01/Index
Writing ↗⌘K
01Index

Zarif Latif

Founder @Railo

I build intelligent systems — from research to production.

Get in touchRésuméGitHubWriting ↗Open to select opportunities
02About

About

I’m a software engineer and AI researcher working at the intersection of artificial intelligence, software engineering, cybersecurity, and formal methods. My research spans machine learning, language models, mechanistic interpretability, adversarially robust security, reinforcement learning, program analysis, automated program repair, and SMT-based verification. I’m particularly interested in building intelligent systems that are not only capable, but reliable, secure, explainable, and verifiable.

I’m the founder and technical builder of Railo, an autonomous DevSecOps system that explores how AI, AST-level program transformation, and formal verification can be combined to automate software security remediation safely. I enjoy taking difficult research problems from first principles and turning them into working systems, and my long-term goal is to advance trustworthy autonomous software by bridging the gap between what AI can generate and what we can rigorously verify.

03Selected Work

Selected Work

A selection of systems I've designed, shipped, and researched.

01
DevSecOps & Formal Methods

Railo — Autonomous DevSecOps & Security Remediation

A deterministic vulnerability remediation compiler that detects backend security flaws, synthesizes zero-regression code patches via CST surgery and Microsoft Z3 SMT verification, and opens merge-ready Fix PRs on GitHub without LLM hallucinations. Landed upstream security fixes on tier-1 repositories including HTTPie (34k★), Dagster (16k★), BentoML (8.8k★), and DeepEval (5k★).

350k+ ★ Audited · <1ms Proofs
2025 – Present
  • Python
  • LibCST
  • Microsoft Z3
  • Semgrep
  • TypeScript
  • FastMCP
  • Docker
  • PostgreSQL
02
Quantitative Risk & NLP

Aetherius — Deterministic Downside-Risk Engine

Open-source quantitative risk intelligence pipeline that screens concentrated public-equity books against real-time SEC EDGAR filings and global financial news feeds using deterministic scoring taxonomies. Backtested with 100% recall across SVB-2023, Wirecard-2020, and FTX-2022 with a median lead time of 2.48 days and 0 false positives.

100% Recall · 2.48d Lead Time
2026
  • Python 3.12
  • SEC EDGAR API
  • GDELT DOC 2.0
  • FastAPI
  • Pytest (Hypothesis)
  • Docker
03
AI Engineering & Multi-Agent

SignalForge — Generative Engine Optimization (GEO)

An open-source Generative Engine Optimization (GEO) and AI Share-of-Voice measurement framework. Measures how AI answer engines (ChatGPT, Claude, Perplexity) rank and cite B2B brands, and deploys autonomous multi-platform earned-media squads to seed LLM training and RAG retrieval pipelines.

0% → 40%+ AI Citation Rate
2025
  • Python 3.11
  • FastAPI
  • React (Vite)
  • PostgreSQL
  • Llama 3.1
  • Ollama
  • Groq
  • Docker
04Research

Research

Peer-reviewed and in-progress work in machine learning.

My research centers on Mechanistic Interpretability, Adversarial Robustness & AI Safety, Formal Verification & SMT Solvers, Automated Program Repair (APR), AST Program Synthesis & Transformation, and neurosymbolic ai systems.

2026Under Review · ACM TOSEM (CORE A*)

VeriPatch: A Verification-Gated Neuro-Symbolic Framework for Secure Program Repair

Md. Zarif Latif, Kazi Tasfin Mahmud

ACM Transactions on Software Engineering and Methodology (TOSEM)

ACM Artifact Badges Candidate

2026Working Paper · Target: KBS (Q1)

Prescriptive Graph Bandits: Safe Causal Policy Learning via Counterfactual Graph Neural Networks and Distributional Offline Reinforcement Learning

Md. Zarif Latif

Knowledge-Based Systems (Elsevier, JCR Q1)

2026Working Paper · Ready for Submission

Lightweight Explainable Static Malware Detection with Temporal Generalization and Adversarial Robustness

Md. Zarif Latif, Tasneem Tuhfa

Journal of Information Security and Applications (Elsevier JISA)

2026Working Paper · In Preparation for TACL

The Tokenization Ceiling: Why Induction Heads Fail for Bengali Despite Being Language-Agnostic at the Token Level

Md. Zarif Latif

Transactions of the Association for Computational Linguistics (TACL)

05Stack

Stack

AI & Machine Learning

  • PyTorch & Transformers
  • LLMs & Alignment (RLHF)
  • Mechanistic Interpretability
  • Adversarial Robustness
  • Model Evaluation & Red-Teaming
  • Sparse Autoencoders (SAEs)
  • RAG & Neural Retrieval

Security & Formal Methods

  • Automated Program Repair (APR)
  • AST Analysis & Rewriting
  • SMT Verification (Z3)
  • Static Analysis & SAST
  • Autonomous DevSecOps
  • Vulnerability Remediation
  • Adversarial AI Defense

Languages

  • Python
  • TypeScript
  • Rust
  • C / C++
  • Go
  • SQL
  • Bash / Shell

Systems & Infrastructure

  • Distributed Systems
  • Docker & Kubernetes
  • Next.js / React & Tailwind
  • FastAPI & Microservices
  • PostgreSQL & Redis
  • Linux Systems & Toolchains
  • CI/CD & Cloud (AWS / GCP)
06Contact

Contact