| 2025 | ICLR | Jailbreaking Leading Safety-Aligned LLMs with Simple Adaptive Attacks. | Maksym Andriushchenko, Francesco Croce, Nicolas Flammarion |
| 2025 | ICLR | Selective induction Heads: How Transformers Select Causal Structures in Context. | Francesco D'Angelo, Francesco Croce, Nicolas Flammarion |
| 2025 | ICLR | Is In-Context Learning Sufficient for Instruction Following in LLMs? | Hao Zhao, Maksym Andriushchenko, Francesco Croce, Nicolas Flammarion |
| 2024 | ECCV | Towards Reliable Evaluation and Fast Training of Robust Semantic Segmentation Models. | Francesco Croce, Naman D. Singh, Matthias Hein |
| 2024 | ICML | Robust CLIP: Unsupervised Adversarial Fine-Tuning of Vision Embeddings for Robust Large Vision-Language Models. | Christian Schlarmann, Naman Deep Singh, Francesco Croce, Matthias Hein |
| 2024 | ICML | Long Is More for Alignment: A Simple but Tough-to-Beat Baseline for Instruction Fine-Tuning. | Hao Zhao, Maksym Andriushchenko, Francesco Croce, Nicolas Flammarion |
| 2023 | CVPR | Seasoning Model Soups for Robustness to Adversarial and Natural Distribution Shifts. | Francesco Croce, Sylvestre-Alvise Rebuffi, Evan Shelhamer, Sven Gowal |
| 2023 | ICLR | Revisiting adapters with adversarial training. | Sylvestre-Alvise Rebuffi, Francesco Croce, Sven Gowal |
| 2023 | ICML | A Modern Look at the Relationship between Sharpness and Generalization. | Maksym Andriushchenko, Francesco Croce, Maximilian Mller, Matthias Hein, Nicolas Flammarion |
| 2022 | AAAI | Sparse-RS: A Versatile Framework for Query-Efficient Sparse Black-Box Adversarial Attacks. | Francesco Croce, Maksym Andriushchenko, Naman D. Singh, Nicolas Flammarion, Matthias Hein |
| 2022 | ICML | Adversarial Robustness against Multiple and Single l | Francesco Croce, Matthias Hein |
| 2022 | ICML | Evaluating the Adversarial Robustness of Adaptive Test-time Defenses. | Francesco Croce, Sven Gowal, Thomas Brunner, Evan Shelhamer, Matthias Hein, A. Taylan Cemgil |
| 2021 | ICML | Mind the Box: l | Francesco Croce, Matthias Hein |
| 2020 | ECCV | Square Attack: A Query-Efficient Black-Box Adversarial Attack via Random Search. | Maksym Andriushchenko, Francesco Croce, Nicolas Flammarion, Matthias Hein |
| 2020 | ICLR | Provable robustness against all adversarial $l_p$-perturbations for $p\geq 1$. | Francesco Croce, Matthias Hein |
| 2020 | ICML | Minimally distorted Adversarial Examples with a Fast Adaptive Boundary Attack. | Francesco Croce, Matthias Hein |
| 2020 | ICML | Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. | Francesco Croce, Matthias Hein |
| 2019 | AISTATS | Provable Robustness of ReLU networks via Maximization of Linear Regions. | Francesco Croce, Maksym Andriushchenko, Matthias Hein |
| 2019 | ICCV | Sparse and Imperceivable Adversarial Attacks. | Francesco Croce, Matthias Hein |