Miju Labs

← All people · Gray Swan AI

CMU security and privacy professor who runs Gray Swan, the company that turned a crowd of prize-paid jailbreakers into a frontier-lab red-teaming and guardrail business. He is the operator of one of the few human-data crowds paid by competition rather than by the hour.

high confidencePittsburghAt Gray Swan AI since 2023Updated 2026-09-19

Background

Associate Professor of Computer Science at Carnegie Mellon, known for foundational privacy and adversarial-ML work: his 2015 model-inversion paper won the ACM CCS Test-of-Time Award (October 2025), and a paper co-authored with Nicolas Papernot and others won the IEEE EuroS&P Test-of-Time Award (July 2026). With Zico Kolter and their student Andy Zou he co-authored the 2023 universal adversarial-suffix attack on aligned LLMs, the research lineage behind Gray Swan.

Gray Swan emerged from stealth in July 2024 as a CMU spinout.

What they run now

Scaling the three-product business after the Series A: enterprise sales of Shade and Cygnal, keeping frontier-lab engagements (system-card red-teaming, indirect prompt injection), and running Arena as both a data engine and a hiring pipeline.

Career

  1. 2023 – presentCo-founder & CEO, Gray Swan AI
  2. presentAssociate Professor, Computer Science, Carnegie Mellon University

On the record

Security lag · 2026-05

Says AI is moving faster than any prior technology and security has not kept pace. source

Automation vs human red-teamers · 2026-06

Shade outperforms human red-teamers only given a fixed time on specific tasks; not yet superhuman across all scenarios. source

Unpredictability · 2026-06

Argues the one reliable expectation in AI security is surprises. source

Recent posts

2 posts archived · most engaged first, then the latest

Matt Fredrikson
CEO @ Gray Swan AI
Congratulations to Anthropic on Claude Fable 5.1 and Mythos 5.1. Gray Swan continues to be part of Anthropic's work on model robustness, alignment, and safety, including helping stress-test the cybersecurity safeguards for this release. External evaluation an essential part of the process, and it is good to see Anthropic value it and report it transparently, as robustness improves with each generation. lnkd.in/gV_tGGTF
1087 comments7 reposts
Matt Fredrikson
CEO @ Gray Swan AI
Agents can coordinate and slip confinement unnoticed in an eval environment designed specifically to watch them. This means that monitoring and enforcing policies on agent behavior is an operational concern for anyone running agents, not just a problem for the frontier labs. lnkd.in/gnWE5_MC
464 comments4 reposts

Interviews & talks

Connections

  • Zico Kolterco-founder, CMU colleague
  • Andy Zouco-founder, former PhD student
  • Jake Flomenberg (Wing VC)Series A co-lead investor
  • Vivek Ramaswami (Madrona)Series A co-lead investor

Who they amplify

Accounts whose posts Matt has reposted recently: AI Security Forum, Gray Swan.

Why it matters here

Gray Swan's Arena is the best-documented example of a competition-based expert crowd: prize pools, leaderboards, verifiable profiles, and direct hiring from top performers. That is a design pattern Julian could borrow for a designer community (challenges judged on taste, paid by placement). Red-teaming itself is far from creative work, so direct commercial overlap is low.

How to reach

Academic channels (CMU) or via the Arena community/Discord. Speculation: questions about how they price prize pools, prevent collusion and convert top performers into contractors are specific and flattering enough to get a reply.

What we could not establish
  • Education (PhD institution) not verified in this pass.
  • No verified X handle.
  • Revenue split between Arena, Shade and Cygnal not disclosed.

Sources

  1. Gray Swan: Series A announcement (2026-05-28)
  2. Gray Swan About page
  3. Personal site
  4. Latent Space: Red-Teaming after Mythos (2026-06-22)
  5. Forbes Australia: army of 15,000 hackers (2026-06-01)
  6. Technical.ly: Gray Swan raises $40M Series A