Gautam Kamath
@gautamkamath
Assistant Prof of CS at the University of Waterloo, Faculty and Canada CIFAR AI Chair at the Vector Institute. Joining NYU Courant in September 2026. Co-EiC of TMLR. My group is The Salon. Privacy, robustness, machine learning.
I'm pleased to share our #ICML2026 tutorial on machine unlearning! Presented by Vinith Suriyakumar and myself, it includes a full set of videos recorded and posted to YouTube! Please check it out: unlearning-tutorial.github.io
Curious how many people actually submit more than 20 papers, so I explored #ICLR2026 data (took at 30 mins w codex). 101 people had over 20 submissions (max 54), contributing 2226 papers (11.2% of 19,814 submissions). Capping them would block at least 500 papers (2.5% total).
Some are understandably upset by the latter policy. Those on the other side may get it. TMLR submissions have 4x'd, largely fueled by single authors who have no prev ML papers. Sadly, due to AI, a (short-term?) downstream effect will be additional gatekeeping and credentialism.
ICLR 2027 has authorship quotas: - No more than 20 submissions per author - No more than 1 submission where no author has a paper previously accepted to a major ML conference From iclr.cc/Conferences/...
The winner is this excellent paper on reconstruction attacks against the 2010 US census arxiv.org/abs/2312.11283
We were the runner up for the Caspar Bowden PETS award. This recognized our work on differentially private fine tuning of language models. It was a big effort by a sizeable group across NA, Europe, and Asia. Thanks to the committee for the recognition.
I haven't been to UCalgary in nearly twenty years. (I feel very old saying that.) I last came for the Shad Valley program in 2007. For nostalgia sake, I'm staying in the same dorm (Rundle Hall) that I did back then.
Cheers from Calgary, where I am for #PETS2026! The general chairs have done a phenomenal job, you can see here they have "pets" (weighted helium balloons) you can adopt and take for a walk.
Computer science is known for its castles: Dagstuhl and Bertinoro, notably. Came to pitch Charles on adding Windsor to the mix, but he dodged me with the chopper...
From ICML to ICALP -- cheers from Royal Holloway, University of London!
Closed out my trip to #ICML2026 with an awesome event with @kyunghyuncho.bsky.social and @aliceatkaist.bsky.social hosted by kaist and upstage. Sadly I only had two days in Seoul but I hope to be back soon for longer. Next, on to #ICALP2026 in London!
Super fun to be on a career advice panel at the KAIST ICML event! With so many lovely folks (Hsuan-Tien Lin, Niloofar Mireshghallah, Yoon Kim, @emtiyaz.mastodon.social.ap.brid.gy, moderated by @hyunwoo-kim.bsky.social). TY @aliceatkaist.bsky.social & others for organizing! Only 1 more day in Seoul🥲
When someone absolutely demands a combinatorial construction for linear-sized cut sparsifiers
Taylor Swift really needs to be more thoughtful about scheduling around ML conferences. First her Eras Tour finale clashed with #NeurIPS2024. And now her wedding conflicts with the start of #ICML2026? No regrets about turning down the wedding invite. See you soon in Seoul!
Looking forward to being at #ICML2026 in Seoul next week! Unfortunately I'll be there for only 60 hours, but 2.5 of those will be at our machine unlearning tutorial (co-presented with Vinith Suriyakumar)! Monday July 6 at 9 AM -- don't miss out!
Congrats to Dr. Argyris Mouzakis @argymouz.bsky.social! He successfully defended his PhD thesis today. He's the first PhD graduate of The Salon. He continues on to a postdoc at @utaustin.bsky.social IFML, hence the cowboy hat. (As you can see, they did not eat the 🍓🧀🎂)
Congratulations to my @nyucourant.bsky.social colleague Allen Liu for winning the @acm.org Doctoral Dissertation Award! "Learning Theoretic Foundations for Understanding Quantum Systems" This is given to the most outstanding CS doctoral dissertation in the world.
Lots more in the paper: how does DPO fit into the picture? What if attackers have different goals? etc. Paper: arxiv.org/abs/2606.04929 Code: github.com/jcksanderson... Led by Jack Sanderson (jcksanderson.com), w/ Yihan Wang, Xiaoqian Lu, co-supervised w/ Yiwei Lu
So far, it seems like the system is shockingly robust, right? Unfortunately, this is an illusion. First row reconfirms [RT24]: with no SFT poison, it's very hard to poison the PPO'd model (needs >5% poison). But, with just a little SFT poison (0.5%), attack succeeds w/ 3%. 5/n
What about poisoning PPO? A remarkable paper of @javirandor.com and @floriantramer.bsky.social (arxiv.org/abs/2311.14455) shows that just 0.5% poison is enough to break a reward model (L)! Again, fear not: somehow, it takes a (high) 5% poisoning before it transfers to the RLHF'd model (R). 4/n
There's multiple post-training phases attackers can infiltrate: SFT, DPO, PPO. Let's start with SFT. With just 2% SFT poisoning, 90% attack success (L)! But not to worry, RLHF works as we hope (?): it wipes away the poison. An RM scores outputs just like a clean model (R). 3/n
🧵Feeling safe against data poisoning in post-training? Think again! Individual components of LLM post-training pipelines are surprisingly robust to data poisoning attacks. In work led by Jack Sanderson (co-advised w Yiwei Lu), we show they crumble when attacked together. 1/n
Laudatio: sigact.org/prizes/g%C3%... Article by @uwcheritoncs.bsky.social comms guy Joe Petrik. Pic's a few years old (you can tell by the gray hairs). He joked, this shot is for when you win the Turing or the Gödel. Didn't think we'd actually get to use it. 7/7 cs.uwaterloo.ca/news/gautam-...
Honoured that our 2016 paper, Robust Estimators in High Dimensions without the Computational Intractability, w/ Ilias Diakonikolas, @daneelssoul.bsky.social, @jerryzli.bsky.social, Ankur Moitra, Alistair Stewart, was awarded the Gödel Prize This is the highest award for papers in theoretical CS 1/7
"People submit too many papers to ML conferences" Meanwhile, at IEEE Transactions on Wireless Communications: "You may not submit more than 36 papers per year." Apparently this is a new policy. I would be super curious to see the stats on how many people are submitting more.