xiaonan.dev

Hi, I'm

Xiaonan Li

AI Systems & Full-Stack Engineer

I build AI features and the systems that run them.

I'm completing a Master of Computer Science at the University of Sydney, focused on data science and AI. I like turning a rough requirement into software that is reliable and maintainable.

Send a message
Jump to2026

Looking for teams building reliable AI products.

How I work

I turn requirements into software that is easier to build, test, and operate. That includes the feature itself, but also service boundaries, data flow, and failure handling.

Based in Sydney, Australia.

01

From requirements to architecture

I turn product requirements into clear service boundaries, data ownership, and failure-handling decisions.

RequirementsArchitectureCode review
02

Long-running AI workflows

I design AI workflows with asynchronous workers, persisted progress, retries, and clear boundaries from the core backend.

WorkerAsyncRAG
03

Across the stack

I have worked across backend, frontend, AI integration, and deployment to take a feature from design through delivery.

Spring BootNext.jsPyTorch
04

Working languages

Chinese is my native language. I study and work in English, and I am continuing to learn Japanese.

中文English日本語

Engineering internships

Experience in production troubleshooting, reliability improvements, testing, data analysis, and developer tooling.

Jun 2025 - Aug 2025

Meituan Platform

Software Development Engineer Intern

Worked on reliability and developer productivity in core systems, including resilient status reporting, issue diagnosis, data analysis, and Gradle build optimisation.

  1. 01

    Improved status reporting and retry logic to increase reliability under weak network conditions.

  2. 02

    Used JADX to diagnose an obfuscated third-party reporting-format defect and correct the payload format.

  3. 03

    Built Spark and SQL dashboards for anomaly detection and trend analysis.

  4. 04

    Analysed the Gradle task DAG and optimised build bottlenecks while preserving build stability.

  5. 05

    Used AI-assisted tools for unfamiliar code analysis, API exploration, and issue investigation.

Education

Two undergraduate degrees in China and Australia, followed by a master's in Sydney focused on data science and AI.

Scroll sideways

01

Now — graduating Nov 2027

The University of Sydney

Master of Computer ScienceData Science and Artificial Intelligence

Current master's study in machine learning, data pipelines, and rigorous evaluation of model results.

Data ScienceMachine LearningAI Systems
02

2026 — graduated with Distinction

Swinburne University of Technology

Bachelor of Engineering (Honours)Software Engineering

Honours study in software engineering, including AI, applied machine learning, and team software delivery.

Software EngineeringApplied MLTeam Delivery
03

Graduated

Shandong University of Science and Technology

Bachelor of EngineeringSoftware Engineering

Undergraduate study in computer science fundamentals. My thesis examined federated learning across devices that cannot share their data.

CS FundamentalsFederated LearningDatabases

Selected projects

Projects in AI security, AI platforms, federated learning, and computer vision.

Creator and Researcher / Jul 2026 - Present

RedCell — Adaptive AI Agent Red Teaming

An open-source tool that probes tool-using LLM agents for prompt injection, data leakage, and unauthorized tool calls within a fixed test budget, then turns confirmed findings into regression tests.

PythonPydanticSQLAlchemyThompson Sampling
View source
01

Challenge

Tool-using LLM agents call databases, files, and business APIs, so a manipulated agent can leak data or take actions it shouldn't. A fixed list of jailbreak prompts doesn't cover this, because the attack surface comes from natural-language decisions and non-deterministic models.

02

Approach

I modelled red teaming as a budget-constrained search problem: a bandit controller decides which attack strategy gets the next attempt, and an LLM mutates the prompt. Success is judged by instrumentation — canaries, tool-permission checks, cross-user access — not by another LLM.

03

Implementation

Built the full pipeline with a deliberately vulnerable benchmark arena, three controllers, budget and reliability guards, experiment fingerprints, and crash-safe resume. The Phase 0 hypothesis was not supported across 18 runs and 1,080 attempts, so I recorded it as a negative result.

04

Tech stack

Python 3.11, asyncio, Pydantic, SQLAlchemy, Typer CLI, Jinja2 reports, pytest. The test suite runs fully offline.

  1. 01

    Designed adaptive attack search: bandit-guided strategy selection with LLM-based prompt mutation under a fixed attempt, token, and cost budget.

  2. 02

    Built deterministic scoring from canary strings, tool-permission checks, and cross-user access, separating violating intent, attempted tool calls, and realized impact.

  3. 03

    Built a benchmark arena of deliberately vulnerable agents, with positive and negative controls plus a check that validates the attacker model itself before any calibration run.

  4. 04

    Made every run reproducible with experiment fingerprints, full trace storage in SQLite, crash-safe resume, and export of confirmed findings as regression tests.

  5. 05

    Reported the Phase 0 research hypothesis as NOT SUPPORTED after 18 runs and 1,080 attempts, and documented the evidence limits publicly rather than reporting a favourable subset.

Technologies I use

Technologies I have used in projects and internships.

01

AI & Machine Learning

Used for model training, video liveness detection, semantic retrieval, and LLM agent evaluation.

PyTorchTensorFlowTensorFlow LiteRAGFAISSSentenceTransformers
02

Backend & Data

Used to build APIs, manage application data, and deploy services.

Spring BootJavaMyBatisMicroservicesPythonPydanticSQLAlchemySparkSQLAWS
03

Frontend & Mobile

Used to build web and Android interfaces, including this site.

Next.jsTypeScriptTailwind CSSAndroidKotlinJUnit

Get in touch

I'm looking for internship and graduate engineering opportunities in AI systems, backend, and full-stack development. The form, LinkedIn, and GitHub are all good ways to reach me.

Currently seeking
Internships and graduate roles

Opportunities in AI engineering, backend systems, and full-stack development.