EDBT 2026 Demo / reviewers in the wild / expert
Tom Blanchard
dblp:120/3340
· DBLP profile ↗
2ranked-venue papers
0as first author
2since 2021 · last 2026
0000-0002-6701-6969ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
2 papers |
Generative modeling · 49% Language models and text generation · 26% Trustworthy machine learning · 25% | |
| Network and information security
1 paper |
Privacy and data protection · 100% |
Topics — the 7 heaviest of 8, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Machine learning › Generative modeling
diffusion model |
1.0 | 1 | 2026 | Beautiful Images, Toxic Words: Understanding and Addressing Offensive Text in Generated Images · AAAI 2026 |
Machine learning › Trustworthy machine learning
generative model safety |
1.0 | 1 | 2026 | Beautiful Images, Toxic Words: Understanding and Addressing Offensive Text in Generated Images · AAAI 2026 |
Machine learning › Generative modeling › diffusion model
text-to-image generation |
1.0 | 1 | 2026 | Beautiful Images, Toxic Words: Understanding and Addressing Offensive Text in Generated Images · AAAI 2026 |
Privacy and data protection
differential privacy |
0.8 | 1 | 2024 | Open LLMs are Necessary for Current Private Adaptations and Outperform their Closed Alternatives · NeurIPS 2024 |
Privacy and data protection
privacy-preserving machine learning |
0.8 | 1 | 2024 | Open LLMs are Necessary for Current Private Adaptations and Outperform their Closed Alternatives · NeurIPS 2024 |
Privacy and data protection › privacy evaluation
privacy-utility tradeoff |
0.8 | 1 | 2024 | Open LLMs are Necessary for Current Private Adaptations and Outperform their Closed Alternatives · NeurIPS 2024 |
Natural language and speech › Language models and text generation › large language model safety
safety fine-tuning |
0.3 | 1 | 2026 | Beautiful Images, Toxic Words: Understanding and Addressing Offensive Text in Generated Images · AAAI 2026 |
Methods — techniques the papers use, named apart from their topics
gradient-based adaptation · 1.5differential privacy · 1.5safety fine-tuning · 1.0fine-tuning · 1.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Beautiful Images, Toxic Words: Understanding and Addressing Offensive Text in Generated ImagesabstractState-of-the-art Diffusion Models (DMs) produce highly realistic images. While prior work has successfully mitigated Not Safe For Work (NSFW) content in the visual domain, we identify a novel threat: the generation of NSFW text embedded within images. This includes offensive language, such as insults, racial slurs, and sexually explicit terms, posing significant risks to users. We show that all state-of-the-art DMs (e.g., SD3, SDXL, Flux, DeepFloyd IF) are vulnerable to this issue. Through extensive experiments, we demonstrate that existing mitigation techniques, effective for visual content, fail to prevent harmful text generation while substantially degrading benign text generation. As an initial step toward addressing this threat, we introduce a novel fine-tuning strategy that targets only the text-generation layers in DMs. Therefore, we construct a safety fine-tuning dataset by pairing each NSFW prompt with two images: one with the NSFW term, and another where that term is replaced with a carefully crafted benign alternative while leaving the image unchanged otherwise. By training on this dataset, the model learns to avoid generating harmful text while preserving benign content and overall image quality. Finally, to advance research in the area, we release ToxicBench, an open-source benchmark for evaluating NSFW text generation in images. It includes our curated fine-tuning dataset, a set of harmful prompts, new evaluation metrics, and a pipeline that assesses both NSFW-ness and text and image quality. Our benchmark aims to guide future efforts in mitigating NSFW text generation in text-to-image models, thereby contributing to their safe deployment. Tom Blanchard, Adam Dziedzic, Franziska Boenisch |
AAAI | 2 |
| 2024 | Open LLMs are Necessary for Current Private Adaptations and Outperform their Closed AlternativesabstractWhile open Large Language Models (LLMs) have made significant progress, they still fall short of matching the performance of their closed, proprietary counterparts, making the latter attractive even for the use on highly *private* data.
Recently, various new methods have been proposed to adapt closed LLMs to private data without leaking private information to third parties and/or the LLM provider.
In this work, we analyze the privacy protection and performance of the four most recent methods for private adaptation of closed LLMs.
By examining their threat models and thoroughly comparing their performance under different privacy levels according to differential privacy (DP), various LLM architectures, and multiple datasets for classification and generation tasks, we find that: (1) all the methods leak query data, i.e., the (potentially sensitive) user data that is queried at inference time, to the LLM provider, (2) three out of four methods also leak large fractions of private training data to the LLM provider while the method that protects private data requires a local open LLM, (3) all the methods exhibit lower performance compared to three private gradient-based adaptation methods for *local open LLMs*, and (4) the private adaptation methods for closed LLMs incur higher monetary training and query costs than running the alternative methods on local open LLMs.
This yields the conclusion that, to achieve truly *privacy-preserving LLM adaptations* that yield high performance and more privacy at lower costs, taking into account current methods and models, one should use open LLMs. Vincent Hanke, Tom Blanchard, Franziska Boenisch, Iyiola E. Olatunji, Michael Backes 0001, Adam Dziedzic |
NeurIPS | 2 |