FIELD NOTES / BLOG

Security notes for the agent era.

Evidence-first writing on prompt-injection defense, agent security benchmarks, and gateway engineering. Numbers over narratives; methodology with every claim.

ARCHIVE

All notes

10 published
10 min

Sub-Millisecond Guardrails: Why 15 kB of Deterministic Logic Outperforms 8B-Parameter LLM Guards

We benchmarked zn-gate against Meta Llama-Guard-3 (8B), NeMo Guardrails, and Lakera Guard across 1,200+ adversarial mutations on our distributed evaluation cluster. The findings: LLM guardrails add 400-850ms of latency, cost dollars per query, and fall prey to C-comment and homoglyph evasions that fail to trigger tokenizers. Why deterministic pre-gating is mathematically necessary for agent security.

13 min

Seventeen failed runs and one flat sigmoid: how we built the supA gate

Our injection detector scored 0.498-0.509 on everything we gave it. The root cause was a training objective that never saw a label, and the fix was embarrassingly ordinary: supervised end-to-end training. The full debugging story, the recipe, the numbers, and what the new gate still cannot do.

5 min

How we rebuilt our prompt-injection dataset after it quietly lied to us

Our fused gate beat a Meta model on our benchmark, and then we found real benign text scoring above attacks inside our own classifier. A post-mortem of the v13d failure and the full rebuild behind v15: family blueprints, deterministic paraphrases, group-aware splits, and the gaps we left open on purpose.