Biography

This page has a few more academic-ish biographies.

Name and Affiliation

Jonas Geiping (Dr. rer. nat.)
Hector Endowed ELLIS Fellow, ELLIS Institute Tübingen
Research Group Leader, Max Planck Institute for Intelligent Systems
Faculty Member, Tübingen AI Center, Tübingen, Germany

My affiliation is

Jonas Geiping, ELLIS Institute Tübingen & Max Planck Institute for Intelligent Systems, Tübingen AI Center

Our research group is called the Safety- and Efficiency-aligned Learning group (SEAL, 🦭).

My last name is Westphalian, so technically it splits as Geip-ing, but most other pronouncations, like ‘Guy-ping’, are fine as well. If you want to, a reasonably accurate way of saying my last name is 溉萍.


Bio Sketch

Jonas Geiping leads a joint research group at the ELLIS Institute Tübingen and the Max Planck Institute for Intelligent Systems, where he works on safety and efficiency in modern machine learning, with a particular focus on large language models. He is a Hector Endowed ELLIS Fellow, a faculty member of the Tübingen AI Center, and an ELLIS scholar. His work on watermarking for language models received an Outstanding Paper Award at ICML 2023, and he received the German Pattern Recognition Award of the DAGM in 2025. Before moving to Tübingen in 2023, he was a postdoctoral researcher at the University of Maryland, College Park.


Longer Bio

Jonas Geiping leads a joint research group at the ELLIS Institute Tübingen, where he holds a Hector Endowed ELLIS Fellowship, and at the Max Planck Institute for Intelligent Systems, where he is a research group leader. He is a faculty member of the Tübingen AI Center, where he also serves on its steering committee, and a member of the ELLIS society as an ELLIS scholar. Before moving to Tübingen in 2023, he was a postdoctoral researcher with Tom Goldstein at the University of Maryland, College Park. He received his PhD in computer science from the University of Siegen in 2021, advised by Michael Möller, and holds a bachelor’s and a master’s degree in mathematics from the University of Münster (WWU).

His research focuses on safety and efficiency in modern machine learning, with a particular emphasis on large language models. As such, his research group works on understanding how to construct safe intelligent systems and how to align machine learning with this goal, for example by understanding reasoning under uncertainty, self-knowledge, persona formation – and a number of related questions concerning the cybernetics of modern LLM-based systems. In particular, this work can often be described as constructive AI safety, as, aside from passive observation and evaluation of frontier models, it investigates whether models or systems could be designed in different ways to improve safety and to design strategies where intelligence and safety reinforce each other. This research helps us to understand in what areas we can expect feasible technical solutions that reduce harm.

Jonas’s earlier work has shown that gradient updates shared in federated learning (a decentralized learning protocol) can leak private information in image and text domains, especially under malicious-server threat models, that data poisoning attacks against industrial-scale image classification models (like Google’s Cloud AutoML platform) are feasible and that language models can be coerced into a wide range of adversarial behaviors beyond jailbreaking. He has also worked on democratizing model training under compute constraints, and investigates the implications of designing latent reasoning models that operate through depth recurrence. A recent preprint on multi-stream LLMs shows that language models can be post-trained to act as intelligent systems with multiple simultaneous I/O streams, with implications for efficiency and safety.

His research on watermarking (the hidden marking of machine-generated text) received an Outstanding Paper Award at ICML 2023, was covered by the New York Times, MIT Technology Review and Nature, and quoted in testimony before the U.S. Congress. Since August 2026, the EU AI Act in Article 50(2) requires providers of AI systems to watermark text outputs in a machine-readable format. In September 2025, he received the German Pattern Recognition Award from the DAGM (Deutsche Arbeitsgemeinschaft für Mustererkennung) for his “outstanding scientific contributions in the area of Understanding of Safety, Security, and Efficiency in Modern Pattern Recognition”. He and his research group have contributed to red-teaming exercises and incident reports for all major AI model providers (most recently OpenAI, Anthropic, Google and Meta, as part of the report ‘Stealing Reasoning Traces from Proprietary LLM APIs’).

He was recognized as an outstanding reviewer at NeurIPS 2022 and ICLR 2022, and has since served yearly as an Area Chair at the three machine learning conferences (ICLR, NeurIPS, and ICML), and as Experiment Chair on the organizing committee of NeurIPS 2025. He is also an occasional German-language commentator on AI for outlets including Tagesschau, Die Zeit, SWR, the Neue Zürcher Zeitung and other news organizations via the Science Media Center. In the summer of 2026, he taught AI safety and LLM Inference at the University of Tübingen.


Further Material