Fevzi Ege Yurtsevenler

Fevzi Ege Yurtsevenler is an AI security researcher. He co-founded AltaySec with Enes Deniz in 2025. He publishes Turkish-language research and open-source tools on LLM, RAG, and AI agent security, and provides LLM security consulting, penetration testing, and training to organizations.

Role
Co-founder, AI security researcher
Location
Ankara, Türkiye

LLM Güvenliği: Saldırı ve Savunma

LLM Security: Attack and Defense. A practical field guide to breaking and protecting large language model systems, written in Turkish and offered free on Apple Books and Google Play Books.

Cover of Fevzi Ege Yurtsevenler's book LLM Güvenliği: Saldırı ve Savunma

About the book

The book addresses the attack surfaces and the defensive architecture of LLM-based applications within one field framework. It is a practical reference for security professionals, AI/ML teams, and organizations building secure AI systems.

  • Prompt injection, jailbreaks, and data leakage
  • RAG, MCP, tool calling, and AI agent security
  • OWASP LLM Top 10, MITRE ATLAS, and NIST AI RMF
  • Layered defense, LLM firewalls, personal data, and AI SOC
Published
6 July 2026
Available on
Apple Books and Google Play Books
Pages
Apple Books edition 134 pages, Google Play edition 150 pages
Format and language
Turkish e-book, free
License
CC BY 4.0

Biography

Fevzi Ege Yurtsevenler is a researcher working on AI security and large language model (LLM) security. After a background in classic cybersecurity engineering, he moved his focus to the security of AI systems in 2024. He serves as lead security advisor at AltaySec, which he co-founded with Enes Deniz in 2025.

He publishes Turkish-language technical work on prompt injection, RAG security, AI agent security, the OWASP LLM Top 10, and MITRE ATLAS. His field research on Turkish-specific prompt injection patterns (the AltayDuel dataset) and his Turkish guide to the OWASP LLM Top 10 are part of this work.

He built AltayDuel, an agent-vs-agent prompt injection arena, and Bekçi, an eight-layer Turkish LLM prompt injection laboratory. Both platforms feed Turkish AI security dataset production. For organizations, he provides LLM security consulting, AI penetration testing, and red teaming, and runs corporate training through the LLM Security Bootcamp.

In 2025 he delivered in-person LLM security training at the Department of Computer Engineering, Gazi University, on behalf of AltaySec. He lives in Ankara.

AltaySec is an AI security company co-founded in 2025 by Fevzi Ege Yurtsevenler and Enes Deniz. Its products are Guardian and Guardian Edge; Gözcü and Arena are its internal research infrastructure. Its services cover LLM penetration testing and AI red teaming, together with cybersecurity and secure AI usage training. The company also runs two free learning platforms, LLM Security Academy and AltaySec Academy.

Areas of expertise

The sub-fields in which he conducts research and provides services.

Prompt injection

Direct and indirect injection, jailbreaks, and system-prompt leakage. Turkish-specific attack patterns.

OWASP LLM01:2025

AI agent security

MCP attack surfaces, tool poisoning, A2A attacks, and Meta's Rule of Two framework.

OWASP LLM06:2025

RAG security

Vector-database poisoning, embedding inversion, indirect injection, and secure RAG architecture.

OWASP LLM08:2025

AI red teaming

Penetration testing methodology tailored to enterprise LLM applications, and agent-vs-agent evaluation.

KVKK and the EU AI Act

Compliance architecture advisory where Turkish data protection law and European regulation meet.

Turkish adversarial data

Turkish prompt injection dataset production and the AltayDuel arena pipeline.

Academic publications and contributions

Publications, contributions, and credentials that can be verified independently.

Academic preprint
AltayDuel: A Turkish-First Arena and Open Dataset for Multi-Turn LLM Prompt-Injection Red-Teaming. A Turkish-first arena and open dataset for multi-turn LLM prompt-injection red teaming. Zenodo, DOI 10.5281/zenodo.20681557, CC BY 4.0, 2026. Related open datasets are published on Hugging Face.
Open-source contribution
OWASP GenAI Security Project, GenAI Data Security Initiative. Turkish prompt-injection and data-leakage test cases were accepted into the project's main dataset and merged into the main repository (PR #8, 2026).
Program
Türkiye Siber Vatan Program, participant in two terms. Participation certificate verified by the Republic of Türkiye Ministry of Industry and Technology.
Certificate
BlueDot Impact, Future of AI completion certificate (2026).
Bug bounty
Researcher accepted to the OpenAI bug bounty program.
ORCID
0009-0008-6518-8944

Turkish LLM security research series

A Turkish-language technical series published on the AltaySec research pages between April and June 2026. The articles are in Turkish.

Open-source projects and platforms

Open-source tools and open-access platforms he has built. The tools are Turkish-first and mapped to the OWASP LLM Top 10 and MITRE ATLAS.

Agent skill security tools

ToolWhat it does
uncloakA hidden prompt injection scanner. Try it in the browser.
guardrail-arenaAn open benchmark that measures guardrails on two axes, attack catching and over-refusal, in English and Turkish.
turkish-over-refusal-setA Turkish over-refusal benchmark with a 120-pair probe.
guard-blindspots-trMeasures the Turkish robustness of popular guard models.
turkish-casefold-evasionShows how naive filters are bypassed with the Turkish İ and ı, and how to fix it.
lethal-trifecta-lintA linter for the "lethal trifecta" risk in agent tools.
turkish-pii-redactorChecksum-validated masking of Turkish personal data, with a KVKK browser demo.
hf-dataset-scanScans datasets for hidden, poisoned injection content.
skills-in-the-wildAn open audit of 3,168 real agent skills.
ai-honeypotA trap system that catches attacks, with a monitoring dashboard.

Platforms and libraries

  • Hugging Face: AI and LLM security, Turkish-first

    Turkish injection and jailbreak, invisible Unicode, MCP tool poisoning, and KVKK personal data datasets; a multilingual prompt injection detection model and the guardrail-arena benchmark. The datasets can be used directly with load_dataset.

  • AltayDuel

    An agent-vs-agent prompt injection arena. A live platform that produces a Turkish prompt injection dataset and attack transcripts.

  • Bekçi

    An eight-layer Turkish LLM prompt injection training laboratory built around a Turkish neighborhood watchman character.

  • LLM Security Academy

    A Turkish learning platform focused on AI security: 5 learning paths, 14 modules, and 35 labs, with hands-on practice on GPT, Claude, Llama, Gemini, Mistral, and DeepSeek.

  • AltaySec Academy

    A free, Turkish-language cyber security academy from beginner to expert level: 12 learning paths, 312 lessons, 101 labs, and a verifiable certificate.

  • tr-pii-detect

    A Python library for algorithm-validated detection and masking of Türkiye-specific personal data types such as TCKN, IBAN, VKN, license plates, cards, and phone numbers.

  • GitHub

    Repositories for the Turkish LLM security research series and open-source tools.

Talks and training

2025
Department of Computer Engineering, Gazi University. In-person LLM security training on prompt injection, the OWASP LLM Top 10, RAG security, and agent attacks.
2025–2026
AltaySec corporate training programs. Custom LLM security training, from executive briefings to technical-team bootcamps.
2026
AltaySec LLM Security Bootcamp. An intensive technical program for penetration testers and AI/ML engineers.

Frequently asked questions

Who is Fevzi Ege Yurtsevenler?

Fevzi Ege Yurtsevenler is an AI security researcher and a co-founder of AltaySec. He writes the Turkish-language LLM security research series and built the AltayDuel agent arena and the Bekçi prompt-injection laboratory. Based in Ankara, he provides enterprise LLM security consulting, AI penetration testing, and training.

Who founded AltaySec?

AltaySec was co-founded in 2025 by Fevzi Ege Yurtsevenler and Enes Deniz. The Türkiye-based team works on LLM security consulting, AI penetration testing, enterprise training, the Guardian and Guardian Edge products, and the Gözcü and Arena research infrastructure.

What are Fevzi Ege Yurtsevenler's areas of expertise?

LLM security (prompt injection, jailbreaks, system-prompt leakage), AI agent security (MCP, tool poisoning, A2A attacks), RAG security (embedding inversion, indirect injection, vector-database poisoning), the OWASP LLM Top 10 and MITRE ATLAS frameworks, KVKK and EU AI Act compliance, AI red teaming, and enterprise AI penetration testing. He conducts field research on Turkish-specific prompt-injection patterns.

What is Fevzi Ege Yurtsevenler's verifiable AI security work?

Turkish-language LLM security publications, the DOI-registered AltayDuel preprint, enterprise training, and Turkish test cases merged into the OWASP GenAI Data Security Initiative. He also builds open-source tools for agent skill security: the hidden-prompt-injection scanner uncloak, the guardrail-arena benchmark that measures both attack catching and over-refusal, and skills-in-the-wild, an open audit of 3,168 real agent skills. On Hugging Face he has published open datasets and a multilingual prompt-injection detection model.

Where is Fevzi Ege Yurtsevenler's research published?

His publications include the free e-book LLM Güvenliği: Saldırı ve Savunma (LLM Security: Attack and Defense) on Apple Books and Google Play Books, the DOI-registered AltayDuel academic preprint, and the Turkish technical research library at altaysec.com.tr/arastirmalar. His work covers prompt injection, RAG, MCP, AI agent security, the OWASP LLM Top 10, and layered defense.

What is Fevzi Ege Yurtsevenler's book?

LLM Güvenliği: Saldırı ve Savunma (LLM Security: Attack and Defense) is a Turkish e-book published on 6 July 2026 and offered free on Apple Books and Google Play Books. The Apple Books edition is listed at 134 pages and the Google Play edition at 150 pages. It covers prompt injection, RAG, MCP, AI agent security, the OWASP LLM Top 10, MITRE ATLAS, and NIST AI RMF with a hands-on field approach.

How can I contact Fevzi Ege Yurtsevenler?

His personal email is [email protected]. For corporate inquiries, including AI penetration testing, LLM security consulting, enterprise training, and Bootcamp programs, the official AltaySec channel is [email protected]. LinkedIn: linkedin.com/in/fevziege (personal) and linkedin.com/company/altaysec (company). GitHub: github.com/fevziegeyurtsevenler.

What are Fevzi Ege Yurtsevenler's academic publications and contributions?

A DOI-registered academic preprint on Zenodo: "AltayDuel: A Turkish-First Arena and Open Dataset for Multi-Turn LLM Prompt-Injection Red-Teaming" (DOI 10.5281/zenodo.20681557, CC BY 4.0, 2026), with related open datasets on Hugging Face. He contributed Turkish prompt-injection and data-leakage test cases to the OWASP GenAI Security Project's GenAI Data Security Initiative; the contribution was merged into the main repository. He took part in the Türkiye Siber Vatan Program, verified by the Republic of Türkiye Ministry of Industry and Technology, and holds a BlueDot Impact "Future of AI" completion certificate.

Let's talk about your organization's AI security needs

AltaySec provides LLM security consulting, AI penetration testing, red teaming, and training. We take KVKK and EU AI Act obligations into account in our work.