Marco Biroli

Marco Biroli

Research Scholar (postdoctoral) · University of Chicago, since 2025.

I work at the interface of theoretical physics and machine learning. Most strongly correlated systems are intractable; I look for the exceptions — the ones where correlations are driven by a handful of hidden variables.

Fig. 1 — resetting brownian gas
FIG. 1 N non-interacting diffusers on the real line, reset together at Poisson times (vertical marks). The reset events alone — no direct interaction — couple them; the apparent independence is, by construction, false. Biroli, Larralde, Majumdar & Schehr, PRL 130, 207101 (2023).

Research

01 — MACHINE LEARNING

The physics of learning

Where statistical mechanics meets generative modeling and AI safety. Why a VAE is structurally a finite-size mean-field model, and what that costs when the data isn't — and why jailbreaking an aligned model looks like a particle escaping a trap.

02 — CORRELATED SYSTEMS

Dynamically emergent correlations

Non-interacting particles coupled only by a shared reset event — enough to correlate a gas that would otherwise never meet. Exact results for extremes, gaps, and order statistics follow from conditioning on a single hidden variable.

03 — RANDOM MATRICES

Spectra under resetting

Dyson Brownian motion of eigenvalues, reset simultaneously. Stationary density, extreme-eigenvalue statistics, and the crossover between repulsion- and reset-dominated regimes.

Currently

A jailbreak is a particle escaping a trap.

Best-of-N jailbreaking breaks an aligned model by brute force: draw N random augmentations of an unsafe prompt, sample M completions of each, and keep whatever gets through. Its success rate has been reported to follow a power law in N. We think it doesn't. The drifting exponent is a finite-size artifact of the adversarial dataset and relatively narrow fitting windows.

We introduce a physically motivated barrier model with stochastic dynamics. Each prompt has a baseline safety level, and each augmentation adds a random, thermally activated barrier. Four interpretable numbers then fix the entire (N, M) attack surface. They extrapolate from N ≤ 100 to N = 104, collapse five models onto one scaling function, and predict attacks at temperatures they were never fitted on.

Read the preprint →

News

2026-09-26

A physical trap model of best-of-N jailbreaking

Statistical physics turned on AI safety: best-of-N jailbreaking as thermally activated escape over random barriers. Four interpretable numbers predict the full attack surface, far beyond the sampling budgets they were fitted on.

2026-06-07

VAEs as latent mean-field models — new preprint

With Max Welling and Vincenzo Vitelli — a capacity bound showing that any successful VAE decoder is a finite-size mean-field factorization, so the microscopic theory can be read off the trained network. Applied to salamander retinal recordings.

2026-03-03

Schmidt AI in Science seminar at UChicago

Presented Variational auto-encoders are finite-size mean-field approximators at the Schmidt AI in Science Speaker Series, University of Chicago.

2025-09-08

Emergent correlations beyond Poissonian resetting

With Gabriele de Mauro, Satya N. Majumdar and Grégory Schehr — how non-Poissonian reset protocols reshape the correlation structure of the resetting gas. Now published in Phys. Rev. E 113, 014120 (2026).

2025-09-01

Joined the University of Chicago

Started as a Research Scholar across the Physics and Computer Science departments, working with Vincenzo Vitelli — supported by the Eric & Wendy Schmidt AI in Science fellowship.

Notes

2026-07-22

A matter of responsibility

Can we learn from our mistakes? A note on my belief in our moral and ethical responsibility as scientists with regard to our discoveries.

Publications

293 citations  ·  h-index 10 — Google Scholar, 2026-09-28

2026
Escaping alignment: a physical trap model of best-of-N jailbreaking
Marco Biroli
arXiv preprint
2026
Discovering and decoding latent mean-field structure with variational autoencoders
Marco Biroli, Max Welling, Vincenzo Vitelli
arXiv preprint
2026
First-passage resetting gas
Marco Biroli, Satya N. Majumdar, Grégory Schehr
Europhysics Letters 153, 31002
2026
Dynamically emergent correlations in Brownian particles subject to simultaneous non-Poissonian resetting protocols
Gabriele de Mauro, Marco Biroli, Satya N. Majumdar, Grégory Schehr
Physical Review E 113, 014120
2026
Experimental evidence for strong emergent correlations between particles in a switching trap
Marco Biroli, Sergio Ciliberto, Manas Kulkarni, Satya N. Majumdar, Artyom Petrosyan, Grégory Schehr
Physical Review Letters 137, 037102
2025
Strongly correlated stochastic systems
Marco Biroli
arXiv preprint (PhD thesis / review)
2025
Resetting Dyson Brownian motion
Marco Biroli, Satya N. Majumdar, Grégory Schehr
Physical Review E 112, 014101
2024
Resetting by rescaling: exact results for a diffusing particle in one dimension
Marco Biroli, Yannick Feld, Alexander K. Hartmann, Satya N. Majumdar, Grégory Schehr
Physical Review E 110, 044142
2024
Dynamically emergent correlations between particles in a switching harmonic trap
Marco Biroli, Manas Kulkarni, Satya N. Majumdar, Grégory Schehr
Physical Review E 109, L032106
2024
Exact extreme, order, and sum statistics in a class of strongly correlated systems
Marco Biroli, Hernán Larralde, Satya N. Majumdar, Grégory Schehr
Physical Review E 109, 014101
2023
Critical number of walkers for diffusive search processes with resetting
Marco Biroli, Satya N. Majumdar, Grégory Schehr
Physical Review E 107, 064141
2023
Extreme statistics and spacing distribution in a Brownian gas correlated by resetting
Marco Biroli, Hernán Larralde, Satya N. Majumdar, Grégory Schehr
Physical Review Letters 130, 207101
2022
Number of distinct sites visited by a resetting random walker
Marco Biroli, Francesco Mori, Satya N. Majumdar
Journal of Physics A 55, 244001
2022
Time, privacy, robustness, accuracy: trade-offs for the open vote network protocol
Fatima-Ezzahra El Orche, Rémi Géraud-Stewart, Peter B. Rønne, Gergei Bana, David Naccache, Peter YA Ryan, Marco Biroli, Megi Dervishi, Hugo Waltsburger
E-Vote-ID 2022 (LNCS 13553)

Contact

I'm happy to hear from anyone working on correlated noise, exact results, or the statistical physics of learning. Email is fastest.