Send email Copy Email Address

Email

Address

Im Oberen Werk 1
66386 St. Ingbert (Germany)

Awards (selection)

2025: Werner-von-Siemens-Fellow

2025: ERC Starting Grant

2024: GI Junior-Fellow 

2024: Busy Beaver Award "Differential Privacy: Mathematical Foundations and Applications in Machine Learning“, Saarland University

 

Short Bio

Franziska Boenisch is a tenure-track faculty member at the CISPA Helmholtz Center for Information Security. At CISPA, she co-leads the SprintML Lab (Secure, Private, Robust, Interpretable, and Trustworthy Machine Learning), where her research focuses on advancing trustworthy machine learning. Prior to joining CISPA, she was a Postdoctoral Fellow at the Vector Institute for Artificial Intelligence, working under the supervision of Prof. Dr. Nicolas Papernot. She received her PhD from Freie Universität Berlin, where she also served as a research associate at the Fraunhofer Institute for Applied and Integrated Security (AISEC).

CV: Last stations

Since 2023
Tenure-Track Faculty at CISPA
2022 - 2023
Postdoctoral Fellow - Vector Institute for Artificial Intelligence, Toronto
2019 - 2022
PhD Student and Research Associate - Department of Secure Systems Engineering, Fraunhofer AISEC

Publications by Franziska Boenisch

Year 2026

Conference / Medium

National Conference of the American Association for Artificial Intelligence (AAAI) On Stealing Graph Neural Network Models

Conference / Medium

Association for the Advancement of Artificial Intelligence (AAAI) Demystifying Foreground-Background Memorization in Diffusion Models

Conference / Medium

International Conference on Learning Representations (ICLR) Curation Leaks: Membership Inference Attacks against Data Curation for Machine Learning

Conference / Medium

AAAI 2026 Workshop on AI Governance Frequency-Domain Model Fingerprinting for Image Autoregressive Models

Conference / Medium

ICLR 2026 Workshop: Principled Design for Trustworthy AI

Year 2025

Conference / Medium

Conference on Neural Information Processing Systems (NeurIPS) Exploring the limits of strong membership inference attacks on large language models

Conference / Medium

Conference on Neural Information Processing Systems (NeurIPS) Memorization in Graph Neural Networks

Conference / Medium

National Conference of the American Association for Artificial Intelligence (AAAI) Beautiful Images, Toxic Words: Understanding and Addressing Offensive Text in Generated Images

Conference / Medium

Conference on Neural Information Processing Systems (NeurIPS) BitMark: Watermarking Bitwise Autoregressive Image Generative Models

Article

Naval Research Logistics Personalized Differential Privacy for Ridge Regression Under Output Perturbation