬  AI Security Researcher — Vulnerability Discovery & Disclosure      ║
║  📄  Authored "The Invisible Window" — 100% Screen Capture Evasion      ║
║  🤖  AI Model Evaluation for Anthropic (Claude Code Human Preference)   ║
║  🧬  LLM Safety · Capability Uplift Measurement · Dual-Use Risk        ║
║  💻  Systems Programming — C/C++ Engines · Python Tooling · Swift       ║
║  🎓  B.Cyber Security — Macquarie University (Graduating Nov 2026)      ║
╚══════════════════════════════════════════════════════════════════════════╝


> cat /research/the-invisible-window.md

📄 The Invisible Window 2026

Exploiting OS-Level Display Affinity to Bypass WebRTC Proctoring Systems

C · Swift · Python · Win32 API · ScreenCaptureKit · WebRTC

  • 100% screen capture evasion across Windows 10/11 and macOS 14–26 via W3C Screen Capture / OS compositing trust boundary violation — zero artefacts over 10,000+ frames
  • Novel finding: Apple's macOS 15 ScreenCaptureKit mitigation remains ineffective on macOS 26 — contradicting vendor assumptions through pixel-level forensic verification
  • Coordinated disclosure to 3 proctoring vendors (ProctorU, Proctorio, Respondus) + 2 OS vendors (Microsoft, Apple) following OWASP/FIRST/CISA frameworks
  • Documented measurable AI capability uplift and characterised intent-vs-artefact safety boundaries — directly relevant to ASL threshold calibration

Read Paper



> skills --list-all


[ LANGUAGES ]

Python C C++ TypeScript JavaScript Swift Kotlin Bash Go   SQL

[ AI / ML ]

LLM Evaluation NLP AI Safety Generative AI

[ SYSTEMS & TOOLS ]

Linux Docker CMake GitHub Actions Cloudflare FastAPI   Google Test libpcap

[ SECURITY TOOLING ]

Kali Linux   Burp Suite Wireshark Nmap

[ FRAMEWORKS ]

OWASP MITRE ATT&CK NIST W3C Screen Capture



> ls -la /projects/

⚙️ Systems & Security

NanoMatchC++20 · CMake · Google Test 2026 High-performance matching engine processing 1M+ orders/sec with sub-microsecond latency — red-black tree price levels, custom memory pool allocator, p50/p99 benchmarks

SentinelFlowC++17 · libpcap · CMake · Google Test · Linux 2026 Real-time packet processing engine parsing 500K+ packets/sec — protocol dissection (Ethernet/IPv4/TCP/UDP/ICMP/DNS), signature-based detection, stateful analysis

🤖 Full-Stack & AI

Nexus ArchivePython/Litestar · React · PostgreSQL · Docker · Terraform 2025 Full-stack data platform with AI recommendation engine, event-driven API, rate limiting, and automated security scanning — end-to-end ownership from schema to deployment

Mehr GuardKotlin Multiplatform · Local ML · Android & iOS 2024 Cross-platform offline threat detection with local ML classification — submitted to KotlinConf global developer conference

70+ additional public projects covering vulnerability research, systems programming, AI/ML tooling, and cloud infrastructure



> cat /etc/education

🎓 Degree 🏛 Institution 📅 Period
Bachelor of Cyber Security Macquarie University May 2024 – Nov 2026
Diploma of Information Technology Macquarie University Jul 2023 – May 2024

Coursework: Digital Forensics · Network Security · Systems Security · Cloud Computing · NLP & Machine Learning · Privacy-Preserving Data Analysis



> cat /community/ai-safety.md

🤖 Anthropic — Completed AI model evaluation (Claude Code Human Preference) — benchmarked LLM code outputs for quality, security, correctness, and reliability

🔬 Research Directions — Proposed systematic uplift measurement across vulnerability classes, intent-vs-artefact safety boundary generalisation, and defensive application development to Anthropic's Fellows team

🎓 Mentoring — Mentored peers in cybersecurity, C/C++ programming, and systems-level problem-solving at Macquarie University



> cat stats.json



   

GitHub Streak



> ./entity --walk

Alien mascot

> htop --graph

Activity Graph



> ping --connect

> Establishing secure channel...
> Protocol   : TLS 1.3  |  Auth: Mutual
> Encryption : AES-256-GCM
> Target     : Mohammad Raouf Abedini
> Status     : [●] ONLINE — ready to collaborate

LinkedIn Portfolio Email ORCID


Footer

Pinned Loading

  1. invisible-window-research invisible-window-research Public

    The Invisible Window: Exploiting OS-Level Display Affinity to Bypass WebRTC Proctoring Systems — Research artifacts, PoC, and IEEE manuscript

    Python 1

  2. Project-Simurgh Project-Simurgh Public

    Zero-trust behavioral AI exam proctor — a working mitigation against the macOS 26 invisible-window exploit. Built on Claude Sonnet 4.5.

    JavaScript

  3. SentinelFlow SentinelFlow Public

    Real-time network intrusion detection system built in C++17 — packet capture, protocol parsing, signature-based threat detection, and structured alerting

    C++

  4. Syllabus-Sync Syllabus-Sync Public

    AI-native Campus OS for Australian universities — LLM OCR pipeline, syllabus-as-code, calendar, WebAuthn passkeys, 503 tests. Built with Next.js 16, Supabase, and TypeScript.

    TypeScript

  5. GitSwitch GitSwitch Public

    A cross-platform desktop Git client inspired by GitHub Desktop, focused on clean UX, intuitive workflows, and seamless repository management for developers.

    TypeScript

  6. Nexus_Archive Nexus_Archive Public

    Nexus Archive is a cyberpunk-inspired personal catalog for anime, movies, and books. It lets you build a complete media history in one dashboard, with status tracking, ratings, reviews, recommendat…

    JavaScript