Amartya Sanyal
Assistant Professor in Machine Learning · University of Copenhagen; Adjunct Assistant Professor at IIT Kanpur
About
I am an Assistant Professor in Machine Learning in the Department of Computer Science in the University of Copenhagen and an Adjunct Assistant Professor at the Department of Computer Science, IIT Kanpur. I lead the Foundations of Responsible Machine Learning group in UCPH, and my research spans trustworthy machine learning, privacy, robustness, fairness, and learning with limited or imperfect data.
Prior to this, I was a postdoctoral fellow at the Empirical Inference group in Max Planck Institute for Intelligent Systems, Tubingen where I worked closely with Prof. Bernhard Schölkopf , and before that I was a postdoctoral fellow at ETH Zurich AI Center where I worked closely with Prof. Fanny Yang . I completed my DPhil (PhD) at the Department of Computer Science, University of Oxford, funded by the Turing Doctoral Studentship; I was also a member of the Torr Vision Group, and my DPhil advisors were Varun Kanade and Philip H.S. Torr.
Prior to that, I completed my undergraduate (B.Tech in Computer Science) at the Indian Institute of Technology, Kanpur. On various occasions, I have spent time at Facebook AI Research (FAIR), Twitter Cortex , Laboratory for Computational and Statistical Learning, Montreal Institute of Learning Algorithms , and Amazon ML.
Foundations of Responsible Machine Learning
Read more about our group here.
PhD Students
- Giorgio Racca (Co-advised with Michal Valko)
- Luka Radić
- Carolin Heinzler (Co-advised with Prof. Amir Yehudayoff)
- Johanna Düngler (DDSA PhD fellow; Co-advised with Prof. Rasmus Pagh)
- Max Cairney-Leeming (ELLIS PhD student; Co-advised with Prof. Christoph H. Lampert)
- Anmol Goel (ELLIS PhD Student; Co-advised with Prof. Iryna Gurevych)
- Omri Ben-Dov (PhD Student; Co-advised with Dr. Samira Samadi)
- Yaxi Hu (PhD Student; Advised by Prof. Bernhard Schölkopf and Prof. Fanny Yang)
Senior Researchers and Postdocs
- Vikrant Singhal (Fixed Term Assistant Professor)
- Prathamesh Dharangutte (Postdoc)
- Christian Janos Lebeda (Carlsberg Reintegration Fellow; Postdoc)
Former Visiting Researchers
- Erell Boutin-Jeanniard du Dot (now a PhD student at the University of British Columbia)
Recent News
Our paper Optimal Rates for Adaptive Private k-PCA was accepted at NeurIPS 2026 as a spotlight. Our paper on private question answering without private training was accepted at InfPriv: The New Landscape of AI Privacy, a workshop at NeurIPS 2026.
My new preprint Private online learning and prediction for Littlestone classes is now available on arXiv.
Our paper Fairness for the People, by the People: Minority Collective Action was accepted at EAAMO 2026.
Our paper Online Learning and Unlearning: Efficient Algorithms with Near-Optimal Regret Guarantees was published in TMLR.
I co-organised the Learning Theory Summer School and Workshop and the Workshop on Differential Privacy and Unlearning in Machine Learning in Copenhagen.
Our paper Language Generation with Replay: A Learning-Theoretic View of Model Collapse was accepted at ICML 2026. Our paper Why Forget-Only Unlearning Needs Memorization was accepted at the Workshop on the Impact of Memorization on Trustworthy Foundation Models at ICML.
Our paper “Learning in an Echo Chamber: Online Learning with Replay Adversary” was accepted at SODA 2026 and selected for FORC highlights.
Our paper “Delta-Influence: Identifying Poisons via Influence Functions” was accepted at TMLR.
Our paper titled An Iterative Algorithm for Differentially Private k-PCA with Adaptive Noise was accepted at NeurIPS 2025.
I co-hosted two events at EurIPS 2025: the Learning Theory Alliance affinity event and the EurIPS Privacy-Preserving Machine Learning Workshop.
I am co-directing the P1 program on Data Privacy in Machine Learning with Claudio Orlandi and Rasmus Pagh.
I received the Villum Young Investigator Grant for research on privacy, unlearning, and online learning. See our current PhD and postdoc openings.
Three papers on differentially private alignment of LLMs, machine unlearning, and training data attribution were accepted at ICLR 2025 and one paper on OOD robustness and label noise at AISTATS 2025.
Publications
41 publications
Recent papers
- Preprint — arXiv 2026Private online learning and prediction for Littlestone classes
- EAAMO — Equity and Access in Algorithms, Mechanisms, and Optimization 2026Fairness for the People, by the People: Minority Collective Action
- TMLR, TPDP — Transactions on Machine Learning Research 2026Online Learning and Unlearning: Efficient Algorithms with Near-Optimal Regret Guarantees
- ICML — International Conference on Machine Learning 2026Language Generation with Replay: A Learning-Theoretic View of Model Collapse
- ICML Workshop — Workshop on the Impact of Memorization on Trustworthy Foundation Models 2026Why Forget-Only Unlearning Needs Memorization
- TPDP — Theory and Practice of Differential Privacy 2026Less Noise, Same Certificate: Retain Sensitivity for Unlearning
All papers by year
No publications match your search. Try another title, author, or topic.
202610 papers
- Preprint — arXiv 2026Private online learning and prediction for Littlestone classes
- EAAMO — Equity and Access in Algorithms, Mechanisms, and Optimization 2026Fairness for the People, by the People: Minority Collective Action
- TMLR, TPDP — Transactions on Machine Learning Research 2026Online Learning and Unlearning: Efficient Algorithms with Near-Optimal Regret Guarantees
- ICML — International Conference on Machine Learning 2026Language Generation with Replay: A Learning-Theoretic View of Model Collapse
- ICML Workshop — Workshop on the Impact of Memorization on Trustworthy Foundation Models 2026Why Forget-Only Unlearning Needs Memorization
- TPDP — Theory and Practice of Differential Privacy 2026Less Noise, Same Certificate: Retain Sensitivity for Unlearning
- TPDP — Theory and Practice of Differential Privacy 2026Adaptive Sampling for Private Worst-Case Group Optimization
- TMLR — Transactions on Machine Learning Research 2026Delta-Influence: Identifying Poisons via Influence Functions
- TPDP — Theory and Practice of Differential Privacy 2026LoRA and Privacy: When Random Projections Help (and When They Don't)
- FORC, SODA — Symposium on Discrete AlgorithmsLearning in an Echo Chamber: Online Learning with Replay Adversary
Symposium on Foundations of Responsible Computing (highlights) 2026
20256 papers
- NeurIPS — Advances in Neural Information Processing Systems 2025An iterative algorithm for Differentially Private k-PCA with adaptive noise
- AISTATS — International Conference on Artificial Intelligence and Statistics 2025Accuracy on the wrong line: On the pitfalls of noisy data for out-of-distribution generalisation
- ICLR — International Conference on Learning Representations 2025PSA: Differentially Private Steering for Large Language Model Alignment
- ICLR — International Conference on Learning Representations 2025Provable unlearning in topic modeling and downstream tasks
- ICLR — International Conference on Learning Representations 2025Protecting against simultaneous data poisoning attacks
- Preprint — arXiv 2025Open Problems in Machine Unlearning for AI Safety
20247 papers
- TMLR — Transactions on Machine Learning Research 2024Corrective Machine Unlearning
- NeurIPS — Advances in Neural Information Processing Systems 2024Robust Mixture Learning when Outliers Overwhelm Small Groups
- NeurIPS — Advances in Neural Information Processing Systems 2024What Makes and Breaks Safety Fine-tuning? A Mechanistic Study
- TPDP, COLT — Conference on Learning Theory 2024On the Growth of Mistakes in Differentially Private Online Learning: A Lower Bound Perspective
- ICML — International Conference on Machine Learning 2024The Role of Learning Algorithms in Collective Action
- TPDP, ICML — International Conference on Machine Learning 2024Provable Privacy with Non-Private Pre-Processing
- TPDP, AISTATS — Artificial Intelligence and StatisticsCertified private data release for sparse Lipschitz functions
Theory and Practice of Differential Privacy 2024
20238 papers
- NeurIPS — Advances in Neural Information Processing Systems 2023Can semi-supervised learning use all the data effectively? A lower bound perspective Spotlight Paper
- PILLAR: How to make semi-private learning more effective
- TMLR — TMLR 2023Catastrophic overfitting can be induced with discriminative non-robust features
- ICML — International Conference on Machine Learning 2023Certifying Ensembles: A General Certification Theory with S-Lipschitzness
- NeurIPS Workshop — Workshop on Understanding Deep Learning Through Empirical Falsification 2023How robust accuracy suffers from certified training with convex relaxations Oral Paper
- Preprint — Arxiv 2023Towards Adversarial Evaluations for Inexact Machine Unlearning
- How robust is unsupervised representation learning to distribution shift?
- A law of adversarial risk, interpolation, and label noise
20223 papers
- NeurIPS — Neural Information Processing Systems (NeurIPS) 2022. 2022Make Some Noise: Reliable and Efficient Single-Step Adversarial Training
- How unfair is private learning ? Oral Paper
- Open Problem: Do you pay for Privacy in Online Learning ?
20212 papers
- How benign is benign overfitting? Spotlight Paper
- Progressive Skeletonization: Trimming more fat from a network at initialization
20202 papers
- NeurIPS — Advances in Neural Information Processing Systems (NeurIPS) 2020Calibrating Deep Neural Networks using Focal Loss
- Stable Rank Normalization for Improved Generalization in Neural Networks and GANs Spotlight Paper
20181 papers
- TAPAS: Tricks to Accelerate (encrypted) Prediction As a Service
Talks and Tutorials
- What can't we learn privately? Lower bounds for Differentially Private Learning
- Tutorial: Introduction to Machine Unlearning
- Keynote: Machine Unlearning: Promises, Failures, and New Directions
- Lower Bounds for Differentially Private Online Learning
Earlier talks
- Tutorial - Building trustworthy ML: The role of label quality and availability
- ELLIS talk: Privacy with Correlated data
Teaching
University of Copenhagen · 2026–27
- Privacy in Machine Learning (PriMaL) — Course coordinator; Block 1. Differential privacy, privacy attacks, and federated learning.
- Machine Learning B — Lecturer with Yevgeny Seldin and Nirupam Gupta; Block 4.
Previous Teaching
- Guarantees in Machine Learning; Projects in Machine Learning Research — ETH Zürich, 2022.
- Computational Learning Theory; Theory of Optimization; Machine Learning — University of Oxford, 2018–21.
- Linear Algebra, Real Analysis and ODEs — IIT Kanpur, 2014.
Funding and Academic Service
Research Funding and Programs
- Villum Young Investigator Grant — PI, 2025–29; DKK 7 million. Privacy, unlearning, and online learning.
- Novo Nordisk Foundation Startup Grant — PI, 2024–28; DKK 4 million.
- P1 Program on Data Privacy in Machine Learning — Co-director with Claudio Orlandi and Rasmus Pagh, 2025–27.
- Hasler Stiftung Grant — PI, 2022–23; CHF 50,000. Privacy and Fairness in Machine Learning.
Organization and Service
- Co-organizer, Learning Theory Summer School and Workshop, Copenhagen, June 2026.
- Co-organizer, Workshop on Differential Privacy and Unlearning in Machine Learning, Copenhagen, June 2026.
- General Chair, IEEE Conference on Secure and Trustworthy Machine Learning (SaTML), Copenhagen, 2025.
- Co-host, Learning Theory Alliance affinity event and Privacy-Preserving Machine Learning Workshop, EurIPS 2025.
- ENCORE Workshop on Defining Holistic Private Data Science for Practice, 2025; ICLR Workshop on Pitfalls of Limited Data and Computation for Trustworthy ML, 2023.
- Area Chair: AISTATS and NeurIPS. Reviewer for journals and conferences including JMLR, TMLR, ICML, ICLR, and COLT.