← Search

Flavio Calmon

30 accepted papers

2026

Optimal Domain-Aware Privacy Mechanisms for Synthetic Data Generation

ICML 2026poster

Differential privacy (DP) imposes fundamental trade-offs between privacy and statistical fidelity in synthetic data generation. While access to public data has been shown to improve these trade-offs empirically, existing approaches exploit public data only indirectly, through pre-processing (e.g., u…

Cited by 0SourceScholar
2026

Optimal conversion from Rényi Differential Privacy to $f$-Differential Privacy

ICML 2026poster

We prove the conjecture stated in Appendix F.3 of Zhu et al.: among all conversion rules that map a Rényi Differential Privacy (RDP) profile $\tau \mapsto \rho(\tau)$ to a valid hypothesis-testing trade-off $f$ (or equivalently, an $(\varepsilon,\delta)$-Differential Privacy curve), the rule based o…

Cited by 1SourceScholar
2026

Robust AI Evaluation through Maximal Lotteries

ICML 2026poster

The standard way to evaluate language models on subjective tasks is through pairwise comparisons: an annotator chooses the "better" of two model responses for a given prompt. These comparisons are then aggregated into a single ranking via the Bradley–Terry (BT) framework, forcing heterogeneous prefe…

Cited by 0SourceScholar
2026

Temporal Sparse Autoencoders: Leveraging the Sequential Nature of Language for Interpretability

ICLR 2026oral

Translating the internal representations and computations of models into concepts that humans can understand is a key goal of interpretability. While recent dictionary learning methods such as Sparse Autoencoders (SAEs) provide a promising route to discover human-interpretable features, they often o…

Cited by 0SourcecodeScholar
2025

HeavyWater and SimplexWater: Distortion-free LLM Watermarks for Low-Entropy Distributions

NeurIPS 2025poster

Large language model (LLM) watermarks enable authentication of text provenance, curb misuse of machine-generated text, and promote trust in AI systems. Current watermarks operate by changing the next-token predictions output by an LLM. The updated (i.e., watermarked) predictions depend on random si…

Cited by 0SourceScholar
2025

Inference-Time Reward Hacking in Large Language Models

NeurIPS 2025spotlight

A common paradigm to improve the performance of large language models is optimizing for a reward model. Reward models assign a numerical score to an LLM’s output that indicates, for example, how likely it is to align with user preferences or safety goals. However, reward models are never perfect. Th…

Cited by 0SourceScholar
2025

Optimizing Noise Distributions for Differential Privacy

ICML 2025poster

We propose a unified optimization framework for designing continuous and discrete noise distributions that ensure differential privacy (DP) by minimizing Rényi DP, a variant of DP, under a cost constraint. Rényi DP has the advantage that by considering different values of the Rényi parameter $\alpha…

Cited by 3SourcePDFScholar
2025

Rigor in AI: Doing Rigorous AI Work Requires a Broader, Responsible AI-Informed Conception of Rigor

NeurIPS 2025poster

In AI research and practice, rigor remains largely understood in terms of methodological rigor---such as whether mathematical, statistical, or computational methods are correctly applied. We argue that this narrow conception of rigor has contributed to the concerns raised by the responsible AI commu…

Cited by 0SourceScholar
2025

Unifying Re-Identification, Attribute Inference, and Data Reconstruction Risks in Differential Privacy

NeurIPS 2025poster

Differentially private (DP) mechanisms are difficult to interpret and calibrate because existing methods for mapping standard privacy parameters to concrete privacy risks---re-identification, attribute inference, and data reconstruction---are both overly pessimistic and inconsistent. In this work, w…

Cited by 0SourceScholar
2024

Attack-Aware Noise Calibration for Differential Privacy

NeurIPS 2024poster

Differential privacy (DP) is a widely used approach for mitigating privacy risks when training machine learning models on sensitive data. DP mechanisms add noise during training to limit the risk of information leakage. The scale of the added noise is critical, as it determines the trade-off between…

Cited by 6SourcePDFScholar
2024

Fair Machine Unlearning: Data Removal while Mitigating Disparities

AISTATS 2024poster

The Right to be Forgotten is a core principle outlined by regulatory frameworks such as the EU’s General Data Protection Regulation (GDPR). This principle allows individuals to request that their personal data be deleted from deployed machine learning models. While "forgetting" can be naively achiev…

2024

Interpreting CLIP with Sparse Linear Concept Embeddings (SpLiCE)

NeurIPS 2024poster

CLIP embeddings have demonstrated remarkable performance across a wide range of multimodal applications. However, these high-dimensional, dense vector representations are not easily interpretable, limiting our understanding of the rich structure of CLIP and its use in downstream applications that r…

2024

Multi-Group Proportional Representation in Retrieval

NeurIPS 2024poster

Image search and retrieval tasks can perpetuate harmful stereotypes, erase cultural identities, and amplify social disparities. Current approaches to mitigate these representational harms balance the number of retrieved items across population groups defined by a small number of (often binary) attri…

2023

Aleatoric and Epistemic Discrimination: Fundamental Limits of Fairness Interventions

NeurIPS 2023spotlight

Machine learning (ML) models can underperform on certain population groups due to choices made during model development and bias inherent in the data. We categorize sources of discrimination in the ML pipeline into two classes: aleatoric discrimination, which is inherent in the data distribution, an…

Cited by 16SourcePDFScholar
2023

The Saddle-Point Method in Differential Privacy

ICML 2023poster

We characterize the differential privacy guarantees of privacy mechanisms in the large-composition regime, i.e., when a privacy mechanism is sequentially applied a large number of times to sensitive data. Via exponentially tilting the privacy loss random variable, we derive a new formula for the pri…

Cited by 13SourcePDFScholar
2022

Beyond Adult and COMPAS: Fair Multi-Class Prediction via Information Projection

NeurIPS 2022accept

We consider the problem of producing fair probabilistic classifiers for multi-class classification tasks. We formulate this problem in terms of ``projecting'' a pre-trained (and potentially unfair) classifier onto the set of models that satisfy target group-fairness requirements. The new, projected…

Cited by 48SourcePDFScholar
2022

On the Epistemic Limits of Personalized Prediction

NeurIPS 2022accept

Machine learning models are often personalized by using group attributes that encode personal characteristics (e.g., sex, age group, HIV status). In such settings, individuals expect to receive more accurate predictions in return for disclosing group attributes to the personalized model. We study wh…

Cited by 13SourcePDFScholar
2021

Analyzing the Generalization Capability of SGLD Using Properties of Gaussian Channels

NeurIPS 2021poster

Optimization is a key component for training machine learning models and has a strong impact on their generalization. In this paper, we consider a particular optimization method---the stochastic gradient Langevin dynamics (SGLD) algorithm---and investigate the generalization of models trained by SGL…

Cited by 29SourcePDFScholar
2021

CPR: Classifier-Projection Regularization for Continual Learning

ICLR 2021poster

We propose a general, yet simple patch that can be applied to existing regularization-based continual learning methods called classifier-projection regularization (CPR). Inspired by both recent results on neural networks with wide local minima and information theory, CPR adds an additional regulariz…

2020

Optimized Score Transformation for Fair Classification

AISTATS 2020poster

This paper considers fair probabilistic classification where the outputs of primary interest are predicted probabilities, commonly referred to as scores. We formulate the problem of transforming scores to satisfy fairness constraints while minimizing the loss in utility. The formulation can be appli…

Cited by 56SourcePDFScholar
2019

Repairing without Retraining: Avoiding Disparate Impact with Counterfactual Distributions

ICML 2019oral

When the performance of a machine learning model varies over groups defined by sensitive attributes (e.g., gender or ethnicity), the performance disparity can be expressed in terms of the probability distributions of the input and output variables over each group. In this paper, we exploit this fact…

2017

Optimized Pre-Processing for Discrimination Prevention

NeurIPS 2017poster

Non-discrimination is a recognized objective in algorithmic decision making. In this paper, we introduce a novel probabilistic formulation of data pre-processing for reducing discrimination. We propose a convex optimization for learning a data transformation with three goals: controlling discriminat…

Cited by 1131SourcePDFScholar
2016

Correcting Forecasts with Multifactor Neural Attention

ICML 2016poster

Automatic forecasting of time series data is a challenging problem in many industries. Current forecast models adopted by businesses do not provide adequate means for including data representing external factors that may have a significant impact on the time series, such as weather, national events,…

Cited by 43SourcePDFScholar