Contact:
ravenben+w at cs dot uchicago dot edu
Glaze@Bluesky,
ravenben@Bluesky,
Quora,
Linkedin.
News in Last 12+ Months
Apr 2026: Talk @IU Bloomington CACR
Mar 2026: interview on Chicago Live Fox32
Mar 2026: panel talk @Chicago Center on Democracy
Feb 2026: talk @ UK CRA
Creators Emergency Summit hosted by IoP
Jan 2026: AI Policy @Notre Dame
Jan 2026: USENIX Security PC
Dec 2025: ETCH is Incorporated
Our new non-profit: Ethical Technology and Computing for Humanity (ETCH)
Dec 2025: Testifed to CA Legislature
Testified to CA Senate/Assembly Hearing on AI & Copyright, on CA AB-412 transparency bill
Dec 2025: Model Provenance @USENIX Security
Congrats to Anna, Wenxin, Stanley, Shawn for their generative model provenance paper to appear at USENIX Security 2026!
Dec 2025: ICML 2026 AC
Nov 2025: Webinar, Assoc. of Medical Illustrators
Nov 2025: UChicago Parents Council Panel
Oct 2025: Glaze panel @Lightbox Expo
Sept 2025: Talks/visit @ Yale
Talks at Yale CS, Yale art gallery, Yale Poli Sci (Civic thought coffee)
Aug 2025: Zhuolin & Shawn graduate!
Congrats to the newly minted Professors Zhuolin Yang (Off to Univ. of Arizona) and Shawn Shan (off to Dartmouth)! You will be missed!
July 2025: Panel @ SD Comic-con!
Love SDCC, but to be on a panel, unreal! Will be on panel hosted by CBLDF on Friday!
June 2025: MMLS Keynote
Honor to give the opening keynote at MMLS 2025!
June 2025: Keynote @OpenRepo
Pleasure to give the closing keynote at 20th Intl Conference on Open Repositories!!
May 2025: Hemlock paper @CCS 2025
Congrats Stanley, Ronik, Anna and Shawn!
May 2025: crawler measurement @IMC 2025
Congrats Shawn and our UCSD collaborators!
Apr 2025: IO Remote, Illustratoren Organisation
Talk to German Association of Illustrators
Mar 2025: SalesForce Distinguished Lecture
Distinguished technical talk at SalesForce
Feb 2025: IEEE S&P 2026 TPC
Feb 2025: MIT AI Film Hack Ethics Panel
Jan 2025: Freakonomics Radio Interview
Dec 2024: Hamburg Assoc. of Illustrators
Dec 2024: Funding from Samsung Research
Oct 2024: CAA Community Impact Award
Concept Art Association awards its 2024 Community Impact Award to the Glaze/Nightshade team! Thank you CAA!
Oct 2024: LightBox Expo
Oct 2024: Distinguished Paper @ CCS
Congrats to Anna, Josephine, Ronik and Shawn for their CCS distinguished paper award!
Oct 2024: TED AI
Giving a TED AI talk on Oct 22.
Sept 2024: TIME Magazine AI100
Humbled to be named to TIME Magazine AI100 most influential in AI.
Sept 2024: Nature article
Quoted in Nature article on hidden risks of AI.
August 2024: Model implosion @CCS
Congrats to Wenxin, Cathy, and Shawn! This paper explains how Nightshade causes model implosion in diffusion models.
June 2024: NeurIPS AC
May 2024: CA State Assembly Hearing
CA Assembly hearing on Use of AI in Film, Music, and the Fine Arts. Recording
CODE
Clickstream modeling code here
Measurement-calibrated
graphs here
Embedding graph coordinate systems here
Other Stuff
(UChicago Calendar)
Google Scholar (39,000+), H-index: 82
Erdos # = 3 (Erdos-M. Saks-K. Hildrum-B. Y. Zhao)
This page, circa 2011
I am a Neubauer Professor of Computer Science at University of Chicago. Together with Prof. Heather Zheng, I co-direct the SAND Lab (Security, Algorithms, Networking and Data) at
University of Chicago. I have a PhD in Computer Science (UC Berkeley 2004, advisors John Kubiatowicz
and Anthony Joseph), MS (UC Berkeley 2000), BS in Computer Science (Yale 1997). During my PhD, I
created the Tapestry distributed hash table (dissertation). Years ago,
I used to work in networking, social networks, wireless, data mining, and some HCI. For the last 10+
years, I have focused on security and privacy in machine learning systems. Since 2022, I have focused
on adversarial machine learning and tools to mitigate harms of generative AI models
against human creatives. Today, I generally publish at CCS/Oakland/USENIX Security, with some NeurIPS, CVPR, IMC, CHI sprinkled in.
Here's a wordle of paper abstracts around 2024-2026. Back when my kids were small and I had "free time,"
I wrote about research and PhD life on Quora.
Awards: ACM Fellow (2021), Concept Art Association Community Impact Award (2024), TIME Magazine
AI/100 (100 Most influential people in AI) (2024), USENIX Internet Defense Prize (2023), Chicago
Innovation Award (2023), TIME Magazine Best Inventions Special Mention (2023), NSF CAREER award (2005),
MIT Tech Review TR-35 (Young Innovators Under 35) (2006), IEEE Internet Technical Committee Early Career
Award (2014), ComputerWorld's Top 40 Technology Innovators under 40.
Distinguished/Best/Test of Time Award papers at CCS, USENIX Security, CHI, SIGMETRICS, ASPLOS.
Teaching, Spring 2026
CMSC 25800-1 (Adversarial Machine Learning), Tu/Th 9:30-10:50AM, Ryerson 276
CMSC 25800-2 (Adversarial Machine Learning), Tu/Th 11:00-12:20PM, Ryerson 276
NOTE: class will move to Rosenwald 015 on March 26 and for the remainder of the quarter.
This is a new course (one of the first for undergraduates in the country) that covers the security and privacy issues inherent in machine learning and AI. We will cover fundamental vulnerabilities for deep neural networks and generative AI architectures, optimization based attacks, (black-box/white-box) evasion attacks, (dirty-label/clean-label) poison attacks, detection/filtering/removal defenses, privacy attacks (membership inference and model extraction). Homework assignments will involve attack generation/defenses, model training/fine-tuning, and experiments on latest generation DNNs and genAI models. (Class limited to undergrads satisfying prerequisites and by instructor permission).
Press/Media: Recent media coverage of our research, including New York Times articles (by the amazing Kashmir Hill) on our art anti-mimicry tool Glaze, our image cloaking tool Fawkes, and our Bracelets of Silence, an ultrasonic, wearable microphone jammer for personal privacy.
Project Links
- Nightshade: proactive content copyrights, Website/paper/downloads
- Glaze: protecting artists against style mimicry, Website/paper/downloads
- Forensics for Poison Attacks on DNNs, Website/code/slides
- Blacklight: scalable defense for DNNs against black-box attacks, Website/code
- Fawkes: image cloaking against facial recognition, Code/Paper/Video/Media and News
- Neural Cleanse: detecting/mitigating backdoors in DNNs, Code/Paper
- Bracelets of Silence: wearable ultrasonic jammers, Project/papers/code/video.
I read all my emails. But due to the volume of emails, I am often unable to reply to individual emails. If you are looking for a summer undergraduate internship, please do not email me directly. UChicago CS has organized a summer undergraduate internship program with more info here. If you are a high school student or undergraduate looking for a summer internship related to data, you might be interested in the DSI Data and Computing Summer Lab. SAND Lab is involved in both programs, although the number of interns we take each summer can vary depending on the applicant pool.
UChicago Undergraduates interested in research?
We generally advise 3-5 undergraduates in my lab in active
research. If you're experienced in ML and interested in working in my lab as an
undergrad, drop me an email. Generally speaking, the best way to join my lab
as an undergrad is to take and do well in my course in adversarial ML.