Bounded autonomy
Security agents should act only within explicit authority, scope, and control boundaries.
AI × Security Engineering
I build and lead agentic AI systems for bounded, evidence-driven security testing—helping teams move from vulnerability discovery to verified exploitable risk.
Authorized by design
Verified by evidence
Explainable in operation
Technical thesis
Autonomous security testing needs more than capable models. It needs enforceable boundaries, defensible evidence, and operator control.
Security agents should act only within explicit authority, scope, and control boundaries.
Findings become useful when evidence distinguishes theoretical exposure from demonstrated risk.
Identity, authorization, tool use, memory, and human intervention belong in the agent threat model.
Reproducibility, audit trails, and explainable decisions turn autonomous testing into accountable practice.
Selected product work
These case studies separate my contribution from external evidence about the product, selection, or use.
Multimodal AI · Communication coaching · 2019–2023
Co-founder and CTO
An AI-powered communication-coaching platform that turns video, audio, and language signals into structured feedback. The product was designed to make repeated practice and individualized guidance available beyond a live classroom or coach.
Selections, customer quotations, and marketplace availability document product-level reception. Yi’s contribution is stated separately; none of these records is presented as a personal award or as proof of individual influence by itself.
Applied AI · Children’s nutrition · 2018–2019
Co-founder and engineering contributor
A free, mobile-first learning experience that used an AI-powered virtual pet to make healthier eating choices concrete and engaging for children. Meal photos became the input to a loop connecting food recognition, nutritional guidance, and play.
These are team, product, or program records. School, student, user, and snack-pack counts vary by source and date, so this page does not merge them or convert them into Yi’s personal impact metrics.
Recognition and reach
Awards matter most when the record also shows what was built, who used it, and how the evidence connects to my work. Every item below carries its attribution and timing.
The latest reach report is shown once. Historical reach milestones remain in the evidence record, while distinct outcome, program-scale, adoption, and distribution measures stay separate.
78,000
A program stakeholder directly thanked Yi for his contribution to LittleMoochi’s growth and reported this continuing reach milestone.
Preserved private correspondence; the measurement definition and total are not yet independently audited.
Source preserved privately75,000+
Food Helpers documented the scale of the school program in which the app supports nutrition education.
Snack packs are program activity—not app users or Yi’s personal reach.
View source77% / 63%
The letter reported that 77% of sustained users maintained or improved weekly nutrition scores, and more than 63% of recommended foods appeared in intake within two weeks.
Letter-reported results; underlying data and methodology have not been independently audited.
Source preserved privately3
Faculty from Wellesley College, St. Lawrence University, and Texas Christian University described using TalkMeUp with students.
Institutional use is separated from company-reported performance multipliers.
View sourceHearst
A Hearst executive publicly described selecting and expanding TalkMeUp for leadership communication development.
Customer use is documented; performance figures remain company-reported.
View source2
Public listings made the platform discoverable and deployable through established cloud and collaboration ecosystems.
Marketplace availability is distribution evidence, not sales or endorsement.
View sourceComplete recognition record
Product and team recognition is not presented as a personal award. The labels show whether an item occurred during, before, or after my documented role.
Yi served as co-founder and CTO during 2019–2021 and 2022–2023.
Yi co-founded the product and led core app, backend, and AI development.
Evidence standard: public organizer, institutional, customer, marketplace, or publisher records where available. The July 2026 LittleMoochi reach figure is stakeholder-reported from private correspondence and is not yet independently audited.
Public work
Public records with stable source links and precise authorship or inventor attribution.
A public analysis of the attack surface created when AI agents invoke tools and connect to sensitive systems, published by Ridge Security under the Oliver Xu byline.
One of four equal-contribution authors of published research on visual context in neural machine translation using the How2 dataset.
Equal-contribution co-author of a How2/ICML workshop paper on visually grounded correction of automatic speech-recognition errors.
Co-authored multimodal research on AI-assisted feedback for communication coaching.
A public proof of concept and implementation note combining workflow orchestration, document parsing, web extraction, and LLM-assisted job-description analysis.
A recorded Silicon Valley Entrepreneurship Forum talk on AI evolution and the role of foundation models in progress toward more general systems.
Inventive record
Named inventor on patent families for AI systems that analyze multimodal communication and generate structured feedback.
About
Formal name: Yi Xu · Professionally known as Oliver Xu
I’m an AI and software engineering leader with more than two decades of experience building products and leading teams across cybersecurity, AI infrastructure, communication intelligence, and enterprise software.
My current focus is trustworthy agentic AI for autonomous penetration testing and continuous security validation. Earlier work spans large-scale infrastructure optimization, machine-learning retrieval, multimodal analysis, and AI-powered communication coaching.
Master of Information Systems Management
Master’s and Bachelor’s in Computer Science
Career throughline
Senior Director of Engineering
Agentic AI security and autonomous security validation
Core System Engineering Manager
Large-scale infrastructure planning and optimization
Co-founder and CTO
Multimodal AI communication assessment and coaching
Senior Director
Machine-learning products and backend engineering
Co-founder
Applied AI for children’s nutrition education
Senior Manager, AI Solutions
Enterprise machine-learning solutions and team building
Engineering manager and software engineer
Enterprise discovery software and globally distributed engineering
Connect