


default search action
Chawin Sitawarin
Person information
- affiliation: University of California, Berkeley, USA
Refine list

refinements active!
zoomed in on ?? of ?? records
view refined list in
2020 – today
- 2026
[i29]David Huang, Jaewon Chang, Avidan Shah, Prateek Mittal, Chawin Sitawarin:
Rapid Poison: Practical Poisoning Attacks Against the Rapid Response Framework. CoRR abs/2606.16242 (2026)- 2025
[c22]Julien Piet
, Xiao Huang
, Dennis Jacob
, Annabella Chow
, Maha Alrashed
, Geng Zhao
, Zhanhao Hu
, Chawin Sitawarin
, Basel Alomair
, David A. Wagner
:
JailbreaksOverTime: Detecting Jailbreak Attacks Under Distribution Shift. AISec@CCS 2025: 230-241
[c21]Sizhe Chen
, Yizhu Wang
, Nicholas Carlini
, Chawin Sitawarin
, David A. Wagner
:
Defending Against Prompt Injection With a Few DefensiveTokens. AISec@CCS 2025: 242-252
[c20]Yangruibo Ding, Yanjun Fu, Omniyyah Ibrahim
, Chawin Sitawarin, Xinyun Chen, Basel Alomair, David A. Wagner, Baishakhi Ray, Yizheng Chen:
Vulnerability Detection with Code Language Models: How Far are We? ICSE 2025: 1729-1741
[c19]David Huang, Avidan Shah, Alexandre Araujo, David A. Wagner, Chawin Sitawarin:
Stronger Universal and Transferable Attacks by Suppressing Refusals. NAACL (Long Papers) 2025: 5850-5876
[c18]Julien Piet, Chawin Sitawarin, Vivian Fang, Norman Mu, David A. Wagner:
MARKMyWORDS: Analyzing and Evaluating Language Model Watermarks. SaTML 2025: 68-91
[c17]Sizhe Chen, Julien Piet, Chawin Sitawarin, David A. Wagner:
StruQ: Defending Against Prompt Injection with Structured Queries. USENIX Security Symposium 2025: 2383-2400
[i28]Julien Piet, Xiao Huang, Dennis Jacob, Annabella Chow, Maha Alrashed, Geng Zhao, Zhanhao Hu, Chawin Sitawarin, Basel Alomair, David A. Wagner:
JailbreaksOverTime: Detecting Jailbreak Attacks Under Distribution Shift. CoRR abs/2504.19440 (2025)
[i27]Chongyang Shi, Sharon Lin, Shuang Song, Jamie Hayes, Ilia Shumailov, Itay Yona, Juliette Pluto, Aneesh Pappu, Christopher A. Choquette-Choo, Milad Nasr, Chawin Sitawarin, Gena Gibson, Andreas Terzis, John Flynn:
Lessons from Defending Gemini Against Indirect Prompt Injections. CoRR abs/2505.14534 (2025)
[i26]John X. Morris, Chawin Sitawarin, Chuan Guo, Narine Kokhlikyan, G. Edward Suh, Alexander M. Rush, Kamalika Chaudhuri, Saeed Mahloujifar:
How much do language models memorize? CoRR abs/2505.24832 (2025)
[i25]Sizhe Chen, Yizhu Wang, Nicholas Carlini, Chawin Sitawarin, David A. Wagner:
Defending Against Prompt Injection With a Few DefensiveTokens. CoRR abs/2507.07974 (2025)
[i24]Tong Wu, Chong Xiang, Jiachen T. Wang, Weichen Yu, Chawin Sitawarin, Vikash Sehwag, Prateek Mittal:
Does More Inference-Time Compute Really Help Robustness? CoRR abs/2507.15974 (2025)
[i23]Milad Nasr, Nicholas Carlini, Chawin Sitawarin, Sander V. Schulhoff, Jamie Hayes, Michael Ilie, Juliette Pluto, Shuang Song, Harsh Chaudhari, Ilia Shumailov, Abhradeep Thakurta, Kai Yuanqing Xiao, Andreas Terzis, Florian Tramèr:
The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections. CoRR abs/2510.09023 (2025)
[i22]Federico Barbero, Xiangming Gu, Christopher A. Choquette-Choo, Chawin Sitawarin, Matthew Jagielski, Itay Yona, Petar Velickovic, Ilia Shumailov, Jamie Hayes:
Extracting alignment data in open models. CoRR abs/2510.18554 (2025)
[i21]Nils Philipp Walter, Chawin Sitawarin, Jamie Hayes, David Stutz, Ilia Shumailov:
Soft Instruction De-escalation Defense. CoRR abs/2510.21057 (2025)- 2024
[b1]Chawin Sitawarin:
New Perspectives on Adversarially Robust Machine Learning Systems. University of California Berkeley, USA, 2024
[c16]Julien Piet, Maha Alrashed, Chawin Sitawarin, Sizhe Chen, Zeming Wei, Elizabeth Sun, Basel Alomair, David A. Wagner:
Jatmo: Prompt Injection Defense by Task-Specific Finetuning. ESORICS (1) 2024: 105-124
[c15]Kathan Shah, Chawin Sitawarin:
SPDER: Semiperiodic Damping-Enabled Object Representation. ICLR 2024
[c14]Chawin Sitawarin, Jaewon Chang, David Huang, Wesson Altoyan, David A. Wagner:
PubDef: Defending Against Transfer Attacks From Public Models. ICLR 2024
[c13]Lin Li, Yifei Wang, Chawin Sitawarin, Michael W. Spratling:
OODRobustBench: a Benchmark and Large-Scale Analysis of Adversarial Robustness under Distribution Shift. ICML 2024: 28830-28869
[i20]Sizhe Chen, Julien Piet, Chawin Sitawarin, David A. Wagner:
StruQ: Defending Against Prompt Injection with Structured Queries. CoRR abs/2402.06363 (2024)
[i19]Chawin Sitawarin, Norman Mu, David A. Wagner, Alexandre Araujo:
PAL: Proxy-Guided Black-Box Attack on Large Language Models. CoRR abs/2402.09674 (2024)
[i18]Yangruibo Ding, Yanjun Fu
, Omniyyah Ibrahim, Chawin Sitawarin, Xinyun Chen, Basel Alomair, David A. Wagner, Baishakhi Ray, Yizheng Chen:
Vulnerability Detection with Code Language Models: How Far Are We? CoRR abs/2403.18624 (2024)- 2023
[c12]Nabeel Hingun, Chawin Sitawarin, Jerry Li, David A. Wagner:
REAP: A Large-Scale Realistic Adversarial Patch Benchmark. ICCV 2023: 4617-4628
[c11]Chawin Sitawarin, Kornrapat Pongmala, Yizheng Chen, Nicholas Carlini, David A. Wagner:
Part-Based Models Improve Adversarial Robustness. ICLR 2023
[c10]Chawin Sitawarin, Florian Tramèr, Nicholas Carlini:
Preprocessors Matter! Realistic Decision-Based Attacks on Machine Learning Systems. ICML 2023: 32008-32032
[c9]Chong Xiang, Chawin Sitawarin, Tong Wu, Prateek Mittal:
Short: Certifiably Robust Perception Against Adversarial Patch Attacks: A Survey. VehicleSec 2023
[i17]Kathan Shah, Chawin Sitawarin:
SPDER: Semiperiodic Damping-Enabled Object Representation. CoRR abs/2306.15242 (2023)
[i16]Lin Li, Yifei Wang, Chawin Sitawarin
, Michael W. Spratling
:
OODRobustBench: benchmarking and analyzing adversarial robustness under distribution shift. CoRR abs/2310.12793 (2023)
[i15]Chawin Sitawarin, Jaewon Chang, David Huang, Wesson Altoyan, David A. Wagner:
Defending Against Transfer Attacks From Public Models. CoRR abs/2310.17645 (2023)
[i14]Julien Piet, Chawin Sitawarin, Vivian Fang, Norman Mu, David A. Wagner:
Mark My Words: Analyzing and Evaluating Language Model Watermarks. CoRR abs/2312.00273 (2023)
[i13]Julien Piet, Maha Alrashed, Chawin Sitawarin, Sizhe Chen, Zeming Wei, Elizabeth Sun, Basel Alomair, David A. Wagner:
Jatmo: Prompt Injection Defense by Task-Specific Finetuning. CoRR abs/2312.17673 (2023)- 2022
[c8]Chawin Sitawarin, Zachary J. Golan-Strieb, David A. Wagner:
Demystifying the Adversarial Robustness of Random Transformation Defenses. ICML 2022: 20232-20252
[i12]Chawin Sitawarin
, Zachary J. Golan-Strieb, David A. Wagner:
Demystifying the Adversarial Robustness of Random Transformation Defenses. CoRR abs/2207.03574 (2022)
[i11]Chawin Sitawarin
, Kornrapat Pongmala, Yizheng Chen, Nicholas Carlini, David A. Wagner:
Part-Based Models Improve Adversarial Robustness. CoRR abs/2209.09117 (2022)
[i10]Chawin Sitawarin, Florian Tramèr, Nicholas Carlini:
Preprocessors Matter! Realistic Decision-Based Attacks on Machine Learning Systems. CoRR abs/2210.03297 (2022)
[i9]Nabeel Hingun, Chawin Sitawarin
, Jerry Li, David A. Wagner:
REAP: A Large-Scale Realistic Adversarial Patch Benchmark. CoRR abs/2212.05680 (2022)- 2021
[c7]Chawin Sitawarin
, Supriyo Chakraborty, David A. Wagner:
SAT: Improving Adversarial Training via Curriculum-Based Loss Smoothing. AISec@CCS 2021: 25-36
[c6]Chawin Sitawarin, Evgenios M. Kornaropoulos, Dawn Song, David A. Wagner:
Adversarial Examples for k-Nearest Neighbor Classifiers Based on Higher-Order Voronoi Diagrams. NeurIPS 2021: 15486-15497- 2020
[c5]Chawin Sitawarin
, David A. Wagner:
Minimum-Norm Adversarial Examples on KNN and KNN based Models. SP (Workshops) 2020: 34-40
[i8]Chawin Sitawarin, David A. Wagner:
Minimum-Norm Adversarial Examples on KNN and KNN-Based Models. CoRR abs/2003.06559 (2020)
[i7]Chawin Sitawarin, Supriyo Chakraborty, David A. Wagner:
Improving Adversarial Robustness Through Progressive Hardening. CoRR abs/2003.09347 (2020)
[i6]Chawin Sitawarin, Evgenios M. Kornaropoulos, Dawn Song, David A. Wagner:
Adversarial Examples for k-Nearest Neighbor Classifiers Based on Higher-Order Voronoi Diagrams. CoRR abs/2011.09719 (2020)
2010 – 2019
- 2019
[c4]Vikash Sehwag, Arjun Nitin Bhagoji, Liwei Song, Chawin Sitawarin, Daniel Cullina
, Mung Chiang, Prateek Mittal:
Analyzing the Robustness of Open-World Machine Learning. AISec@CCS 2019: 105-116
[c3]Chawin Sitawarin
, David A. Wagner:
On the Robustness of Deep K-Nearest Neighbors. IEEE Symposium on Security and Privacy Workshops 2019: 1-7
[i5]Chawin Sitawarin, David A. Wagner:
On the Robustness of Deep K-Nearest Neighbors. CoRR abs/1903.08333 (2019)
[i4]Vikash Sehwag, Arjun Nitin Bhagoji, Liwei Song, Chawin Sitawarin, Daniel Cullina, Mung Chiang, Prateek Mittal:
Better the Devil you Know: An Analysis of Evasion Attacks using Out-of-Distribution Adversarial Examples. CoRR abs/1905.01726 (2019)- 2018
[c2]Vikash Sehwag, Chawin Sitawarin
, Arjun Nitin Bhagoji
, Arsalan Mosenia, Mung Chiang, Prateek Mittal:
Not All Pixels are Born Equal: An Analysis of Evasion Attacks under Locality Constraints. CCS 2018: 2285-2287
[c1]Arjun Nitin Bhagoji
, Daniel Cullina
, Chawin Sitawarin
, Prateek Mittal:
Enhancing robustness of machine learning systems via data transformations. CISS 2018: 1-5
[i3]Chawin Sitawarin, Arjun Nitin Bhagoji, Arsalan Mosenia, Prateek Mittal, Mung Chiang:
Rogue Signs: Deceiving Traffic Sign Recognition with Malicious Ads and Logos. CoRR abs/1801.02780 (2018)
[i2]Chawin Sitawarin, Arjun Nitin Bhagoji, Arsalan Mosenia, Mung Chiang, Prateek Mittal:
DARTS: Deceiving Autonomous Cars with Toxic Signs. CoRR abs/1802.06430 (2018)- 2017
[i1]Mark Martinez, Chawin Sitawarin, Kevin Finch, Lennart Meincke, Alex Yablonski, Alain L. Kornhauser:
Beyond Grand Theft Auto V for Training, Testing and Enhancing Deep Learning in Self Driving Cars. CoRR abs/1712.01397 (2017)
Coauthor Index

manage site settings
To protect your privacy, all features that rely on external API calls from your browser are turned off by default. You need to opt-in for them to become active. All settings here will be stored as cookies with your web browser. For more information see our F.A.Q.
Unpaywalled article links
Add open access links from
to the list of external document links (if available).
Privacy notice: By enabling the option above, your browser will contact the API of unpaywall.org to load hyperlinks to open access articles. Although we do not have any reason to believe that your call will be tracked, we do not have any control over how the remote server uses your data. So please proceed with care and consider checking the Unpaywall privacy policy.
Archived links via Wayback Machine
For web page which are no longer available, try to retrieve content from the
of the Internet Archive (if available).
Privacy notice: By enabling the option above, your browser will contact the API of archive.org to check for archived content of web pages that are no longer available. Although we do not have any reason to believe that your call will be tracked, we do not have any control over how the remote server uses your data. So please proceed with care and consider checking the Internet Archive privacy policy.
Reference lists
Add a list of references from
,
, and
to record detail pages.
load references from crossref.org and opencitations.net
Privacy notice: By enabling the option above, your browser will contact the APIs of crossref.org, opencitations.net, and semanticscholar.org to load article reference information. Although we do not have any reason to believe that your call will be tracked, we do not have any control over how the remote server uses your data. So please proceed with care and consider checking the Crossref privacy policy and the OpenCitations privacy policy, as well as the AI2 Privacy Policy covering Semantic Scholar.
Citation data
Add a list of citing articles from
and
to record detail pages.
load citations from opencitations.net
Privacy notice: By enabling the option above, your browser will contact the API of opencitations.net and semanticscholar.org to load citation information. Although we do not have any reason to believe that your call will be tracked, we do not have any control over how the remote server uses your data. So please proceed with care and consider checking the OpenCitations privacy policy as well as the AI2 Privacy Policy covering Semantic Scholar.
OpenAlex data
Load additional information about publications from
.
Privacy notice: By enabling the option above, your browser will contact the API of openalex.org to load additional information. Although we do not have any reason to believe that your call will be tracked, we do not have any control over how the remote server uses your data. So please proceed with care and consider checking the information given by OpenAlex.
last updated on 2026-07-10 02:09 CEST by the dblp team
all metadata released as open data under CC0 1.0 license
see also: Terms of Use | Privacy Policy | Imprint


Google
Google Scholar
Semantic Scholar
Internet Archive Scholar
CiteSeerX
ORCID






