Sign in

A. Feder Cooper

@afedercooper.bsky.social
564 followers 252 following 291 posts

ML prof @ Yale My work on copyright and generative AI has been called "somewhat famous" by the popular press. attention-is-not-all-you-need.githu…

PostsRepliesMedia
A. Feder Cooper @afedercooper.bsky.social · 30m
Our large-scale study of memorization of books in open-weight LLMs (e.g., Llama, Qwen) will appear at the 2026 Conference on Language Modeling as an oral. We made a website for exploring our results on 200 books and 14 models: books-memorization.github.io
books-memorization.github.io
How much do open-weight LLMs memorize specific books?
Open-weight LLMs memorize books far more than previously believed. Memorization varies by model family, model size, and book. In extreme cases, entire books are memorized, and we can generate them eff...
193
Reposted by A. Feder Cooper
Meera Desai @madesai.bsky.social · 28/09/2026
Excited to share our new paper, “What AI Benchmarks Actually Measure: Adapting Convergent and Discriminant Validity to Interrogate Fifty-Six AI Benchmarks,” accepted as an oral at COLM! arxiv.org/pdf/2609.08812
Heatmap of average correlations between model rankings on benchmarks grouped into 11 assigned concepts: four capability concepts (reasoning, knowledge, comprehension, summarization) and seven safety concepts (over-refusal, refusal, safety detection, ethics, bias, privacy, unsafe behavior). Diagonal cells show within-concept correlations, ranging from 0.87 (knowledge) and 0.72 (over-refusal) down to 0.20 (bias) and 0.02 (safety detection). Reasoning, knowledge, and comprehension correlate with each other at 0.69 to 0.78, higher than reasoning's and comprehension's own within-concept values (0.66 and 0.68). Ethics correlates more with knowledge (0.70) than with itself (0.55), and bias correlates more with capability concepts (0.41 to 0.45) than with itself (0.20). Privacy and unsafe behavior correlate negatively with reasoning, knowledge, and comprehension (−0.41 to −0.49). Over-refusal and refusal correlate at −0.42.
16118
Reposted by A. Feder Cooper
Kylie Cheung @kylietcheung.bsky.social · 28/09/2026
I think its important to understand the campus sexual assault crisis is way worse than you think. universities suspend just 1/12,400 students each year for sexual misconduct & expel 1/22,900. once you read title ix administrators in their own words, you get a sense why that is:
jezebel.com
Not Only Do Campus Sexual Assailants Go Unpunished, They Often Get Special Treatment
Since 2007, Jezebel has been the Internet's most treasured source for everything celebrities, sex, and politics...with teeth.
1662227
Reposted by A. Feder Cooper
@NewsJennifer (Jennifer Schulze) @newsjennifer.bsky.social · 27/09/2026
I think it’s fair to say that the student journalists at Cornell are braver than the news networks who just gave up on their WH pool ban even though CNN is still being denied access. www.cornellsun.com/article/2026...
cornellsun.com
EDITORIAL | Cornell Won’t, We Will
The Editorial Board demands that Cornell stops protecting the alleged Chi Phi rapists through the University's opaque sexual assault policies.
342478762
Reposted by A. Feder Cooper
Brandon Butler @bb.usefairuse.com · 24/09/2026
Reporters revisiting the study in light of this litigation news should also read Cooper’s substantive critiques, as it shows this is not just a gotcha game about money. The study has real flaws that consistently bias its analysis in favor of the funder.
081
A. Feder Cooper @afedercooper.bsky.social · 27/09/2026
I think this is a really important read. @masnick.com carefully explains what is so shocking about recent revelations in court about undisclosed COIs concerning research on copyright and LLMs. www.techdirt.com/2026/09/25/o...
techdirt.com
OpenAI Accuses Plaintiffs’ Lawyers Of Paying For, Hiding, And Then Laundering Sketchy Key Evidence In AI Copyright Case
A ton of attention was paid recently to some offhand statements from OpenAI and Microsoft employees that surfaced in filings in the NY Times' ongoing case against OpenAI, which has been consolidated into a much larger class action lawsuit. As I argued earlier, that struck me as something of a nothingburger of a story, because...
12810
Reposted by A. Feder Cooper
Mark Lemley @marklemley.bsky.social · 26/09/2026
@afedercooper.bsky.social's critique of the methodology is here: afedercooper.info/whack-a-mole/
afedercooper.info
Playing Whack-a-Mole with misconceptions about memorization, extraction, and copyright
A response to Alignment Whack-a-Mole and some broader thoughts on the field
083
Reposted by A. Feder Cooper
James Grimmelmann @jtlg.bsky.social · 24/09/2026
Congratulations to Meta, I guess, on failing to take reasonable measures to protect its trade secrets, and on authorizing extensive access to a protected computer.
38326
A. Feder Cooper @afedercooper.bsky.social · 15/09/2026
Like many of my colleagues, I'm receiving dozens of EOI emails a day from prospective students. It's worth reading those emails before clicking send. (I expect most are using AI to draft emails. This tiny prompt injection is just to see if the sender bothered to even read the output.)
140
Reposted by A. Feder Cooper
Maria Antoniak @mariaa.bsky.social · 10/09/2026
New from our lab! #COLM2026 When people generate stories, they don't just write one prompt. Instead, they explore narrative space via branching edits 🌱 We reconstruct 24k of these edit trees 🌳 from chat logs and map edit types, story formats, how they relate to tree depth, and more!
The Garden of Forking Prompts: How Users Explore Narrative
Space in Story Generation
Advait Deshmukh♣ Nora Benedict♠ Melanie Walsh♡ Maria Antoniak♣
♣University of Colorado Boulder ♠University of Georgia ♡University of Washington

Abstract

Large language models (LLMs) have changed the way people engage
with stories. Drawing on public chatbot logs, we can see that when users
generate stories, they iteratively edit their prompts to explore narrative
possibilities, adjusting characters, redirecting plots, and swapping fictional universes. As aggregated data, these prompts represent rich traces of creative preference at scale. Yet story generation evaluation benchmarks rely on static, one-shot prompts that cannot capture this exploratory behavior. In this work, we study how users revise consecutive story prompts in the wild. Using a dataset of naturally occurring user-chatbot conversations, we construct WildStories, a sample of 275,635 story generation prompts (labeled with story format, prompt components, and explicitness), and WildEdits, a collection of 24,291 edit trees that model how users iteratively edit base story prompts and explore branching story possibilities. From these trees we develop a framework of edit types crossing four directions (adding, removing, changing, and extending) with fourteen targets (e.g., plot, character, genre). We then use our datasets and this framework to
analyze user behavior in navigating narrative space via LLMs. Finally, we
show how automated permutations based on the framework can be used
for story generation benchmarking. Content Warning: This paper works with “wild” chatbot logs, which often include toxic and sexually explicit themes.
29629
Reposted by A. Feder Cooper
angela zhou @angelamczhou.bsky.social · 08/09/2026
You should read this statement. Difficult to follow all the details at times, but (no surprise) it seems that all the corporatization of math with gazillions of $$ at stake has ratcheted up the toxicity in math. And disappointingly, former academics (Seb) as front-gunners for the coporate machine
2245
Reposted by A. Feder Cooper
A. Feder Cooper @afedercooper.bsky.social · 06/09/2026
Prospective copyright plaintiffs have started asking me my opinion about citing "Alignment Whack-a-Mole" in litigation. It reports that fine-tuning makes frontier LLMs reproduce up to 85-90% of copyrighted books. I don't think the headline results hold up: afedercooper.info/whack-a-mole/
afedercooper.info
Playing Whack-a-Mole with misconceptions about memorization, extraction, and copyright
A response to Alignment Whack-a-Mole: why its headline book-memorization coverage numbers rest on a measurement procedure that can't separate memorization from coincidence or prompt leakage.
12012
A. Feder Cooper @afedercooper.bsky.social · 06/09/2026
Prospective copyright plaintiffs have started asking me my opinion about citing "Alignment Whack-a-Mole" in litigation. It reports that fine-tuning makes frontier LLMs reproduce up to 85-90% of copyrighted books. I don't think the headline results hold up: afedercooper.info/whack-a-mole/
afedercooper.info
Playing Whack-a-Mole with misconceptions about memorization, extraction, and copyright
A response to Alignment Whack-a-Mole: why its headline book-memorization coverage numbers rest on a measurement procedure that can't separate memorization from coincidence or prompt leakage.
12012
Reposted by A. Feder Cooper
danah boyd @zephoria.bsky.social · 28/08/2026
PhD candidates/new grads: Postdoc opportunity with me focused on political economy and tech. See details here: academicjobsonline.org/ajo/jobs/32502
academicjobsonline.org
Cornell University, Department of Communication
Job #AJO32502, Postdoctoral Associate, Department of Communication, Cornell University, Ithaca, New York, US
16561
A. Feder Cooper @afedercooper.bsky.social · 06/08/2026
is anyone else finding Opus 5 to be an utter disaster? I've seen some other people complaining about taking actions that don't make sense without approval. I don't use AI that way (yet); I iterate slowly/ co-work through what I'm working on. And Opus 5 just can't do that.
360
A. Feder Cooper @afedercooper.bsky.social · 05/08/2026
A colleague sent along the decision in GEMA v. Suno, which I got to reading today: media.licdn.com/dms/document... I have my own thoughts on aspects of the decision, but regardless of the details, it continues to blow my mind that papers from my PhD and postdoc get cited in litigation.
media.licdn.com
170
Reposted by A. Feder Cooper
Casey Stegman @caseystegman.com · 27/07/2026
People who think Emily Wilson is being mean have clearly never presented a paper at an academic conference
743679481
A. Feder Cooper @afedercooper.bsky.social · 20/07/2026
I'm unreasonably pleased at having used my graphics/animation background to implement the "physics" here. i think the paper is important but also this
050
A. Feder Cooper @afedercooper.bsky.social · 18/07/2026
in our new preprint (with @marklemley.bsky.social and others), we revisit what it means to run valid extraction experiments from first principles. i recently gave a talk on this work at ICML, and we'll be wrapping up the preprint soon monkey-emeritus.github.io
monkey-emeritus.github.io
Extractable Memorization From First Principles
It’s time to retire the ‘monkey at the typewriter.’ We revisit extractable memorization from first principles: whether a model can produce any string was never the question — what matters is how many ...
0133
Reposted by A. Feder Cooper
Mark Lemley @marklemley.bsky.social · 07/07/2026
@afedercooper.bsky.social and I have a new paper working through the surprisingly tricky problem of whether storing model weights that might or might not generate copyrighted output when prompted makes the model a "copy" under copyright law papers.ssrn.com/sol3/papers....
papers.ssrn.com
Probabilistic "Copies" in Generative AI Models
<div> <span>Recent work shows that it is possible to extract verbatim or near-verbatim text of some copyrighted works from some large language models (LLMs or
12212
Reposted by A. Feder Cooper
Eugene Vinitsky 🍒 @eugenevinitsky.bsky.social · 07/07/2026
If your paper doesn't have a big limitations section, you're doing your readers a disservice by forcing them to discover failures you already know about
3403
Reposted by A. Feder Cooper
James Grimmelmann @jtlg.bsky.social · 04/06/2026
I have a new blog post updating the story of how Cornell President Kotlikoff backed his car into a student. The trustee committee's investigation utterly failed to consider the central issue: whether his actions (rather than the others') were misconduct. 🧵 3d.laboratorium.net/2026-05-22-h...
3d.laboratorium.net
How Not to Investigate a University President
I regret to inform you that there is even more to the story of how Cornell President Michael Kotlikoff backed his car into a student. I also regret to inform you that Cornell’s Board of Trustees has m...
1126
Reposted by A. Feder Cooper
Alexandra Olteanu @aolteanu.bsky.social · 30/05/2026
Sometimes it feels like some folks are losing the plot about what the goal of publishing research actually is. The goal is certainly not meant to be the productions of papers, but rather the production and communication of science.
1173
Reposted by A. Feder Cooper
Mark Lemley @marklemley.bsky.social · 23/05/2026
My latest paper discusses new tools @afedercooper.bsky.social and I, with others, are using to identify not just verbatim memorization in AI models but text that is extractable with only minor changes. We find significantly more memorization once we include non-exact copies. arxiv.org/abs/2603.24917
arxiv.org
Estimating near-verbatim extraction risk in language models with decoding-constrained beam search
Recent work shows that standard greedy-decoding extraction methods for quantifying memorization in LLMs miss how extraction risk varies across sequences. Probabilistic extraction -- computing the prob...
1214
Reposted by A. Feder Cooper
Eugene Vinitsky 🍒 @eugenevinitsky.bsky.social · 08/05/2026
The thing about AI in science is it could lead to way more papers *or* it could lead to each individual paper getting better. No one is forcing you to do the former!
2615
Reposted by A. Feder Cooper
James Grimmelmann @jtlg.bsky.social · 07/05/2026
I wrote an op-ed: "[President Kotlikoff] should correct the record and accept responsibility for his dangerous driving. … A Cornell student who intentionally drove their car into someone else and then lied about it would be subject to disciplinary action … ." 1/ www.cornellsun.com/article/2026...
cornellsun.com
GUEST ROOM | Kotlikoff Makes the Rules; He Needs to Follow Them Too
Cornell Law Professor James Grimmelmann analyzes and discusses the legality of the incident between students and President Kotlikoff following the April 30 Cornell Political Union debate.
1226
A. Feder Cooper @afedercooper.bsky.social · 02/05/2026
If you only read the NYT headline, you'd maybe think Kotlikoff's car was a malicious AI www.nytimes.com/2026/05/01/u...
nytimes.com
Cornell President’s Car Bumps Into Students After Confrontation Over Gaza
020
A. Feder Cooper @afedercooper.bsky.social · 16/04/2026
My work with @marklemley.bsky.social and others on extracting copyrighted books from language models recently featured in the UK House of Lords, Communications and Digital Committee report on AI, copyright and the creative industries publications.parliament.uk/pa/ld5901/ld...
publications.parliament.uk
0155
Reposted by A. Feder Cooper
James Grimmelmann @jtlg.bsky.social · 04/04/2026
New book on the idea shelf: Hasok Chang: _Inventing Temperature: Measurement and Scientific Progress_ What even is temperature? The history of science is a struggle both to make consistent measurements and to think clearly about what they are actually measuring. james.grimmelmann.net/idea-shelf
391
Reposted by A. Feder Cooper
Mark Lemley @marklemley.bsky.social · 29/03/2026
Yes, we hope to have both a more lay oriented paper focused on the results and a paper that focuses on the legal implications in the definition of a copy available soon
021
Reposted by A. Feder Cooper
Mark Lemley @marklemley.bsky.social · 29/03/2026
@afedercooper.bsky.social and I have a new paper that expands AI memorization tests to include near-verbatim copies, not just exact copies. We find that increases extraction/memorization of copyrighted content significantly. arxiv.org/abs/2603.24917
arxiv.org
Estimating near-verbatim extraction risk in language models with decoding-constrained beam search
Recent work shows that standard greedy-decoding extraction methods for quantifying memorization in LLMs miss how extraction risk varies across sequences. Probabilistic extraction -- computing the prob...
1324
A. Feder Cooper @afedercooper.bsky.social · 11/03/2026
i'm writing my last memorization paper (i say for the 10th time), and hopefully what is my last first author paper for a bit. this one also isn't about copyright. i'm excited to start thinking about other things. if anyone is looking for a new research buddy, i'm down to clown.
160
A. Feder Cooper @afedercooper.bsky.social · 25/02/2026
someone sent me this from the other place and this timeline really is something else
140
A. Feder Cooper @afedercooper.bsky.social · 28/01/2026
Position: ML conferences should consider removing the position paper track (...and just acknowledge that every scientific paper is articulating at least one position)
190
A. Feder Cooper @afedercooper.bsky.social · 14/01/2026
it’s hard to work at the intersection of ML and copyright because “both sides” of the debate are angry and, in my experience, most haven’t done much of the background reading in ML or copyright to have an informed opinion. it’s just vibes and anger. i should probably write something up about this.
171
Reposted by A. Feder Cooper
Riana @riana.bsky.social · 13/01/2026
got to experience the "I did not write that headline" phenomenon firsthand The article: "Correctly scoping a legal safe harbor for A.I.-generated child sexual abuse material testing is tough." The headline: "There's One Easy Solution to the A.I. Porn Problem"
3505
Reposted by A. Feder Cooper
Paul Eric @pauleric70.bsky.social · 13/01/2026
After twelve years of work, the world’s most beautiful subway station has been inaugurated in Rome: Colosseo, an underground archaeological museum.⚜️💙⚜️💙⚜️💙⚜️
16268104
A. Feder Cooper @afedercooper.bsky.social · 12/01/2026
The Atlantic posted an article about memorization and generative AI, and it mentions our work on extraction of books from production LLms and open-weight models. www.theatlantic.com/technology/2... The referenced work reflects research with @marklemley.bsky.social @jtlg.bsky.social and others.
theatlantic.com
AI’s Memorization Crisis
Large language models don’t “learn”—they copy. And that could change everything for the tech industry.
1135
Reposted by A. Feder Cooper
YY Ahn @yyahn.bsky.social · 10/01/2026
"In some cases, jailbroken Claude 3.7 Sonnet outputs entire books near-verbatim ... Taken together, our work highlights that, even with model- and system-level safeguards, extraction of (in-copyright) training data remains a risk for production LLMs." arxiv.org/abs/2601.02671
arxiv.org
Extracting books from production language models
Many unresolved legal questions over LLMs and copyright center on memorization: whether specific training data have been encoded in the model's weights during training, and whether those memorized dat...
1499
Reposted by A. Feder Cooper
Mark Lemley @marklemley.bsky.social · 09/01/2026
This new Atlantic piece cites my work with @afedercooper.bsky.social, Amy Cyphert, and others in discussing the complexities around AI memorization of training content www.theatlantic.com/technology/2...
theatlantic.com
AI’s Memorization Crisis
Large language models don’t “learn”—they copy. And that could change everything for the tech industry.
810034
A. Feder Cooper @afedercooper.bsky.social · 07/01/2026
We extracted (parts of) 12 books in experiments with 4 frontier-lab, production LLMs. We prompted the LLMs with a short prefix of a book and asked them to complete the rest. For Harry Potter and the Sorcerer’s Stone, we extracted 95.8% of the book from jailbroken Claude 3.7 Sonnet.
Screenshot of the paper title with authors listed
610336
A. Feder Cooper @afedercooper.bsky.social · 06/01/2026
3-minute explanation of my relationship to LLM memorization research m.youtube.com/watch?v=unfz...
m.youtube.com
ABBA - Mamma Mia (Official Music Video)
YouTube video by AbbaVEVO
040
Reposted by A. Feder Cooper
Kari Maaren @angrykem.bsky.social · 20/12/2025
The whole point of being an academic is that you need to be willing to spend three days creating a 700-word footnote that you will later delete. And you need to LIKE IT.
24897162
A. Feder Cooper @afedercooper.bsky.social · 05/12/2025
[NeurIPS '25] Our poster (1110) for “Comparison requires valid measurement: Rethinking attack success rate comparisons in AI red teaming ” is on Friday, December 5, 4:30pm-7:30pm PST in Exhibit Hall C,D,E. [openreview.net/forum?id=d7hqAhLvWG]
120
A. Feder Cooper @afedercooper.bsky.social · 05/12/2025
I’ll be hanging out at our poster on membership inference, but in the same slot Brian Lester will present our work on “The Common Pile v0.1: An 8TB Dataset of Public Domain and Openly Licensed Text” (poster 102)! [arxiv.org/abs/2506.05209]
152
A. Feder Cooper @afedercooper.bsky.social · 05/12/2025
[NeurIPS '25] Really excited to present “Exploring the limits of strong membership inference attacks on large language models” (poster 1300) this morning (Friday December 5, 11am-2pm in Exhibit Hall C-E)! [arxiv.org/abs/2505.18773]
120
A. Feder Cooper @afedercooper.bsky.social · 03/12/2025
[NeurIPS '25] Our oral slot and poster session on "Machine Unlearning Doesn't Do What You Think: Lessons for Generative AI Policy and Research" are tomorrow, December 4! [arxiv.org/abs/2412.06966] Oral: 3:30-4pm PST, Upper Level Ballroom 20AB Poster 1307: 4:30:-7:30pm PST, Exhibit Hall C-E
132
A. Feder Cooper @afedercooper.bsky.social · 01/12/2025
Tutorial tomorrow at 1:30PM PST! My talk slots will cover memorization + copying in models and their outputs, canonical extraction methods, and recent work with @marklemley.bsky.social and others on extracting pieces of memorized books from open-weight models. arxiv.org/abs/2505.12546
arxiv.org
Extracting memorized pieces of (copyrighted) books from open-weight language models
Plaintiffs and defendants in copyright lawsuits over generative AI often make sweeping, opposing claims about the extent to which large language models (LLMs) have memorized plaintiffs' protected expr...
094