Sign in

Nicolas Papernot

@nicolaspapernot.bsky.social
703 followers 236 following 29 posts

Security and Privacy of Machine Learning at UofT, Vector Institute, and Google 🇨🇦🇫🇷🇪🇺 Co-Director of Canadian AI Safety Institute (CAISI) Research Program at CIFAR. Opinions mine

PostsRepliesMedia
Reposted by Nicolas Papernot
University of Toronto @utoronto.ca · 10/09/2026
For #UofT researcher Nicolas Papernot, the secret to strengthening cybersecurity in the age of AI is transparency – sharing information about threats & allowing researchers to probe these systems before attackers do. 💻 uoft.me/cE4
Images shows Nicolas Papernot
052
Reposted by Nicolas Papernot
Schwartz Reisman Institute for Technology and Society @torontosri.bsky.social · 08/09/2026
What do new AI capabilities mean for Canada's critical digital infrastructure, economy, & national security? Join @nicolaspapernot.bsky.social, @alexposadzki.bsky.social, Avi Goldfarb (@utoronto.ca), Kathryn Hume (@vectorinstitute.ai ), & Samir Chhabra (ISED) to find out! Register: shorturl.at/RSOhK
Join Samir Chhabra (Innovation, Science and Economic Development Canada), Kathryn Hume (Vector Institute), Alexandra Posadzki (The Globe and Mail), and University of Toronto's Avi Goldfarb and Nicolas Papernot in-person on 10 September for a discussion on AI-powered threats and Canada's future.
002
Reposted by Nicolas Papernot
Conference on Secure and Trustworthy Machine Learning @satml.org · 09/09/2026
The submission server for #SaTML2027 is now open! There are also some changes to the Call for Papers, diffs are indicated on the website. Dates: Mandatory abstract deadline: Sep 22 Paper deadline: Sep 29 satml.org
196
Reposted by Nicolas Papernot
Schwartz Reisman Institute for Technology and Society @torontosri.bsky.social · 03/09/2026
How is AI changing the cybersecurity threat landscape? Join @nicolaspapernot.bsky.social and @alexposadzki.bsky.social in-person on Sept. 10 to find out! 📅 Sept. 10, 2026 🕓 4:00 PM – 5:30 PM 📍 Schwartz Reisman Innovation Campus Limited seats available! Register: nicolaspapernot.rsvpify.com
Nicolas Papernot, associate professor in the University of Toronto’s Department Electrical and Computer Engineering and an expert in AI security.
021
Reposted by Nicolas Papernot
Conference on Secure and Trustworthy Machine Learning @satml.org · 23/07/2026
On top of our Call for Papers, #SaTML2027 has a Call for Competitions and a Call for Workshops (first time ever!!). Dates (easy to remember, same for both) Deadline: August 28, 2026 Notifications: September 18, 2026 Topics can be anything in trustworthy and secure ML!
112
Reposted by Nicolas Papernot
Conference on Secure and Trustworthy Machine Learning @satml.org · 29/06/2026
We're pleased to announce that #SaTML2027 will be in Reykjavik, Iceland! Thanks to General Chair Giovanni Apruzzese for making the arrangements. The conference will be in early May 2027. Get your submissions ready: the deadline will be September 29, 2026. Details on the new website: satml.org
074
Nicolas Papernot @nicolaspapernot.bsky.social · 03/06/2026
We discovered that it is possible to create an AI-driven computer worm using an open-weight AI model that anyone can download. This research was conducted in a lab walled off from the outside world, and shared only after removing details that could aid bad actors. www.nytimes.com/2026/06/02/t...
nytimes.com
Scientists Find Way to Supercharge Dangerous Computer ‘Worms’ With A.I.
183
Reposted by Nicolas Papernot
Conference on Secure and Trustworthy Machine Learning @satml.org · 06/04/2026
SaTML is looking for a host for #SaTML2027! If you're interested in bringing SaTML to a city near you, please fill out this form by April 15! 🏘️🏙️🏡🌆 docs.google.com/forms/d/e/1F...
075
Nicolas Papernot @nicolaspapernot.bsky.social · 22/09/2025
Thank you to Samsung for the AI Researcher of 2025 award! I'm privileged to collaborate with many talented students & postdoctoral fellows @utoronto.ca @vectorinstitute.ai . This would not have been possible without them! It was a great honour to receive the award from @yoshuabengio.bsky.social !
1141
Reposted by Nicolas Papernot
Konrad Rieck 🌈 @rieck.mlsec.org · 03/09/2025
Three weeks to go until the SaTML 2026 deadline! ⏰ We look forward to your work on security, privacy, and fairness in AI. 🗓️ Deadline: Sept 24, 2025 We have also updated our Call for Papers with a statement on LLM usage, check it out: 👉 satml.org/call-for-pap... @satml.org
IEEE Conference on Secure and Trustworthy Machine Learning
Technical University of Munich, Germany
March 23–25, 2026
044
Nicolas Papernot @nicolaspapernot.bsky.social · 23/07/2025
Thank you to @schmidtsciences.bsky.social for funding our lab's work on cryptographic approaches for verifiable guarantees in ML systems and for connecting us to other groups working on these questions!
030
Reposted by Nicolas Papernot
Stephan Rabanser @stvrb.bsky.social · 11/07/2025
📄 Selective Prediction Via Training Dynamics Paper ➡️ arxiv.org/abs/2205.13532 Workshop ➡️ 3rd Workshop on High-dimensional Learning Dynamics (HiLD) Poster ➡️ West Meeting Room 118-120 on Sat 19 Jul 10:15 a.m. — 11:15 a.m. & 4:45 p.m. — 5:30 p.m.
101
Reposted by Nicolas Papernot
Stephan Rabanser @stvrb.bsky.social · 11/07/2025
📄 Suitability Filter: A Statistical Framework for Classifier Evaluation in Real-World Deployment Settings (✨ oral paper ✨) Paper ➡️ arxiv.org/abs/2505.22356 Poster ➡️ E-504 on Thu 17 Jul 4:30 p.m. — 7 p.m. Oral Presentation ➡️ West Ballroom C on Thu 17 Jul 4:15 p.m. — 4:30 p.m.
101
Reposted by Nicolas Papernot
Stephan Rabanser @stvrb.bsky.social · 11/07/2025
📄 Confidential Guardian: Cryptographically Prohibiting the Abuse of Model Abstention TL;DR ➡️ We show that a model owner can artificially introduce uncertainty and provide a detection mechanism. Paper ➡️ arxiv.org/abs/2505.23968 Poster ➡️ E-1002 on Wed 16 Jul 11 a.m. — 1:30 p.m.
101
Reposted by Nicolas Papernot
ePrint Updates @eprint.ing.bot · 02/06/2025
Secure Noise Sampling for Differentially Private Collaborative Learning (Olive Franzese, Congyu Fang, Radhika Garg, Somesh Jha, Nicolas Papernot, Xiao Wang, Adam Dziedzic) ia.cr/2025/1025
Abstract. Differentially private stochastic gradient descent (DP-SGD) trains machine learning (ML) models with formal privacy guarantees for the training set by adding random noise to gradient updates. In collaborative learning (CL), where multiple parties jointly train a model, noise addition occurs either (i) before or (ii) during secure gradient aggregation. The first option is deployed in distributed DP methods, which require greater amounts of total noise to achieve security, resulting in degraded model utility. The second approach preserves model utility but requires a secure multiparty computation (MPC) protocol. Existing methods for MPC noise generation require tens to hundreds of seconds of runtime per noise sample because of the number of parties involved. This makes them impractical for collaborative learning, which often requires thousands or more samples of noise in each training step.

We present a novel protocol for MPC noise sampling tailored to the collaborative learning setting. It works by constructing an approximation of the distribution of interest which can be efficiently sampled by a series of table lookups. Our method achieves significant runtime improvements and requires much less communication compared to previous work, especially at higher numbers of parties. It is also highly flexible – while previous MPC sampling methods tend to be optimized for specific distributions, we prove that our method can generically sample noise from statistically close approximations of arbitrary discrete distributions. This makes it compatible with a wide variety of DP mechanisms. Our experiments demonstrate the efficiency and utility of our method applied to a discrete Gaussian mechanism for differentially private collaborative learning. For 16 parties, we achieve a runtime of 0.06 seconds and 11.59 MB total communication per sample, a 230× runtime improvement and 3× less communication compared to the prior state-of-the-art for sampling from discrete Gaussian distribution in MPC.
Image showing part 2 of abstract.
021
Nicolas Papernot @nicolaspapernot.bsky.social · 05/06/2025
Excited to share the first batch of research projects funded through the Canadian AI Safety Institute's research program at CIFAR! The projects will tackle topics ranging from misinformation to safety in AI applications to scientific discovery. Learn more: cifar.ca/cifarnews/20...
050
Reposted by Nicolas Papernot
Stephan Rabanser @stvrb.bsky.social · 02/06/2025
📢 New ICML 2025 paper! Confidential Guardian: Cryptographically Prohibiting the Abuse of Model Abstention 🤔 Think model uncertainty can be trusted? We show that it can be misused—and how to stop it! Meet Mirage (our attack💥) & Confidential Guardian (our defense🛡️). 🧵1/10
133
Nicolas Papernot @nicolaspapernot.bsky.social · 27/05/2025
If you are submitting to @ieeessp.bsky.social this year, a friendly reminder that there is an abstract submission deadline this Thursday May 29 (AoE). More details: sp2026.ieee-security.org/cfpapers.html
020
Reposted by Nicolas Papernot
Asia Biega @asiabiega.bsky.social · 23/05/2025
As part of the theme Societal Aspects of Securing the Digital Society, I will be hiring PhD students and postdocs at #MPI-SP, focusing in particular on the computational and sociotechnical aspects of technology regulations and the governance of emerging tech. Get in touch if interested.
023
Reposted by Nicolas Papernot
Conference on Secure and Trustworthy Machine Learning @satml.org · 12/05/2025
🌍 Help shape the future of SaTML! We are on the hunt for a 2026 host city - and you could lead the way. Submit a bid to become General Chair of the conference: forms.gle/vozsaXjCoPzc...
forms.gle
Bid to host SaTML 2026
Thank you for considering to host SaTML! SaTML has been organized as a 3 day conference so far. We are looking for volunteers interested in finding a venue to host the conference in 2026. By submitti...
068
Reposted by Nicolas Papernot
Tudor Cebere @tcebere.bsky.social · 21/04/2025
Excited to be in Singapore for ICLR, presenting our work on privacy auditing (w/ Aurélien & @nicolaspapernot.bsky.social). If you are interested in differential privacy/privacy auditing/security for ML, drop by (#497 26 Apr 10-12:30 pm) or let's grab a coffee! ☕ openreview.net/forum?id=xzK...
openreview.net
Tighter Privacy Auditing of DP-SGD in the Hidden State Threat Model
Machine learning models can be trained with formal privacy guarantees via differentially private optimizers such as DP-SGD. In this work, we focus on a threat model where the adversary has access...
041
Reposted by Nicolas Papernot
Conference on Secure and Trustworthy Machine Learning @satml.org · 09/04/2025
👋 Welcome to #SaTML25! Kicking things off with opening remarks --- excited for a packed schedule of keynotes, talks and competitions on secure and trustworthy machine learning.
163
Reposted by Nicolas Papernot
University of Toronto @utoronto.ca · 01/04/2025
Karina Vold says the rapid development of AI systems has left both philosophers & computer scientists grappling with difficult questions. #UofT 💻 uoft.me/bsp
Image shows Karina Vold
2138
Nicolas Papernot @nicolaspapernot.bsky.social · 13/03/2025
Congratulations again, Stephan, on this brilliant next step! Looking forward to what you will accomplish with @randomwalker.bsky.social & @msalganik.bsky.social!
060
Nicolas Papernot @nicolaspapernot.bsky.social · 12/03/2025
The Canadian AI Safety Institute (CAISI) Research Program at CIFAR is now accepting Expressions of Interest for Solution Networks in AI Safety under two themes: * Mitigating the Safety Risks of Synthetic Content * AI Safety in the Global South. cifar.ca/ai/ai-and-so...
073
Nicolas Papernot @nicolaspapernot.bsky.social · 05/03/2025
I will be giving a talk at the MPI-IS @maxplanckcampus.bsky.social in Tübingen next week (March 12 @ 11am). The talk will cover my group's overall approach to trust in ML, with a focus on our work on unlearning and how to obtain verifiable guarantees of trust. Details: is.mpg.de/events/speci...
174
Nicolas Papernot @nicolaspapernot.bsky.social · 31/01/2025
For Canadian colleagues, CIFAR and the CPI at UWaterloo are sponsoring a special issue "Artificial Intelligence Safety and Public Policy in Canada" in Canadian Public Policy / Analyse de politiques More details: www.cpp-adp.ca
cpp-adp.ca
English Menu
The December issue is available. o
051
Nicolas Papernot @nicolaspapernot.bsky.social · 31/01/2025
One of the first components of the CAISI (Canadian AI Safety Institute) research program has just launched: a call for Catalyst Grant Projects on AI Safety. Funding: up to 100K for one year Deadline to apply: February 27, 2025 (11:59, AoE) More details: cifar.ca/ai/cifar-ai-...
cifar.ca
CIFAR AI Catalyst Grants - CIFAR
Encouraging new collaborations and original research projects in the field of machine learning, as well as its application to different sectors of science and society.
082
Reposted by Nicolas Papernot
Konrad Rieck 🌈 @rieck.mlsec.org · 21/01/2025
The list of accepted papers for @satml.org 2025 is now online: 📃 satml.org/accepted-pap... If you’re intrigued by secure and trustworthy machine learning, join us April 9-11 in Copenhagen, Denmark 🇩🇰. Find more details here: 👉 satml.org/attend/
satml.org
Accepted Papers
0157
Nicolas Papernot @nicolaspapernot.bsky.social · 14/01/2025
If you work at the intersection of security, privacy, and machine learning, or more broadly how to trust ML, SaTML is a small-scale conference with highly-relevant work where you'll be able to have high-quality conversations with colleagues working in your area.
2125
Reposted by Nicolas Papernot
Conference on Secure and Trustworthy Machine Learning @satml.org · 20/12/2024
Hello world! The SaTML conference is now flying the blue skies! SaTML is the IEEE Conference on Secure and Trustworthy Machine Learning. The 2025 iteration, chaired by @someshjha.bsky.social @mlsec.org, will be in beautiful Copenhagen! Follow for the latest updates on the conference! satml.org
0166
Nicolas Papernot @nicolaspapernot.bsky.social · 12/12/2024
I look forward to co-directing the Canadian AI Safety Institute (CAISI) Research Program at CIFAR with @catherineregis.bsky.social We will be designing the program in the coming months and will soon share ways to get involved with this new community. Read more here: cifar.ca/cifarnews/20...
4305