Machine unlearning is often introduced as efficient data deletion: when specified training records must be removed, update the model to match retraining without them. But language-model unlearning now includes requests such as removing a concept or suppressing a copyrighted work, where neither the relevant training records nor the right retraining counterfactual may be obvious. As unlearning moves beyond record deletion, specifying what to forget becomes part of the technical problem. My recent work studies this shift from three directions: certifying model updates once the forget set is given, selecting data to remove when the target is a distribution, and constructing forget sets from higher-level requests for language models. These results suggest separating three parts of the problem—what should be forgotten, which data should represent that goal, and how the model should be updated—and asking for guarantees that match the intended form of forgetting.
About AdvML-Frontiers × CoTMA
The AdvML-Frontiers × CoTMA workshop is a cross-community effort that unifies two complementary workshop brands: AdvML-Frontiers and CoTMA (Compositional Threats in Multi-Agent AI Systems). As foundation models evolve from standalone predictors into reusable assets and interconnected multi-agent systems, the adversarial surface of AI has expanded far beyond traditional input-output robustness. Building on the AdvML-Frontiers theme, the workshop focuses on securing frontier models both as valuable assets and as complex systems. This includes emerging security challenges surrounding provenance, watermarking, fingerprinting, unauthorized distillation, supply-chain attacks, model integrity, reasoning-time intervention, and system-level robustness. Complementing this perspective, CoTMA focuses on compositional and interaction-layer threats in multi-agent AI systems, where vulnerabilities emerge through communication, delegation, shared memory, tool use, and coordination among agents. By bridging these two themes, AdvML-Frontiers × CoTMA aims to advance a broader vision of AI security and safety for interconnected, evolving, and deployable AI ecosystems, while fostering collaboration across adversarial ML, foundation models, systems security, and agentic AI communities.
Invited Speakers
TBD
Schedule
Opening Remarks
Invited Talk (AdvML)
Nicole Nichols
Palo Alto Networks
Invited Talk (AdvML)
Somesh Jha
University of Wisconsin–Madison
☕ Coffee Break
AdvML Rising Star Award Announcement
AdvML Rising Star Award Presentation
Awardee: Youssef Allouah
Title: What Does It Mean for a Language Model to Forget?
AdvML Rising Star Award Presentation
Awardee: Vaidehi Patil
Title: Unlearning, Privacy Leakage, and Adversarial Interaction: Stress-Testing Privacy in Modern LLM Systems
As large language models (LLMs) evolve into multimodal, multi-agent, and conversational systems, privacy risks extend far beyond simple memorization. In this talk, I present a cohesive view of my recent work on understanding and controlling sensitive information leakage in LLMs or agentic systems under adversarial interaction. I begin by examining whether sensitive information can truly be deleted from model weights, showing that even state-of-the-art unlearning and model editing methods leave recoverable traces under both white-box and black-box attacks. I then extend this analysis to multimodal LLMs, introducing UnLOK-VQA, a benchmark for multimodal unlearning, and demonstrating that cross-modal attacks are significantly more effective than text- or image-only attacks. Next, I address the core tension between deletion and utility, presenting UPCORE, a coreset-selection based framework that improves unlearning by selectively pruning forget data to reduce collateral damage. I then move to multi-agent settings, where privacy leakage emerges compositionally across interactions. I show how Theory-of-Mind reasoning and collaborative defenses mitigate these risks. Finally, I introduce the Double-Agent paradigm, where privacy protection becomes a strategic interaction: the defender must model the adversary’s beliefs and deliberately steer them toward a false belief that sensitive information has been extracted. Overall, this talk argues that safeguarding privacy in modern LLM systems requires moving beyond static notions of information deletion toward adversarially robust, interaction-aware, and utility-preserving approaches.
AdvML Rising Star Award Presentation
Awardee: Jianing Zhu
Title: Reliability Over the Lifetime of Evolving AI Systems
For most of the last decade, machine learning treated reliability as something to be established once: a model was evaluated before deployment, and that evaluation was trusted for its entire service life. Modern AI systems no longer fit this picture. They run continually, accumulate history, and update their own state, so the system in deployment gradually drifts away from the one that was evaluated. This talk asks what it takes to sustain reliability over that lifetime. Drawing on my research, I will discuss how to withstand corruption of an agent’s operating process, how to detect degradation that emerges only along a trajectory, and how to govern what a long-running agent retains and exposes. I will close with an outlook on reliability as something we sustain across a lifetime, rather than establish once and trust.
Invited Talk (CoTMA)
Evangelos Papalexakis
University of California, Riverside
Title: Tensor Methods for Trustworthy & Robust AI Models
Evangelos (Vagelis) Papalexakis is a Full Professor and the Ross Family Chair of the CSE Dept. at University of California Riverside. He received his PhD degree at the School of Computer Science at Carnegie Mellon University (CMU). Prior to CMU, he obtained his Diploma and MSc in Electronic & Computer Engineering at the Technical University of Crete, in Greece. Broadly, his research interests span the fields of Data Science, Machine Learning, Artificial Intelligence, and Signal Processing.
His research involves designing interpretable models and scalable algorithms for extracting knowledge from large multi-aspect datasets, with specific emphasis on tensor factorization models, and applying those algorithms to a variety of real-world problems, including AI for Science and Engineering, explainable AI, gravitational wave detection, cybersecurity, transportation and railway safety, and precision agriculture.
He is heavily involved in the data science research community with extensive experience in conference organization, including organizing a workshop at ACM SIGKDD 2019 on "Tensor Methods for Emerging Data Science Problems", being the Deep Learning Day Co-Chair for ACM SIGKDD 2019, the Doctoral Forum Co-Chair for SIAM SDM 2021, the Demos Co-Chair for ACM WSDM 2022, the Program Co-Chair for SIAM SDM 2022, the General Co-Chair for SIAM SDM 2024 and SIAM SDM 2025, the Blue Sky Track Co-Chair for KDD 2026, and is currently serving as the Steering Committee Chair for SIAM SDM.
His work has appeared in top-tier conferences and journals, and has attracted a number of distinctions, including the 2017 SIGKDD Dissertation Award (runner-up), a number of paper awards, the National Science Foundation CAREER award, the 2021 IEEE DSAA Next Generation Data Scientist Award, the 2022 IEEE Signal Processing Society Donald G. Fink Overview Paper Award, and the IEEE ICDM 2022 Tao Li Award and 2025 PAKDD Early Career Research Award, both of which award excellence in early-career researchers in data mining. Finally, Prof. Papalexakis is a 2025 alumnus of the Frontiers of Engineering (FOE) Symposium by the National Academy of Engineering (NAE).
Tensors methods have been traditionally widely used in expressing complex relations in data and extracting interpretable latent insights. At the same time, more recently, tensor methods have been shown to represent model weights, with model compression through low-rank factorization being the most successful such application. In this talk we explore a number of exciting examples where tensor methods, whether applied directly on a model or indirectly in inputs or outputs of a model, can lead to more compact, trustworthy, and robust models.
Invited Talk (CoTMA)
Rahul Gupta
Amazon AGI
Oral/Spotlight Paper Presentations I
(15 min)
Auditing Prompt Injection Defenses Before They Reach Users: What Strong Adversaries RevealXiaoxue Yang, Bozhidar Stevanoski, Matthieu Meeus, Yves-Alexandre de Montjoye
🍽 Lunch
Poster Session 1
Invited Talk (AdvML)
Nathalie Baracaldo
IBM Research
Invited Talk (CoTMA)
Eugene Bagdasarian
UMass Amherst & Google
Invited Talk (AdvML)
Motahhare Eslami
Carnegie Mellon University
Oral/Spotlight Paper Presentations II
(15 min)
CoT-Guard: Small Models for Strong MonitoringNirav Diwan, Han Wang, Berkcan Kapusuzoglu, Ramin Moradi, Supriyo Chakraborty, Giri Iyengar, Sambit Sahu, Huan Zhang, Gang Wang
☕ Coffee Break + Poster Session 2
Panel
Evtimov, Beirami, Cameron, Bagdasarian
Closing Remarks
AdvML Rising Star Award — Call for Application
Application Instructions
- Eligibility and Requirements: Senior PhD students enrolled in a PhD program before December 2022 or researchers holding postdoctoral positions (including faculty positions) who obtained PhD degree after April 2023.
- Applicants are required to submit the following materials:
- CV (including a list of publications).
- Research statement (up to 2 pages, single column, excluding references), including your research accomplishments and future research directions.
- A 5-minute video recording for your research summary.
- Two letters of recommendation uploaded to this form by the referees before July 31st, 2026 (AoE).
- The awardee must attend the COLM AdvML-Frontiers × CoTMA Workshop and give a presentation in person.
- Submit the required materials (a),(b),(c) to this form by July 24th, 2026 (AoE).
Important dates
| Application materials | Jul 24, 2026 |
| Recommendation letters | Jul 31, 2026 |
Call For Papers
Submission Instructions
Submission Format
We invite paper submissions of up to 6 pages (excluding references and supplementary material).
Please ensure that all submissions conform to the COLM template and submit via OpenReview. Accepted papers are non-archival (which will not appear in formal conference proceedings). Concurrent submissions are allowed, but it is the responsibility of the authors to verify compliance with other venues' policies. Accepted papers will be allocated either a spotlight talk or a poster presentation.
Important Dates
| Submission deadline | |
| Notification to authors | |
| Workshop date | Oct 9, 2026 |
Topics
The topics for AdvML-Frontiers × CoTMA include, but are not limited to:
- Adversarial machine learning for foundation models
- Multi-agent AI security and compositional threats
- Inter-agent attacks and trust exploitation
- Prompt injection and indirect prompt attacks
- Memory poisoning and RAG security
- Tool-use and API exploitation
- Model provenance, fingerprinting, and watermarking
- Model stealing and supply-chain attacks
- Backdoors and poisoning in frontier model pipelines
- Adversarial attacks on reasoning models and chain-of-thought
- Test-time adaptation and intervention security
- Robustness of agentic and embodied AI systems
- Security for multimodal models and VLAs
- Alignment and safety evaluation for frontier systems
- Theoretical foundations of robustness, controllability, and identifiability
- Governance, auditing, and accountability for AI agents
- Benchmarks and red-teaming frameworks for agentic systems
Organizers
AdvML-Frontiers Organizers
Sijia Liu
Michigan State University
Pin-Yu Chen
IBM Research, USA
Dongxiao Zhu
Wayne State University, USA
Eric Wong
University of Pennsylvania, USA
Yao Qin
UC Santa Barbara, USA
Kathrin Grosse
IBM Research Europe, Switzerland
Baharan Mirzasoleiman
UCLA, USA
Sanmi Koyejo
Stanford University, USA
CoTMA Organizers
Abhinav Mohanty
Amazon AGI
Tong Wang
Amazon AGI
Swabha Swayamdipta
University of Southern California
Ninareh Mehrabi
Meta
Anil Ramakrishna
Meta
Yeonsung Jung
KAIST AI
Homa Hosseinmardi
UCLA
Christos Christodoulopoulos
UK ICO
Workshop Publicity Student Chair
Bingqi Shang
Michigan State University
Contacts
For website-related questions, please contact the Workshop Publicity Student Chair. For paper submission and logistics questions, please contact the organizing committee at advml-frontiers-cotma26@googlegroups.com.