Short Bio
Balazs Pejo (CV) was born in 1989 in Budapest, Hungary. He received a BSc degree in Mathematics from the Budapest University of Technology and Economics (BME, Hungary) in 2012 and two MSc degree in Computer Science in the Security and Privacy program of EIT Digital from the University of Trento (UNITN, Italy) and Eotvos Lorand University (ELTE, Hungary) in 2014. He earned the PhD degree in Informatics from the University of Luxembourg (UNILU, Luxembourg) in 2019. Currently, he is a member of the Laboratory of Cryptography and Systems Security (CrySyS Lab).
List of Courses
Research interests
- Trustworthy AI/ML
- Collaborative/Federated Learning
- Contribution Evaluation / XAI
- Inference Attacks / Robust Learning
- Differential Privacy
Projects
- Bolyai: Trustworthy Collaborative Learning: Privacy, Security, Fairness and Explainability Pillar Analysis (2026/09-2029/08)
- NEFA: National Federated Data Warehouse (2025/05-2027/04)
- OTKA-PD: Contribution Score Computation for Secure and Private Federated Learning (2024/01-2026/12)
- SECURED: Scaling Up Processing, Anonymization and generation of Health Data for EU cross border collaborative research and Innovation (2023/01-2025/12)
- MELLODDY: Machine Learning Ledger Orchestration For Drug Discovery (2019/09-2021/08)
- REQUISTE: Reconciling the Relationship between the Economics of Personal Data and Privacy (2016/08-2019/07)
Research Visits
- [2025/01; 2026/01]: University of Luxembourg (ERASMUS+)
- [2025/06]: University of Sassari (ERASMUS+)
- [2025/02]: Chalmers University (HUNREN Mobility)
Student Project Proposals
Topics marked (ongoing) already have a student working on them - you can still apply to join one. Topics marked (open) are free.
-
Personalized Shapley Values (open)
Contribution scores depend on the test data used for evaluation — but each participant may have a different local distribution. How can we merge these different viewpoints into a single, fair score everyone accepts? This project asks you to design and evaluate ways to combine per-client evaluations into a consensus contribution score, balancing fairness, privacy, and incentive compatibility. Ideal for students who like fairness, game theory ideas, and careful evaluation. (related paper)
-
Post-Training Contribution Evaluation (open)
When data points are removed from a trained model (machine unlearning), their influence drops — but can we measure that to infer contributions after training? This topic explores using input sensitivity and other post-hoc signals to approximate Shapley values or to build new attacks/diagnostics. It’s a mix of theory (why signals correlate with contribution) and practice (implementing measurements on trained models). (related paper)
-
Non-accuracy-based Membership Inference (open)
Classic membership inference decides if a sample was used for training by looking at accuracy/loss. This project asks: can we detect membership using other properties, such as how much a sample affects fairness or robustness of the model? You will design alternative inference strategies, test them empirically, and evaluate when they work or fail. This is a creative topic for students who enjoy thinking beyond standard metrics. (related paper)
-
Combining Multi-Dimensional Contribution Values (ongoing)
Once you can score a client along each separate dimension - performance, fairness, robustness, privacy - the harder question begins: how do you combine and balance ALL of them into one value? Published trust-score work optimises a single target, never the full balance. This project builds a principled combination: an optimisation framework for the centralised case and a game-theoretic one for the federated case, using component-wise multi-output Shapley values with objective-specific weighting rather than an ad-hoc weighted sum. Suited to students who like optimisation, game theory and clean formulations. (related paper)
-
SoK: Theoretical Foundations of Contribution Evaluation (ongoing)
In Federated Learning, evaluating client contributions (e.g., via Shapley Value) is critical but computationally expensive. While literature is flooded with approximations, most rely on empirical validation rather than theoretical guarantees. In this project, you will author a Systematization of Knowledge (SoK) paper. You will cut through the empirical noise, classify methods by their mathematical approximation techniques, and build a definitive taxonomy focusing on error bounds, algorithmic complexity, and generalization. Highly recommended for students with a strong mathematical background.
-
Manipulating Contribution Scores in Federated Learning (ongoing)
Can a malicious client manipulate their perceived contribution score to gain an unfair advantage? This project explores intentional manipulation attacks against contribution evaluation mechanisms. You will investigate advanced attack vectors, such as predicting past/future gradients, using only aggregated gradients, stealthy targeted decrease attacks, and distributed strategies with multiple colluding attackers (e.g., self-improvement vs. free-riding). Ideal for students interested in adversarial machine learning, game theory, and attack modeling. (related paper)
-
Robust and Non-accuracy-based Fairness Metrics (ongoing)
Traditional fairness metrics (like Demographic Parity or Equalized Odds) rely heavily on model accuracy. This project asks: how can we evaluate fairness using robustness metrics (like reliability and resilience) or alternative performance metrics (like loss)? You will adapt standard fairness definitions to these new dimensions, implement them using existing codebases and evaluate them empirically. Perfect for students interested in Trustworthy AI, algorithmic fairness, and software implementation. (related paper)
-
Quality Inference & Everyone Else (ongoing)
Evaluating contributions in FL is often expensive or leaks data. This project explores Quality Inference (QI) and Everyone-Else (EE) methods that privately estimate a client’s value with minimal computation. Building on recent papers you will implement, test, and optimize these methods against traditional approaches. Good for students interested in privacy, efficiency, and experiments. (QI paper) | (EE paper)
-
Improvement Prediction (ongoing)
Before starting a federated project, partners would like to estimate in advance how much the joint training will improve their model. This project investigates prediction methods that estimate collaboration benefit from available data and uses those predictions to choose privacy/security settings optimally. You’ll evaluate trade-offs between prediction accuracy and privacy assumptions. Recommended for students interested in practical FL. (related reading)
-
Interdependent Privacy in Collaborative Learning (ongoing)
In collaborative learning your accuracy depends on what everybody else contributes - but so does your PRIVACY, and that half is usually ignored. Existing game-theoretic treatments make the utility interdependent while keeping each participant's privacy loss separable; recent work shows the loss is interdependent too, because a shared noise level or a fixed batch size couples participants' real vulnerability to inference attacks even when their nominal privacy parameters are untouched. This project replaces the separable privacy-loss term with an interdependent one and works out what that does to the equilibrium. For students interested in differential privacy, game theory and inference attacks. (related reading)
Selection of Thesis
- Flora Ulrich (BSc, BME): Robustness Scores for Federated Learning Clients (Manuscript)
- Ádám Horváth (BSc, BME): Freerider Detection via Property Inference (Manuscript)
- Marcell Frank (BSc, BME): Altruism in Fuzzy Message Detection (Manuscript)
- Nikolett Kapui (BSc, BME): SQLi Detection Using Machine Learning (Manuscript)
- András Tótth (BSc, BME): Distributed Approximation of the Shapley Value (Manuscript)
- Mathias Parisot (BSc, VU-AMS): Property Inference Attacks on Convolutional Neural Networks (Manuscript)
Dissertations Opponents
- Sumit Paul (PhD, University of Ottawa): Privacy-Enhancing Web Technologies
Program Committees
- [2026-]: Neural Information Processing Systems (NeurIPS)
- [2026-]: Knowledge Discovery and Data Mining (KDD)
- [2026-]: Uncertainty in Artificial Intelligence (UAI)
- [2023-]: Association for the Advancement of Artificial Intelligence (AAAI)
- [2023-]: Artificial Intelligence and Statistics (AISTATS)
- [2023-2024]: Conference on Computer and Communications Security (CCS)
- [2021-2024]: Emerging Security Information, Systems and Technologies (SECURWARE)
- [2020-2022; 2024; 2026-]: Privacy Enhancing Technologies Symposium (PETS)
- [2020-2022]: Workshop on Privacy in Natural Language Processing (PrivateNLP)
Journal Reviews
- IEEE Transactions on Dependable and Secure Computing
- IEEE Transactions on Neural Networks and Learning Systems
- IEEE Transactions on Information Forensics and Security
- Future Generation Computer Systems
List of Publications
- To Appear
- 2026
- Balázs Pejó, Marcell Frank, Krisztian Varga, Peter Veliczky, Gergely Biczók: "On the Fragility of Contribution Score Computation in Federated Learning", IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)
- Delio Jaramillo Velez; Gergely Biczók; Alexandre Graell i Amat; Johan Ostman; Balázs Pejó: "Private and Robust Contribution Evaluation in Federated Learning", Intelligent Systems with Applications (ISWA)
- Pol G. Recasens, Ádám Horváth, Alberto Gutierrez-Torre, Jordi Torres, Josep Ll. Berral, Balázs Pejó: "FRIDA: Free-Rider Detection Using Privacy Attacks", Journal of Information Security and Applications (JISA)
- Bence Soóki-Tóth; István András Seres; Kamilla Kara; Ábel Nagy; Balázs Pejó; Gergely Biczók: "Bribers, Bribers on The Chain, Is Resisting All in Vain? Trustless Consensus Manipulation Through Bribing Contracts", Financial Cryptography and Data Security (FC)
- 2025
- 2024
- Marcell Frank; Balázs Pejó; Gergely Biczók: "Effective Anonymous Messaging: the Role of Altruism", 2024 Conference on Game Theory and AI for Security (GameSec)
- Francesco Regazzoni; Gergely Acs; Albert Zoltan Aszalos; Christos Avgerinos; Nikolaos Bakalos; Josep Ll. Berral; Joppe W. Bos; Marco Brohet; Andrés G. Castillo Sanz; Gareth T. Davies; Stefanos Florescu; Pierre-Elisée Flory; Alberto Gutierrez-Torre; Evangelos Haleplidis; Alice Héliou; Sotirios Ioannidis; Alexander Islam El-Kady; Katarzyna Kapusta; Konstantina Karagianni; Pieter Kruizinga; Kyrian Maat; Zoltán Ádám Mann; Kalliopi Mastoraki; SeoJeong Moon; Maja Nisevic; Balázs Pejó; Kostas Papagiannopoulos; Vassilis Paliuras; Paolo Palmieri; Francesca Palumbo; Juan Carlos Perez Baun; Peter Pollner; Eduard Porta-Pardo; Luca Pulina; Muhammad Ali Siddiqi; Daniela Spajic; Christos Strydis; Georgios Tasopoulos; Vincent Thouvenot; Christos Tselios; Apostolos P. Fournaris: "SECURED for Health: Scaling Up Privacy to Enable the Integration of the European Health Data Space", Design, Automation & Test in Europe Conference & Exhibition (DATE)
- Johannes Mueller; Balázs Pejó; Ivan Pryvalov: "DeVoS: Deniable Yet Verifiable Vote Updating", 24th Privacy Enhancing Technologies (PoPETs)
- 2023
- Wouter Heyndrickx; Lewis Mervin; Tobias Morawietz; Noé Sturm; Lukas Friedrich; Adam Zalewski; Anastasia Pentina; Lina Humbeck; Martijn Oldenhof; Ritsuya Niwayama; Peter Schmidtke; Nikolas Fechner; Jaak Simm; Ádám Arany; Nicolas Drizard; Rama Jabal; Arina Afanasyeva; Regis Loeb; Shlok Verma; Simon Harnqvist; Matthew Holmes; Balázs Pejó; Maria Telenczuk; Nicholas Holway; Arne Dieckmann; Nicola Rieke; Friederike Zumsande; Djork-Arné Clevert; Michael Krug; Christopher Luscombe; Darren Green; Peter Ertl; Péter Antal; David Marcus; Nicolas Do Huu; Hideyoshi Fuji; Stephen Pickett; Gergely Ács; Eric Boniface; Bernd Beck; Yax Sun; Arnaud Gohier; Friedrich Rippmann; Ola Engkvist; Andreas H. Göller; Yves Moreau; Mathieu N. Galtier; Ansgar Schuffenhauer; Hugo Ceulemans: "MELLODDY: cross pharma federated learning at unprecedented scale unlocks benefits in QSAR without compromising proprietary information", Journal of Chemical Information and Modeling (JCIM)
- Bowen Liu; Balázs Pejó; Qiang Tang: "Privacy-preserving Federated Singular Value Decomposition", MDPI Journal of Applied Sciences (AppSci)
- Balázs Pejó; Nikolett Kapui: "SQLi Detection with ML: A Data-Source Perspective", 20th International Conference on Security and Cryptography (SECRYPT)
- Balázs Pejó; Gergely Biczók: "Quality Inference in Federated Learning with Secure Aggregation", IEEE Transactions on Big Data (IEEE TBD)
- Martijn Oldenhof; Gergely Ács; Balázs Pejó; Ansgar Schuffenhauer; Nicholas Holway; Noé Sturm; Arne Dieckmann; Oliver Fortmeier; Eric Boniface; Clément Mayer; Arnaud Gohier; Peter Schmidtke; Ritsuya Niwayama; Dieter Kopecky; Lewis Mervin; Prakash Chandra Rathi; Lukas Friedrich; András Formanek; Péter Antal; Jordon Rahaman; Adam Zalewski; Wouter Heyndrickx; Ezron Oluoch; Manuel Stößel; Michal Vančo; David Endico; Fabien Gelus; Thaïs de Boisfossé; Adrien Darbier; Ashley Nicollet; Matthieu Blottière; Maria Telenczuk; Van Tien Nguyen; Thibaud Martinez; Camille Boillet; Kelvin Moutet; Alexandre Picosson; Aurélien Gasser; Inal Djafar; Antoine Simon; Ádám Arany; Jaak Simm; Yves Moreau; Ola Engkvist; Hugo Ceulemans; Camille Marini; Mathieu Galtier: "Industry-Scale Orchestrated Federated Learning for Drug Discovery", 35th Annual Conference on Innovative Applications of Artificial Intelligence (IAAI)
- 2022
- 2021
- 2020
- 2019
- 2017
- 2016