Skip to content

Florian Tramr

Publication record assembled from the DBLP archive of ranked conferences.

Papers indexed

46

Venues

10

Active years

2015–2026

Best venue rank

A*

Where they publish

Papers

46 indexed papers, newest first.

YearVenueTitleAuthors
2026ACLApertus: Democratizing Open and Compliant LLMs for Global Language Environments.Alejandro Hernndez-Cano, Alexander Hgele, Allen Hao Huang, Angelika Romanou, Antoni-Joan Solergibert i Llaquet, Barna Psztor, Bettina Messmer, Dhia Garbaya, Eduard Frank Durech, Ido Hakimi, Juan Garcia Giraldo, Mete Ismayilzada, Negar Foroutan, Skander Moalla, Tiancheng Chen, Vinko Sabolcec, Yixuan Even Xu, Michael Aerni, Badr AlKhamissi, Ines Altemir Marinas, Mohammad Hossein Amani, Matin Ansaripour, Ilia Badanin, Harold Benoit, Emanuela Boros, Nicholas John Browning, Fabian Bsch, Maximilian Bther, Niklas Canova, Camille Challier, Clment Charmillot, Jonathan Coles, Jan Milan Deriu, Arnout Devos, Lukas Drescher, Daniil Dzenhaliou, Maud Ehrmann, Dongyang Fan, Simin Fan, Silin Gao, Miguel Gila, Mara Grandury, Diba Hashemi, Alexander Miserlis Hoyle, Jiaming Jiang, Mark Klein, Andrei Kucharavy, Anastasiia Kucherenko, Frederike Lbeck, Roman Machacek, Theofilos Ioannis Manitaras, Andreas Marfurt, Kyle Matoba, Simon Matrenok, Henrique Mendona, Fawzi Roberto Mohamed, Syrielle Montariol, Luca Mouchel, Sven Najem-Meyer, Jingwei Ni, Gennaro Oliva, Matteo Pagliardini, Elia Palme, Andrei Panferov, Lo Paoletti, Marco Passerini, Ivan Pavlov, Auguste Poiroux, Kaustubh Ponkshe, Nathan Ranchin, Javier Rando, Mathieu Sauser, Jakhongir Saydaliev, Mukhammadali Sayfiddinov, Marian Schneider, Stefano Schuppli, Marco Scialanga, Andrei Semenov, Kumar Shridhar, Raghav Singhal, Anna Sotnikova, Alexander Sternfeld, Ayush Kumar Tarun, Paul Teiletche, Jannis Vamvas, Xiaozhe Yao, Hao Zhao, Alexander Ilic, Ana Klimovic, Andreas Krause, Caglar Gulcehre, David Rosenthal, Elliott Ash, Florian Tramr, Joost VandeVondele, Livio Veraldi, Martin Rajman, Thomas C. Schulthess, Torsten Hoefler, Antoine Bosselut, Martin Jaggi, Imanol Schlag
2026AsiaCCSAuditing Differentially Private Interactive Database Systems.Sagar Sharma, Wanrong Zhang, Qiang Yan, Florian Tramr
2025ICLRMeasuring Non-Adversarial Reproduction of Training Data in Large Language Models.Michael Aerni, Javier Rando, Edoardo Debenedetti, Nicholas Carlini, Daphne Ippolito, Florian Tramr
2025ICLRAdversarial Perturbations Cannot Reliably Protect Artists From Generative AI.Robert Hnig, Javier Rando, Nicholas Carlini, Florian Tramr
2025ICLRScalable Extraction of Training Data from Aligned, Production Language Models.Milad Nasr, Javier Rando, Nicholas Carlini, Jonathan Hayase, Matthew Jagielski, A. Feder Cooper, Daphne Ippolito, Christopher A. Choquette-Choo, Florian Tramr, Katherine Lee
2025ICLRAdversarial Search Engine Optimization for Large Language Models.Fredrik Nestaas, Edoardo Debenedetti, Florian Tramr
2025ICLRConsistency Checks for Language Model Forecasters.Daniel Paleka, Abhimanyu Pallavi Sudhir, Alejandro Alvarez, Vineeth Bhat, Adam Shen, Evan Wang, Florian Tramr
2025ICLRPersistent Pre-training Poisoning of LLMs.Yiming Zhang, Javier Rando, Ivan Evtimov, Jianfeng Chi, Eric Michael Smith, Nicholas Carlini, Florian Tramr, Daphne Ippolito
2025ICMLAutoAdvExBench: Benchmarking Autonomous Exploitation of Adversarial Example Defenses.Nicholas Carlini, Edoardo Debenedetti, Javier Rando, Milad Nasr, Florian Tramr
2025ICMLExploring and Mitigating Adversarial Manipulation of Voting-Based Leaderboards.Yangsibo Huang, Milad Nasr, Anastasios Nikolas Angelopoulos, Nicholas Carlini, Wei-Lin Chiang, Christopher A. Choquette-Choo, Daphne Ippolito, Matthew Jagielski, Katherine Lee, Ken Liu, Ion Stoica, Florian Tramr, Chiyuan Zhang
2025ICMLThe Jailbreak Tax: How Useful are Your Jailbreak Outputs?Kristina Nikolic, Luze Sun, Jie Zhang, Florian Tramr
2025SPMembership Inference Attacks on Sequence Models.Lorenzo Rossi, Michael Aerni, Jie Zhang, Florian Tramr
2025SPSoK: Watermarking for AI-Generated Content.Xuandong Zhao, Sam Gunn, Miranda Christ, Jaiden Fairoze, Andrs Fbrega, Nicholas Carlini, Sanjam Garg, Sanghyun Hong, Milad Nasr, Florian Tramr, Somesh Jha, Lei Li, Yu-Xiang Wang, Dawn Song
2024CCSEvaluations of Machine Learning Privacy Defenses are Misleading.Michael Aerni, Jie Zhang, Florian Tramr
2024ICLRUniversal Jailbreak Backdoors from Poisoned Human Feedback.Javier Rando, Florian Tramr
2024ICMLStealing part of a production language model.Nicholas Carlini, Daniel Paleka, Krishnamurthy Dj Dvijotham, Thomas Steinke, Jonathan Hayase, A. Feder Cooper, Katherine Lee, Matthew Jagielski, Milad Nasr, Arthur Conmy, Eric Wallace, David Rolnick, Florian Tramr
2024ICMLPrivacy Backdoors: Stealing Data with Corrupted Pretrained Models.Shanglun Feng, Florian Tramr
2024ICMLExtracting Training Data From Document-Based VQA Models.Francesco Pinto, Nathalie Rauschmayr, Florian Tramr, Philip Torr, Federico Tombari
2024ICMLPosition: Considerations for Differentially Private Learning with Large-Scale Public Pretraining.Florian Tramr, Gautam Kamath, Nicholas Carlini
2024SPPoisoning Web-Scale Training Datasets is Practical.Nicholas Carlini, Matthew Jagielski, Christopher A. Choquette-Choo, Daniel Paleka, Will Pearce, Hyrum S. Anderson, Andreas Terzis, Kurt Thomas, Florian Tramr
2023ICLRQuantifying Memorization Across Neural Language Models.Nicholas Carlini, Daphne Ippolito, Matthew Jagielski, Katherine Lee, Florian Tramr, Chiyuan Zhang
2023ICLR(Certified!!) Adversarial Robustness for Free!Nicholas Carlini, Florian Tramr, Krishnamurthy (Dj) Dvijotham, Leslie Rice, Mingjie Sun, J. Zico Kolter
2023ICLRMeasuring Forgetting of Memorized Training Examples.Matthew Jagielski, Om Thakkar, Florian Tramr, Daphne Ippolito, Katherine Lee, Nicholas Carlini, Eric Wallace, Shuang Song, Abhradeep Guha Thakurta, Nicolas Papernot, Chiyuan Zhang
2023ICMLPreprocessors Matter! Realistic Decision-Based Attacks on Machine Learning Systems.Chawin Sitawarin, Florian Tramr, Nicholas Carlini
2023INLGPreventing Generation of Verbatim Memorization in Language Models Gives a False Sense of Privacy.Daphne Ippolito, Florian Tramr, Milad Nasr, Chiyuan Zhang, Matthew Jagielski, Katherine Lee, Christopher A. Choquette-Choo, Nicholas Carlini
2023SPSNAP: Efficient Extraction of Private Properties with Poisoning.Harsh Chaudhari, John Abascal, Alina Oprea, Matthew Jagielski, Florian Tramr, Jonathan R. Ullman
2022CCSAISec '22: 15th ACM Workshop on Artificial Intelligence and Security.Ambra Demontis, Xinyun Chen, Florian Tramr
2022CCSTruth Serum: Poisoning Machine Learning Models to Reveal Their Secrets.Florian Tramr, Reza Shokri, Ayrton San Joaquin, Hoang Le, Matthew Jagielski, Sanghyun Hong, Nicholas Carlini
2022ICLRLarge Language Models Can Be Strong Differentially Private Learners.Xuechen Li, Florian Tramr, Percy Liang, Tatsunori Hashimoto
2022ICLRData Poisoning Won't Save You From Facial Recognition.Evani Radiya-Dixit, Sanghyun Hong, Nicholas Carlini, Florian Tramr
2022ICMLDetecting Adversarial Examples Is (Nearly) As Hard As Classifying Them.Florian Tramr
2022SPMembership Inference Attacks From First Principles.Nicholas Carlini, Steve Chien, Milad Nasr, Shuang Song, Andreas Terzis, Florian Tramr
2021DSNFourth International Workshop on Dependable and Secure Machine Learning - DSML 2021.Hui Xu, Guanpeng Li, Homa Alemzadeh, Rakesh Bobba, Varun Chandrasekaran, David E. Evans, Nicolas Papernot, Karthik Pattabiraman, Florian Tramr
2021ICLRDifferentially Private Learning Needs Better Features (or Much More Data).Florian Tramr, Dan Boneh
2021ICMLLabel-Only Membership Inference Attacks.Christopher A. Choquette-Choo, Florian Tramr, Nicholas Carlini, Nicolas Papernot
2021NDSSSquirRL: Automating Attack Analysis on Blockchain Incentive Mechanisms with Deep Reinforcement Learning.Charlie Hou, Mingxun Zhou, Yan Ji, Phil Daian, Florian Tramr, Giulia Fanti, Ari Juels
2021SPIs Private Learning Possible with Instance Encoding?Nicholas Carlini, Samuel Deng, Sanjam Garg, Somesh Jha, Saeed Mahloujifar, Mohammad Mahmoody, Abhradeep Thakurta, Florian Tramr
2020DSNThird International Workshop on Dependable and Secure Machine Learning - DSML 2020.Homa Alemzadeh, Rakesh Bobba, Varun Chandrasekaran, David E. Evans, Nicolas Papernot, Karthik Pattabiraman, Florian Tramr
2020ICMLFundamental Tradeoffs between Invariance and Sensitivity to Adversarial Perturbations.Florian Tramr, Jens Behrmann, Nicholas Carlini, Nicolas Papernot, Jrn-Henrik Jacobsen
2020SPSentiNet: Detecting Localized Universal Attacks Against Deep Learning Systems.Edward Chou, Florian Tramr, Giancarlo Pellegrino
2019CCSAdVersarial: Perceptual Ad Blocking meets Adversarial Machine Learning.Florian Tramr, Pascal Dupr, Gili Rusak, Giancarlo Pellegrino, Dan Boneh
2019ICLRSlalom: Fast, Verifiable and Private Execution of Neural Networks in Trusted Hardware.Florian Tramr, Dan Boneh
2018ICLREnsemble Adversarial Training: Attacks and Defenses.Florian Tramr, Alexey Kurakin, Nicolas Papernot, Ian J. Goodfellow, Dan Boneh, Patrick D. McDaniel
2017EuroCryptFormal Abstractions for Attested Execution Secure Processors.Rafael Pass, Elaine Shi, Florian Tramr
2015CCSDifferential Privacy with Bounded Priors: Reconciling Utility and Privacy in Genome-Wide Association Studies.Florian Tramr, Zhicong Huang, Jean-Pierre Hubaux, Erman Ayday
2015EuroCryptBetter Algorithms for LWE and LWR.Alexandre Duc, Florian Tramr, Serge Vaudenay