AltaySec Fevzi Ege Yurtsevenler
AI Red Team — breaks and defends language models
Fevzi Ege Yurtsevenler — AI Security Researcher, Co-Founder of AltaySec
CO-FOUNDER OF ALTAYSEC · AI SECURITY RESEARCHER

Fevzi Ege Yurtsevenler

A researcher building open-source tools and community around AI security in Türkiye. As Co-Founder of AltaySec, he is building the Turkish-language LLM security literature and provides enterprise AI pentesting, LLM security consulting, and training services.

Cover of Fevzi Ege Yurtsevenler's book LLM Güvenliği: Saldırı ve Savunma
PUBLISHED BOOK · APPLE BOOKS · GOOGLE PLAY BOOKS

LLM Güvenliği: Saldırı ve Savunma

LLM Security: Attack and Defense — a practical field guide to breaking and protecting large language model systems (Turkish-language book)

Written by Fevzi Ege Yurtsevenler, this book addresses the attack surfaces and the defensive architecture of LLM-based applications within the same field framework. It offers an actionable reference for security professionals, AI/ML teams, and organizations building secure AI systems.

6 JULY 2026 · APPLE BOOKS: 134 PAGES · GOOGLE PLAY: 150 PAGES · TURKISH · E-BOOK · CC BY 4.0
  • Prompt injection, jailbreak, and data leakage
  • RAG, MCP, tool calling, and AI agent security
  • OWASP LLM Top 10, MITRE ATLAS, and NIST AI RMF
  • Layered defense, LLM firewall, PII, and AI SOC

Biography

Fevzi Ege Yurtsevenler is one of the researchers building open-source tools and community in AI security (AI Security) and large language model security (LLM Security) in Türkiye. In 2025 he co-founded AltaySec — a team focused on AI security — together with Enes Deniz, and serves as its lead security advisor.

After a background in classic cybersecurity engineering, he shifted his focus entirely to the security of AI systems from 2024 onward. He has authored a substantial part of the Turkish technical literature on prompt injection, RAG security, AI agent security, and the OWASP LLM Top 10 and MITRE ATLAS frameworks. More than 11 comprehensive Turkish research articles, first-hand field research on Turkish-specific prompt injection patterns (the AltayDuel dataset), and the first comprehensive Turkish guide to the OWASP LLM Top 10 form the backbone of this work.

His work is not limited to written content: he is the lead architect of open-source platforms such as AltayDuel — an agent-vs-agent prompt injection arena — and Bekçi — an 8-layer Turkish LLM prompt injection laboratory. These platforms feed directly into Turkish AI security dataset production. On the enterprise side, he provides LLM security consulting, AI pentesting, and red teaming services, and runs corporate training programs through the LLM Security Bootcamp.

In 2025 he taught a university-level LLM Security course within Gazi University Computer Engineering on behalf of AltaySec. He lives in Ankara.

Areas of Expertise

The sub-fields in which he actively conducts research and provides services:

OWASP LLM01
Prompt Injection

Direct and indirect injection, jailbreak, system-prompt leakage. Turkish-specific patterns.

OWASP LLM06
AI Agent Security

MCP attack surfaces, tool poisoning, A2A attacks, Meta's Rule of Two framework.

OWASP LLM08
RAG Security

Vector-DB poisoning, embedding inversion, indirect injection, secure RAG architecture.

RED TEAMING
AI Red Teaming

Pentest methodology tailored to enterprise LLM applications, agent-vs-agent evaluation.

COMPLIANCE
KVKK + EU AI Act

Compliance architecture advisory at the intersection of local legislation and European regulation.

DATA
Turkish Adversarial Data

Turkish prompt injection dataset production, the AltayDuel arena pipeline.

Academic Recognition & Achievements

Independently verifiable academic publications, open-source contributions, and credentials:

Publications — Turkish LLM Security Research Series

A comprehensive Turkish technical research series published at altaysec.com.tr/arastirmalar (April – June 2026):

#12
Machiavellian in Words, Angelic in Action: 100 AIs in One Arena

A cross-tier (haiku/sonnet/opus) behavior experiment with 100 autonomous agents. LLMs produce betrayal abundantly at the discourse level but rarely act on it — empirical evidence of the say-do gap. Open data, CC BY 4.0.

#11
AI Security in Türkiye: Leading Companies and Names (2026)

A four-layer field map of Türkiye's AI security ecosystem; sector analysis, gaps, and areas of opportunity.

#10
Turkish Prompt Injection: 5 Attack Patterns from Field Data

First-hand field data. Authority bomb, verification trap, translation exploit, role switching, system-prompt leakage. Real transcripts.

#09
AltayDuel: Designing an Agent-vs-Agent Prompt Injection Arena

Judge architecture, 5 win conditions, provider rotation, and methodology.

#08
Bekçi: Architecture of a Turkish LLM Prompt Injection Lab

An 8-layer laboratory built around a Turkish neighborhood watchman character; KVKK compliance, defensive layers.

#07
AI Security Learning Guide — From Zero to Expertise

A career path from 0 to 9+ months; setting direction as a researcher, pentester, engineer, or entrepreneur.

#06
LLM Security Roadmap — How to Enter This Field in Türkiye

A 7-stage learning path; CTF platforms, bug bounty programs, opportunities specific to Türkiye.

#05
What Is AI Agent Security? The Security Problems of Autonomous AI

MCP security, tool poisoning, A2A attacks, Meta's Rule of Two framework.

#04
What Is RAG Security? The Dark Side of Vector Databases

Data poisoning, indirect injection, embedding inversion, secure RAG architecture.

#03
OWASP LLM Top 10 2025 — Comprehensive Turkish Guide

A comprehensive Turkish reference to the OWASP LLM Top 10. 10 critical vulnerabilities, real cases, defensive strategies.

#02
What Is Prompt Injection? The Most Critical Vulnerability of LLMs

An in-depth look at OWASP LLM01:2025; direct and indirect injection, real-world scenarios.

#01
What Is LLM Security? The New Frontier of AI Security

How it differs from classic cybersecurity, model-specific threats, the Türkiye context.

Open Source Projects and Platforms

Founder and lead architect of open-source or open-access platforms:

Talks and Training

2025
Gazi University Computer Engineering — LLM Security Course

A university-level LLM Security course in Türkiye. A comprehensive program on prompt injection, the OWASP LLM Top 10, RAG security, and agent attacks.

2025–26
AltaySec Corporate Training Programs

Custom LLM security training for Türkiye's leading brands, from executive briefings to technical-team bootcamps.

2026
AltaySec LLM Security Bootcamp (intensive corporate program)

A 2–4 week intensive technical program for pentesters and AI/ML engineers.

AltaySec — The Company He Co-Founded

AltaySec, co-founded in 2025 by Fevzi Ege Yurtsevenler and Enes Deniz, is one of Türkiye's first companies focused on AI security. The company has a product portfolio built around the Guardian and AltayPrisma SaaS platforms and the Gözcü and Arena internal technologies, a B2B service layer (LLM Pentest & AI Red Teaming, Cybersecurity and Secure AI Usage training), two free academies (LLM Security Academy + AltaySec Academy), and 14+ free community platforms.

The company's positioning: "With a KVKK- and local-critical-infrastructure-compliant, Turkish-first LLM security gateway and agent red-team arena, AltaySec builds the leading testing, certification, and runtime defense layer in Türkiye's AI supply chain."

Learn more: About · Services · Products.

Links

Frequently Asked Questions

Who is Fevzi Ege Yurtsevenler?

He is one of the researchers building open source and community around AI security in Türkiye. As Co-Founder of AltaySec, he is the author of a continuously expanding Turkish-language LLM security research series and the lead architect of the AltayDuel agent arena and the Bekçi prompt-injection laboratory. He provides enterprise LLM security consulting, AI pentesting, and training services.

Who founded AltaySec?

AltaySec was co-founded in 2025 by Fevzi Ege Yurtsevenler and Enes Deniz. The Türkiye-based team focuses on AI application security.

What are his areas of expertise?

LLM security (prompt injection, jailbreak, system-prompt leakage), AI agent security (MCP, tool poisoning, A2A), RAG security (embedding inversion, indirect injection), the OWASP LLM Top 10 and MITRE ATLAS frameworks, KVKK and EU AI Act compliance, AI red teaming, and enterprise AI pentesting.

What is Fevzi Ege Yurtsevenler's verifiable AI security work?

He works on Turkish-language LLM security publications, the AltayDuel DOI record, enterprise training, and Turkish test cases merged into the OWASP GenAI Data Security Initiative. He also runs a laboratory of 23 open-source AI security tools: the hidden-prompt-injection scanner uncloak, the two-axis (attack catching + over-refusal) multilingual guardrail benchmark guardrail-arena, and skills-in-the-wild, an open audit of 3,168 real agent skills. On Hugging Face he has published 15+ open datasets and a multilingual prompt-injection detection model with F1 ≈ 0.94.

Where is his research published?

His publications include the book "LLM Güvenliği: Saldırı ve Savunma" (LLM Security: Attack and Defense), offered free on Apple Books and Google Play Books, the DOI-registered AltayDuel academic preprint, and the Turkish technical research library at altaysec.com.tr/en/research.

What is Fevzi Ege Yurtsevenler's book?

"LLM Güvenliği: Saldırı ve Savunma" (LLM Security: Attack and Defense) is a Turkish e-book published on 6 July 2026 and offered free on Apple Books and Google Play Books. The Apple Books edition is listed at 134 pages and the Google Play edition at 150 pages. It covers prompt injection, RAG, MCP, AI agent security, and layered defense with a hands-on field approach.

How can I request enterprise services or consulting?

Email: [email protected] · Web: AltaySec Services. The official AltaySec channel is preferred for AI pentesting, LLM security consulting, enterprise training, and Bootcamp programs.

What is his academic and international recognition?

DOI-registered academic preprint: "AltayDuel: A Turkish-First Arena and Open Dataset for Multi-Turn LLM Prompt-Injection Red-Teaming" (DOI: 10.5281/zenodo.20681557, CC-BY-4.0). OWASP GenAI Security Project — GenAI Data Security Initiative contributor (Turkish test cases merged into the main repository). Verified participation in the Türkiye Siber Vatan Program (Republic of Türkiye Ministry of Industry and Technology) and a BlueDot Impact "Future of AI" certificate.

Do You Have an Enterprise AI Security Need?

AltaySec provides enterprise LLM security consulting, AI pentesting, red teaming, and training services. KVKK- and EU AI Act-compliant local solutions.