निरुपम गुप्ता  /  Nirupam Gupta

I am a Tenure-Track Assistant Professor in the ML Section of the Department of Computer Science at the University of Copenhagen (DIKU). Before joining DIKU, I was a postdoctoral researcher at EPFL (Switzerland) and Georgetown University (USA). I obtained my PhD from the University of Maryland — College Park and my Bachelor's degree from IIT Delhi.

Research. I work on the foundations of trustworthy machine learning, focusing on robustness and privacy in distributed and federated learning. My goal is to make rigorous protection of patients, users and models a practical default in real AI deployments, rather than a guarantee that exists only on paper. A pedagogical introduction to the robustness side of this work is in my book Robust Machine Learning: Distributed Methods for Safe AI (Springer, 2024). Active projects are listed below.

Teaching. At DIKU I teach Privacy in Machine Learning (PriMaL), Machine Learning B (MLB), and a new course on Robust Machine Learning launching in 2026–27. PriMaL runs in the Fall and MLB in the Spring; both support hybrid and fully remote participation. Course details are on the DIKU ML courses site.

“It seems complex only because of ignorance; otherwise everything is simple.” — OSHO (The Book of Secrets)

Ongoing Projects

My group builds rigorous theory and principled algorithms for trustworthy machine learning; proofs first, then the algorithms and open-source tools those proofs justify. Two programmes anchor the work. I am actively looking for PhD students and postdocs who are excited by provable guarantees and clean algorithm design; if either thread speaks to you, write to me at nigu[at]di.ku.dk.

ATLAS Adversary-Tailored Learning Scheme

Making privacy and robustness affordable by calibrating them to realistic adversaries rather than worst-case ones.

Differential privacy and Byzantine resilience are the gold-standard guarantees for private, robust learning, yet both are calibrated to an omniscient, all-powerful adversary, and the protective noise this demands often collapses accuracy. ATLAS starts from one observation: privacy and robustness are the same sensitivity problem seen through two adversary lenses. We replace worst-case sensitivity with expected adversarial sensitivity (EAS), the sensitivity to a realistic, resource-bounded adversary, and cast the defender's task as an online-learning problem, so smart defences adapt to the adversary's observed behaviour. This yields auditable certificates and training algorithms that recover most of the accuracy today's tools give away.

You might work on: generalisation bounds under differential privacy, online and adaptive defences against bounded adversaries, reconstruction-risk certification, or the open-source EAS toolkit.

AGORA Across-architecture Generalization via Open Representation Alignment

Letting independently trained models exchange knowledge across different architectures, with provable guarantees.

Federated learning assumes every participant shares one architecture, so it can only average parameters. AGORA drops that assumption: models living in different hypothesis spaces, say a lightweight convolutional net, a large transformer, or a physics-informed model, exchange knowledge through their predictions rather than their weights, via functional-distance alignment with PAC-Bayes guarantees. The aim is open infrastructure for collaborative learning that no single institution owns, a step toward developing large-scale AI models democratically rather than concentrating them in a few hands, with robustness, privacy, unlearning and fairness built in from the start.

You might work on: functional distillation and representation alignment (optimal-transport / Bregman geometry), generalisation theory for cross-architecture merging, or robust and privacy-preserving aggregation protocols.

A few related threads feed into both programmes: robustness in decentralised learning over sparse communication graphs, robust federated inference, and privacy-preserving collaboration for healthcare. Background reading: my book on Robust Machine Learning and my chapter in Large Language Models in Cybersecurity on the difficulty of provable robustness and privacy for LLMs.

Recent Publications last 5 years

A complete list is available on my DBLP profile and Google Scholar. Entries marked α follow the alphabetical author-order convention common in CS theory.

  1. Tight Stability Bounds for Robust Distributed Learning: Byzantine Failures Hurt Generalization More than Data Poisoning. Thomas Boudou, Batiste Le Bars, Nirupam Gupta, Aurélien Bellet. ICML 2026.
  2. On the Relevance of Byzantine Robust Optimization Against Data Poisoning. α Sadegh Farhadkhani, Rachid Guerraoui, Nirupam Gupta, Rafael Pinot. JMLR 2026.
  3. Robust Federated Inference. α Akash Dhasade, Sadegh Farhadkhani, Rachid Guerraoui, Nirupam Gupta, Maxime Jacovella, Anne-Marie Kermarrec, Rafael Pinot. ICLR 2026.
  4. Reconciling Communication Compression and Byzantine-Robustness in Distributed Learning. Diksha Gupta, Nirupam Gupta, Antonio Honsell, Giovanni Neglia, Chuan Xu. AISTATS 2026.
  5. Adaptive Gradient Clipping for Robust Federated Learning. α Youssef Allouah, Rachid Guerraoui, Nirupam Gupta, Ahmed Jellouli, Geovani Rizk, John Stephan. ICLR 2025. Spotlight · top 5%
  6. Revisiting Ensembling in One-Shot Federated Learning. α Youssef Allouah, Akash Dhasade, Rachid Guerraoui, Nirupam Gupta, Anne-Marie Kermarrec, Rafael Pinot, Rafael Pires, Rishi Sharma. NeurIPS 2024.
  7. Fine-Tuning Personalization in Federated Learning to Mitigate Adversarial Clients. α Youssef Allouah, Abdellah El Mrini, Rachid Guerraoui, Nirupam Gupta, Rafael Pinot. NeurIPS 2024.
  8. Tackling Byzantine Clients in Federated Learning. α Youssef Allouah, Sadegh Farhadkhani, Rachid Guerraoui, Nirupam Gupta, Rafael Pinot, Geovani Rizk, Sasha Voitovych. ICML 2024.
  9. Robust Distributed Learning: Tight Error Bounds and Breakdown Point under Data Heterogeneity. α Youssef Allouah, Rachid Guerraoui, Nirupam Gupta, Rafael Pinot, Geovani Rizk. NeurIPS 2023. Spotlight · top 5%
  10. On the Privacy-Robustness-Utility Trilemma in Distributed Learning. α Youssef Allouah, Rachid Guerraoui, Nirupam Gupta, Rafael Pinot, John Stephan. ICML 2023.
  11. Robust Collaborative Learning with Linear Gradient Overhead. α Sadegh Farhadkhani, Rachid Guerraoui, Nirupam Gupta, Lê-Nguyên Hoang, Rafael Pinot, John Stephan. ICML 2023.
  12. Fixing by Mixing: A Recipe for Optimal Byzantine ML under Heterogeneity. α Youssef Allouah, Sadegh Farhadkhani, Rachid Guerraoui, Nirupam Gupta, Rafael Pinot, John Stephan. AISTATS 2023.
  13. Byzantine Machine Learning Made Easy by Resilient Averaging of Momentums. α Sadegh Farhadkhani, Rachid Guerraoui, Nirupam Gupta, Rafael Pinot, John Stephan. ICML 2022.