<?xml version="1.0" encoding="utf-8" standalone="yes"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:xhtml="http://www.w3.org/1999/xhtml"><url><loc>https://www.michaelaerni.com/publication-type/1/</loc><lastmod>2026-01-28T07:58:02+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/memorization/</loc><lastmod>2026-01-28T07:58:02+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/</loc><lastmod>2026-01-28T07:58:02+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/publication/modal-aphasia/</loc><lastmod>2026-01-28T07:58:02+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/multimodal-language-models/</loc><lastmod>2026-01-28T07:58:02+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/publication_types/</loc><lastmod>2026-01-28T07:58:02+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/safety/</loc><lastmod>2026-01-28T07:58:02+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/tags/</loc><lastmod>2026-01-28T07:58:02+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/unified-representations/</loc><lastmod>2026-01-28T07:58:02+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/data-extraction/</loc><lastmod>2025-03-03T23:48:08+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/large-language-models/</loc><lastmod>2025-03-03T23:48:08+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/publication/measuring-non-adversarial-reproduction-of-training-data-in-large-language-models/</loc><lastmod>2025-03-03T23:48:08+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/originality/</loc><lastmod>2025-03-03T23:48:08+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/privacy/</loc><lastmod>2025-03-03T23:48:08+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/auditing/</loc><lastmod>2024-10-08T10:56:25+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/publication/evaluations-of-machine-learning-privacy-defenses-are-misleading/</loc><lastmod>2024-10-08T10:56:25+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/membership-inference/</loc><lastmod>2024-10-08T10:56:25+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/ml-privacy/</loc><lastmod>2024-10-08T10:56:25+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/benign-overfitting/</loc><lastmod>2026-01-28T07:58:02+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/deep-learning-theory/</loc><lastmod>2026-01-28T07:58:02+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/generalization-bounds/</loc><lastmod>2026-01-28T07:58:02+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/high-dimensional-statistics/</loc><lastmod>2026-01-28T07:58:02+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/non-parametric-regression/</loc><lastmod>2026-01-28T07:58:02+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/publication/strong-inductive-biases-provably-prevent-harmless-interpolation/</loc><lastmod>2026-01-28T07:58:02+01:00</lastmod></url><url><loc>https://www.michaelaerni.com/publication/interpolation-can-hurt-robust-generalization-even-when-there-is-no-noise/</loc><lastmod>2024-04-29T16:23:12+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/learning-theory/</loc><lastmod>2024-04-29T16:23:12+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/regularization/</loc><lastmod>2024-04-29T16:23:12+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/robustness/</loc><lastmod>2024-04-29T16:23:12+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/publication-type/8/</loc><lastmod>2021-08-15T22:59:34+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/adversarial-robustness/</loc><lastmod>2021-08-15T22:59:34+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/interpolation/</loc><lastmod>2021-08-15T22:59:34+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/ridge-regularization/</loc><lastmod>2021-08-15T22:59:34+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/publication/surprising-benefits-of-ridge-regularization-for-noiseless-regression/</loc><lastmod>2021-08-15T22:59:34+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/theory/</loc><lastmod>2021-08-15T22:59:34+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/adversarial-training/</loc><lastmod>2021-08-15T22:59:34+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/publication/maximizing-the-robust-margin-provably-overfits-on-noiseless-data/</loc><lastmod>2021-08-15T22:59:34+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/tag/robust-overfitting/</loc><lastmod>2021-08-15T22:59:34+02:00</lastmod></url><url><loc>https://www.michaelaerni.com/categories/</loc></url><url><loc>https://www.michaelaerni.com/publication/</loc><lastmod>2021-01-23T19:43:06+00:00</lastmod></url></urlset>