An independent AI security research lab. Open-source tooling for LLM red-teaming, adversarial ML, and AI governance.
From breaking LLMs to governing them. Six tracks, one method: systematic, evidence-led, reproducible.
Offensive
Automated and manual adversarial testing of LLM-powered applications. Probe design, evidence collection, and findings mapped to OWASP LLM Top 10 and MITRE ATLAS.
Break My Bot · Garak · PyRIT
Research
Evolutionary algorithms applied to probe generation. Attack populations adapt against model defences across generations, finding what static probe packs miss.
Active research · 2026–2027
Intelligence
Application of AI and open-source intelligence methods to complex investigative contexts. Methodology development, tool evaluation, and practitioner training.
Research & training
Governance
Design and implementation of AI management systems. Risk frameworks, conformity assessments, and governance structures for organisations deploying AI at scale.
ISO/IEC 42001 · Certified
Engineering
Local inference stacks, Dockerised ML pipelines, RAG architectures, and observability tooling. Practical experience from bare metal to production.
Ollama · Docker · Local inference
Publishing
Original research on LLM vulnerabilities, adversarial ML, and alignment failures in production systems. Writing, benchmarks, and open datasets. All free.
Publications · Dec 2027 roadmap
An open-source Dockerised scanner for adversarial testing of LLM-powered applications. Runs automated probes, captures immutable evidence, classifies findings against OWASP LLM Top 10, and generates a structured report. Runs locally; no data leaves your server.
A self-hosted CTF arena for hands-on AI and application security training. Challenges cover prompt injection, jailbreaks, and web vulnerabilities. Students can connect using Kali Linux virtual machines provided by the platform. Runs on the Black Mountain lab. Open to anyone.
Technical writing and research notes on LLM security, adversarial ML, AI governance, and AI-assisted investigation. Practitioner-focused, grounded in real tool runs and real threat models.
Published · Poster
AI Against Crime: Retrieval-Augmented Generation with Contrastive Language–Image Pretraining in Criminal Network Analysis
A proof-of-concept AI system combining RAG and CLIP to enrich multimodal, offline criminal-network analysis, generating actionable intelligence reports for investigators.
Research Week 2025 · Ostia, Rome · F. M. Trujillo Montenegro
Open poster (PDF) →
Founder
Francisco Manuel
Trujillo Montenegro
AI security researcher & systems engineer. Based in Europe.
Open Black Mountain is an independent research lab focused on the security boundaries of AI systems: what breaks, how it breaks, and how to test it rigorously before it reaches production.
The lab produces open-source tooling, research notes, and practitioner-level writing. Everything is built to be reproducible, evidence-led, and free to use.
If you're a researcher, practitioner, or organisation working on AI security and want to collaborate, reach out.