M. R. Briglia

Maria Rosaria Briglia

PhD student in AI for Government and Public Security, Sapienza University of Rome

Visiting researcher at IFML, UT Austin with Prof. Adam Klivans — applying representation learning and mechanistic interpretability to protein engineering. November 2025 – present

I work on the safety and robustness of generative models. My research asks what breaks when a model is attacked, and what a principled defense would look like — through the geometry of representation space, energy-based formulations, and the security of multimodal systems.

I am currently visiting IFML at UT Austin, working with Adam Klivans on generative models for proteins — representation learning and mechanistic interpretability applied to protein engineering.

Before Sapienza I completed an M.Sc. in Computer Engineering at the University of Salerno, specialising in artificial intelligence and intelligent robotics.

Austin, Texas briglia@di.uniroma1.it Curriculum vitae

Portrait of Maria Rosaria Briglia.

News

Research

Four threads, with the papers that belong to each.

Adversarial training through an energy lens

Reinterpreting robust classifiers as energy-based models, which reframes catastrophic overfitting and robust overfitting as behaviour of the energy landscape rather than isolated training artifacts.

natural sample adversarial example

ΔE −0.30 · lower energy than the natural sample

Schematic, not measured data. Untargeted attacks land at lower energy than real data; targeted attacks do the opposite.

The geometry of representation space

Concept control and prompt safety depend on the shape of the space you are steering in. Euclidean adjustments to text embeddings are the standard tool; hyperbolic space, with parallel geodesics and boundary structure, gives a more faithful geometry for some representational phenomena.

The Poincaré disk: hyperbolic geodesics meet the boundary at right angles. Drag it — the arcs move by a Möbius isometry, so the structure is preserved.

Threats to generative media, and defenses that hold

Proactive image protection rests on an assumed threat model, and I test those assumptions — whether watermark-style defenses survive diffusion-based reconstruction that re-synthesise the original image content.

AI for Biology

On the structure side, benchmarking antibody–antigen complex prediction at scale: cofolding thousands of complexes to ask not only whether models recover the right interface, but whether the evaluation captures the real failure modes.

VL — CDR-L1 VL — VH/VL beta-sheet VL — VH/VL beta-sheet VL — CDR-L2 VL — CDR-L3 VL — VH/VL beta-sheet antigen — antigen VL — VH/VL beta-sheet VL — VH/VL beta-sheet VL — VH/VL beta-sheet VH — VH/VL beta-sheet VL — VH/VL beta-sheet VL — framework loop VH — CDR-H3 VH — VH/VL beta-sheet VL — VH/VL beta-sheet VL — framework loop VH — VH/VL beta-sheet VH — CDR-H2 VL — VH/VL beta-sheet VL — framework loop VH — VH/VL beta-sheet VH — CDR-H1 VH — VH/VL beta-sheet VH — framework loop VH — VH/VL beta-sheet VH — framework loop VH — VH/VL beta-sheet VH — framework loop VH — VH/VL beta-sheet linker — flexible linker VH — VH/VL beta-sheet
Schematic scFv: two variable domains, six CDR loops meeting at the combining site, an antigen above. Drag to rotate.

Publications

9 papers. Abstracts expand in place.

2026

Neutralizing Proactive Defense using Diffusion-based Upsampling

ACM Workshop on Information Hiding and Multimedia Security (IH&MMSec)

›Abstract

The rapid spread of open-source generative models has made it easy to create highly realistic manipulated media, posing a critical threat to content authenticity and provenance. Proactive image protection methods aim to neutralize this risk, but their assumptions may not hold under modern generative pipelines. We study how diffusion-based upsampling can erase or evade several common protective schemes and quantify the consequences for threat modeling.

2026

Harnessing Hyperbolic Geometry for Harmful Prompt Detection and Sanitization

ICLR 2026

›Abstract

Vision–Language Models (VLMs) have become essential for tasks such as image synthesis, captioning, and retrieval by aligning textual and visual information in a shared embedding space. In this work, we show that harmful and benign prompts can be separated more naturally in hyperbolic space, and we exploit that geometry to improve both detection and sanitization.

2026

Semantic Steering via Hyperbolic Geometry

Beyond Euclidean Workshop, ECCV 2026Oral

›Abstract

As modern text-to-image (T2I) models draw closer to synthesizing highly realistic content, the threat of unsafe content generation grows, and it becomes paramount to exercise control over the semantic directions that the model follows. We show that hyperbolic geometry offers a more stable and interpretable basis for semantic steering than standard Euclidean alternatives.

2026

APEX: Anchored Protein Engineering via Quantized Expectation

NeurIPS 2026Poster

›Abstract

We introduce APEX, a method for anchored protein engineering that combines quantized expectation with structure-aware editing to generate constrained protein variants while preserving desired interface properties.

2026

Folding scFv–Antigen Complexes at Scale

GEM Workshop, ICLR 2026

›Abstract

Accurate modeling of antibody–antigen (Ab–Ag) complexes is central to biologic development, yet the reliability and failures of modern Ab–Ag folding pipelines remain poorly understood. We benchmark large-scale complex folding to identify where models succeed, where they fail, and what this means for engineering and evaluation.

2025

What is Adversarial Training for Diffusion Models?

ICLR 2026

›Abstract

We answer the question in the title, showing that adversarial training (AT) for diffusion models (DMs) fundamentally differs from classifiers: while AT in classifiers enforces output robustness, the challenge in DMs is to preserve data fidelity while controlling the generative trajectory under adversarial perturbations.

2025

Implicit Inversion turns CLIP into a Decoder

ICLR 2026

›Abstract

CLIP is a discriminative model trained to align images and text in a shared embedding space. Due to its multimodal structure, it serves as the backbone of many generative pipelines, yet the inversion problem remains underexplored. We show that implicit inversion can recover a decoder-like behavior from CLIP, with implications for controllable generation and representation understanding.

2025

Understanding Adversarial Training with Energy-based Models

arXiv preprintPreprint

›Abstract

We aim at using the Energy-based Model (EBM) framework to better understand adversarial training (AT) in classifiers, and additionally to analyze the intrinsic generative capabilities that emerge from robustly trained discriminative models.

2024

Shedding More Light on Robust Classifiers under the Lens of Energy-based Models

ECCV 2024

›Abstract

By reinterpreting a robust discriminative classifier as an Energy-based Model (EBM), we offer a new take on the dynamics of adversarial training (AT). Our analysis of the energy landscape provides a clearer explanation of robust overfitting and the geometric behavior of decision boundaries.

Background

Education, and the research position that came before the PhD.

  • 2025 Nov – present

    Visiting researcher

    NSF AI Institute for Foundations of Machine Learning (IFML), UT Austin

    Visiting period under the supervision of Prof. Adam Klivans, applying representation learning and mechanistic interpretability to protein engineering.

  • 2026 – present

    Member

    The Good AI Lab

    A collective of researchers and engineers from universities, labs and companies, working on AI research with social impact.

  • 2023 – present

    PhD, National PhD programme in AI for Government and Public Security

    Sapienza University of Rome

    Developing practical defense techniques against the media manipulation enabled by generative AI.

  • 2021 – 2023

    M.Sc. Computer Engineering (LM-32), Artificial Intelligence and Intelligent Robotics

    University of Salerno

    Thesis: Automatic Generation of Identity-Preserving Gesture Videos.

  • 2023

    Research scholarship, artificial vision for autonomous driving on rail

    RFI and University of Salerno

    Designed the on-board hardware acquisition system, and the real-time anomaly detection along the railway track.

  • 2018 – 2021

    B.Sc. Computer Engineering (L-8)

    University of Salerno

    Graduated 110/110 cum laude, and recognised for completing the degree with highest honours in the shortest time possible. Thesis: Automatic Speaker Recognition Using a Neural Network.

Summer schools

  • 2025CISPA – ELLIS Summer School, Saarbrücken, Germany
  • 2024Generative Modeling Summer School, Eindhoven University of Technology

Service

Collaborations

The institutions behind this work, and where they are.

Sapienza University of Rome — Rome, Italy IFML, UT Austin — Austin, Texas University of Salerno — Fisciano, Italy RFI (Rete Ferroviaria Italiana) — Italy CISPA Helmholtz Center for Information Security — Saarbrücken, Germany Eindhoven University of Technology — Eindhoven, Netherlands

Filled markers are institutions I have worked with; hollow ones are schools I attended. Coastlines from Natural Earth, public domain.

Curriculum vitae

Publications, education, and the visiting position, generated from the same source as this page. Papers under review are left out, as they are here.

Download CV (PDF)

Contact

I'm glad to hear from anyone working on adversarial robustness, model safety, or the geometry of representation. Email is the surest way to reach me.