Research Scholar (postdoctoral) · University of Chicago, since 2025.
I work at the interface of theoretical physics and machine learning. Most
strongly correlated systems are intractable; I look for the exceptions —
the ones where correlations are driven by a handful of hidden variables.
Fig. 1 — resetting brownian gas
FIG. 1N non-interacting diffusers on the real line, reset together at
Poisson times (vertical marks). The reset events alone — no direct
interaction — couple them; the apparent independence is, by construction,
false. Biroli, Larralde,
Majumdar & Schehr, PRL 130, 207101 (2023).
Research
01 — MACHINE LEARNING
The physics of learning
Where statistical mechanics meets generative modeling and AI safety. Why a VAE is structurally a finite-size mean-field model, and what that costs when the data isn't — and why jailbreaking an aligned model looks like a particle escaping a trap.
Non-interacting particles coupled only by a shared reset event — enough to correlate a gas that would otherwise never meet. Exact results for extremes, gaps, and order statistics follow from conditioning on a single hidden variable.
Dyson Brownian motion of eigenvalues, reset simultaneously. Stationary density, extreme-eigenvalue statistics, and the crossover between repulsion- and reset-dominated regimes.
Best-of-N jailbreaking breaks an aligned model by brute force:
draw N random augmentations of an unsafe prompt, sample
M completions of each, and keep whatever gets through. Its
success rate has been reported to follow a power law in N. We
think it doesn't. The drifting exponent is a finite-size artifact of
the adversarial dataset and relatively narrow fitting windows.
We introduce a physically motivated barrier model with stochastic
dynamics. Each prompt has a baseline safety
level, and each augmentation adds a random, thermally activated
barrier. Four interpretable numbers then fix the entire
(N, M) attack surface. They extrapolate from
N ≤ 100 to N = 104, collapse five models
onto one scaling function, and predict attacks at temperatures they
were never fitted on.
Statistical physics turned on AI safety: best-of-N jailbreaking as thermally
activated escape over random barriers. Four interpretable numbers predict the
full attack surface, far beyond the sampling budgets they were fitted on.
With Max Welling and Vincenzo Vitelli — a capacity bound showing that any
successful VAE decoder is a finite-size mean-field factorization, so the
microscopic theory can be read off the trained network. Applied to salamander
retinal recordings.
2026-03-03
Schmidt AI in Science seminar at UChicago
Presented Variational auto-encoders are finite-size mean-field approximators at
the Schmidt AI in Science Speaker Series, University of Chicago.
With Gabriele de Mauro, Satya N. Majumdar and Grégory Schehr — how
non-Poissonian reset protocols reshape the correlation structure of the
resetting gas. Now published in Phys. Rev. E 113, 014120 (2026).
2025-09-01
Joined the University of Chicago
Started as a Research Scholar across the Physics and Computer Science
departments, working with Vincenzo Vitelli — supported by the Eric & Wendy
Schmidt AI in Science fellowship.
Time, privacy, robustness, accuracy: trade-offs for the open vote network protocol
Fatima-Ezzahra El Orche, Rémi Géraud-Stewart, Peter B. Rønne, Gergei Bana, David Naccache, Peter YA Ryan, Marco Biroli, Megi Dervishi, Hugo Waltsburger