Sign in

George Kaissis

@g-k.ai
80 followers 80 following 19 posts

Professor for Human-Centred Transformative AI @ Hasso-Plattner-Institut. Previously @ Google DeepMind, Imperial College London, TU Munich. 🇪🇺 🏳️‍🌈 www.g-k.ai

PostsRepliesMedia
George Kaissis @g-k.ai · 01/09/2026
@simonwillison.net To mitigate the (pernicious) effects of bike-pelicanmaxxing that's widespread in current-generation LLMs, I propose a new benchmark of "A Pelican waiting in line to get fish and chips" as per youtu.be/grIJjMCh0cw?...
youtu.be
Pelican Waiting in Line for Fish & Chips
YouTube video by Jack Simpson
000
Reposted by George Kaissis
arXiv cs.LG Machine Learning @cslg-bot.bsky.social · 11/08/2026
Kristian Schwethelm, Daniel Rueckert, Georgios Kaissis: Depth-adaptive Inference of Looped Language Models via Continuous Depth Batching arxiv.org/abs/2608.09444 arxiv.org/pdf/2608.09444 arxiv.org/html/2608.09444
011
George Kaissis @g-k.ai · 11/08/2026
Check out our new preprint on Continuous Depth Batching! Looped LMs promise depth-adaptive inference: easy tokens get less compute, hard ones get more. But adaptive depth breaks standard batching. We address this problem, reaching up to 99% of the theoretical speedup. arxiv.org/abs/2608.09444
arxiv.org
Depth-adaptive Inference of Looped Language Models via Continuous Depth Batching
A main promise of looped language models (LMs) is depth-adaptive inference. By iterating a block of shared layers a variable number of times, the model can use less compute for "easy" tokens and more ...
120
Reposted by George Kaissis
A. Feder Cooper @afedercooper.bsky.social · 18/07/2026
in our new preprint (with @marklemley.bsky.social and others), we revisit what it means to run valid extraction experiments from first principles. i recently gave a talk on this work at ICML, and we'll be wrapping up the preprint soon monkey-emeritus.github.io
monkey-emeritus.github.io
Extractable Memorization From First Principles
It’s time to retire the ‘monkey at the typewriter.’ We revisit extractable memorization from first principles: whether a model can produce any string was never the question — what matters is how many ...
0133
Reposted by George Kaissis
Nature Portfolio @natureportfolio.nature.com · 25/06/2026
Individuals whose data are used to train medical #AI models may be at risk of being identified in cyber-attacks, according to a paper in Nature. Underrepresented groups may face disproportionately higher risks of having their data compromised. go.nature.com/3QEx4AU #medsky 🧪
This is figure 1, which shows MIA and evaluation strategies.
1105
George Kaissis @g-k.ai · 24/06/2026
Thrilled to share our @nature.com paper, led by the superb Moritz Knolle and a brilliant team! Medical AI can look private in aggregate while individual patients, often the underrepresented, remain highly exposed. I'm humbled and deeply grateful to all my coauthors! www.nature.com/articles/s41...
nature.com
Disparate privacy risks from medical AI - Nature
AI models for medical diagnostics are vulnerable to membership inference attacks.
121
Reposted by George Kaissis
Ted @desfontain.es · 18/05/2026
✨ New guest blog post ✨ by Bogdan Kulynych on how to report differential privacy guarantees for ML deployments, explaining the relationship between DP definitions and attacker success along the way: desfontain.es/blog/reporting-privac… 🌈
desfontain.es
Guest post: Goodbye (ε,δ), hello μ! Reporting privacy guarantees in machine learning - Ted is writing things
Why is Gaussian DP a much better compact representation of privacy guarantees than (ε,δ)-DP.
054
Reposted by George Kaissis
Differential Privacy Papers @dppapers.bsky.social · 21/04/2026
Tight Auditing of Differential Privacy in MST and AIM Georgi Ganev, Meenatchi Sundaram Muthu Selva Annamalai, Bogdan Kulynych arxiv.org/abs/2604.18352
Tight Auditing of Differential Privacy in MST and AIM

Georgi Ganev, Meenatchi Sundaram Muthu Selva Annamalai, Bogdan Kulynych

http://arxiv.org/abs/2604.18352

State-of-the-art Differentially Private (DP) synthetic data generators such as MST and AIM are widely used, yet tightly auditing their privacy guarantees remains challenging. We introduce a Gaussian Differential Privacy (GDP)-based auditing framework that measures privacy via the full false-positive/false-negative tradeoff. Applied to MST and AIM under worst-case settings, our method provides the first tight audits in the strong-privacy regime. For $(ε,δ)=(1,10^{-2})$, we obtain $μ_{emp}\approx0.43$ vs. implied $μ=0.45$, showing a small theory-practice gap.
  Our code is publicly available: https://github.com/sassoftware/dpmm.
021
Reposted by George Kaissis
Florian Hölzl @hlzl.eurosky.social · 08/04/2026
👋 We have two fully-funded PhD positions open at @hpi.bsky.social with the Chair of Human-Centered Transformative AI. 1) On efficient transformer architectures with a focus on recurrent approaches jobs.plattnerfoundation.org/HPI/job/Pots... 1/2
jobs.plattnerfoundation.org
PhD Candidate (f/m/x) - Efficient Reasoning Architectures for Medical AI
PhD Candidate (f/m/x) - Efficient Reasoning Architectures for Medical AI
154
Reposted by George Kaissis
Bogdan Kulynych @bogdankulynych.bsky.social · 23/03/2026
A Gaussian mechanism with ε = 6 can be less private than one with ε = 8. This points to a problem with how we report privacy guarantees in machine learning. A thread 🧵
194
Reposted by George Kaissis
Marton Szep @martonszep.bsky.social · 10/03/2026
Thrilled to present our paper "Unintended Memorization of Sensitive Information in Fine-Tuned Language Models" at #EACL2026 in Rabat! 🇲🇦 w/ J. Marin Ruiz, G. Kaissis, P. Seidl, R. v. Eisenhart-Rothe, F. Hinterwimmer & @danielrueckert.bsky.social. Read here: arxiv.org/abs/2601.174...
A promotional graphic for an oral presentation at the EACL 2026 conference in Morocco. The background features a sunny, historic Moroccan stone fortress gate with palm trees, a clear blue sky, and decorative geometric tile patterns in the corners. Text in the top left indicates the event is at Palais Des Congres, Rabat, from March 24-29, 2026. A banner across the middle displays the presentation title: "Unintended Memorization of Sensitive Information in Fine-Tuned Language Models." Below the title is a flowchart diagram illustrating how Large Language Models (LLMs) trained on sensitive medical text can inadvertently memorize Personally Identifiable Information (PII), and how a "True-Prefix Attack" can extract a patient's name even when fine-tuned for downstream tasks that do not contain PII. Text at the very bottom reads, "Oral Presentation: March 27 | 11:00 AM | Salle La Palmeraie."
252
Reposted by George Kaissis
Differential Privacy Papers @dppapers.bsky.social · 05/02/2026
Optimal conversion from Rényi Differential Privacy to $f$-Differential Privacy Anneliese Riess, Juan Felipe Gomez, Flavio du Pin Calmon, Julia Anne Schnabel, Georgios Kaissis arxiv.org/abs/2602.04562
Optimal conversion from Rényi Differential Privacy to $f$-Differential Privacy

Anneliese Riess, Juan Felipe Gomez, Flavio du Pin Calmon, Julia Anne Schnabel, Georgios Kaissis

http://arxiv.org/abs/2602.04562

We prove the conjecture stated in Appendix F.3 of [Zhu et al. (2022)]: among all conversion rules that map a Rényi Differential Privacy (RDP) profile $τ\mapsto ρ(τ)$ to a valid hypothesis-testing trade-off $f$, the rule based on the intersection of single-order RDP privacy regions is optimal. This optimality holds simultaneously for all valid RDP profiles and for all Type I error levels $α$. Concretely, we show that in the space of trade-off functions, the tightest possible bound is $f_{ρ(\cdot)}(α) = \sup_{τ\geq 0.5} f_{τ,ρ(τ)}(α)$: the pointwise maximum of the single-order bounds for each RDP privacy region. Our proof unifies and sharpens the insights of [Balle et al. (2019)], [Asoodeh et al. (2021)], and [Zhu et al. (2022)]. Our analysis relies on a precise geometric characterization of the RDP privacy region, leveraging its convexity and the fact that its boundary is determined exclusively by Bernoulli mechanisms. Our results establish that the "intersection-of-RDP-privacy-regions" rule is not only valid, but optimal: no other black-box conversion can uniformly dominate it in the Blackwell sense, marking the fundamental limit of what can be inferred about a mechanism's privacy solely from its RDP guarantees.
031
Reposted by George Kaissis
A. Feder Cooper @afedercooper.bsky.social · 07/01/2026
We extracted (parts of) 12 books in experiments with 4 frontier-lab, production LLMs. We prompted the LLMs with a short prefix of a book and asked them to complete the rest. For Harry Potter and the Sorcerer’s Stone, we extracted 95.8% of the book from jailbroken Claude 3.7 Sonnet.
Screenshot of the paper title with authors listed
610336
Reposted by George Kaissis
Julia Schnabel @ja-schnabel.bsky.social · 08/11/2025
Let’s today not only commemorate Rosalind Franklin, but also Raymond Gosling, her @kingscollegelondon.bsky.social postgraduate who took photo 51…
021
George Kaissis @g-k.ai · 04/11/2025
I am overjoyed to announce that I have joined HPI as a full professor for Human-Centred Transformative AI. I am looking forward to working with my amazing new and current collaborators and would like to deeply thank everyone who has been part of the journey that led me here! @hpi.bsky.social
140
Reposted by George Kaissis
Hasso-Plattner-Institut @hpi.bsky.social · 03/11/2025
Zum 1. November trat Prof. Dr. med. Georg Kaissis seine Professur für #DigitalHealth: Human-Centred Transformative AI an. Sein Forschungsschwerpunkt: die Entwicklung der nächsten Generation multimodaler #KI-Modelle. Mehr Infos zur neuen Professur: hpi.de/artikel/prof...
Neue Professur für #DigitalHealth: Prof. Dr. med. Georg Kaissis
151
Reposted by George Kaissis
TUM AI in Medicine Lab @tum-aim-lab.bsky.social · 03/11/2025
We celebrated the 5th anniversary of our research chair at @tum.de! 💙🥂 It's been an incredible journey of research and collaboration. Thank you to everyone who has made this possible. We are very much looking forward to the next years to come! #AIMAnniversary #AIMNews
052
Reposted by George Kaissis
Differential Privacy Papers @dppapers.bsky.social · 20/10/2025
VaultGemma: A Differentially Private Gemma Model Amer Sinha, Thomas Mesnard, Ryan McKenna, Daogao Liu, Christopher A. Choquette-Choo, Yangsibo Huang, Da Yu, George Kaissis, Zachary Charles, Ruibo Liu, Lynn Chua, Pritish Kamath, Pasin Manurangsi, Steve He, Chiyuan ... arxiv.org/abs/2510.15001
VaultGemma: A Differentially Private Gemma Model

Amer Sinha, Thomas Mesnard, Ryan McKenna, Daogao Liu, Christopher A. Choquette-Choo, Yangsibo Huang, Da Yu, George Kaissis, Zachary Charles, Ruibo Liu, Lynn Chua, Pritish Kamath, Pasin Manurangsi, Steve He, Chiyuan Zhang, Badih Ghazi, Borja De Balle Pigem, Prem Eruvbetine, Tris Warkentin, Armand Joulin, Ravi KumarAmer Sinha, Thomas Mesnard, Ryan McKenna, Daogao Liu, Christopher A. Choquette-Choo, Yangsibo Huang, Da Yu, George Kaissis, Zachary Charles, Ruibo Liu, Lynn Chua, Pritish Kamath, Pasin Manurangsi, Steve He, Chiyuan Zhang, Badih Ghazi, Borja De Balle Pigem, Prem Eruvbetine, Tris Warkentin, Armand Joulin, Ravi Kumar

http://arxiv.org/abs/2510.15001

We introduce VaultGemma 1B, a 1 billion parameter model within the Gemma
family, fully trained with differential privacy. Pretrained on the identical
data mixture used for the Gemma 2 series, VaultGemma 1B represents a
significant step forward in privacy-preserving large language models. We openly
release this model to the community
021
George Kaissis @g-k.ai · 17/09/2025
It has been a privilege to work with so many amazing colleagues across Google and Google DeepMind to build VaultGemma, an LLM trained from scratch with Differential Privacy. Weights are openly available! Check it out here: research.google/blog/vaultge...
research.google
VaultGemma: The world's most capable differentially private LLM
000
Reposted by George Kaissis
Zeynep Akata @zeynepakata.bsky.social · 28/08/2025
Due to physical resource constraints, we currently estimate that around 300–400 of the candidate papers recommended for acceptance by the ACs will need to be rejected. We seek the support of our 41 SACs in addressing this distributed optimization problem in a fair and professional manner.
9203
Reposted by George Kaissis
Zeynep Akata @zeynepakata.bsky.social · 28/08/2025
NeurIPS has decided to do what ICLR did: As a SAC I received the message 👇 This is wrong! If the review process cannot handle so many papers, the conference needs yo split instead of arbitrarily rejecting 400 papers.
810518
Reposted by George Kaissis
Konrad Rieck 🌈 @rieck.mlsec.org · 27/08/2025
📣 Researchers in AI security, privacy & fairness: It's time to share your latest work! The SaTML 2026 submission site is live 👉 hotcrp.satml.org 🗓️ Deadline: Sept 24, 2025 @satml.org
hotcrp.satml.org
SaTML 2026
053
Reposted by George Kaissis
NeurIPS Conference @neuripsconf.bsky.social · 16/07/2025
NeurIPS is endorsing EurIPS, an independently-organized meeting which will offer researchers an opportunity to additionally present NeurIPS work in Europe concurrently with NeurIPS. Read more in our blog post and on the EurIPS website: blog.neurips.cc/2025/07/16/n... eurips.cc
eurips.cc
eurips.cc
A NeurIPS-endorsed conference in Europe held in Copenhagen, Denmark
112439
Reposted by George Kaissis
Bogdan Kulynych @bogdankulynych.bsky.social · 10/07/2025
New preprint on the most precise as of yet mapping between differential privacy and common operational notions of privacy risk used in practice:
021
Reposted by George Kaissis
Differential Privacy Papers @dppapers.bsky.social · 23/06/2025
The Hitchhiker's Guide to Efficient, End-to-End, and Tight DP Auditing Meenatchi Sundaram Muthu Selva Annamalai, Borja Balle, Jamie Hayes, Georgios Kaissis, Emiliano De Cristofaro arxiv.org/abs/2506.16666
The Hitchhiker's Guide to Efficient, End-to-End, and Tight DP Auditing

Meenatchi Sundaram Muthu Selva Annamalai, Borja Balle, Jamie Hayes, Georgios Kaissis, Emiliano De Cristofaro

http://arxiv.org/abs/2506.16666

This paper systematizes research on auditing Differential Privacy (DP)
techniques, aiming to identify key insights into the current state of the art
and open challenges. First, we introduce a comprehensive framework for
reviewing work in the field and establish three cross-contextual desiderata
that DP audits should target--namely, efficiency, end-to-end-ness, and
tightness. Then, we systematize the modes of operation of state-of-the-art DP
auditing techniques, including threat models, attacks, and evaluation
functions. This allows us to highlight key details overlooked by prior work,
analyze the limiting factors to achieving the three desiderata, and identify
open research problems. Overall, our work provides a reusable and systematic
methodology geared to assess progress in the field and identify friction points
and future directions for our community to focus on.
041
Reposted by George Kaissis
TUM AI in Medicine Lab @tum-aim-lab.bsky.social · 12/06/2025
Responsible medical AI demands patient-level privacy. Our recent #TPDP '25 paper extends Differential Privacy #DP beyond individual data points to protect entire patient profiles. 🧠 📄 Read the paper: tinyurl.com/k9fz456a 🎥 Watch the video: tinyurl.com/2jx528m5
tpdp.journalprivacyconfidentiality.org
031
Reposted by George Kaissis
Paul Hager @paulhager.bsky.social · 11/06/2025
Going to be at CVPR the next couple of days presenting our paper „A Tale of Two Classes: Adapting Supervised Contrastive Learning to Binary Imbalanced Datasets“. arxiv.org/abs/2503.17024 Always happy to meet anyone working on representation learning or tabular DL and medical data
arxiv.org
A Tale of Two Classes: Adapting Supervised Contrastive Learning to Binary Imbalanced Datasets
Supervised contrastive learning (SupCon) has proven to be a powerful alternative to the standard cross-entropy loss for classification of multi-class balanced datasets. However, it struggles to learn ...
073
Reposted by George Kaissis
Hasso-Plattner-Institut @hpi.bsky.social · 30/05/2025
Markiert es euch im Kalender: Die IOI 2027 kommt ans HPI! 🎉 Zum ersten Mal seit 1992 kommt die Internationale Informatik-Olympiade (IOI) zurück nach Deutschland und wir sind in Kooperation mit Bundesweite Informatikwettbewerbe (BWINF) stolze Gastgeber des renommierten Wettbewerbs.
Grafik die auf die Internationale Informatik Olympiade 2027 hinweist. Datum: 12.–19. September 2027Grafik die auf die Internationale Informatik Olympiade 2027 hinweist. Datum: 12.–19. September 2027Grafik die auf die Internationale Informatik Olympiade 2027 hinweist. Datum: 12.–19. September 2027
032
George Kaissis @g-k.ai · 27/05/2025
Check out our new pre-print "Strong Membership Inference Attacks on Massive Datasets and (Moderately) Large Language Models", joint work with fantastic colleagues from Google (DeepMind) and many other great institutions! Find it here: arxiv.org/abs/2505.18773
arxiv.org
Strong Membership Inference Attacks on Massive Datasets and (Moderately) Large Language Models
State-of-the-art membership inference attacks (MIAs) typically require training many reference models, making it difficult to scale these attacks to large pre-trained language models (LLMs). As a resu...
042
George Kaissis @g-k.ai · 26/05/2025
Check out our new pre-print "Redirection for Erasing Memory (REM): Towards a universal unlearning method for corrupted data", joint work with excellent colleagues from Google DeepMind, Google Research and University of Cambridge. Check it out here! arxiv.org/abs/2505.17730
arxiv.org
Redirection for Erasing Memory (REM): Towards a universal unlearning method for corrupted data
Machine unlearning is studied for a multitude of tasks, but specialization of unlearning methods to particular tasks has made their systematic comparison challenging. To address this issue, we propose...
020
Reposted by George Kaissis
TUM AI in Medicine Lab @tum-aim-lab.bsky.social · 22/05/2025
We are incredibly proud of Prof @danielrueckert.bsky.social for being elected as Fellow of the Royal Society! Well deserved and a testament to your dedication to research 🎉
182
Reposted by George Kaissis
European Commission @ec.europa.eu · 14/05/2025
Now, it's time to up the ante. We are committed to enshrining scientific freedom in EU law, creating a 7-year ‘super grant’ to attract top researchers, and expanding support for the most promising scientists. More → europa.eu/!TTbWbJ
37717
Reposted by George Kaissis
TUM AI in Medicine Lab @tum-aim-lab.bsky.social · 20/04/2025
Data attribution is crucial for debugging models and detecting low quality data (spotting mislabeled samples, bias etc.). But many methods aren't mathematically sound and don’t scale. But how could we improve this for large models? 1/n
141
Reposted by George Kaissis
Paul Hager @paulhager.bsky.social · 01/04/2025
Excited to share: “A Tale of Two Classes: Adapting Supervised Contrastive Learning to Binary Imbalanced Datasets” has been accepted to #CVPR2025! 🎉 Paper: lnkd.in/esKRqF5p Code: lnkd.in/eZFvDA5Q (Thread incoming 👇)
1125
Reposted by George Kaissis
Serge Belongie @serge.belongie.com · 30/03/2025
Would you present your next NeurIPS paper in Europe instead of traveling to San Diego (US) if this was an option? Søren Hauberg (DTU) and I would love to hear the answer through this poll: (1/6)
docs.google.com
NeurIPS participation in Europe
We seek to understand if there is interest in being able to attend NeurIPS in Europe, i.e. without travelling to San Diego, US. In the following, assume that it is possible to present accepted papers ...
6279161
George Kaissis @g-k.ai · 20/03/2025
Congratulations to my revered mentor and dear friend @danielrueckert.bsky.social for this great honour and for the outstanding and enduring achievements that underlie it!
130
Reposted by George Kaissis
Differential Privacy Papers @dppapers.bsky.social · 17/03/2025
$( varepsilon, δ)$ Considered Harmful: Best Practices for Reporting Differential Privacy Guarantees Juan Felipe Gomez, Bogdan Kulynych, Georgios Kaissis, Jamie Hayes, Borja Balle, Antti Honkela arxiv.org/abs/2503.10945
$( varepsilon, δ)$ Considered Harmful: Best Practices for Reporting Differential Privacy Guarantees
Juan Felipe Gomez, Bogdan Kulynych, Georgios Kaissis, Jamie Hayes, Borja Balle, Antti Honkela
http://arxiv.org/abs/2503.10945
Current practices for reporting the level of differential privacy (DP)
guarantees for machine learning (ML) algorithms provide an incomplete and
potentially misleading picture of the guarantees and make it difficult to
compare privacy levels across different settings. We argue for using Gaussian
differential privacy (GDP) as the primary means of communicating DP guarantees
in ML, with the full privacy profile as a secondary option in case GDP is too
inaccurate. Unlike other widely used alternatives, GDP has only one parameter,
which ensures easy comparability of guarantees, and it can accurately capture
the full privacy profile of many important ML applications. To support our
claims, we investigate the privacy profiles of state-of-the-art DP large-scale
image classification, and the TopDown algorithm for the U.S. Decennial Census,
observing that GDP fits the profiles remarkably well in all three cases.
Although GDP is ideal for reporting the final guarantees, other formalisms
(e.g., privacy loss random variables) are needed for accurate privacy
accounting. We show that such intermediate representations can be efficiently
converted to GDP with minimal loss in tightness.
0125
Reposted by George Kaissis
Helmholtz Munich @helmholtzmunich.bsky.social · 12/03/2025
#FUTURE-AI: International Experts Define Guidelines for Trustworthy Healthcare AI 📝 👉Learn more: t1p.de/2rgfh 👉Check out the interview with Prof. Julia Schnabel & Dr. Georgios Kaissis: t1p.de/e9g6a #TrustworthyAI
International Experts Establish FUTURE-AI Guidelines for Trustworthy Healthcare AI
165
Reposted by George Kaissis
TUM AI in Medicine Lab @tum-aim-lab.bsky.social · 12/03/2025
Huge congratulations to our two PhD students, Tamara Müller and @zilleralex.bsky.social , on completing their doctoral journeys! Your hard work and dedication have paid off. Wishing you both all the best for your future endeavors!
182
Reposted by George Kaissis
TUM AI in Medicine Lab @tum-aim-lab.bsky.social · 05/03/2025
#WACV2025 just wrapped up and our group was also present, with a novel framework for improving image-to-graph transformation! Have a look at how Alex Berger et al. enable cross-domain & cross-dimension learning to outperform standard transfer learning on vessel graph extraction! 🚀 shorturl.at/v6SJi
084
Reposted by George Kaissis
Helmholtz Munich @helmholtzmunich.bsky.social · 05/03/2025
🎙️Interview with Prof Julia Schnabel, #HelmholtzMunich: FUTURE-AI – Making #AI in Healthcare Trustworthy by Design 👉 Learn how FUTURE-AI is paving the way for transparent & deployable medical AI tools: t1p.de/e9g6a @ja-schnabel.bsky.social @helmholtzai.bsky.social @www.helmholtz.de #TrustworthyAI
195
Reposted by George Kaissis
David Picard @davidpicard.eurosky.social · 01/03/2025
European alternatives for digital services. Sovereignty matters.
1186
Reposted by George Kaissis
A. Feder Cooper @afedercooper.bsky.social · 02/02/2025
Registration for CSLaw 2025 is now open! Please share far and wide! Early bird prices are available until February 24. The main conference will begin March 25! Register here: web.cvent.com/event/dbf97d...
web.cvent.com
4th ACM Symposium on Computer Science & Law (CS&Law 2025).
<div class="ag87-crtemvc-hsbk"><div class="css-vsf5of"><p style="text-align:center;" class="carina-rte-public-DraftStyleDefault-block">The ACM Symposium on Computer .
133
George Kaissis @g-k.ai · 16/02/2025
I unceremoniously departed from Twitter/X and I'm here now 😀.
070