
- title: 'Data Quality as a Causal Variable in Smartphone Health Monitoring'
  abstract: 'Smartphone-based health monitoring studies commonly treat data quality as a preprocessing step: flag or remove low-quality recordings, then proceed with the remainder. This places data quality outside the model when it belongs inside, as part of the data-generating process if it is associated with the outcome of interest, filtering on it changes what the remaining data represent. We test this on the mPower 2.0 Parkinson’s disease dataset (81 participants, 15,398 resting tremor recordings), applying an automated assessment framework at three levels – study-level session completion, task-level recording duration, and signal-level flat-segment detection – and testing each check against diagnosis at the participant level. The three behave differently. Duration filtering removes recordings from Parkinson’s disease participants (clustered odds ratio 2.23, 95% CI 1.50–3.32); flat signal filtering removes control recordings (OR 0.52, 0.23–1.19), because on a resting tremor task low signal variation is the expected observation for a participant without tremor rather than a measurement failure; session completion shows no association once follow-up length is accounted for (OR 1.13, 0.53–2.37). Filtering on data quality is therefore not neutral, and its direction cannot be assumed. The main classification results are nonetheless stable after duration filtering. Data quality belongs inside the causal model as separate variables, each tested against the outcome before it is filtered on.'
  volume: 348
  URL: https://proceedings.mlr.press/v348/aloyayri26a.html
  PDF: https://raw.githubusercontent.com/mlresearch/v348/main/assets/aloyayri26a/aloyayri26a.pdf
  edit: https://github.com/mlresearch//v348/edit/gh-pages/_posts/2026-09-30-aloyayri26a.md
  series: 'Proceedings of Machine Learning Research'
  container-title: 'Proceedings of the Fourth UK AI Conference 2026'
  publisher: 'PMLR'
  author: 
  - given: Abdulrahman A.
    family: Aloyayri
  - given: Max A.
    family: Little
  - given: Nawfal A.
    family: Zakar
  editor: 
  - given: Alistair
    family: Benford
  - given: Baturalp
    family: Büyükateş
  - given: Christian
    family: Cabrera
  - given: Sarah
    family: Kiden
  - given: Arianna
    family: Salili-James
  - given: Vincent
    family: Zakka
  - given: Feng
    family: Zhou
  page: 1-11
  id: aloyayri26a
  issued:
    date-parts: 
      - 2026
      - 9
      - 30
  firstpage: 1
  lastpage: 11
  published: 2026-09-30 00:00:00 +0000
- title: 'Prompt Injection Detection is Regime-Dependent: A Deployment-Aware Evaluation with Interpretable Structural Signals'
  abstract: 'Prompt injection poses a critical threat to the safe deployment of large language models, yet existing detection approaches are typically evaluated under limited settings that do not reflect real-world operating constraints. In this work, we present a deployment-aware evaluation of prompt injection detection using a multi-model and multi-regime experimental framework. We compare lexical, semantic, structural, and transformer-based detectors across multiple out-of-distribution settings, repeated data splits, and both ranking and thresholded deployment metrics. We introduce interpretable structural signals that capture hierarchy overrides, system prompt spoofing, role redefinition, and evasion patterns, and assess their contribution both within sparse models and in combination with strong encoder baselines. Our results show that detection performance is highly regime-dependent and sensitive to threshold selection, with no single model dominating across all settings. Transformer-based models achieve the strongest overall performance, while structural signals provide modest but consistent gains in certain regimes and improve low false positive rate behaviour in harder scenarios. These findings highlight the gap between ranking performance and deployment effectiveness and underscore the importance of evaluating prompt injection defences under realistic operational constraints. Code: \url{https://github.com/TimiAkinrele/ai-jailbreak-framework}'
  volume: 348
  URL: https://proceedings.mlr.press/v348/akinrele26a.html
  PDF: https://raw.githubusercontent.com/mlresearch/v348/main/assets/akinrele26a/akinrele26a.pdf
  edit: https://github.com/mlresearch//v348/edit/gh-pages/_posts/2026-09-30-akinrele26a.md
  series: 'Proceedings of Machine Learning Research'
  container-title: 'Proceedings of the Fourth UK AI Conference 2026'
  publisher: 'PMLR'
  author: 
  - given: Akindoyin
    family: Akinrele
  - given: Shreyank N
    family: Gowda
  editor: 
  - given: Alistair
    family: Benford
  - given: Baturalp
    family: Büyükateş
  - given: Christian
    family: Cabrera
  - given: Sarah
    family: Kiden
  - given: Arianna
    family: Salili-James
  - given: Vincent
    family: Zakka
  - given: Feng
    family: Zhou
  page: 12-30
  id: akinrele26a
  issued:
    date-parts: 
      - 2026
      - 9
      - 30
  firstpage: 12
  lastpage: 30
  published: 2026-09-30 00:00:00 +0000
- title: 'Separating the Art from the Algorithm: Detecting Moral Decoupling in Consumer Discourse About Generative AI'
  abstract: 'Some consumers who learn that a generative AI tool was trained on creative work taken without consent condemn the practice and stop using it. Others condemn it and keep using it. The second response is moral decoupling: separating judgements about wrongdoing from judgements about usefulness. The construct is established in laboratory research but has not been measured in naturally occurring discourse. We present a stance detection study of 7,371 Reddit posts from three professional communities differently exposed to generative AI. Each post is human-annotated on two axes, stance toward AI content and type of justification, with decoupling operationalised as a supportive stance co-occurring with explicit ethical acknowledgement. Across five calibration rounds, two annotators reached Cohen’s kappa of 0.654 on stance and 0.621 on argument type; GPT-4o, given the same guidelines, reached 0.058 and 0.209 and never used the MIXED label. Fine-tuned RoBERTa reached macro-F1 of 0.63 and 0.82. Moral positions differ sharply across communities (V = 0.23), and among engaged posts the decoupling-coupling balance differs too (V = 0.15). Marketers rarely engage morally at all, whereas artists produce most moral reasoning and resolve it against the tools three times in four. Involvement governs primarily whether ethical evaluation happens; secondarily, which way it falls.'
  volume: 348
  URL: https://proceedings.mlr.press/v348/chimezie26a.html
  PDF: https://raw.githubusercontent.com/mlresearch/v348/main/assets/chimezie26a/chimezie26a.pdf
  edit: https://github.com/mlresearch//v348/edit/gh-pages/_posts/2026-09-30-chimezie26a.md
  series: 'Proceedings of Machine Learning Research'
  container-title: 'Proceedings of the Fourth UK AI Conference 2026'
  publisher: 'PMLR'
  author: 
  - given: Onuchukwu Joseph
    family: Chimezie
  - given: Julius Sechang
    family: Mboli
  editor: 
  - given: Alistair
    family: Benford
  - given: Baturalp
    family: Büyükateş
  - given: Christian
    family: Cabrera
  - given: Sarah
    family: Kiden
  - given: Arianna
    family: Salili-James
  - given: Vincent
    family: Zakka
  - given: Feng
    family: Zhou
  page: 31-41
  id: chimezie26a
  issued:
    date-parts: 
      - 2026
      - 9
      - 30
  firstpage: 31
  lastpage: 41
  published: 2026-09-30 00:00:00 +0000
- title: 'Auditing Feature Importance Rankings in Nonstationary Data Streams'
  abstract: 'Feature importance explanations are often evaluated on fixed tabular data, although many deployed models operate on nonstationary streams in which the data distribution and relevant signal may change over time. In such settings, a ranking can appear stable while failing to respond to drift, or change for reasons unrelated to the label signal learned by the model. This paper proposes a protocol for evaluating feature importance rankings in data streams. The protocol combines a sanity gate based on label randomization, deletion tests for faithfulness, keep-top-k sufficiency, temporal rank stability, negative controls, and Drift–Explanation Alignment (DEA), a diagnostic that relates distributional drift to changes in feature rankings. We evaluate the protocol on controlled synthetic streams representing stable, abrupt, gradual, and correlated proxy conditions, as well as selected real datasets from electricity markets, insect monitoring, gas sensing, and industrial fault detection. Controls that are independent of the trained model fail the sanity gate, even when they are perfectly stable or responsive to drift. Rankings derived from trained models recover known signal features in controlled streams but show mixed reliability on real data. These findings support interpreting DEA and temporal stability only after establishing model dependence.'
  volume: 348
  URL: https://proceedings.mlr.press/v348/daneshvar26a.html
  PDF: https://raw.githubusercontent.com/mlresearch/v348/main/assets/daneshvar26a/daneshvar26a.pdf
  edit: https://github.com/mlresearch//v348/edit/gh-pages/_posts/2026-09-30-daneshvar26a.md
  series: 'Proceedings of Machine Learning Research'
  container-title: 'Proceedings of the Fourth UK AI Conference 2026'
  publisher: 'PMLR'
  author: 
  - given: Bahareh
    family: Daneshvar
  - given: Conor
    family: Fahy
  - given: Shengxiang
    family: Yang
  editor: 
  - given: Alistair
    family: Benford
  - given: Baturalp
    family: Büyükateş
  - given: Christian
    family: Cabrera
  - given: Sarah
    family: Kiden
  - given: Arianna
    family: Salili-James
  - given: Vincent
    family: Zakka
  - given: Feng
    family: Zhou
  page: 42-51
  id: daneshvar26a
  issued:
    date-parts: 
      - 2026
      - 9
      - 30
  firstpage: 42
  lastpage: 51
  published: 2026-09-30 00:00:00 +0000
- title: 'An AI-Based Decision-Support Pipeline for Day-Ahead Photovoltaic Forecasting'
  abstract: 'Reliable photovoltaic (PV) forecasts can support low-carbon energy systems, but deployed sites may have only short and incomplete records. Physical and hybrid methods can be sensitive to weather inputs, calibration, and timestamp-alignment, while individual machine learning models may capture different parts of the forecasting problem. We study hourly day-ahead PV forecasting at a United Kingdom charging station using one year of inverter measurements, with 9.25% of hours missing. The pipeline checks timestamp-alignment, derives solar and clearness features, adds short-term weather context, and combines five complementary models using non-negative least squares stacking, with the combination fitted only on validation observations. We compare against smart persistence, a weather-scaled baseline that carries the previous day’s PV behaviour forward using target-day irradiance. With retrospective weather, the combined model reduces daylight normalised root mean square error (RMSE) by 31.2% under random day-fold evaluation and by 2.9% under rolling-origin evaluation, although the latter improvement is not robust across days. It also improves by 3.0% over the single model selected from validation performance. Replacing retrospective weather with a public product sampled at a constant 24-hour lead increases daylight RMSE by 13.1% and 4.2% under the two protocols, while retaining positive skill over smart persistence.'
  volume: 348
  URL: https://proceedings.mlr.press/v348/dehghan26a.html
  PDF: https://raw.githubusercontent.com/mlresearch/v348/main/assets/dehghan26a/dehghan26a.pdf
  edit: https://github.com/mlresearch//v348/edit/gh-pages/_posts/2026-09-30-dehghan26a.md
  series: 'Proceedings of Machine Learning Research'
  container-title: 'Proceedings of the Fourth UK AI Conference 2026'
  publisher: 'PMLR'
  author: 
  - given: Fariba
    family: Dehghan
  - given: Sebastian
    family: Stein
  - given: Vahid
    family: Yazdanpanah
  - given: Stephanie
    family: Gauthier
  - given: Masood
    family: Nazari
  editor: 
  - given: Alistair
    family: Benford
  - given: Baturalp
    family: Büyükateş
  - given: Christian
    family: Cabrera
  - given: Sarah
    family: Kiden
  - given: Arianna
    family: Salili-James
  - given: Vincent
    family: Zakka
  - given: Feng
    family: Zhou
  page: 52-67
  id: dehghan26a
  issued:
    date-parts: 
      - 2026
      - 9
      - 30
  firstpage: 52
  lastpage: 67
  published: 2026-09-30 00:00:00 +0000
- title: 'Denoising Diffusion Probabilistic Models for Source Camera Identification in Image Forensics'
  abstract: 'Source Camera Identification (SCI) is a forensic task to determine the physical imaging device for a given digital image or video. The problem has raised concern with the proliferation of digital cameras in consumer devices, the ease with image capturing, editing, and sharing at scale across social media and messaging platforms, and the operational need to attribute illicit content in important evidence cases like child abuse to specific recording devices in criminal investigations. The main signal for SCI is Photo-Response Non-Uniformity (PRNU), classically extracted via a denoising filter such as the Wiener filter, which degrades substantially on small image patches. We propose a combined framework in which a per-camera Denoising Diffusion Probabilistic Model (DDPM) acts as a camera-dependent residual extractor, replacing the classical filter, and Linear Discriminant Analysis (LDA) exploits the full NCC score vector across all candidate cameras for the final identification decision. Evaluated on three benchmarks at $128\times128$ patches, our method achieves macro-averaged balanced accuracies of 93.74%, 93.84%, and 92.50% on the Northumbria, Dresden, and VISION datasets respectively, outperforming the Wiener filter on all three benchmarks.'
  volume: 348
  URL: https://proceedings.mlr.press/v348/farzadpour26a.html
  PDF: https://raw.githubusercontent.com/mlresearch/v348/main/assets/farzadpour26a/farzadpour26a.pdf
  edit: https://github.com/mlresearch//v348/edit/gh-pages/_posts/2026-09-30-farzadpour26a.md
  series: 'Proceedings of Machine Learning Research'
  container-title: 'Proceedings of the Fourth UK AI Conference 2026'
  publisher: 'PMLR'
  author: 
  - given: Zahra
    family: Farzadpour
  - given: Farah Nafees
    family: Ahmed
  - given: Fouad
    family: Khelifi
  editor: 
  - given: Alistair
    family: Benford
  - given: Baturalp
    family: Büyükateş
  - given: Christian
    family: Cabrera
  - given: Sarah
    family: Kiden
  - given: Arianna
    family: Salili-James
  - given: Vincent
    family: Zakka
  - given: Feng
    family: Zhou
  page: 68-77
  id: farzadpour26a
  issued:
    date-parts: 
      - 2026
      - 9
      - 30
  firstpage: 68
  lastpage: 77
  published: 2026-09-30 00:00:00 +0000
- title: 'Adaptive Data Dropout: Towards Self-Regulated Learning in Deep Neural Networks'
  abstract: 'Deep neural networks are typically trained by uniformly sampling large datasets across epochs, despite evidence that not all samples contribute equally throughout learning. Recent work shows that progressively reducing the amount of training data can improve efficiency and generalization, but existing methods rely on fixed schedules that do not adapt during training. In this work, we propose Adaptive Data Dropout, a simple framework that dynamically adjusts the subset of training data based on performance feedback. Inspired by self-regulated learning, our approach treats data selection as an adaptive process, increasing or decreasing data exposure in response to changes in training accuracy. We introduce a lightweight stochastic update mechanism that modulates the dropout schedule online, allowing the model to balance exploration and consolidation over time. Experiments on standard image classification benchmarks show that our method reduces effective training steps while maintaining competitive accuracy compared to static data dropout strategies. These results highlight adaptive data selection as a promising direction for efficient and robust training. Code will be released.'
  volume: 348
  URL: https://proceedings.mlr.press/v348/gahir26a.html
  PDF: https://raw.githubusercontent.com/mlresearch/v348/main/assets/gahir26a/gahir26a.pdf
  edit: https://github.com/mlresearch//v348/edit/gh-pages/_posts/2026-09-30-gahir26a.md
  series: 'Proceedings of Machine Learning Research'
  container-title: 'Proceedings of the Fourth UK AI Conference 2026'
  publisher: 'PMLR'
  author: 
  - given: Amar
    family: Gahir
  - given: Varshil
    family: Patel
  - given: Shreyank N
    family: Gowda
  editor: 
  - given: Alistair
    family: Benford
  - given: Baturalp
    family: Büyükateş
  - given: Christian
    family: Cabrera
  - given: Sarah
    family: Kiden
  - given: Arianna
    family: Salili-James
  - given: Vincent
    family: Zakka
  - given: Feng
    family: Zhou
  page: 78-87
  id: gahir26a
  issued:
    date-parts: 
      - 2026
      - 9
      - 30
  firstpage: 78
  lastpage: 87
  published: 2026-09-30 00:00:00 +0000
- title: 'Hybrid Thompson-UCB for Risk-Aware Classification of Brain Tumours under Limited Data'
  abstract: 'Brain tumour classification under limited MRI data is not just an accuracy problem. It is a risk-aware task because tumour cases misclassified as healthy may lead to false reassurance. This study reframes four-class brain image classification (glioma, meningioma, pituitary, and healthy) as a single-step contextual bandit problem. We propose a framework based on contextual bandits for cost-sensitive classification framework for risk-aware learning. The framework incorporates cost-sensitive learning directly into the reward system, enabling the agent to focus on clinically risky tumour-to-healthy errors and to reduce them by iteratively improving the classification policy. This paper employs hybrid Thompson Sampling with Upper Confidence Bound (TS-UCB), $\epsilon$-greedy, and Boltzmann exploration policies for risk-aware classification with limited brain-tumour data, and evaluates these policies across three data regimes using cross-validation. The hybrid TS-UCB exploration policy achieves the strongest safety-performance balance, obtaining the lowest tumour-to-healthy error rate and the highest healthy-class precision while maintaining competitive validation and test accuracies. The results further demonstrate that reward shaping can tune the safety-accuracy trade-off by prioritising clinically risky confusions while remaining competitive with, and, in some cases, outperforming traditional deep learning techniques under limited data. These results suggest that hybrid TS-UCB is suitable for risk-aware brain tumour classification when labelled data are scarce and false negatives must be controlled.'
  volume: 348
  URL: https://proceedings.mlr.press/v348/marghalani26a.html
  PDF: https://raw.githubusercontent.com/mlresearch/v348/main/assets/marghalani26a/marghalani26a.pdf
  edit: https://github.com/mlresearch//v348/edit/gh-pages/_posts/2026-09-30-marghalani26a.md
  series: 'Proceedings of Machine Learning Research'
  container-title: 'Proceedings of the Fourth UK AI Conference 2026'
  publisher: 'PMLR'
  author: 
  - given: Bashayer Fouad
    family: Marghalani
  - given: J. Michael
    family: Herrmann
  editor: 
  - given: Alistair
    family: Benford
  - given: Baturalp
    family: Büyükateş
  - given: Christian
    family: Cabrera
  - given: Sarah
    family: Kiden
  - given: Arianna
    family: Salili-James
  - given: Vincent
    family: Zakka
  - given: Feng
    family: Zhou
  page: 88-97
  id: marghalani26a
  issued:
    date-parts: 
      - 2026
      - 9
      - 30
  firstpage: 88
  lastpage: 97
  published: 2026-09-30 00:00:00 +0000
- title: 'Must Success Make Sense?'
  abstract: 'Explainable AI begins from a curious, powerful hope. If the operations of an artificial system can be explained, then its opacity can be overcome. This paper questions that hope. Explanation may inform us without restoring understanding. Intelligibility is a distinct human epistemic achievement.'
  volume: 348
  URL: https://proceedings.mlr.press/v348/mridula26a.html
  PDF: https://raw.githubusercontent.com/mlresearch/v348/main/assets/mridula26a/mridula26a.pdf
  edit: https://github.com/mlresearch//v348/edit/gh-pages/_posts/2026-09-30-mridula26a.md
  series: 'Proceedings of Machine Learning Research'
  container-title: 'Proceedings of the Fourth UK AI Conference 2026'
  publisher: 'PMLR'
  author: 
  - given: Jaia
    family: Mridula
  - given: David James Edward
    family: Elks
  editor: 
  - given: Alistair
    family: Benford
  - given: Baturalp
    family: Büyükateş
  - given: Christian
    family: Cabrera
  - given: Sarah
    family: Kiden
  - given: Arianna
    family: Salili-James
  - given: Vincent
    family: Zakka
  - given: Feng
    family: Zhou
  page: 98-105
  id: mridula26a
  issued:
    date-parts: 
      - 2026
      - 9
      - 30
  firstpage: 98
  lastpage: 105
  published: 2026-09-30 00:00:00 +0000
- title: 'Fixing the Background: Segmentation-Guided Feature Refinement for Multiple Object Tracking'
  abstract: 'Tracking-by-detection algorithms in multiple object tracking systems rely on bounding boxes for object localization and data association. Bounding boxes also contain extraneous background information, which contaminates appearance features, thereby increasing false or missed detections. This paper proposes a multiple object tracking framework that integrates segmentation-based background removal into the tracking pipeline. Mask R-CNN is used to eliminate background clutter within the bounding boxes, producing refined detections. Deep SORT uses a Kalman filter for motion modeling and, in parallel, a convolutional neural network extracts appearance features from these refined detections. Data association is performed by evaluating the similarity between predicted tracks and detections using both motion and appearance features. The final matching between tracks and detections is performed using the Hungarian matching, enabling improved object detections over time. The robustness of data association is enhanced in challenging situations, such as occlusion and clutter, by improving appearance features. The approach demonstrated improvement in the overall tracking performance on the MOT16 challenge dataset, resulting in reduction in false or missed detections, and an increase in multiple object tracking accuracy (MOTA).'
  volume: 348
  URL: https://proceedings.mlr.press/v348/nisar26a.html
  PDF: https://raw.githubusercontent.com/mlresearch/v348/main/assets/nisar26a/nisar26a.pdf
  edit: https://github.com/mlresearch//v348/edit/gh-pages/_posts/2026-09-30-nisar26a.md
  series: 'Proceedings of Machine Learning Research'
  container-title: 'Proceedings of the Fourth UK AI Conference 2026'
  publisher: 'PMLR'
  author: 
  - given: Muhammad Hassan
    family: Nisar
  - given: Syeda Umme
    family: Umama
  - given: Muhammad Imran
    family: Shehzad
  - given: Hazrat
    family: Ali
  - given: Shoaib
    family: Azmat
  editor: 
  - given: Alistair
    family: Benford
  - given: Baturalp
    family: Büyükateş
  - given: Christian
    family: Cabrera
  - given: Sarah
    family: Kiden
  - given: Arianna
    family: Salili-James
  - given: Vincent
    family: Zakka
  - given: Feng
    family: Zhou
  page: 106-115
  id: nisar26a
  issued:
    date-parts: 
      - 2026
      - 9
      - 30
  firstpage: 106
  lastpage: 115
  published: 2026-09-30 00:00:00 +0000
- title: 'From AI Trustworthiness to Perceived User Trust in High-Risk AI: An Expert-Derived Conceptual Model'
  abstract: 'Artificial intelligence (AI) systems are increasingly used in high-risk domains where their decisions can significantly affect people’s lives. While trustworthy AI frameworks emphasize attributes such as accuracy, fairness, transparency, and reliability, these attributes do not necessarily translate into user trust. This study examines expert perspectives on this relationship through 14 interviews across four high-risk industries and six countries. Thematic analysis identified interconnected technical, human, organizational, and contextual factors that experts believe influence perceived trust. Participants associated trust with system performance and reliability, but also emphasized usefulness, contextual relevance, transparency, accountability, human agency, user control, and organizational reputation. Building on these findings, we propose an expert-derived conceptual framework that extends the established distinction between AI trustworthiness and human trust by explaining how the two may become connected. Rather than assuming that trustworthy system characteristics directly generate trust, our framework proposes that trustworthiness attributes are translated into perceived trust through users’ interpretation and experience of the system. This interpretive stage is shaped by two distinct sets of factors: user dispositional factors, such as demographics, risk tolerance, AI literacy, prior AI experience, and propensity to trust, and contextual influences, such as organizational reputation, social and domain norms, and regulatory context. Perceived trust in turn influences reliance and system use, while remaining distinct from them; because reliance is directly observable, experts often infer trust from it, even though continued use is an ambiguous signal that may instead reflect convenience, necessity, or a lack of alternatives. This framework represents experts’ perspectives rather than direct evidence of users’ trust experiences and provides a foundation for future empirical research with end-users.'
  volume: 348
  URL: https://proceedings.mlr.press/v348/palazzolo26a.html
  PDF: https://raw.githubusercontent.com/mlresearch/v348/main/assets/palazzolo26a/palazzolo26a.pdf
  edit: https://github.com/mlresearch//v348/edit/gh-pages/_posts/2026-09-30-palazzolo26a.md
  series: 'Proceedings of Machine Learning Research'
  container-title: 'Proceedings of the Fourth UK AI Conference 2026'
  publisher: 'PMLR'
  author: 
  - given: Puntis
    family: Palazzolo
  - given: Bernd Carsten
    family: Stahl
  - given: Helena
    family: Webb
  editor: 
  - given: Alistair
    family: Benford
  - given: Baturalp
    family: Büyükateş
  - given: Christian
    family: Cabrera
  - given: Sarah
    family: Kiden
  - given: Arianna
    family: Salili-James
  - given: Vincent
    family: Zakka
  - given: Feng
    family: Zhou
  page: 116-133
  id: palazzolo26a
  issued:
    date-parts: 
      - 2026
      - 9
      - 30
  firstpage: 116
  lastpage: 133
  published: 2026-09-30 00:00:00 +0000
- title: 'Certified Multi-Source Integrity for Structured Agent Actions'
  abstract: 'LLM agents increasingly take privileged, often irreversible structured actions, such as paying an invoice. They assemble each action from action-critical fields in documents and tool outputs that an adversary can corrupt, and indirect prompt injection can drive the model itself to extract attacker-chosen values. Current defenses gate on a source’s trust label or certify free-text answer quality. None certifies the integrity of a coupled, policy-bound structured action under a corruption budget that accounts for shared upstream sources. We characterize when such an action is safely certifiable and give the maximally live safe certifier. It admits an action only when each field clears the rule its evidence structure supports: a bounded corruption radius over corruption-distinct evidence classes, counted by a minimum hitting set so that re-publishing or laundered copies cannot manufacture quorum, deterministic reconciliation for complementary fields, and a trusted anchor where the evidence leaves a field single-sourced. We formalize two robustness notions, validate each mechanism by ablation, and measure how often the multi-source precondition holds on sanctions designations (70,966 entities) and software supply-chain provenance (450 packages). Under upper-bound proxies, genuine corroboration is a minority phenomenon in both, and naive attestation counting overstates it, since witnesses that look independent collapse to two corruption-distinct domains once shared origin is counted. Across five current models in a real agent loop, a realistic injection fools every model but one and a naive agent then executes the fraudulent action on most attacks. The certifier admits no unsafe action and recovers the correct value where corroboration permits, while action-gating and provenance baselines are broken in every world of our harness.'
  volume: 348
  URL: https://proceedings.mlr.press/v348/pandey26a.html
  PDF: https://raw.githubusercontent.com/mlresearch/v348/main/assets/pandey26a/pandey26a.pdf
  edit: https://github.com/mlresearch//v348/edit/gh-pages/_posts/2026-09-30-pandey26a.md
  series: 'Proceedings of Machine Learning Research'
  container-title: 'Proceedings of the Fourth UK AI Conference 2026'
  publisher: 'PMLR'
  author: 
  - given: Anmol
    family: Pandey
  - given: Aditya
    family: Jain
  - given: Liang
    family: Chen
  - given: Carsten
    family: Maple
  - given: Christo
    family: Panchev
  editor: 
  - given: Alistair
    family: Benford
  - given: Baturalp
    family: Büyükateş
  - given: Christian
    family: Cabrera
  - given: Sarah
    family: Kiden
  - given: Arianna
    family: Salili-James
  - given: Vincent
    family: Zakka
  - given: Feng
    family: Zhou
  page: 134-147
  id: pandey26a
  issued:
    date-parts: 
      - 2026
      - 9
      - 30
  firstpage: 134
  lastpage: 147
  published: 2026-09-30 00:00:00 +0000
- title: 'Boundary-Uncertainty Active Learning for Efficient Segmentation of Robotic Performance Trajectories'
  abstract: 'Robotic art installations generate rich, high-frequency motion data during live performance, yet this data is rarely used by AI that could model, analyse or generatively reproduce the behaviours it captures. Performance recordings are unstructured, variable in length and arrive unlabelled, often requiring segmentation through manual segmentation that is prohibitive at scale. We present an active-learning pipeline that transforms raw recordings from Embrace Angels (2025-), an ongoing robotic art performative project in which a pair of Franka Panda arms embrace audience members, into a stage-segmented dataset suitable for future modelling. The pipeline combines an integrated annotation interface, self-supervised pretraining and a boundary-uncertainty acquisition function. We benchmark segmentation methods spanning zero-label baselines, classical template matching, window-based classical active learning with three base machine learning models and three neural sequence-model variants. A Temporal Convolutional Network (TCN) initialised from self-supervised pretraining achieves a boundary mean absolute error of 5.9 $\pm$ 0.9 seconds with a 76% reduction in annotation effort relative to fully manual labelling. Overall, active learning combined with self-supervised pretraining is particularly well suited to performance datasets where intra-class variability is high, class boundaries are inherently subjective and the marginal value of each additional labelled example can be extremely informative.'
  volume: 348
  URL: https://proceedings.mlr.press/v348/woodward26a.html
  PDF: https://raw.githubusercontent.com/mlresearch/v348/main/assets/woodward26a/woodward26a.pdf
  edit: https://github.com/mlresearch//v348/edit/gh-pages/_posts/2026-09-30-woodward26a.md
  series: 'Proceedings of Machine Learning Research'
  container-title: 'Proceedings of the Fourth UK AI Conference 2026'
  publisher: 'PMLR'
  author: 
  - given: Kieran
    family: Woodward
  - given: Gabriella
    family: Giannachi
  - given: Steve
    family: Benford
  editor: 
  - given: Alistair
    family: Benford
  - given: Baturalp
    family: Büyükateş
  - given: Christian
    family: Cabrera
  - given: Sarah
    family: Kiden
  - given: Arianna
    family: Salili-James
  - given: Vincent
    family: Zakka
  - given: Feng
    family: Zhou
  page: 148-158
  id: woodward26a
  issued:
    date-parts: 
      - 2026
      - 9
      - 30
  firstpage: 148
  lastpage: 158
  published: 2026-09-30 00:00:00 +0000
