u9up:~$ whoami

We break it, we fix it, we write about it. 

U9UP /9up/ verb

An independent AI security community from Malaysia. We publishes hands-on research, raising awareness, and sharing what we learn.

Research

Latest from the lab

Deep dives into AI security blind spots, written by people who actually break them.

First page of How AI Changed the Trust Model
Offensive

How AI Changed the Trust Model

git clone && get owned: one poisoned supplier reaches everyone downstream. Pickle-based model formats run code on load, and coding agents moved the trust boundary from “you wrote it” to “can the agent tell intent from injection?”

2026-07 Read slides
First page of The Next `npm install`: AI Tooling’s Hidden Supply Chain Risk
Offensive

The Next `npm install`: AI Tooling’s Hidden Supply Chain Risk

Models, datasets, plugins — the AI stack has a supply chain, but none of the controls. Walking a poisoned MCP server from marketplace upload to backdoor on your host.

2026-07 Read slides
What We Do

Two sides of the same coin

AI security isn't just breaking things or defending them, it's both. We research across the full spectrum.

Offensive Security

Finding the cracks before the bad actors do. We research attack vectors, test guardrails, and publish what we find so the community can learn.

Prompt injectionJailbreaksAdversarial MLModel extractionSupply Chain attacksAgent-In-The-Middle

Defensive Security

Building resilience into AI systems. We study detection, guardrail architectures, and monitoring strategies that actually work in production.

Guardrail designInput validationAI observabilityThreat detectionModel hardeningCanary Token
People

The crew behind it

A handful of curious people who'd rather break things than read the manual.

Lancer

Lancer

AI Tamer
Gregory

Gregory

Building and Breaking AI
Yam

Yam

Co-founder of u9
Trailbl4z3r

Trailbl4z3r

Learning AI
Tommy

Tommy

Boss @ 4rthur.ai & BoB
Get Involved
join.sh — u9up
u9up:~$ ./join --community

Come hang with us.

Whether you're deep into adversarial ML or just getting curious about AI security — pull up a chair. No gatekeeping.

Research & write-ups
Community discussions
No gatekeeping, just good vibes