German-OCR-3 v0.2 · live Apr 2026

Applied AI Researcher.
Engineer. Builder.

I build the German AI stack — compact, local-first vision-language models, agentic systems, and LLM infrastructure. Research-grade, production-shipped, open-source-first.

🎓 PhD Researcher · TU Darmstadt 💼 Lead AI Engineer · ZM-I Group 🇩🇪 Munich, Germany
6
Published CVEs
(4× Critical)
100+
Public repos
on GitHub
ICLR'26
TurboQuant integration
for llama.cpp
0 %
Hallucination · 200+
German invoices tested
Just shipped · April 2026

German-OCR-3 v0.2

Compact German document Vision-OCR — two editions (1.0 GB / 2.7 GB) on Qwen3.5, Apache 2.0. Zero hallucination on 200+ anonymized German invoices.

JSON validity
100 %
Sender correct
95 %
Hallucination
0 %
$ ollama pull Keyvan/german-ocr-3
Security Research

6 published CVEs · 10 advisories in triage

Responsible-disclosure security research via NVD, GitHub Security Lab, Patchstack and vendor programs. Targets include enterprise-grade systems at Siemens, Tutanota, Mailcow, Shopware, Pimcore, Einride and NousResearch.

CVE Severity Type Target Year
CVE-2026-404929.8 CriticalNative RCE vectorSAIL image library2026
CVE-2026-404939.8 CriticalNative RCE vectorSAIL image library2026
CVE-2026-404949.8 CriticalNative RCE vectorSAIL image library2026
CVE-2021-44559.8 CriticalArbitrary File Upload · RCEWordPress · Smart Product Review2021
CVE-2021-249976.5 MediumAuth / Info DisclosureWordPress · WP Guppy2021
CVE-2025-09904.3 MediumCSRFWordPress · I Am Gloria2025
In Triage · Pending Disclosure
  • Siemens — KAS · linux-entra-sso (2 findings)
  • NousResearch — hermes-agent (2 findings · incl. Critical)
  • Tutanota — end-to-end encrypted mail
  • Mailcow — dockerized mail server
  • Shopware — commerce platform (2 findings)
  • Pimcore — admin-ui-classic-bundle
  • Einride — iam-go identity framework
Certifications & Disclosure
  • OSCP · Offensive Security Certified Professional
  • CEH · Certified Ethical Hacker
  • ISTQB · Certified Tester Foundation
  • ISO 21434 · Automotive Cybersecurity (Vector)

Responsible disclosure only via NVD, GitHub Security Lab, Patchstack. No 0-day sales, no PoC leakage.

Research

Academic work · Publications

PhD · in progress

AI for Engineering Systems

Technical University (TU) Darmstadt

Focus: Intelligent document processing, agent-based systems for civil engineering and industrial applications.

MSc · 2025

Cybersecurity (HDBW Munich)

Master's Thesis

"Manipulation of Neural Language Models — Security Risks and Defense Strategies for Trojaned AI Models"

Publications
  • Verbesserung von Belohnungsmodellen durch Adversariale Trigger-Generierung Zenodo · 2024
  • SecIDS-CNN: Advanced Convolutional Neural Network for Intrusion Detection Zenodo · HF · 2023
  • SecIDS-CNN: Ein CNN für Intrusion Detection in Fahrzeugnetzwerken Zenodo · HF · 2023
  • AI-Bilderkennungs-Klassifizierung GitHub · HDBW · 2021
Stack

What I use to build this

Languages
Python · C/C++ · Go · TypeScript · SQL · Rust
ML / AI
PyTorch · Transformers · PEFT/LoRA · vLLM · llama.cpp · Ollama · ONNX
Agentic / LLM
LangChain · RAG · Vector DBs (Weaviate, FAISS, Pinecone) · Fine-tuning
Infra
Docker · CUDA · FastAPI · GPU orchestration · CI/CD · MLOps
Work with me

Advisory · Consulting · Research collaboration

Selectively taking on engagements where I can contribute deep technical work — agentic AI, document intelligence, LLM infrastructure, on-premise / DSGVO-compliant ML stacks, AI security.

Short advisory

Architecture reviews, model-selection, fine-tuning strategy, GPU sizing.

Research collaboration

Joint work on VLMs, document AI, agentic systems, AI safety.

Start a conversation