Nicholas Carlini
Publication record assembled from the DBLP archive of ranked conferences.
Papers indexed
46
Venues
9
Active years
2017–2025
Best venue rank
A*
Where they publish
Papers
46 indexed papers, newest first.
| Year | Venue | Title | Authors |
|---|---|---|---|
| 2025 | CCS | Evaluating the Robustness of a Production Malware Detection System to Transferable Adversarial Attacks. | Milad Nasr, Yanick Fratantonio, Luca Invernizzi, Ange Albertini, Loua Farah, Alex Petit-Bianco, Andreas Terzis, Kurt Thomas, Elie Bursztein, Nicholas Carlini |
| 2025 | EuroCrypt | Polynomial Time Cryptanalytic Extraction of Deep Neural Networks in the Hard-Label Setting. | Nicholas Carlini, Jorge Chvez-Saab, Anna Hambitzer, Francisco Rodrguez-Henrquez, Adi Shamir |
| 2025 | ICLR | Measuring Non-Adversarial Reproduction of Training Data in Large Language Models. | Michael Aerni, Javier Rando, Edoardo Debenedetti, Nicholas Carlini, Daphne Ippolito, Florian Tramr |
| 2025 | ICLR | Adversarial Perturbations Cannot Reliably Protect Artists From Generative AI. | Robert Hnig, Javier Rando, Nicholas Carlini, Florian Tramr |
| 2025 | ICLR | Scalable Extraction of Training Data from Aligned, Production Language Models. | Milad Nasr, Javier Rando, Nicholas Carlini, Jonathan Hayase, Matthew Jagielski, A. Feder Cooper, Daphne Ippolito, Christopher A. Choquette-Choo, Florian Tramr, Katherine Lee |
| 2025 | ICLR | On Evaluating the Durability of Safeguards for Open-Weight LLMs. | Xiangyu Qi, Boyi Wei, Nicholas Carlini, Yangsibo Huang, Tinghao Xie, Luxi He, Matthew Jagielski, Milad Nasr, Prateek Mittal, Peter Henderson |
| 2025 | ICLR | Persistent Pre-training Poisoning of LLMs. | Yiming Zhang, Javier Rando, Ivan Evtimov, Jianfeng Chi, Eric Michael Smith, Nicholas Carlini, Florian Tramr, Daphne Ippolito |
| 2025 | ICML | AutoAdvExBench: Benchmarking Autonomous Exploitation of Adversarial Example Defenses. | Nicholas Carlini, Edoardo Debenedetti, Javier Rando, Milad Nasr, Florian Tramr |
| 2025 | ICML | Exploring and Mitigating Adversarial Manipulation of Voting-Based Leaderboards. | Yangsibo Huang, Milad Nasr, Anastasios Nikolas Angelopoulos, Nicholas Carlini, Wei-Lin Chiang, Christopher A. Choquette-Choo, Daphne Ippolito, Matthew Jagielski, Katherine Lee, Ken Liu, Ion Stoica, Florian Tramr, Chiyuan Zhang |
| 2025 | ICML | Position: In-House Evaluation Is Not Enough. Towards Robust Third-Party Evaluation and Flaw Disclosure for General-Purpose AI. | Shayne Longpre, Kevin Klyman, Ruth Elisabeth Appel, Sayash Kapoor, Rishi Bommasani, Michelle Sahar, Sean McGregor, Avijit Ghosh, Borhane Blili-Hamelin, Nathan Butters, Alondra Nelson, Amit Elazari, Andrew Sellars, Casey John Ellis, Dane Sherrets, Dawn Song, Harley Geiger, Ilona Cohen, Lauren McIlvenny, Madhulika Srikumar, Mark M. Jaycox, Markus Anderljung, Nadine Farid Johnson, Nicholas Carlini, Nicolas Miailhe, Nik Marda, Peter Henderson, Rebecca S. Portnoff, Rebecca Weiss, Victoria Westerhoff, Yacine Jernite, Rumman Chowdhury, Percy Liang, Arvind Narayanan |
| 2025 | SP | SoK: Watermarking for AI-Generated Content. | Xuandong Zhao, Sam Gunn, Miranda Christ, Jaiden Fairoze, Andrs Fbrega, Nicholas Carlini, Sanjam Garg, Sanghyun Hong, Milad Nasr, Florian Tramr, Somesh Jha, Lei Li, Yu-Xiang Wang, Dawn Song |
| 2024 | CVPR | Initialization Matters for Adversarial Transfer Learning. | Andong Hua, Jindong Gu, Zhiyu Xue, Nicholas Carlini, Eric Wong, Yao Qin |
| 2024 | ICML | Stealing part of a production language model. | Nicholas Carlini, Daniel Paleka, Krishnamurthy Dj Dvijotham, Thomas Steinke, Jonathan Hayase, A. Feder Cooper, Katherine Lee, Matthew Jagielski, Milad Nasr, Arthur Conmy, Eric Wallace, David Rolnick, Florian Tramr |
| 2024 | ICML | Position: Considerations for Differentially Private Learning with Large-Scale Public Pretraining. | Florian Tramr, Gautam Kamath, Nicholas Carlini |
| 2024 | SP | Poisoning Web-Scale Training Datasets is Practical. | Nicholas Carlini, Matthew Jagielski, Christopher A. Choquette-Choo, Daniel Paleka, Will Pearce, Hyrum S. Anderson, Andreas Terzis, Kurt Thomas, Florian Tramr |
| 2023 | ICLR | Quantifying Memorization Across Neural Language Models. | Nicholas Carlini, Daphne Ippolito, Matthew Jagielski, Katherine Lee, Florian Tramr, Chiyuan Zhang |
| 2023 | ICLR | (Certified!!) Adversarial Robustness for Free! | Nicholas Carlini, Florian Tramr, Krishnamurthy (Dj) Dvijotham, Leslie Rice, Mingjie Sun, J. Zico Kolter |
| 2023 | ICLR | Measuring Forgetting of Memorized Training Examples. | Matthew Jagielski, Om Thakkar, Florian Tramr, Daphne Ippolito, Katherine Lee, Nicholas Carlini, Eric Wallace, Shuang Song, Abhradeep Guha Thakurta, Nicolas Papernot, Chiyuan Zhang |
| 2023 | ICLR | Part-Based Models Improve Adversarial Robustness. | Chawin Sitawarin, Kornrapat Pongmala, Yizheng Chen, Nicholas Carlini, David A. Wagner |
| 2023 | ICML | Preprocessors Matter! Realistic Decision-Based Attacks on Machine Learning Systems. | Chawin Sitawarin, Florian Tramr, Nicholas Carlini |
| 2023 | INLG | Reverse-Engineering Decoding Strategies Given Blackbox Access to a Language Generation System. | Daphne Ippolito, Nicholas Carlini, Katherine Lee, Milad Nasr, Yun William Yu |
| 2023 | INLG | Preventing Generation of Verbatim Memorization in Language Models Gives a False Sense of Privacy. | Daphne Ippolito, Florian Tramr, Milad Nasr, Chiyuan Zhang, Matthew Jagielski, Katherine Lee, Christopher A. Choquette-Choo, Nicholas Carlini |
| 2022 | ACL | Deduplicating Training Data Makes Language Models Better. | Katherine Lee, Daphne Ippolito, Andrew Nystrom, Chiyuan Zhang, Douglas Eck, Chris Callison-Burch, Nicholas Carlini |
| 2022 | CCS | Truth Serum: Poisoning Machine Learning Models to Reveal Their Secrets. | Florian Tramr, Reza Shokri, Ayrton San Joaquin, Hoang Le, Matthew Jagielski, Sanghyun Hong, Nicholas Carlini |
| 2022 | ICLR | AdaMatch: A Unified Approach to Semi-Supervised Learning and Domain Adaptation. | David Berthelot, Rebecca Roelofs, Kihyuk Sohn, Nicholas Carlini, Alexey Kurakin |
| 2022 | ICLR | Evading Adversarial Example Detection Defenses with Orthogonal Projected Gradient Descent. | Oliver Bryniarski, Nabeel Hingun, Pedro Pachuca, Vincent Wang, Nicholas Carlini |
| 2022 | ICLR | Poisoning and Backdooring Contrastive Learning. | Nicholas Carlini, Andreas Terzis |
| 2022 | ICLR | Data Poisoning Won't Save You From Facial Recognition. | Evani Radiya-Dixit, Sanghyun Hong, Nicholas Carlini, Florian Tramr |
| 2022 | SP | Membership Inference Attacks From First Principles. | Nicholas Carlini, Steve Chien, Milad Nasr, Shuang Song, Andreas Terzis, Florian Tramr |
| 2021 | CCS | Session details: Session 1: Adversarial Machine Learning. | Nicholas Carlini |
| 2021 | CCS | Session details: Session 2A: Machine Learning for Cybersecurity. | Nicholas Carlini |
| 2021 | ICML | Label-Only Membership Inference Attacks. | Christopher A. Choquette-Choo, Florian Tramr, Nicholas Carlini, Nicolas Papernot |
| 2021 | SP | Is Private Learning Possible with Instance Encoding? | Nicholas Carlini, Samuel Deng, Sanjam Garg, Somesh Jha, Saeed Mahloujifar, Mohammad Mahmoody, Abhradeep Thakurta, Florian Tramr |
| 2021 | SP | Adversary Instantiation: Lower Bounds for Differentially Private Machine Learning. | Milad Nasr, Shuang Song, Abhradeep Thakurta, Nicolas Papernot, Nicholas Carlini |
| 2020 | CCS | AISec'20: 13th Workshop on Artificial Intelligence and Security. | Sadia Afroz, Nicholas Carlini, Ambra Demontis |
| 2020 | CRYPTO | Cryptanalytic Extraction of Neural Network Models. | Nicholas Carlini, Matthew Jagielski, Ilya Mironov |
| 2020 | CVPR | Evading Deepfake-Image Detectors with White- and Black-Box Attacks. | Nicholas Carlini, Hany Farid |
| 2020 | ICLR | ReMixMatch: Semi-Supervised Learning with Distribution Matching and Augmentation Anchoring. | David Berthelot, Nicholas Carlini, Ekin D. Cubuk, Alex Kurakin, Kihyuk Sohn, Han Zhang, Colin Raffel |
| 2020 | ICML | Fundamental Tradeoffs between Invariance and Sensitivity to Adversarial Perturbations. | Florian Tramr, Jens Behrmann, Nicholas Carlini, Nicolas Papernot, Jrn-Henrik Jacobsen |
| 2019 | CCS | AISec'19: 12th ACM Workshop on Artificial Intelligence and Security. | Sadia Afroz, Battista Biggio, Nicholas Carlini, Yuval Elovici, Asaf Shabtai |
| 2019 | ICML | Adversarial Examples Are a Natural Consequence of Test Error in Noise. | Justin Gilmer, Nicolas Ford, Nicholas Carlini, Ekin D. Cubuk |
| 2019 | ICML | Imperceptible, Robust, and Targeted Adversarial Examples for Automatic Speech Recognition. | Yao Qin, Nicholas Carlini, Garrison W. Cottrell, Ian J. Goodfellow, Colin Raffel |
| 2018 | ICML | Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples. | Anish Athalye, Nicholas Carlini, David A. Wagner |
| 2018 | SP | Audio Adversarial Examples: Targeted Attacks on Speech-to-Text. | Nicholas Carlini, David A. Wagner |
| 2017 | CCS | Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods. | Nicholas Carlini, David A. Wagner |
| 2017 | SP | Towards Evaluating the Robustness of Neural Networks. | Nicholas Carlini, David A. Wagner |