Memorization, Privacy, and Legal Risk in FMs
Workshop at NeurIPS 2026
Foundation models trained on large-scale datasets can encode sensitive/private information about individuals, even when trained on ostensibly de-identified data. As these systems are deployed across domains, concerns about privacy leakage, memorization, and model-mediated disclosure are becoming increasingly central — not only as technical challenges, but also as questions of legal liability, regulatory compliance, and responsible deployment. A key open problem is how to identify such memorization, how to translate it into actionable risk assessments, and how technical and legal solutions can help mediate these issues.
This workshop brings together researchers and practitioners across machine learning, security, and law to examine privacy risks in foundation models through the lens of memorization and related attack vectors. We focus on a range of technical mechanisms, including membership inference, data extraction, and training data attribution, and how these interact with model behavior at both embedding and generative levels. Particular attention is given to evaluation: how memorization can be systematically measured in realistic, black-box settings, and how these measurements can inform deployment decisions. The workshop will highlight open problems, including robust measurement of memorization, standardization of privacy evaluations, trade-offs between utility and privacy, and the role of auditing and documentation in governance.
Beyond technical analysis, the workshop emphasizes the legal and regulatory implications of memorization and privacy leakage. Existing frameworks such as the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA) were not designed to address model-mediated disclosure risks, creating uncertainty around compliance, liability, and acceptable use. The workshop will explore how emerging legal interpretations and governance frameworks intersect with technical realities, and what this implies for practitioners designing, training, and deploying foundation models.
By fostering dialogue between technical and legal communities, this workshop aims to advance practical, deployment-relevant approaches to assessing and mitigating privacy risks in foundation models, and to identify new research directions at the intersection of machine learning, security, and law.
Location: NeurIPS 2026 (preferred location: Paris)
Schedule
Two tracks: morning (technical) / afternoon (audit)
| Time | Duration | Event |
|---|---|---|
| 09:00 – 09:15 | 15 min | Opening Remarks from Organizers |
| 09:15 – 09:45 | 30 min | Invited Talk 1 (25 min + 5 min Q&A) |
| 09:45 – 10:15 | 30 min | Invited Talk 2 (25 min + 5 min Q&A) |
| 10:15 – 11:15 | 60 min |
|
| 11:15 – 11:45 | 30 min | Invited Talk 3 (25 min + 5 min Q&A) |
| 11:45 – 12:15 | 30 min | Invited Talk 4 (25 min + 5 min Q&A) |
| 12:15 – 13:00 | 45 min | 🍽 Networking / Mentorship Lunch |
| 13:00 – 14:00 | 60 min | Spotlight Oral Presentations |
| 14:00 – 15:00 | 60 min |
|
| 15:00 – 15:30 | 30 min | Invited Talk 5 (25 min + 5 min Q&A) |
| 15:30 – 16:00 | 30 min | Invited Talk 6 (25 min + 5 min Q&A) |
| 16:00 – 16:50 | 50 min | Interactive Panel with Invited Speakers |
| 16:50 – 17:00 | 10 min | Closing Remarks from Organizers |
Invited Speakers
Technical track
- Nicolas Carlini — Privacy, industry
- Dawn Song — UC Berkeley
- Aurélien Bellet — Inria
- Julie Josse — Inria / École Polytechnique
- Nicolas Papernot — University of Toronto / Vector Institute
- Carmela Troncoso — Max Planck Institute for Security and Privacy
Applied track (law + policy)
- Corinna — Law & CS
- Florence G’sell — Stanford Law School
- Economics perspective — TBD
Note: some speaker confirmations are still tentative; personal/institutional links above are also preliminary.
Call for Papers
We cordially invite submissions and participation in our workshop “Memorization, Privacy, and Legal Risk in Foundation Models: Measurement, Attacks, and Governance (MPLR-FM),” to be held at NeurIPS 2026.
Motivation and Topics
This workshop examines privacy risks in foundation models through the lens of memorization and related attack vectors, spanning technical mechanisms (membership inference, data extraction, training data attribution) and their legal/regulatory implications. Topics of interest include, but are not limited to:
- Detection and mitigation methods for memorization in foundation models
- Theoretical foundations and quantification of memorization
- Membership inference, data extraction, and training data attribution
- Relationships between memorization and security, privacy, and safety
- Trade-offs between utility, generalization, and privacy
- Standardization of privacy evaluations and black-box measurement
- Auditing, documentation, and governance frameworks
- Legal perspectives: GDPR, HIPAA, and model-mediated disclosure
- Societal impact and ethical aspects of memorization
Format: Non-proceedings, position/applied track, up to 4 pages (excluding references, acknowledgments, or appendices), submitted via OpenReview. The workshop complies with NeurIPS guidelines, including those on LLM use. Dual submission with other recent workshops/conferences is allowed; the workshop is non-archival with no official proceedings.
⚠️ Each submission must have at least one author serving as a reviewer. Failure to submit reviews, or submitting low-quality reviews, will result in desk rejection. ⚠️
Important Dates
- Submission deadline: Aug 29 ‘26 (Anywhere on Earth)
- Author notification: TBA
- Camera-ready deadline: TBA
- Workshop date: NeurIPS 2026 (December 11th or 12th, exact date TBA)
Diversity Commitment
We place strong emphasis on diversity and inclusion in the composition of our organizing team and invited speakers. Our organizers represent a balance of gender (60% women), institutions (five universities and two companies across four countries), career stages (postdocs, research scientists, and professors), and disciplines (law, computer science, and security).
To further support inclusion, we will organize a mentorship lunch prioritizing trainees from underrepresented groups, and will advertise the mentorship opportunity and call for papers through established affinity groups (e.g., WiML, Black in AI). Pending sponsorship, we plan to provide travel grants to enable participation from individuals from underrepresented backgrounds or those facing barriers to attendance.
Attendance and Reviewing
We anticipate about 200 attendees, supported by targeted outreach through social media, industry partnerships, and engagement with underrepresented communities via affinity groups such as WiML and Black in AI. We will recruit 100 reviewers from prior program committees and additional outreach (with reciprocal reviewing if necessary), aiming for 3 reviewers per paper. Each organizer will serve as an area chair for meta-reviewing.
Workshop Sponsors
- Microsoft Germany (Sin Yu Bonnie Ho)
- Borealis AI
- Barcelona (Axel Brando Guillaumes)
Organizers
Organizer bios
- Lena Stempfle is a postdoctoral researcher at MIT working on reliable and safe AI methods for healthcare, focusing on privacy risks and memorization in structured data such as electronic health records (EHRs), including recent work on protecting patient privacy in clinical foundation models.
- Sana Tonekaboni is a senior research scientist at Borealis AI and research affiliate at MIT, working on safe and reliable multimodal methods for human health. She was a founding co-chair of the Learning from Time Series for Health Workshop (NeurIPS 2022, ICLR 2024, NeurIPS 2025) and has organized several other workshops including ML4H 2024.
- Linus Bleistein is a postdoctoral researcher at EPFL and EPFL AI Center Fellow, working on foundation models for precision healthcare and trustworthy machine learning. He has co-authored work on causal evaluation of membership inference attacks and has extensive workshop organizing experience, including as a leading organizer of NeurIPS in Paris for 3 years.
- Maryam Molamohamadi — bio TBA.
- Franziska Boenisch is a faculty member at CISPA Helmholtz Center for Information Security, co-leading the SprintML lab, focused on private and trustworthy machine learning. Her research focuses on private and trustworthy machine learning. Franziska is the recipient of an ERC Starting Grant (2025) for research on privacy in foundation models, and her work has been recognised with the Fraunhofer ICT Dissertation Award (2023), GI Junior Fellowship (2024), and Werner-von-Siemens Fellowship (2025).
- Adam Dziedzic is a faculty member at CISPA Helmholtz Center for Information Security, co-leading the SprintML group, focused on secure and trustworthy machine learning. Adam is a founding organizer of the European Championship on AI and Security. This bold initiative invests in the next generation of researchers by fostering interest in AI, promoting cybersecurity skills, and raising awareness of the need for trustworthy technologies.





