M. Bilgehan Ertan

PhD Student in AI Safety & Privacy, CWI Amsterdam

prof_pic.jpg

Amsterdam, Netherlands

I am Murat Bilgehan Ertan, a researcher at the intersection of AI safety, privacy, and machine learning, currently pursuing my PhD at CWI (Centrum Wiskunde & Informatica) in Amsterdam under the supervision of Prof. Marten van Dijk.

I hold a BSc in Computer Science and Engineering from Sabancı University, Türkiye, and an MSc in Computer Security (cum laude) from Vrije Universiteit Amsterdam. Beyond my academic research, I have professional experience as a Security Researcher and Developer at PRODAFT.

My research focuses on building safe, secure, and privacy-preserving AI systems, combining theoretical analysis with practical engineering. I study how information leaks and adversarial behavior arise in modern AI, developing formal frameworks based on Differential Privacy, f-DP, and PAC privacy to understand and bound these effects. More recently, my work has expanded from privacy toward the broader question of AI safety. Together with Prof. Srini Devadas at MIT, I study certified defenses against data poisoning in LLM post-training, as well as the safety of agentic systems. In parallel, I work on adversarial and membership inference attacks on large language models to evaluate and strengthen their real-world resilience.

I’m broadly interested in how we can make AI systems safe, secure, and private while remaining practically useful.

selected publications

  1. IEEE S&P
    beyond-stop-signs.png
    Beyond Stop Signs: Why Evasion Attacks Matter Even More
    Kaleel Mahmood, Murat Bilgehan Ertan, and Marten van Dijk
    IEEE Security & Privacy, 2026
  2. Preprint
    paczero.png
    PACZero: PAC-Private Fine-Tuning of Language Models via Sign Quantization
    Murat Bilgehan Ertan, Xiaochen Zhu, Phuong Ha Nguyen, Marten van Dijk, and Srinivas Devadas
    Accepted at NeurIPS’26 (poster), 2026
  3. Preprint
    fundamental-dpsgd.png
    Fundamental Limitations of Favorable Privacy-Utility Guarantees for DP-SGD
    Murat Bilgehan Ertan and Marten van Dijk
    Accepted at ACM CCS 2026, 2026
  4. Preprint
    evidentiary-limits.png
    On the Evidentiary Limits of Membership Inference for Copyright Auditing
    Murat Bilgehan Ertan, Emirhan Böge, Min Chen, Kaleel Mahmood, and Marten van Dijk
    CoRR, 2026