Eleni Triantafillou

dblp:183/8430 · DBLP profile ↗
← Back
13ranked-venue papers
3as first author
9since 2021 · last 2025
0000-0002-2993-9674ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 12 · 3 first-author · 8 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
12 papers
Trustworthy machine learning · 51% Transfer learning and domain adaptation · 41% Planning, search and constraint satisfaction · 5%
Databases, data mining, and information retrieval
2 papers
Query processing and optimization · 49% Machine learning and data management · 21% Recommender systems · 21%
Network and information security
3 papers
Security and privacy of machine learning · 63% Privacy and data protection · 37%

Topics — the 26 heaviest of 28, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning
machine unlearning
3.242025
From Dormant to Deleted: Tamper-Resistant Unlearning Through Weight-Space Regularization · NeurIPS 2025
Selective Unlearning via Representation Erasure Using Domain Adversarial Training · ICLR 2025
What makes unlearning hard and what to do about it · NeurIPS 2024
Security and privacy of machine learning
machine unlearning
1.722025
Machine Unlearning Doesn't Do What You Think: Lessons for Generative AI Policy and Research · NeurIPS 2025
Leveraging Per-Instance Privacy for Machine Unlearning · ICML 2025
Machine learning › Transfer learning and domain adaptation
few-shot learning
1.642021
Learning a Universal Template for Few-shot Dataset Generalization · ICML 2021
Meta-Dataset: A Dataset of Datasets for Learning to Learn from Few Examples · ICLR 2020
Meta-Learning for Semi-Supervised Few-Shot Classification · ICLR (Poster) 2018
Machine learning › Transfer learning and domain adaptation
meta-learning
1.332021
Learning a Universal Template for Few-shot Dataset Generalization · ICML 2021
Meta-Dataset: A Dataset of Datasets for Learning to Learn from Few Examples · ICLR 2020
Meta-Learning for Semi-Supervised Few-Shot Classification · ICLR (Poster) 2018
Machine learning › Trustworthy machine learning
robustness
1.122025
From Dormant to Deleted: Tamper-Resistant Unlearning Through Weight-Space Regularization · NeurIPS 2025
Leveraging Per-Instance Privacy for Machine Unlearning · ICML 2025
Privacy and data protection
differential privacy
0.912025
Leveraging Per-Instance Privacy for Machine Unlearning · ICML 2025
Query processing and optimization
cardinality estimation
0.812024
Machine Unlearning in Learned Databases: An Experimental Analysis · Proc. ACM Manag. Data 2024
Machine learning and data management
learned database components
0.812024
Machine Unlearning in Learned Databases: An Experimental Analysis · Proc. ACM Manag. Data 2024
Recommender systems
machine unlearning
0.812024
Machine Unlearning in Learned Databases: An Experimental Analysis · Proc. ACM Manag. Data 2024
Query processing and optimization
selectivity estimation
0.812024
Machine Unlearning in Learned Databases: An Experimental Analysis · Proc. ACM Manag. Data 2024
Machine learning › Transfer learning and domain adaptation
domain shift
0.712023
In Search for a Generalizable Method for Source Free Domain Adaptation · ICML 2023
Machine learning › Trustworthy machine learning › out-of-distribution generalization
natural distribution shift
0.712023
In Search for a Generalizable Method for Source Free Domain Adaptation · ICML 2023
Machine learning › Trustworthy machine learning
privacy and data protection
0.712023
Towards Unbounded Machine Unlearning · NeurIPS 2023
Machine learning › Trustworthy machine learning › privacy
right to be forgotten
0.712023
Towards Unbounded Machine Unlearning · NeurIPS 2023
Machine learning › Transfer learning and domain adaptation › domain adaptation
source-free domain adaptation
0.712023
In Search for a Generalizable Method for Source Free Domain Adaptation · ICML 2023
Empirical software engineering › benchmarking
benchmark dataset
0.412020
Meta-Dataset: A Dataset of Datasets for Learning to Learn from Few Examples · ICLR 2020
Machine learning › Transfer learning and domain adaptation › meta-learning
few-shot meta-learning
0.312018
Meta-Learning for Semi-Supervised Few-Shot Classification · ICLR (Poster) 2018
Knowledge, reasoning and agents › Planning, search and constraint satisfaction
nondeterministic planning
0.312017
Non-Deterministic Planning with Temporally Extended Goals: LTL over Finite and Infinite Traces · AAAI 2017
Knowledge, reasoning and agents › Planning, search and constraint satisfaction › temporal planning
temporally extended goals
0.312017
Non-Deterministic Planning with Temporally Extended Goals: LTL over Finite and Infinite Traces · AAAI 2017
Machine learning › Transfer learning and domain adaptation › domain adaptation › distribution adaptation
adversarial domain adaptation
0.312025
Selective Unlearning via Representation Erasure Using Domain Adversarial Training · ICLR 2025
Machine learning › Transfer learning and domain adaptation
fine-tuning
0.312025
From Dormant to Deleted: Tamper-Resistant Unlearning Through Weight-Space Regularization · NeurIPS 2025
Privacy and data protection › privacy-enhancing technologies
data deletion
0.312025
Machine Unlearning Doesn't Do What You Think: Lessons for Generative AI Policy and Research · NeurIPS 2025
Query processing and optimization
approximate query processing
0.212024
Machine Unlearning in Learned Databases: An Experimental Analysis · Proc. ACM Manag. Data 2024
Security and privacy of machine learning
membership inference
0.212023
Towards Unbounded Machine Unlearning · NeurIPS 2023
Computer vision › Image recognition and object detection
image classification
0.112020
Meta-Dataset: A Dataset of Datasets for Learning to Learn from Few Examples · ICLR 2020
Logic in computer science › temporal logic
linear temporal logic
0.112017
Non-Deterministic Planning with Temporally Extended Goals: LTL over Finite and Infinite Traces · AAAI 2017

Methods — techniques the papers use, named apart from their topics

stochastic gradient langevin dynamics · 1.7rényi divergence · 1.7policy analysis · 1.7noisy gradient descent · 1.7fine-tuning · 1.7meta-learning · 1.2representation erasure · 0.9linear mode connectivity · 0.9l2 distance · 0.9gradient reversal · 0.9unlearning algorithms · 0.8retraining · 0.8membership inference attack · 0.7empirical evaluation · 0.7structured prediction · 0.3mean average precision optimization · 0.3compilation · 0.3LTL-to-automata translation · 0.3
YearPublicationVenuePosition
2025 Selective Unlearning via Representation Erasure Using Domain Adversarial Training
abstract
When deploying machine learning models in the real world, we often face the challenge of “unlearning” specific data points or subsets after training. Inspired by Domain-Adversarial Training of Neural Networks (DANN), we propose a novel algorithm,SURE, for targeted unlearning.SURE treats the process as a domain adaptation problem, where the “forget set” (data to be removed) and a validation set from the same distribution form two distinct domains. We train a domain classifier to discriminate between representations from the forget and validation sets.Using a gradient reversal strategy similar to DANN, we perform gradient updates to the representations to “fool” the domain classifier and thus obfuscate representations belonging to the forget set. Simultaneously, gradient descent is applied to the retain set (original training data minus the forget set) to preserve its classification performance. Unlike other unlearning approaches whose training objectives are built based on model outputs, SURE directly manipulates the representations.This is key to ensure robustness against a set of more powerful attacks than currently considered in the literature, that aim to detect which examples were unlearned through access to learned embeddings. Our thorough experiments reveal that SURE has a better unlearning quality to utility trade-off compared to other standard unlearning techniques for deep neural networks.
Nazanin Mohammadi Sepahvand, Eleni Triantafillou, Hugo Larochelle, Doina Precup, James J. Clark, Daniel M. Roy 0001, Gintare Karolina Dziugaite
ICLR2
2025 Leveraging Per-Instance Privacy for Machine Unlearning
abstract
We present a principled, per-instance approach to quantifying the difficulty of unlearning via fine-tuning. We begin by sharpening an analysis of noisy gradient descent for unlearning (Chien et al., 2024), obtaining a better utility–unlearning trade-off by replacing worst-case privacy loss bounds with per-instance privacy losses (Thudi et al., 2024), each of which bounds the (R ´enyi) divergence to retraining without an individual datapoint. To demonstrate the practical applicability of our theory, we present empirical results showing that our theoretical predictions are born out both for Stochastic Gradient Langevin Dynamics (SGLD) as well as for standard fine-tuning without explicit noise. We further demonstrate that per-instance privacy losses correlate well with several existing data difficulty metrics, while also identifying harder groups of data points, and introduce novel evaluation methods based on loss barriers. All together, our findings provide a foundation for more efficient and adaptive unlearning strategies tailored to the unique properties of individual data points.
Nazanin Mohammadi Sepahvand, Anvith Thudi, Berivan Isik, Ashmita Bhattacharyya, Nicolas Papernot, Eleni Triantafillou, Daniel M. Roy 0001, Gintare Karolina Dziugaite
ICML6
2025 Machine Unlearning Doesn't Do What You Think: Lessons for Generative AI Policy and Research
abstract
"Machine unlearning" is a popular proposed solution for mitigating the existence of content in an AI model that is problematic for legal or moral reasons, including privacy, copyright, safety, and more. For example, unlearning is often invoked as a solution for removing the effects of specific information from a generative-AI model's parameters, e.g., a particular individual's personal data or the inclusion of copyrighted content in the model's training data. Unlearning is also proposed as a way to prevent a model from generating targeted types of information in its outputs, e.g., generations that closely resemble a particular individual's data or reflect the concept of "Spiderman." Both of these goals--the targeted removal of information from a model and the targeted suppression of information from a model's outputs--present various technical and substantive challenges. We provide a framework for ML researchers and policymakers to think rigorously about these challenges, identifying several mismatches between the goals of unlearning and feasible implementations. These mismatches explain why unlearning is not a general-purpose solution for circumscribing generative-AI model behavior in service of broader positive impact.
A. Feder Cooper, Christopher A. Choquette-Choo, Miranda Bogen, Kevin Klyman, Matthew Jagielski, Katja Filippova, Ziyu Liu 0002, Alexandra Chouldechova, Jamie Hayes, Yangsibo Huang, Eleni Triantafillou, Peter Kairouz, Nicole Mitchell, Niloofar Mireshghallah, Abigail Z. Jacobs, James Grimmelmann, Vitaly Shmatikov, Christopher De Sa, Ilia Shumailov, Andreas Terzis, Solon Barocas, Jennifer Wortman Vaughan, danah boyd, Yejin Choi 0001, Oluwasanmi Koyejo, Fernando A. Delgado, Percy Liang, Daniel E. Ho, Pamela Samuelson, Miles Brundage, David Bau, Seth Neel, Hanna M. Wallach, Amy Cyphert, Mark A. Lemley, Nicolas Papernot, Katherine Lee
NeurIPS11
2025 From Dormant to Deleted: Tamper-Resistant Unlearning Through Weight-Space Regularization
abstract
Recent unlearning methods for LLMs are vulnerable to relearning attacks: knowledge believed-to-be-unlearned re-emerges by fine-tuning on a small set of (even seemingly-unrelated) examples. We study this phenomenon in a controlled setting for example-level unlearning in vision classifiers. We make the surprising discovery that forget-set accuracy can recover from around 50\% post-unlearning to nearly 100\% with fine-tuning on just the *retain* set---i.e., zero examples of the forget set. We observe this effect across a wide variety of unlearning methods, whereas for a model retrained from scratch excluding the forget set (gold standard), the accuracy remains at 50\%. We observe that resistance to relearning attacks can be predicted by weight-space properties, specifically, $L_2$-distance and linear mode connectivity between the original and the unlearned model. Leveraging this insight, we propose a new class of methods that achieve state-of-the-art resistance to relearning attacks.
Shoaib Ahmed Siddiqui, Adrian Weller, David Krueger 0001, Gintare Karolina Dziugaite, Michael C. Mozer, Eleni Triantafillou
NeurIPS6
2024 What makes unlearning hard and what to do about it
abstract
Machine unlearning is the problem of removing the effect of a subset of training data (the ``forget set'') from a trained model without damaging the model's utility e.g. to comply with users' requests to delete their data, or remove mislabeled, poisoned or otherwise problematic data. With unlearning research still being at its infancy, many fundamental open questions exist: Are there interpretable characteristics of forget sets that substantially affect the difficulty of the problem? How do these characteristics affect different state-of-the-art algorithms? With this paper, we present the first investigation aiming to answer these questions. We identify two key factors affecting unlearning difficulty and the performance of unlearning algorithms. Evaluation on forget sets that isolate these identified factors reveals previously-unknown behaviours of state-of-the-art algorithms that don't materialize on random forget sets. Based on our insights, we develop a framework coined Refined-Unlearning Meta-algorithm (RUM) that encompasses: (i) refining the forget set into homogenized subsets, according to different characteristics; and (ii) a meta-algorithm that employs existing algorithms to unlearn each subset and finally delivers a model that has unlearned the overall forget set. We find that RUM substantially improves top-performing unlearning algorithms. Overall, we view our work as an important step in (i) deepening our scientific understanding of unlearning and (ii) revealing new pathways to improving the state-of-the-art.
Kairan Zhao, Meghdad Kurmanji, George-Octavian Barbulescu, Eleni Triantafillou, Peter Triantafillou
NeurIPS4
2024 Machine Unlearning in Learned Databases: An Experimental Analysis
abstract
Machine learning models based on neural networks (NNs) are enjoying ever-increasing attention in the Database (DB) community, both in research and practice. However, an important issue has been largely overlooked, namely the challenge of dealing with the inherent, highly dynamic nature of DBs, where data updates are fundamental, highly-frequent operations (unlike, for instance, in ML classification tasks). Although some recent research has addressed the issues of maintaining updated NN models in the presence of new data insertions, the effects of data deletions (a.k.a., "machine unlearning") remain a blind spot. With this work, for the first time to our knowledge, we pose and answer the following key questions: What is the effect of unlearning algorithms on NN-based DB models? How do these effects translate to effects on key downstream DB tasks, such as cardinality/selectivity estimation (SE), approximate query processing (AQP), data generation (DG), and upstream tasks like data classification (DC)? What metrics should we use to assess the impact and efficacy of unlearning algorithms in learned DBs? Is the problem of (and solutions for) machine unlearning in DBs different from that of machine learning in DBs in the face of data insertions? Is the problem of (and solutions for) machine unlearning for DBs different from unlearning in the ML literature? what are the overhead and efficiency of unlearning algorithms (versus the naive solution of retraining from scratch)? What is the sensitivity of unlearning on batching delete operations (in order to reduce model updating overheads)? If we have a suitable unlearning algorithm (forgetting old knowledge), can we combine it with an algorithm handling data insertions (new knowledge) en route to solving the general adaptability/updatability requirement in learned DBs in the face of both data inserts and deletes? We answer these questions using a comprehensive set of experiments, various unlearning algorithms, a variety of downstream DB tasks (such as SE, AQP, and DG), and an upstream task (DC), each with different NNs, and using a variety of metrics (model-internal, and downstream-task specific) on a variety of real datasets, making this also a first key step towards a benchmark for learned DB unlearning.
Meghdad Kurmanji, Eleni Triantafillou, Peter Triantafillou
Proc. ACM Manag. Data2
2023 In Search for a Generalizable Method for Source Free Domain Adaptation
abstract
Source-free domain adaptation (SFDA) is compelling because it allows adapting an off-the-shelf model to a new domain using only unlabelled data. In this work, we apply existing SFDA techniques to a challenging set of naturally-occurring distribution shifts in bioacoustics, which are very different from the ones commonly studied in computer vision. We find existing methods perform differently relative to each other than observed in vision benchmarks, and sometimes perform worse than no adaptation at all. We propose a new simple method which outperforms the existing methods on our new shifts while exhibiting strong performance on a range of vision datasets. Our findings suggest that existing SFDA methods are not as generalizable as previously thought and that considering diverse modalities can be a useful avenue for designing more robust models.
Malik Boudiaf, Tom Denton, Bart van Merrienboer, Vincent Dumoulin, Eleni Triantafillou
ICML5
2023 Towards Unbounded Machine Unlearning
abstract
Deep machine unlearning is the problem of 'removing' from a trained neural network a subset of its training set. This problem is very timely and has many applications, including the key tasks of removing biases (RB), resolving confusion (RC) (caused by mislabelled data in trained models), as well as allowing users to exercise their 'right to be forgotten' to protect User Privacy (UP). This paper is the first, to our knowledge, to study unlearning for different applications (RB, RC, UP), with the view that each has its own desiderata, definitions for 'forgetting' and associated metrics for forget quality. For UP, we propose a novel adaptation of a strong Membership Inference Attack for unlearning. We also propose SCRUB, a novel unlearning algorithm, which is the only method that is consistently a top performer for forget quality across the different application-dependent metrics for RB, RC, and UP. At the same time, SCRUB is also consistently a top performer on metrics that measure model utility (i.e. accuracy on retained data and generalization), and is more efficient than previous work. The above are substantiated through a comprehensive empirical evaluation against previous state-of-the-art.
Meghdad Kurmanji, Peter Triantafillou, Jamie Hayes, Eleni Triantafillou
NeurIPS4
2021 Learning a Universal Template for Few-shot Dataset Generalization
abstract
Few-shot dataset generalization is a challenging variant of the well-studied few-shot classification problem where a diverse training set of several datasets is given, for the purpose of training an adaptable model that can then learn classes from \emph{new datasets} using only a few examples. To this end, we propose to utilize the diverse training set to construct a \emph{universal template}: a partial model that can define a wide array of dataset-specialized models, by plugging in appropriate components. For each new few-shot classification problem, our approach therefore only requires inferring a small number of parameters to insert into the universal template. We design a separate network that produces an initialization of those parameters for each given task, and we then fine-tune its proposed initialization via a few steps of gradient descent. Our approach is more parameter-efficient, scalable and adaptable compared to previous methods, and achieves the state-of-the-art on the challenging Meta-Dataset benchmark.
Eleni Triantafillou, Hugo Larochelle, Richard S. Zemel, Vincent Dumoulin
ICML1
2020 Meta-Dataset: A Dataset of Datasets for Learning to Learn from Few Examples
Eleni Triantafillou, Tyler Zhu, Vincent Dumoulin, Pascal Lamblin, Utku Evci, Kelvin Xu, Ross Goroshin, Carles Gelada, Kevin Swersky, Pierre-Antoine Manzagol, Hugo Larochelle
ICLR1
2018 Meta-Learning for Semi-Supervised Few-Shot Classification
Mengye Ren, Eleni Triantafillou, Sachin Ravi, Jake Snell, Kevin Swersky, Josh Tenenbaum, Hugo Larochelle, Richard S. Zemel
ICLR (Poster)2
2017 Non-Deterministic Planning with Temporally Extended Goals: LTL over Finite and Infinite Traces
abstract
Temporally extended goals are critical to the specification of a diversity of real-world planning problems. Here we examine the problem of non-deterministic planning with temporally extended goals specified in linear temporal logic (LTL), interpreted over either finite or infinite traces. Unlike existing LTL planners, we place no restrictions on our LTL formulae beyond those necessary to distinguish finite from infinite interpretations. We generate plans by compiling LTL temporally extended goals into problem instances described in the Planning Domain Definition Language that are solved by a state-of-the-art fully observable non-deterministic planner. We propose several different compilations based on translations of LTL to (Büchi) alternating or (Büchi) non-deterministic finite state automata, and evaluate various properties of the competing approaches. We address a diverse spectrum of LTL planning problems that, to this point, had not been solvable using AI planning techniques, and do so in a manner that demonstrates highly competitive performance.
Alberto Camacho, Eleni Triantafillou, Christian J. Muise, Jorge A. Baier, Sheila A. McIlraith
AAAI2
2017 Few-Shot Learning Through an Information Retrieval Lens
abstract
Few-shot learning refers to understanding new concepts from only a few examples. We propose an information retrieval-inspired approach for this problem that is motivated by the increased importance of maximally leveraging all the available information in this low-data regime. We define a training objective that aims to extract as much information as possible from each training batch by effectively optimizing over all relative orderings of the batch points simultaneously. In particular, we view each batch point as a `query' that ranks the remaining ones based on its predicted relevance to them and we define a model within the framework of structured prediction to optimize mean Average Precision over these rankings. Our method achieves impressive results on the standard few-shot classification benchmarks while is also capable of few-shot retrieval.
Eleni Triantafillou, Richard S. Zemel, Raquel Urtasun
NIPS1