about
I am a researcher at LinkedIn currently working on LLM fairness and safety. Before joining LinkedIn, I did similar work at Meta from 2018 to 2025, after completing my PhD in Computer Science at the University of Michigan in 2018. I was advised by Michael Wellman.
I'm primarily interested in understanding and mitigating bias in AI systems, but my research interests include the incentives and dynamics in complex systems. My research often involves embedding learning, user representation, fairness, recommender systems as markets, and general learning.
research
Red teaming assesses how large language models (LLMs) can produce content that violates norms, policies, and rules set during their safety training. However, most existing automated methods in the literature are not representative of the way humans tend to interact with AI models. Common users of AI models may not have advanced knowledge of adversarial machine learning methods or access to model internals, and they do not spend a lot of time crafting a single highly effective adversarial prompt. Instead, they are likely to make use of techniques commonly shared online and exploit the multi-turn conversational nature of LLMs. While manual testing addresses this gap, it is an inefficient and often expensive process. To address these limitations, we introduce the Generative Offensive Agent Tester (GOAT), an automated agentic red teaming system that simulates plain language adversarial conversations while leveraging multiple adversarial prompting techniques to identify vulnerabilities in LLMs. We instantiate GOAT with 7 red teaming attacks by prompting a general-purpose model in a way that encourages reasoning through the choices of methods available, the current target model’s response, and the next steps. Our approach is designed to be extensible and efficient, allowing human testers to focus on exploring new areas of risk while automation covers the scaled adversarial stress-testing of known risk territory. We present the design and evaluation of GOAT, demonstrating its effectiveness in identifying vulnerabilities in state-of-the-art LLMs, with an ASR@10 of 97% against Llama 3.1 and 88% against GPT-4-Turbo on the JailbreakBench dataset.
Several recent authors have advocated for financial markets to move from continuous clearing to discrete or batched clearing, as a way to defeat the latency arms race: the never-ending quest for small advantages in time to access markets. How frequently should such a modern batch auction clear? We conduct a systematic simulation-based investigation on the relationship between clearing frequency and metrics of market quality, such as allocative efficiency, comparing the performance of discrete and continuous auction mechanisms under empirical equilibrium behavior of all participating traders. In effect we perform empirical mechanism design on frequent batch auctions. We find that in a wide array of environments, equilibrium efficiency is improved for small positive intervals but falls off dramatically when there are too few opportunities to trade. The result is a large range of batch frequencies that are near optimally efficient; this range is more pronounced in thick markets.
contact
You can find more information about me via any of the following services:
- GitHubgithub.com/erikbrinkman
- Google Scholarscholar.google.com
- emailerik.brinkman@gmail.com
- LinkedInlinkedin.com/in/erikbrinkman
- hafa.iohafaio.github.io
Thanks to Alison Wilcox for the logo design, Melanie David for inspiring the design of this website, and Sarah Forrest for design guidance.
All project hero images come from Unsplash courtesy of Matteo Catanese and Marek Piwnicki.