← Search

Emily Wenger

9 accepted papers

2026

Causes and Consequences of Representational Similarity in Machine Learning Models

ICML 2026poster

Numerous works have noted similarities in how machine learning models represent the world, even across modalities. Although much effort has been devoted to uncovering properties and metrics on which these models align, surprisingly little work has explored causes of this similarity. To advance this …

Cited by 0SourceScholar
2026

Improving ML attacks on LWE with data repetition and stepwise regression

ICML 2026poster

ML attacks on Learning with Errors (LWE) with binary or small secrets only succeed on LWE settings with very simple secrets. For example, they can recover secrets with up to three non-zero bits when models are trained on not-reduced LWE data, and three non-zero bits in the ''cruel region'' [9] when …

Cited by 0SourceScholar
2026

What happens when generative AI models train recursively on each others' outputs?

ICLR 2026poster

The internet serves as a common source of training data for generative AI (genAI) models but is increasingly populated with AI-generated content. This duality raises the possibility that future genAI models may be trained on other models' generated outputs. Prior work has studied consequences of mo…

Cited by 0SourceScholar
2025

Making Hard Problems Easier with Custom Data Distributions and Loss Regularization: A Case Study in Modular Arithmetic

ICML 2025poster

Recent work showed that ML-based attacks on Learning with Errors (LWE), a hard problem used in post-quantum cryptography, outperform classical algebraic attacks in certain settings. Although promising, ML attacks struggle to scale to more complex LWE settings. Prior work connected this issue to the…

Cited by 0SourcePDFScholar
2025

TAPAS: Datasets for Learning the Learning with Errors Problem

NeurIPS 2025poster

AI-powered attacks on Learning with Errors (LWE)—an important hard math problem in post-quantum cryptography—rival or outperform "classical" attacks on LWE under certain parameter settings. Despite the promise of this approach, a dearth of accessible data limits AI practitioners' ability to study an…

Cited by 0SourceScholar
2023

SALSA VERDE: a machine learning attack on LWE with sparse small secrets

NeurIPS 2023poster

Learning with Errors (LWE) is a hard math problem used in post-quantum cryptography. Homomorphic Encryption (HE) schemes rely on the hardness of the LWE problem for their security, and two LWE-based cryptosystems were recently standardized by NIST for digital signatures and key exchange (KEM). Thus…

Cited by 16SourcePDFScholar
2022

Finding Naturally Occurring Physical Backdoors in Image Datasets

NeurIPS 2022accept

Extensive literature on backdoor poison attacks has studied attacks and defenses for backdoors using “digital trigger patterns.” In contrast, “physical backdoors” use physical objects as triggers, have only recently been identified, and are qualitatively different enough to resist most defenses tar…

Cited by 19SourcePDFScholar
2022

SALSA: Attacking Lattice Cryptography with Transformers

NeurIPS 2022accept

Currently deployed public-key cryptosystems will be vulnerable to attacks by full-scale quantum computers. Consequently, "quantum resistant" cryptosystems are in high demand, and lattice-based cryptosystems, based on a hard problem known as Learning With Errors (LWE), have emerged as strong contende…

Cited by 43SourcePDFScholar
2021

Backdoor Attacks Against Deep Learning Systems in the Physical World

CVPR 2021poster

Backdoor attacks embed hidden malicious behaviors into deep learning models, which only activate and cause misclassifications on model inputs containing a specific "trigger." Existing works on backdoor attacks and defenses, however, mostly focus on digital attacks that apply digitally generated patt…

Cited by 248PDFScholar