Deep Dive Workshop

Security, Safety, and Privacy in AI: Cross-disciplinary Perspectives on Trustworthy AI

Friday 9 October 10.05

Lead organizer: Johannes Bjerva, Professor of Natural Language Processing and Artificial Intelligence, Aalborg University, Department of Computer Science

AI systems can break in unexpected and interconnected ways. A privacy leak may be enabled by language, an adversarial perturbation may trigger unsafe behaviour, and rare instabilities may emerge only after deployment. This interactive workshop combines perspectives from dynamical systems, privacy-preserving machine learning, NLP, and adversarial robustness to examine how AI vulnerabilities arise, how they can be detected, and what meaningful mitigation or guarantees might look like.

Through expert inputs, structured discussion, and hands-on vulnerability mapping, participants will explore topics such as privacy inference, prompt manipulation, multilingual jailbreaks, data poisoning, adversarial speech, and rare catastrophic failures. The goal is to build a shared vocabulary, map complementary methods, and identify new opportunities for collaboration on trustworthy AI.

 

Programme

Welcome and framing  5 minutes
Brief introduction to the Security, Safety, and Privacy in AI consortium, the motivation for the workshop, and the relevance of the topic for the D3A community. The framing will introduce the workshop’s central structure: understanding AI vulnerabilities, detecting them, and developing mitigation strategies or guarantees.

Section 1 – Lightning research perspectives  25 minutes
Four short research-group pitches will introduce complementary perspectives from the participating research groups. Each pitch will focus on one central vulnerability perspective, the methods used to study it, and the open challenges it raises.

  • Rafal Wisniewski / Abhijit Mazumdar: Safety of AI systems from dynamical and stochastic systems perspectives — 6 minutes
  • Qiongxiu Li: Privacy risks, inference-based exposure, and security implications of generative AI — 6 minutes
  • Johannes Bjerva: NLP, linguistic structure, multilingual vulnerabilities, and language as an AI attack surface — 6 minutes
  • Zheng-Hua Tan: Adversarial robustness, detection, and generative purification methods — 6 minutes

Structured mingling: What counts as an AI vulnerability?   25 minutes
Participants will take part in a structured mingling exercise designed to establish a shared cross-disciplinary vocabulary. Participants will discuss how different fields define AI vulnerabilities, which forms of failure they consider most serious, and what kinds of evidence or guarantees they consider convincing. The exercise is intended to connect perspectives from dynamical systems, privacy, NLP, adversarial robustness, and applied AI safety.

Break  10 minutes

Section 2 – Invited perspectives  25 minutes
An invited speaker will provide external perspectives on AI security, safety, privacy, or trustworthy AI. The talk will connect the consortium’s research themes to broader developments in the field and to the interests of the D3A community.

  • Invited talk— 15 minutes + 10 minutes Q&A

Vulnerability mapping exercise  30 minutes
Participants will work in small interdisciplinary groups to map concrete AI vulnerabilities across the workshop’s three main dimensions: understanding, detection, and mitigation. Each group will analyse one vulnerability scenario, identify the mechanisms behind it, discuss how it could be detected, and propose possible mitigation strategies or guarantees. Example vulnerability types include inference-based privacy exposure, prompt manipulation, multilingual jailbreaks, poisoned data, adversarial perturbations, instability under deployment, and rare catastrophic failures. The output will be a shared map of AI vulnerabilities and cross-disciplinary methods relevant to the D3A community.

Break  10 minutes

Section 3 – Shared methods and collaboration points  30 minutes
Participants will continue in small groups to identify methodological overlaps and possible collaboration points across the perspectives presented in the workshop. The aim is to identify where cross-disciplinary collaboration could lead to stronger approaches for understanding, detecting, and mitigating AI vulnerabilities.

Section 4 – Future vision synthesis  15 minutes
Rafal Wisniewski will present a forward-looking synthesis on Classical Dynamical and Stochastic Systems as Tools for Safe AI. This session will connect the workshop themes to mathematical tools such as dynamical systems theory, stochastic stability, certificates, and rare event analysis, and outline how these tools can contribute to principled approaches to AI safety.

Wrap-up and next steps  5 minutes
Final synthesis of key takeaways, possible collaborations, and future activities within the Security, Safety, and Privacy in AI consortium and the broader D3A community. The wrap-up will identify concrete next steps emerging from the structured mingling, vulnerability mapping, and group discussions.

Speakers’ list
  • Mario Fritz – CISPA Helmholtz Center for Information Security; Professor, Saarland University: Trustworthy AI at the Intersection of Security, Privacy, and Machine Learning (not yet invited)
  • Carmela Troncoso – Associate Professor, EPFL; Head of SPRING Lab / Max Planck Institute for Security and Privacy: Engineering Privacy-Preserving AI Systems for Societal Risk Reduction (not yet invited)
  • Qiongxiu Li – Tenure Track Assistant Professor – AAU
  • Rafal Wisniewski – Professor – AAU
  • Zheng-Hua Tan – AAU
Level

Intermediate: For attendees who have basic understanding or some experience with the subject but are not yet advanced.

Organizers
  • Johannes Bjerva (lead organizer) – Professor of Natural Language Processing and Artificial Intelligence – Aalborg University, Department of Computer Science
  • Qiongxiu Li – Tenure-Track Assistant Professor, Aalborg University, Department of Electronic Systems
  • Rafal Wisniewski – Professor; Head of Research, Department of Electronic Systems – Aalborg University, Department of Electronic Systems
  • Zheng-Hua Tan – Professor of Machine Learning and Speech Processing – Aalborg University, Department of Electronic Systems
  • Yuting Hou, PhD student, AAU
  • Abhijit Mazumdar, Postdoc, AAU
  • Rahul Misra, Postdoc, AAU
  • Kevin Wilkinghoff, Postdoc, AAU
  • Wenrui Yu, PhD student, AAU
  • Flavio La Manna, PhD student, AAU