Yves-Alexandre de Montjoye @yvesalexandre.bsky.social · 26/06/2025New work from the team on identifying memorized training samples for free 000
Yves-Alexandre de Montjoye @yvesalexandre.bsky.social · 20/06/2025Have you ever uploaded a PDF 📄 to ChatGPT 🤖 and asked for a summary? There is a chance the model followed hidden instructions inside the file instead of your prompt 😈 A thread 🧵 100
Yves-Alexandre de Montjoye @yvesalexandre.bsky.social · 20/05/2025🚨One (more!) fully-funded PhD position in our group at Imperial College London – Privacy & Machine Learning 🔐🤖 starting Oct 2025 Plz RT 🔄 111
Reposted by Yves-Alexandre de MontjoyeEmiliano De Cristofaro @emilianodc.com · 14/05/2025Huge congrats to @spalab.cs.ucr.edu's Georgi Ganev for receiving the Distinguished Paper Award at IEEE S&P for his work "The Inadequacy of Similarity-based Privacy Metrics: Privacy Attacks against “Truly Anonymous” Synthetic Datasets." Paper: arxiv.org/pdf/2312.051... 1184
Reposted by Yves-Alexandre de MontjoyeConference on Secure and Trustworthy Machine Learning @satml.org · 12/05/2025🌍 Help shape the future of SaTML! We are on the hunt for a 2026 host city - and you could lead the way. Submit a bid to become General Chair of the conference: forms.gle/vozsaXjCoPzc...forms.gleBid to host SaTML 2026Thank you for considering to host SaTML! SaTML has been organized as a 3 day conference so far. We are looking for volunteers interested in finding a venue to host the conference in 2026. By submitti... 068
Yves-Alexandre de Montjoye @yvesalexandre.bsky.social · 09/05/2025How do you know your synthetic data is anonymous 🥸? If your answer is “we checked Distance to Closest Record (DCR),” then… we might have bad news for you. Our latest work shows DCR and other proxy metrics to be inadequate measures of the privacy risk of synthetic data. 121
Yves-Alexandre de Montjoye @yvesalexandre.bsky.social · 07/05/2025Yes yes I know the fundamental law of information recovery and differential privacy, but if there are really just a few summary statistics, surely it should be anonymous? 🥸 I definitely used to think this, until we started looking into it two years ago. A thread 🧵arxiv.orgDeSIA: Attribute Inference Attacks Against Limited Fixed Aggregate StatisticsEmpirical inference attacks are a popular approach for evaluating the privacy risk of data release mechanisms in practice. While an active attack literature exists to evaluate machine learning models ... 100
Reposted by Yves-Alexandre de MontjoyeConference on Secure and Trustworthy Machine Learning @satml.org · 09/04/2025🏆 And the Best Paper Award at #SaTML25 goes to “SoK: Membership Inference Attacks on LLMs are Rushing Nowhere (and How to Fix It)” by Matthieu Meeus, Igor Shilov, Shubham Jain, Manuel Faysse, Marek Rei, Yves-Alexandre de Montjoye. Well deserved! 0104
Reposted by Yves-Alexandre de MontjoyeSune Lehmann @sunelehmann.com · 01/04/2025People of Copenhagen: On Tuesday April 8th, we have awesome privacy researcher @yvesalexandre.bsky.social visiting the group. Yves is a bold and creative scientist, and also former advisor to Marianne Vestager. Yves will give a talk at SODAS at 3pm that's open to the public (details below) 131
Yves-Alexandre de Montjoye @yvesalexandre.bsky.social · 10/01/2025🚨 In a new paper in @NatureComms, we propose a scaling law for identification technologies, from browser and device fingerprinting 🌐 to facial recognition 📸 and stylometry ✍️. A thread 🧵: 163
Yves-Alexandre de Montjoye @yvesalexandre.bsky.social · 17/12/2024Join us at Imperial College for an exciting event on the future of privacy in machine learning! 🔒🤖 The application for lightning talks is open. 🗓️ Date: Feb 4 @ 6pm 📍 Imperial College London 001
Reposted by Yves-Alexandre de MontjoyeScoiattolo @scarnecchia.net · 13/12/2024Can confirm: there is a reason we have to mask small cell counts, especially around rare diagnoses, even when using aggregated data. @yvesalexandre.bsky.social’s entire body of work is instructive herescholar.google.comYves-Alexandre de MontjoyeAssociate Professor at Imperial College London - Cited by 9,182 - Privacy - Machine learning - AI Safety - Memorization - Automated attacks 0306
Reposted by Yves-Alexandre de MontjoyeBogdan Kulynych @bogdankulynych.bsky.social · 10/12/2024The standard practice in differential privacy of targeting ε at small δ is extremely lossy for interpreting the level of privacy protection. For many real-world algorithms (e.g., for DP-SGD), we can do much better! We show how in the #NeurIPS2024 paper: arxiv.org/abs/2407.02191 Short summary👇arxiv.orgAttack-Aware Noise Calibration for Differential PrivacyDifferential privacy (DP) is a widely used approach for mitigating privacy risks when training machine learning models on sensitive data. DP mechanisms add noise during training to limit the risk of i... 193