Portrait of Kamalika Chaudhuri

Kamalika Chaudhuri

Adjunct Professor, CSE, UC San Diego

Principal Scientist, Google DeepMind

I am an AI researcher generally interested in AI security and alignment. I lead a research team at Google DeepMind working broadly on prompt injections and contextual security. Prior to Google, I built up and led a research team at FAIR at Meta on AI privacy, security, and reliability. I hold an Adjunct Professor position at UCSD CSE, where I was previously a Full Professor until 2024. I currently serve as the Board President of the ICML Foundation.

What's new

News

  • Invited keynote talk at the NSF SaTC PI Meeting [ Slides ] (Aug 2026)
  • Invited talk at the SAGAI Workshop [ Slides ] (May 2026)
  • Invited talk at the Simons Workshop on Federated and Collaborative Learning (Jan 2026)
  • Invited talk at the Kempner Institute, Harvard (Nov 2025)
  • Invited talk at IFDS Workshop, University of Washington (Aug 2025)
  • Board President, ICML Foundation (July 2025)
  • Invited talk, ICML 2025 R2FM Workshop (July 2025)
  • Keynote, IEEE Secure and Trustworthy ML (SaTML) (Apr 2025)
Research

Research

My research focuses on AI privacy, security, safety, and alignment (formerly known as trustworthy machine learning). This includes understanding how to measure privacy and security leaks in LLMs, as well as issues such as uncertainty estimation. I am also broadly interested in many aspects of safety and post-training, such as confidentiality, misalignment, and others. Here are the slides from a talk I gave at Harvard about our work at FAIR at Meta. Here and here are two recent talks I gave about how AI security changed from 2025 to 2026, and challenges and open problems in the security of agentic AI.

My former UCSD group used to maintain a group blog with guest posts from collaborators. I also have a personal blog.

People

Group

Current

  • Pengrun Huang (co-advised with Yu-Xiang Wang)
  • Konstantin Garov (co-advised with Misha Belkin)

Alumni

Selected & recent

Publications

For a complete list, see Google Scholar.

2026
Safety Alignment of LMs via Non-cooperative Games Anselm Paulus, Ilia Kulikov, Brandon Amos, Rémi Munos, Ivan Evtimov, Kamalika Chaudhuri and Arman Zharmagambetov. ICML, 2026. Spotlight
How much can language models memorize? John Xavier Morris, Chawin Sitawarin, Chuan Guo, Narine Kokhlikyan, G. Edward Suh, Alexander M Rush, Kamalika Chaudhuri and Saeed Mahloujifar. ICML, 2026. Outstanding Paper Honorable Mention Award
CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs Niloofar Mireshghallah, Neal Mangaokar, Narine Kokhlikyan, Arman Zharmagambetov, Manzil Zaheer, Saeed Mahloujifar, and Kamalika Chaudhuri. ICLR, 2026.
Learning-time Encoding Shapes Unlearning in LLMs Ruihan Wu, Konstantin Garov and Kamalika Chaudhuri. ICLR, 2026.
Influence-based Attributions can be Manipulated Chhavi Yadav, Ruihan Wu and Kamalika Chaudhuri. AISTATS, 2026.
Beyond Discrepancy: A Closer Look at the Theory of Distribution Shift Robi Bhattacharjee, Nicholas Rittler and Kamalika Chaudhuri. ALT, 2026.
Evaluating Deep Unlearning in Large Language Models Ruihan Wu, Chhavi Yadav, Ruslan Salakhutdinov, Kamalika Chaudhuri. SaTML, 2026.
2025
Can We Infer Confidential Properties of Training Data from LLMs? Pengrun Huang, Chhavi Yadav, Ruihan Wu and Kamalika Chaudhuri. NeurIPS, 2025. Spotlight
WASP: Benchmarking Web Agent Security against Prompt Injection Attacks Ivan Evtimov, Arman Zharmagambetov, Aaron Grattafiori, Chuan Guo and Kamalika Chaudhuri. NeurIPS (Datasets & Benchmarks), 2025.
AgentDAM: Privacy Leakage Evaluation for Autonomous Web Agents Arman Zharmagambetov, Chuan Guo, Ivan Evtimov, Maya Pavlova, Ruslan Salakhutdinov and Kamalika Chaudhuri. NeurIPS (Datasets & Benchmarks), 2025.
AbstentionBench: Reasoning LLMs Fail on Unanswerable Questions Polina Kirichenko, Mark Ibrahim, Kamalika Chaudhuri, and Samuel J. Bell. NeurIPS (Datasets & Benchmarks), 2025.
Rethinking the Role of Verbatim Memorization in LLM Privacy Tom Sander, Bargav Jayaraman, Mark Ibrahim, Kamalika Chaudhuri and Chuan Guo. NeurIPS, 2025.
Do LLMs really forget? Evaluating Unlearning with Knowledge Correlation and Confidence Awareness Rongzhe Wei, Peizhi Niu, Hans Hao-Hsun Hsu, Ruihan Wu, Haoteng Yin, Yifan Li, Eli Chien, Kamalika Chaudhuri, Olgica Milenkovic, and Pan Li. NeurIPS, 2025.
SecAlign: Defending Against Prompt Injections with Preference Optimization Sizhe Chen, Arman Zharmagambetov, Saeed Mahloujifar, Kamalika Chaudhuri, David Wagner, and Chuan Guo. CCS, 2025.
EXP-Proof: Operationalizing Explanations for Confidential Models with ZKP Chhavi Yadav, Evan Monroe Laufer, Dan Boneh, and Kamalika Chaudhuri. ICML, 2025.
Auditing f-Differential Privacy in One Run Saeed Mahloujifar, Luca Melis and Kamalika Chaudhuri. ICML, 2025.
On the Reliability of Membership Inference Attacks Amrita Roy Chowdhury, Zhifeng Kong, and Kamalika Chaudhuri. SaTML, 2025.
Machine Learning with Privacy on Protected Attributes Saeed Mahloujifar, Chuan Guo, Edward G. Suh and Kamalika Chaudhuri. IEEE Security and Privacy, 2025.
2024
Distribution Learning with Valid Outputs Beyond the Worst-Case Nicholas Rittler and Kamalika Chaudhuri. NeurIPS, 2024.
Measuring Deja Vu Memorization Efficiently Narine Kokhlikyan, Bargav Jayaraman, Florian Bordes, Chuan Guo and Kamalika Chaudhuri. NeurIPS, 2024.
Deja Vu Memorization in Vision Language Models Bargav Jayaraman, Chuan Guo and Kamalika Chaudhuri. NeurIPS, 2024.
On Differentially Private U Statistics Kamalika Chaudhuri, Po-Ling Loh, Shourya Pandey and Purna Sarkar. NeurIPS, 2024.
Metric Differential Privacy at the User Level Jacob Imola, Amrita Roy Chowdhury and Kamalika Chaudhuri. CCS, 2024.
FairProof: Confidential and Certifiable Fairness for Neural Networks Chhavi Yadav, Amrita Roy Chowdhury, Dan Boneh, and Kamalika Chaudhuri. ICML, 2024. Best Paper, ICLR PRPML 2024
Differentially Private Representation Learning via Image Captioning Tom Sander, Yaodong Yu, Maziar Sanjabi, Alain Durmus, Yi Ma, Kamalika Chaudhuri, and Chuan Guo. ICML, 2024.
ViP: A Differentially Private Foundation Model for Computer Vision Yaodong Yu, Maziar Sanjabi, Yi Ma, Kamalika Chaudhuri and Chuan Guo. ICML, 2024.
Effective Pruning of Web-Scale Datasets based on Complexity of Concept Clusters Amro Abbas, Evgenia Rusak, Kushal Tirumala, Wieland Brendel, Kamalika Chaudhuri and Ari Morcos. ICLR, 2024.
Differentially Private Multi-Site Treatment Effect Estimation Tatsuki Koga, Kamalika Chaudhuri and David Page. SaTML, 2024.
Data Redaction for Conditional Generative Models Zhifeng Kong and Kamalika Chaudhuri. SaTML, 2024. Distinguished Paper
2023
Do SSL Models Have Déjà Vu? A Case of Unintended Memorization in Self-supervised Learning Casey Meehan, Florian Bordes, Pascal Vincent, Kamalika Chaudhuri and Chuan Guo. NeurIPS, 2023.
Agnostic Multi-Group Active Learning Nicholas Rittler and Kamalika Chaudhuri. NeurIPS, 2023.
A Two-Stage Active Learning Algorithm for k-Nearest Neighbors Nicholas Rittler and Kamalika Chaudhuri. ICML, 2023.
Data Copying in Generative Models: A Formal Framework Robi Bhattacharjee, Sanjoy Dasgupta and Kamalika Chaudhuri. ICML, 2023.
Why does Throwing Away Data Improve Worst-Group Error? Kamalika Chaudhuri, Kartik Ahuja, Martin Arjovsky and David Lopez-Paz. ICML, 2023.
Privacy-Aware Compression for Federated Learning through Numerical Mechanism Design Chuan Guo, Kamalika Chaudhuri, Pierre Stock and Mike Rabbat. ICML, 2023.
Robust Empirical Risk Minimization with Tolerance Robi Bhattacharjee, Max Hopkins, Akash Kumar, Hantao Yu and Kamalika Chaudhuri. ALT, 2023.
Probing Predictions on OOD Images via Nearest Categories Yao-Yuan Yang, Cyrus Rashtchian, Ruslan Salakhutdinov, and Kamalika Chaudhuri. TMLR, 2023.
Data Redaction from Pre-Trained GANs Zhifeng Kong and Kamalika Chaudhuri. SaTML, 2023.
2022
Differentially Private Triangle and 4-Cycle Counting in the Shuffle Model Jacob Imola, Takao Murakami and Kamalika Chaudhuri. CCS, 2022.
Sentence-Level Privacy for Document Embeddings Casey Meehan, Khalil Mrini and Kamalika Chaudhuri. ACL, 2022.
Privacy-Aware Compression for Federated Data Analysis Kamalika Chaudhuri, Chuan Guo and Mike Rabbat. UAI, 2022.
Bounding Training Data Reconstruction in Private (Deep) Learning Chuan Guo, Brian Karrer, Kamalika Chaudhuri and Laurens van der Maaten. ICML, 2022.
Thompson Sampling for Robust Transfer in Multi-task Bandits Zhi Wang, Chicheng Zhang and Kamalika Chaudhiuri. ICML, 2022.
Communication Efficient Triangle Counting under Local Differential Privacy Jacob Imola, Takao Murakami and Kamalika Chaudhuri. USENIX Security, 2022.
Privacy Amplification by Subsampling in the Time Domain Tatsuki Koga, Casey Meehan and Kamalika Chaudhuri. AISTATS, 2022.
Privacy Implications of Shuffling Casey Meehan, Amrita RoyChowdhury, Kamalika Chaudhuri and Somesh Jha. ICLR, 2022.
Privacy Amplification via Shuffling in Linear Contextual Bandits Evrard Garcelon, Kamalika Chaudhuri, Vianney Perchet, and Matteo Pirotta. ALT, 2022.
2021
Understanding Instance-based Interpretability of Variational Auto-Encoders Zhifeng Kong and Kamalika Chaudhuri. NeurIPS, 2021.
Consistent Non-Parametric Methods for Adaptive Robustness Robi Bhattacharjee and Kamalika Chaudhuri. NeurIPS, 2021.
Connecting Interpretability and Robustness in Decision Trees through Separation Michal Moshkovitz, Yao-Yuan Yang and Kamalika Chaudhuri. ICML, 2021.
Sample Complexity of Adversarially Robust Linear Classification on Separated Data Robi Bhattacharjee, Somesh Jha and Kamalika Chaudhuri. ICML, 2021.
Locally Differentially Private Analysis of Graph Statistics Jacob Imola, Takao Murakami and Kamalika Chaudhuri. USENIX Security, 2021.
Location Trace Privacy Through Conditional Priors Casey Meehan and Kamalika Chaudhuri. AISTATS, 2021.
Revisiting Model-Agnostic Private Learning: Faster Rates and Active Learning Chong Liu, Yuqing Zhu, Kamalika Chaudhuri and Yu-Xiang Wang. AISTATS, 2021.
Multitask Bandit Learning through Heterogeneous Feedback Aggregation Zhi Wang, Chicheng Zhang, Manish Singh, Laurel D. Riek and Kamalika Chaudhuri. AISTATS, 2021.
Approximate Data Deletion from Machine Learning Models: Algorithms and Evaluation Zachary Izzo, Mary Anne Smart, Kamalika Chaudhuri and James Zou. AISTATS, 2021.
2020
Successive Refinement of Privacy Antonious M. Girgis, Deepesh Data, Kamalika Chaudhuri, Christina Fragouli, Suhas Diggavi. IEEE JSAIT, 2020.
A Closer Look at Robustness vs. Accuracy Yao-Yuan Yang, Cyrus Rashtchian, Hongyang Zhang, Ruslan Salakhutdinov and Kamalika Chaudhuri. NeurIPS, 2020.
When are Non-Parametric Methods Robust? Robi Bhattacharjee and Kamalika Chaudhuri. ICML, 2020.
A Non-Parametric Test to Detect Data-Copying in Generative Models Casey Meehan, Kamalika Chaudhuri and Sanjoy Dasgupta. AISTATS, 2020.
The Expressive Power of a Class of Normalizing Flow Models Zhifeng Kong and Kamalika Chaudhuri. AISTATS, 2020.
Robustness for Non-Parametric Methods: A Generic Attack and Defense Yao-Yuan Yang, Cyrus Rashtchian, Yizhen Wang and Kamalika Chaudhuri. AISTATS, 2020.
Variational Bayes in Private Settings (VIPS) Mijung Park, James Foulds, Kamalika Chaudhuri and Max Welling. JAIR, 2020.
Model Extraction and Active Learning Varun Chandrasekaran, Kamalika Chaudhuri, Irene Giacomelli, Somesh Jha and Songbai Yan. USENIX Security, 2020.
2019
Capacity Bounded Differential Privacy Kamalika Chaudhuri, Jacob Imola and Ashwin Machanavajjhala. NeurIPS, 2019.
The Label Complexity of Active Learning from Observational Data Songbai Yan, Kamalika Chaudhuri and Tara Javidi. NeurIPS, 2019.
Profile-Based Privacy for Locally Private Computations Joseph Geumlek and Kamalika Chaudhuri. ISIT, 2019.
2018
Active Learning from Logged Data Songbai Yan, Kamalika Chaudhuri and Tara Javidi. ICML, 2018.
Analyzing the Robustness of Nearest Neighbors to Adversarial Examples Yizhen Wang, Somesh Jha and Kamalika Chaudhuri. ICML, 2018.
2017
Renyi Differential Privacy Mechanisms for Posterior Sampling Joseph Geumlek, Shuang Song and Kamalika Chaudhuri. NIPS, 2017.
Approximation and Convergence Properties of Generative Adversarial Learning Shuang Liu, Olivier Bousquet and Kamalika Chaudhuri. NIPS, 2017.
Composition Properties of Inferential Privacy for Time-Series Data Shuang Song and Kamalika Chaudhuri. Allerton, 2017.
Learning to Blame: Localizing Novice Type Errors with Data-Driven Diagnosis Eric Seidel, Huma Sibghat, Kamalika Chaudhuri, Westley Weimer and Ranjit Jhala. OOPSLA, 2017.
Active Heteroscedastic Regression Kamalika Chaudhuri, Prateek Jain and Nagarajan Natarajan. ICML, 2017.
Bolt-On Differential Privacy for Stochastic Gradient Descent-based Analytics Xi Wu, Fengan Li, Arun Kumar, Kamalika Chaudhuri, Somesh Jha and Jeff Naughton. SIGMOD, 2017.
Pufferfish Privacy Mechanisms for Correlated Data Shuang Song, Yizhen Wang and Kamalika Chaudhuri. SIGMOD, 2017.
Practical Privacy for Expectation Maximization Mijung Park, James Foulds, Kamalika Chaudhuri and Max Welling. AISTATS, 2017.
2016
Private Topic Modeling Mijung Park, James Foulds, Kamalika Chaudhuri and Max Welling. NIPS Workshop on Private Multi-party ML, 2016.
Active Learning from Imperfect Labelers Songbai Yan, Kamalika Chaudhuri and Tara Javidi. NIPS, 2016.
On the Theory and Practice of Privacy-preserving Bayesian Data Analysis James Foulds, Joseph Geumlek, Max Welling and Kamalika Chaudhuri. UAI, 2016.
The Extended Littlestone's Dimension for Learning with Mistakes and Abstentions Chicheng Zhang and Kamalika Chaudhuri. COLT, 2016.
2015
Spectral Learning of Large Structured HMMs for Comparative Epigenomics Chicheng Zhang, Jimin Song, Kamalika Chaudhuri and Kevin Chen. NIPS, 2015.
Active Learning from Weak and Strong Labelers Chicheng Zhang and Kamalika Chaudhuri. NIPS, 2015.
Convergence Rates of Active Learning for Maximum Likelihood Estimation Kamalika Chaudhuri, Sham Kakade, Praneeth Netrapalli and Sujay Sanghavi. NIPS, 2015.
Active Learning from Noisy and Abstention Feedback Songbai Yan, Kamalika Chaudhuri and Tara Javidi. Allerton, 2015.
Crowdsourcing Feature Discovery via Adaptively Chosen Comparisons James Y. Zou, Kamalika Chaudhuri and Adam Tauman Kalai. HCOMP, 2015.
Noisy Bayesian Active Learning Mohammad Naghshvar, Tara Javidi and Kamalika Chaudhuri. IEEE Trans. Info. Theory, 2015.
Learning from Data with Heterogenous Noise using SGD Shuang Song, Kamalika Chaudhuri and Anand D. Sarwate. AISTATS, 2015.
2014
The Large Margin Mechanism for Differentially Private Maximization Kamalika Chaudhuri, Daniel Hsu and Shuang Song. NIPS, 2014.
Beyond Disagreement-Based Agnostic Active Learning Chicheng Zhang and Kamalika Chaudhuri. NIPS, 2014.
Rates of Convergence for Nearest Neighbor Classification Kamalika Chaudhuri and Sanjoy Dasgupta. NIPS, 2014.
Consistent Procedures for Cluster Tree Estimation and Pruning Kamalika Chaudhuri, Sanjoy Dasgupta, Samory Kpotufe and Ulrike Von Luxburg. IEEE Trans. Info. Theory, 2014.
2013
Improved Algorithms for Confidence-Rated Prediction with Error Guarantees Kamalika Chaudhuri and Chicheng Zhang. NIPS Workshop, 2013.
Stochastic Gradient Descent with Differentially Private Updates Shuang Song, Kamalika Chaudhuri and Anand Sarwate. GlobalSIP, 2013.
Signal Processing and Machine Learning with Differential Privacy: Theory, Algorithms and Challenges Anand Sarwate and Kamalika Chaudhuri. IEEE Signal Processing Magazine, 2013.
2012
Near-Optimal Algorithms for Differentially Private Principal Components Kamalika Chaudhuri, Anand Sarwate and Kaushik Sinha. NIPS, 2012.
Convergence Rates for Differentially Private Statistical Estimation Kamalika Chaudhuri and Daniel Hsu. ICML, 2012.
Spectral Clustering of Graphs with General Degrees in the Extended Planted Partition Model Kamalika Chaudhuri, Fan Chung and Alexander Tsiatas. COLT, 2012.
2011
Spectral Methods for Learning Multivariate Latent Tree Structure Animashree Anandkumar, Kamalika Chaudhuri, Daniel Hsu, Sham Kakade, Le Song and Tong Zhang. NIPS, 2011.
Sample Complexity Bounds for Differentially Private Learning Kamalika Chaudhuri and Daniel Hsu. COLT, 2011.
Differentially Private ERM Kamalika Chaudhuri, Claire Monteleoni, and Anand Sarwate. JMLR, 2011.
2010
Rates of Convergence for the Cluster Tree Kamalika Chaudhuri and Sanjoy Dasgupta. NIPS, 2010.
An Online Learning-based Framework for Tracking Kamalika Chaudhuri, Yoav Freund and Daniel Hsu. UAI, 2010.
2009 and Before
A New Parameter-Free Hedging Algorithm Kamalika Chaudhuri, Yoav Freund and Daniel Hsu. NIPS, 2009.
Online Bipartite Matching with Augmentations Kamalika Chaudhuri, Costis Daskalakis, Robert Kleinberg and Henry Lin. INFOCOM, 2009.
Multiview Clustering via Canonical Correlation Analysis Kamalika Chaudhuri, Sham Kakade, Karen Livescu and Karthik Sridharan. ICML, 2009.
A Network Coloring Game Kamalika Chaudhuri, Fan Chung Graham, Mohammad S. Jamall. WINE, 2008.
Finding Metric Structure in Information-Theoretic Clustering Kamalika Chaudhuri and Andrew McGregor. COLT, 2008.
Privacy, Accuracy, and Consistency Too: A Holistic Solution to Contingency Table Release Boaz Barak, Kamalika Chaudhuri, Cynthia Dwork, Satyen Kale, Frank Mcsherry and Kunal Talwar. PODS, 2007.
A Rigorous Analysis of Population Stratification with Limited Data Kamalika Chaudhuri, Eran Halperin, Satish Rao and Shuheng Zhou. SODA, 2007.
Push-Relabel and an Improved Approximation Algorithm for the Bounded-degree MST Problem Kamalika Chaudhuri, Satish Rao, Samantha Riesenfeld, and Kunal Talwar. ICALP, 2006.
When Random Sampling preserves Privacy Kamalika Chaudhuri and Nina Mishra. CRYPTO, 2006.
On the tandem duplication-random loss model of genome rearrangement Kamalika Chaudhuri, Kevin Chen, Radu Mihaescu, and Satish Rao. SODA, 2006.
Server Allocation Algorithms for Tiered Systems Kamalika Chaudhuri, Anshul Kothari, Rudi Pendavingh, Ram Swaminathan, Robert Tarjan, and Yunhong Zhou. COCOON, 2005.
What would Edmonds do? Augmenting Paths, Witnesses and Improved Approximations for Bounded-degree MSTs Kamalika Chaudhuri, Satish Rao, Samantha Riesenfeld, and Kunal Talwar. APPROX, 2005.
Value-Maximizing Deadline Scheduling and its Application to Animation Rendering Eric Anderson, Dirk Beyer, Kamalika Chaudhuri, Terrance Kelly, Norman Salazar, Ciprano Santos, Ram Swaminathan, Robert Tarjan, Janet Wiener, and Yunhong Zhou. SPAA, 2005.
Selfish Caching in Distributed Systems: A Game Theoretic Analysis Byung-Gon Chun, Kamalika Chaudhuri, Hoeteck Wee, Marco Barreno, Christos Papadimitriou, and John Kubiatowicz. PODC, 2004.
Paths, Trees and Minimum Latency Tours Kamalika Chaudhuri, Brighten Godfrey, Satish Rao, and Kunal Talwar. FOCS, 2003.