Outstanding second- and third-year undergraduates and first-year Masters students in Informatics and other STEM disciplines are invited to learn about cutting-edge research in computer science. Leading researchers will engage with attendees in their areas of expertise through short courses, seminars, discussions, and informal interactions.
Attendance is by invitation only. Required application materials include information about your undergraduate/graduate academic record, and a concise description of your key accomplishments to date.
Applicants submitting their applications by August 13 will receive notification of their status by August 17. Submissions received after August 13 will be evaluated on a rolling basis until all positions are filled. We encourage you to apply as early as possible.
Participation to the event is free and food and accommodation will be provided to all participants.
Battista Biggio (MSc 2006, PhD 2010) is a Professor of Computer Engineering at the University of Cagliari, Italy, and research co-director of AI Security at the sAIfer lab (www.saiferlab.ai). He has been attacking machine-learning (ML) models well before adversarial examples were discovered, in the context of cybersecurity applications such as spam filtering, malware detection, web security, and biometric recognition (PRJ 2018). His team was the first to formalize attacks on ML models as optimization problems and to demonstrate gradient-based evasion (ECML-PKDD 2013) and poisoning (ICML 2012) attacks on ML algorithms, playing a leading role in the establishment and advancement of this research field. His seminal paper on “Poisoning Attacks against Support Vector Machines” won the 2022 ICML Test of Time Award. His work on “Wild Patterns” won the 2021 Best Paper Award and Pattern Recognition Medal from Elsevier Pattern Recognition. Prof. Biggio has managed several industrial, national, and EU-funded projects, and regularly serves as Area Chair for top-tier conferences in machine learning and computer security, such as NeurIPS and the IEEE Symposium on Security and Privacy. He is an Associate Editor-in-Chief of Pattern Recognition and chaired IAPR TC1 (2016-2020). He is a Fellow of IEEE, IAPR, and AAIS, a Senior Member of ACM, and a member of IAPR and ELLIS.
Daniele Micciancio is a leading authority in cryptography, complexity theory, and lattice-based cryptographic primitives. He is currently a Professor in the Computer Science and Engineering Department at the University of California, San Diego (UCSD), where he has been a faculty member since 1999. He received his Ph.D. in Computer Science from the Massachusetts Institute of Technology (MIT) in 1998.
Dr. Micciancio’s foundational research focuses on the computational complexity of lattice problems, worst-to-average-case reductions, fully homomorphic encryption, and efficient post-quantum cryptographic schemes. He co-authored the influential book Complexity of Lattice Problems: A Cryptographic Perspective and has published numerous classic papers detailing lattice trapdoors, compact knapsacks, and advanced bootstrapping methods.
Throughout his career, Dr. Micciancio has been recognized with prestigious honors, including the NSF CAREER Award (2001), a Hellman Fellowship (2001), a Sloan Fellowship (2003), and multiple FOCS Test of Time Awards (2022, 2024). In 2019, he was named a Fellow of the International Association for Cryptologic Research (IACR) for his pioneering contributions to lattice-based cryptography.
Kilian Q. Weinberger is a Professor of Computer Science at Cornell University. He received his Ph.D. in Machine Learning from the University of Pennsylvania under the supervision of Lawrence Saul and holds an undergraduate degree in Mathematics and Computing from the University of Oxford. He was born and raised on planet Earth.
His research focuses on machine learning and its applications, including learning under resource constraints, metric learning, AI for science, computer vision, autonomous vehicles, Gaussian processes, and deep learning. Before joining Cornell, he was an Associate Professor at Washington University in St. Louis and previously a research scientist at Yahoo! Research in Santa Clara.
He has received Best Paper Awards at ICML CVPR, AISTATS, and KDD, the AAAI Outstanding Senior Program Chair Award, an NSF CAREER Award, the Daniel M. Lazar ’29 Excellence in Teaching Award, and the Ann S. Bowers Teaching and Advising Excellence Award.
He served as the seventh President of ICML, and has been a member of the Sloan Research Fellowships Selection Committee since 2024. When he is not working or injured he loves running.
Machine learning systems are everywhere — filtering spam, detecting malware, and now writing code and making decisions on our behalf. But these systems can be fooled, sometimes surprisingly easily. A tiny, almost invisible change to an image can make a classifier see a different object entirely. A few crafted inputs slipped into training data can quietly corrupt a model’s behavior. For twenty years, security researchers and attackers have been locked in a back-and-forth: every new defense inspires a cleverer attack, and every clever attack inspires a new defense. So far, nobody has won.
In this talk, I’ll walk through that history — starting with the earliest attacks on spam and malware detectors, through the discovery of “adversarial examples” that fool image classifiers, and up to the brand-new challenges posed by large language models and autonomous AI agents. Along the way, I’ll explain the core ideas of adversarial machine learning in plain terms: what makes a model vulnerable, how attackers find its weak points, and why building a truly robust defense has proved so hard.
I’ll also get a bit critical: why do so many proposed defenses look great on paper but fail in practice? Part of the answer lies in how we evaluate these systems — we often lack rigorous, scalable ways to stress-test models under adversarial or unusual conditions, and we don’t have good tools for catching evaluation mistakes, biased datasets, or models that are right for the wrong reasons. I’ll share some of our lab’s recent work tackling these problems and end with a broader idea: maybe the path to trustworthy AI isn’t a single, unbreakable model, but rather AI embedded as a carefully engineered component within a larger, more resilient system with a defense-in-depth approach.
Public-key cryptography is essential for securing modern communication, but traditional number-theoretic constructions will be broken by quantum computers. To address this threat, in 2024 NIST has standardized new cryptographic systems based on the hardness of algorithmic problems on point lattices, which offer “post-quantum” security, i.e., security against the threat posed by quantum computers.
This course offers an intensive introduction to lattice-based cryptography, from mathematical theory to deployed post-quantum standards. Specific topics covered by the course include:
Relevant prerequisites include basic knowledge of linear algebra, some abstract algebra (polynomial rings), basic probability theory, and algorithms, as offered by introductory level courses on these subjects.
How did machine learning evolve from simple algorithms that separate two classes to AI systems capable of holding conversations, writing software, and answering questions? This course tells the story of modern machine learning through the sequence of ideas that led from linear classifiers to today’s large language models. Along the way, students will learn the foundations of supervised learning, optimization, neural networks, Transformers, and language modeling. Rather than presenting these topics as isolated techniques, the course aims to develop a coherent narrative in which each new generation of models overcomes the limitations of its predecessors. The emphasis is on intuition, visual explanations, and practical examples, making the course accessible to undergraduate students with a basic background in linear algebra and calculus.
Oratorio di San Filippo Neri, Bologna
L’Oratorio di San Filippo Neri è un affascinante contenitore culturale di proprietà della Fondazione del Monte. Al suo interno si svolgono le iniziative e i convegni promossi dalla Fondazione che, tra l’altro, ogni anno offre alla città un ricco cartellone di spettacoli, incontri, concerti, tutti a ingresso libero. La Fondazione concede inoltre l’utilizzo dell’Oratorio a enti e organizzazioni che ne facciano richiesta.
Qui le informazioni.
L’Oratorio si trova in pieno centro a Bologna, in via Manzoni 5, ed è visitabile il primo fine settimana di ogni mese dalle 10 alle 19.
© ELICSIR Foundation ETS 2026 - All right reserved
Questo sito utilizza cookie tecnici e di profilazione per migliorare la tua esperienza di navigazione. Continuando a navigare nel sito acconsenti all'uso dei cookie.