Hi! I'm an industrial PhD researcher at TU Berlin and Huawei Munich Research Center, working with Prof. Stefan Schmid and Dr. Yong Li.
I work on LLM agent security and privacy-preserving machine learning. I'm interested in how agents can use tools safely, stay within the permissions users give them, and keep sensitive data private. My work also covers secure LLM inference and private retrieval-augmented generation.
Before my PhD, I studied at KTH Royal Institute of Technology and Southeast University. I also worked on security at Huawei 2012 Labs and did my master's thesis at Ericsson in Stockholm. Outside research, I enjoy traveling and taking photos.
") does not match the recommended repository name for your site ("").
", so that your site can be accessed directly at "http://".
However, if the current repository name is intended, you can ignore this message by removing "{% include widgets/debug_repo_name.html %}" in index.html.
",
which does not match the baseurl ("") configured in _config.yml.
baseurl in _config.yml to "".
Yuhan Ma, Stefan Schmid
Conference on Neural Information Processing Systems (NeurIPS) 2026 Accepted
A security architecture for tool-using LLM agents that confines sensitive plaintext at the read boundary and authorizes external actions through a trusted executor.
Yuhan Ma, Stefan Schmid
Conference on Neural Information Processing Systems (NeurIPS) 2026 Accepted
A security architecture for tool-using LLM agents that confines sensitive plaintext at the read boundary and authorizes external actions through a trusted executor.
Yuhan Ma, Yong Li, Stefan Schmid
International Conference on Machine Learning (ICML) 2026 Accepted
A function-secret-sharing based framework for efficient two-server secure LLM inference, targeting fixed-point comparisons, interval lookup, low-degree polynomial evaluation, and predicate-dependent computation.
Yuhan Ma, Yong Li, Stefan Schmid
International Conference on Machine Learning (ICML) 2026 Accepted
A function-secret-sharing based framework for efficient two-server secure LLM inference, targeting fixed-point comparisons, interval lookup, low-degree polynomial evaluation, and predicate-dependent computation.