EDBT 2026 Demo / reviewers in the wild / expert
Michael Aerni
dblp:299/1497
· DBLP profile ↗
5ranked-venue papers
3as first author
5since 2021 · last 2026
0000-0003-3276-2678ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 4 · 2 first-author · 4 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
4 papers |
Learning theory · 45% Language models and text generation · 32% Trustworthy machine learning · 9% | |
| Network and information security
2 papers |
Privacy and data protection · 58% Security and privacy of machine learning · 42% |
Topics — the 15 heaviest of 15, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Natural language and speech › Language models and text generation
multilingual language models |
1.0 | 1 | 2026 | Apertus: Democratizing Open and Compliant LLMs for Global Language Environments · ACL (1) 2026 |
Natural language and speech › Language models and text generation › large language model › knowledge in language models
memorization |
0.9 | 1 | 2025 | Measuring Non-Adversarial Reproduction of Training Data in Large Language Models · ICLR 2025 |
Security and privacy of machine learning › privacy attack
training data extraction |
0.9 | 1 | 2025 | Measuring Non-Adversarial Reproduction of Training Data in Large Language Models · ICLR 2025 |
Machine learning › Learning theory › over-parameterization
interpolation |
0.8 | 2 | 2023 | Strong inductive biases provably prevent harmless interpolation · ICLR 2023 Interpolation can hurt robust generalization even when there is no noise · NeurIPS 2021 |
Privacy and data protection
differential privacy |
0.8 | 1 | 2024 | Evaluations of Machine Learning Privacy Defenses are Misleading · CCS 2024 |
Privacy and data protection › differential privacy › differentially private deep learning
DP-SGD |
0.8 | 1 | 2024 | Evaluations of Machine Learning Privacy Defenses are Misleading · CCS 2024 |
Security and privacy of machine learning
membership inference |
0.8 | 1 | 2024 | Evaluations of Machine Learning Privacy Defenses are Misleading · CCS 2024 |
Privacy and data protection
privacy evaluation |
0.8 | 1 | 2024 | Evaluations of Machine Learning Privacy Defenses are Misleading · CCS 2024 |
Machine learning › Learning theory
inductive bias |
0.7 | 1 | 2023 | Strong inductive biases provably prevent harmless interpolation · ICLR 2023 |
Machine learning › Learning theory
generalization bounds |
0.5 | 1 | 2021 | Interpolation can hurt robust generalization even when there is no noise · NeurIPS 2021 |
Machine learning › Deep learning architectures and training
regularization |
0.5 | 1 | 2021 | Interpolation can hurt robust generalization even when there is no noise · NeurIPS 2021 |
Machine learning › Learning theory › statistical learning theory › regularization theory
ridge regularization |
0.5 | 1 | 2021 | Interpolation can hurt robust generalization even when there is no noise · NeurIPS 2021 |
Machine learning › Trustworthy machine learning › robustness › robust learning
robust generalization |
0.5 | 1 | 2021 | Interpolation can hurt robust generalization even when there is no noise · NeurIPS 2021 |
Machine learning › Efficient and distributed learning
distributed training |
0.3 | 1 | 2026 | Apertus: Democratizing Open and Compliant LLMs for Global Language Environments · ACL (1) 2026 |
Machine learning › Learning theory › over-parameterization › interpolation
minimum-norm interpolation |
0.1 | 1 | 2021 | Interpolation can hurt robust generalization even when there is no noise · NeurIPS 2021 |
Methods — techniques the papers use, named apart from their topics
prompt-based evaluation · 1.7membership inference · 0.8differential privacy · 0.8generalization theory · 0.7theoretical analysis · 0.5ridge regularization · 0.5
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Apertus: Democratizing Open and Compliant LLMs for Global Language EnvironmentsabstractAlejandro Hernández-Cano, Alexander Hägele, Allen Hao Huang, Angelika Romanou, Antoni-Joan Solergibert, Barna Pásztor, Bettina Messmer, Dhia Garbaya, Eduard Frank Ďurech, Ido Hakimi, Juan Garcia Giraldo, Mete Ismayilzada, Negar Foroutan, Skander Moalla, Tiancheng Chen, Vinko Sabolčec, Yixuan Xu, Michael Aerni, Badr AlKhamissi, Inés Altemir Marinas, Mohammad Hossein Amani, Matin Ansaripour, Ilia Badanin, Harold Benoit, Emanuela Boros, Nicholas John Browning, Fabian Bösch, Maximilian Böther, Niklas Canova, Camille Challier, Clément Charmillot, Jonathan Coles, Jan Milan Deriu, Arnout Devos, Lukas Drescher, Daniil Dzenhaliou, Maud Ehrmann, Dongyang Fan, Simin Fan, Silin Gao, Miguel Gila, María Grandury, Diba Hashemi, Alexander Miserlis Hoyle, Jiaming Jiang, Mark Klein, Andrei Kucharavy, Anastasiia Kucherenko, Frederike Lübeck, Roman Machacek, Theofilos Ioannis Manitaras, Andreas Marfurt, Kyle Matoba, Simon Matrenok, Henrique Mendonça, Fawzi Roberto Mohamed, Syrielle Montariol, Luca Mouchel, Sven Najem-Meyer, Jingwei Ni, Gennaro Oliva, Matteo Pagliardini, Elia Palme, Andrei Panferov, Léo Paoletti, Marco Passerini, Ivan Pavlov, Auguste Poiroux, Kaustubh Ponkshe, Nathan Ranchin, Javier Rando, Mathieu Sauser, Jakhongir Saydaliev, Mukhammadali Sayfiddinov, Marian Schneider, Stefano Schuppli, Marco Scialanga, Andrei Semenov, Kumar Shridhar, Raghav Singhal, Anna Sotnikova, Alexander Sternfeld, Ayush Kumar Tarun, Paul Teiletche, Jannis Vamvas, Xiaozhe Yao, Hao Zhao, Alexander Ilic, Ana Klimovic, Andreas Krause, Caglar Gulcehre, David Rosenthal, Elliott Ash, Florian Tramèr, Joost VandeVondele, Livio Veraldi, Martin Rajman, Thomas C. Schulthess, Torsten Hoefler, Antoine Bosselut, Martin Jaggi, Imanol Schlag. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Alejandro Hernández-Cano, Alexander Hägele, Allen Hao Huang, Angelika Romanou, Antoni-Joan Solergibert i Llaquet, Barna Pásztor, Bettina Messmer, Dhia Garbaya, Eduard Durech, Ido Hakimi, Juan Garcia Giraldo, Mete Ismayilzada, Negar Foroutan Eghlidi, Skander Moalla, Tiancheng Chen, Vinko Sabolcec, Yixuan Even Xu, Michael Aerni, Badr AlKhamissi, Ines Altemir Marinas, Mohammad Hossein Amani, Matin Ansaripour, Ilia Badanin, Harold Benoit, Emanuela Boros, Nicholas John Browning, Fabian Bösch, Maximilian Böther, Niklas Canova, Camille Challier, Clément Charmillot, Jonathan Coles, Jan Deriu, Arnout Devos, Lukas Drescher, Daniil Dzenhaliou, Maud Ehrmann, Dongyang Fan, Simin Fan, Silin Gao, Miguel Gila, María Grandury, Diba Hashemi, Alexander Miserlis Hoyle, Jiaming Jiang, Mark Klein 0002, Andrei Kucharavy, Anastasiia Kucherenko, Frederike Lübeck, Roman Machacek, Theofilos Ioannis Manitaras, Andreas Marfurt, Kyle Matoba, Simon Matrenok, Henrique Mendonça, Fawzi Roberto Mohamed, Syrielle Montariol, Luca Mouchel, Sven Najem-Meyer, Jingwei Ni, Gennaro Oliva, Matteo Pagliardini, Elia Palme, Andrei Panferov, Léo Paoletti, Marco Passerini, Ivan Pavlov, Auguste Poiroux, Kaustubh Ponkshe, Nathan Ranchin, Javier Rando, Mathieu Sauser, Jakhongir Saydaliev, Mukhammadali Sayfiddinov, Marian Schneider, Stefano Schuppli, Marco Scialanga, Andrei Semenov, Kumar Shridhar, Raghav Singhal, Anna Sotnikova, Alexander Sternfeld, Ayush K. Tarun, Paul Teiletche, Jannis Vamvas, Xiaozhe Yao, Alexander Ilic, Ana Klimovic, Andreas Krause 0001, Caglar Gulcehre, David Rosenthal, Elliott Ash, Florian Tramèr, Joost VandeVondele, Livio Veraldi, Martin Rajman, Thomas C. Schulthess, Torsten Hoefler, Antoine Bosselut, Martin Jaggi, Imanol Schlag |
ACL (1) | 18 |
| 2025 | Measuring Non-Adversarial Reproduction of Training Data in Large Language ModelsabstractLarge language models memorize parts of their training data. Memorizing short snippets and facts is required to answer questions about the world and to be fluent in any language. But models have also been shown to reproduce long verbatim sequences of memorized text when prompted by a motivated adversary. In this work, we investigate an intermediate regime of memorization that we call non-adversarial reproduction, where we quantify the overlap between model responses and pretraining data when responding to natural and benign prompts. For a variety of innocuous prompt categories (e.g., writing a letter or a tutorial), we show that up to 15% of the text output by popular conversational language models overlaps with snippets from the Internet. In worst cases, we find generations where 100% of the content can be found exactly online. For the same tasks, we find that human-written text has far less overlap with Internet data. We further study whether prompting strategies can close this reproduction gap between models and humans. While appropriate prompting can reduce non-adversarial reproduction on average, we find that mitigating worst-case reproduction of training data requires stronger defenses—even for benign interactions. Michael Aerni, Javier Rando, Edoardo Debenedetti, Nicholas Carlini, Daphne Ippolito, Florian Tramèr |
ICLR | 1 |
| 2024 | Evaluations of Machine Learning Privacy Defenses are MisleadingabstractEmpirical defenses for machine learning privacy forgo the provable guarantees of differential privacy in the hope of achieving higher utility while resisting realistic adversaries. We identify severe pitfalls in existing empirical privacy evaluations (based on membership inference attacks) that result in misleading conclusions. In particular, we show that prior evaluations fail to characterize the privacy leakage of the most vulnerable samples, use weak attacks, and avoid comparisons with practical differential privacy baselines. In 5 case studies of empirical privacy defenses, we find that prior evaluations underestimate privacy leakage by an order of magnitude. Under our stronger evaluation, none of the empirical defenses we study are competitive with a properly tuned, high-utility DP-SGD baseline (with vacuous provable guarantees). Michael Aerni, Jie Zhang 0107, Florian Tramèr |
CCS | 1 |
| 2023 | Strong inductive biases provably prevent harmless interpolation
Michael Aerni, Marco Milanta, Konstantin Donhauser, Fanny Yang |
ICLR | 1 |
| 2021 | Interpolation can hurt robust generalization even when there is no noiseabstractNumerous recent works show that overparameterization implicitly reduces variance for min-norm interpolators and max-margin classifiers. These findings suggest that ridge regularization has vanishing benefits in high dimensions. We challenge this narrative by showing that, even in the absence of noise, avoiding interpolation through ridge regularization can significantly improve generalization. We prove this phenomenon for the robust risk of both linear regression and classification, and hence provide the first theoretical result on \emph{robust overfitting}. Konstantin Donhauser, Alexandru Tifrea, Michael Aerni, Reinhard Heckel, Fanny Yang |
NeurIPS | 3 |