People / Christian Schroeder de Witt

Christian Schroeder de Witt
Founder and PI. Associate Professor, University of Oxford
Incoming Associate Professor of AI and Information Security, UCL Computer Science and UCL AI Centre, from October 2026
Christian founded Witt Lab to study multi-agent security: what becomes of security when the parties to a system are learned agents that reason, communicate and pursue goals. He holds an EPSRC Open Fellowship, a Royal Academy of Engineering Research Fellowship and a Schmidt Sciences AI2050 Early Career Fellowship. He joins UCL in October 2026 from the University of Oxford, where he is Associate Professor and founded the lab in the Department of Engineering Science. He holds a DPhil in Engineering Science from Oxford, supervised by Philip Torr and Shimon Whiteson, on communication and coordination in deep multi-agent reinforcement learning. He has been a visiting researcher at Mila with Yoshua Bengio and at Lawrence Livermore National Laboratory, a UK Intelligence Community Research Fellow, and Stipendiary Lecturer in Computer Science at St Catherine's College, Oxford. He designed and lectures Superintelligence: What do we actually know? at the Oxford AIMS CDT, lead-organised the Multi-Agent Security workshops at NeurIPS 2023 and DAI 2025, and is an Area Chair for NeurIPS 2026.
Interests
Education
DPhil in Engineering Science, University of Oxford
Publications with the lab
Full publication list on Google Scholar.
- 2026Architecture Matters for Multi-Agent SecurityB. Hagag, W. L. Anderson, C. Schroeder de Witt, S. SchefflerICML 2026Paper
- 2026Tool Use Enables Undetectable Steganography in Multi-Agent LLM SystemsJ. L. Rippin, S. C. Marshall, D. D. Africa, C. Schroeder de WittarXiv preprint 2606.28425Paper
- 2026Detecting Multi-Agent Collusion Through Multi-Agent InterpretabilityA. Rose, C. Cullen, S. Abdelnabi, P. Torr, B. G. Kaplowitz, C. Schroeder de WittarXiv preprint 2604.01151Paper
- 2026
- 2026Chronos: The AI Co-HistorianL. Hufe, N. Griesshaber, G. Greif, S. O. Eck, P. Francois, W. Samek, C. Schroeder de Witt, and othersarXiv preprint 2604.03553Paper
- 2026Spatial Generalization Tests for Machine Learning-based Weather Models to Assess Physical ConsistencyM. Höver, M. Klöwer, C. Schroeder de Witt, H. M. ChristensenarXiv preprint; abstract at EGU 2026Paper
- 2026Exploring the Cryptographic Limits of Transformer NetworksS. Domunco, A. Draguns, P. Torr, I. Robinson, C. Schroeder de WittarXiv preprint 2606.29389Paper
- 2026A Low-Rank Subspace Analysis of LLM InterventionsA. Sharma, C. Schroeder de Witt, P. Torr, A. Calinescu, J. YuarXiv preprint 2606.14388Paper
- 2026When Language Representations Interact: Separability and Cross-Lingual Effects in LLMsB. Marinov, A. Sharma, C. Schroeder de Witt, P. Torr, A. Calinescu, J. YuarXiv preprint; workshop version at CoLoRAI, ICML 2026Paper
- 2026Multimodal Model Diffing for Feature Discovery and ControlH. Batra, L. Naghashyar, A. Khakzar, P. Torr, R. Clark, C. Schroeder de Witt, C. VenhoffarXiv preprint; workshop version at AI4GOOD, ICML 2026Paper
- 2026Towards Understanding Multimodal Fine-Tuning: Spatial FeaturesL. Naghashyar, H. Batra, A. Khakzar, P. Torr, R. Clark, C. Schroeder de Witt, C. VenhoffarXiv preprint 2602.08713Paper
- 2026Entangled Representations Amplify Collateral Damage in UnlearningE. Wybitul, T. G. J. Rudner, C. Schroeder de WittarXiv preprint 2609.02285Paper
- 2026OpenSanctions Pairs: Large-Scale Entity Matching with LLMsC. Smith, M. Sesodia, F. Lindenberg, C. Schroeder de Witt, and othersarXiv preprint 2603.11051Paper
- 2026PerturbAgent: An Agentic AI System for Analysis and Prediction of Genetic PerturbationsK. Pei, S. Qu, P. Torr, J. G. Hedley, C. Schroeder de WittSecond Workshop on XAI4Science, 2026
- 2026LLM-guided Acquisition for Pathway-specific Perturb-seq Design under Experimental BudgetsM. Aiyar, K. Pei, S. Qu, P. Torr, C. Schroeder de Witt, W. J. Bolton, J. G. HedleyWorkshop on Generative and Agentic AI for Biology, 2026
- 2026AI Models Can Provably Hide Arbitrary CapabilitiesA. Draguns, S. R. Motwani, R. Douglas, C. Schroeder de WittPreprint
- 2026h1: Bootstrapping LLMs to Reason over Longer Horizons via Reinforcement LearningA. Ivanova*, S. R. Motwani*, Z. Cai, P. Torr, R. Islam, S. Shah, C. Schroeder de Witt†, Charlie London (* equal contribution, † joint supervision)ICML 2026Paper
- 2026Rubric Curriculum RL: Exploiting the Generation-Verification Gap in Non-Verifiable DomainsT. Krishnan*, S. R. Motwani*, C. London, S. M. Bhat, H. Jiao, P. Torr, R. Islam, C. Summerfield, C. Schroeder de Witt, Q. Gu, S. Shah (* equal contribution)ICML 2026
- 2026Vet Your Agent: Towards Host-independent Autonomy via Verifiable Execution TracesA. Grigor, C. Schroeder de Witt, S. Birnbach, I. MartinovicACM ASIA CCS 2026
- 2026Delta-Influence: Unlearning Poisons via Influence FunctionsW. Li, J. Li, P. Zeng, C. Schroeder de Witt, A. Prabhu, A. SanyalTransactions on Machine Learning ResearchPaper
- 2026Fact-checking with Contextual Narratives: Leveraging Retrieval-augmented LLMs for Social Media AnalysisA. U. Dey, M. J. Awan, G. Channing, C. Schroeder de Witt, J. CollomosseIEEE Transactions on Computational Social Systems
- 2025PSyDUCK: Hiding Information in the Denoising Process of Latent Diffusion ModelsA. Mahfuz, G. Channing, M. van der Wilk, P. H. S. Torr, F. Pizzati, C. Schroeder de WittIEEE WIFS 2025Paper
- 2025Multi-Agent Security Tax: Trading Off Security and Collaboration Capabilities in Multi-Agent SystemsP. Peigné, M. Kniejski, F. Sondej, M. David, J. Hoelscher-Obermaier, C. Schroeder de Witt, E. KranAAAI 2025Paper
- 2025Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI AgentsC. Schroeder de Witt, K. Krawiecka, I. Krawczuk, B. Hagag, and othersarXiv preprint 2505.02077Paper
- 2025MALT: Improving Reasoning with Multi-Agent LLM TrainingS. R. Motwani, C. Smith, R. J. Das, R. Rafailov, I. Laptev, P. H. S. Torr, F. Pizzati, R. Clark, C. Schroeder de WittCOLM 2025Paper
- 2025Fundamental Limitations in Pointwise Defences of LLM Finetuning APIsX. Davies, E. Winsor, A. Souly, T. Korbak, R. Kirk, C. Schroeder de Witt, Y. GalNeurIPS 2025Paper
- 2025AnnoCaseLaw: A Richly-annotated Dataset for Benchmarking Explainable Legal Judgment PredictionM. Sesodia, A. Petrova, J. Armour, T. Lukasiewicz, C. Schroeder de Witt, and othersarXiv preprint 2503.00128Paper
- 2025Mixture of Experts Made Intrinsically InterpretableX. Yang, C. Venhoff, A. Khakzar, C. Schroeder de Witt, P. K. Dokania, A. Bibi, P. TorrarXiv preprint 2503.07639Paper
- 2025REAL: Benchmarking Autonomous Agents on Deterministic Simulations of Real WebsitesD. Garg, D. Caples, A. Draguns, N. Ravi, P. Putta, N. Garg, P. Hebbar, and others, C. Schroeder de Witt, S. MotwaniNeurIPS 2025Paper
- 2025Architecting Resilient LLM Agents: A Guide to Secure Plan-then-Execute ImplementationsR. F. Del Rosario, K. Krawiecka, C. Schroeder de WittarXiv preprint 2509.08646Paper
- 2025Extending the OWASP Multi-Agentic System Threat Modeling Guide: Insights from Multi-Agent Security ResearchK. Krawiecka, C. Schroeder de WittarXiv preprint 2508.09815Paper
- 2025Predicting Weak-to-Strong Generalization from Latent RepresentationsB. Wilop, C. Schroeder de Witt, Y. Gal, P. Torr, C. VenhoffPreprint
- 2025DEEDEE: Fast and Scalable Out-of-Distribution Dynamics DetectionT. Aljaafari, V. Kanade, P. Torr, C. Schroeder de WittarXiv preprint 2510.21638Paper
- 2025Testing the Limits of the World's Largest Control Task: Solar Geoengineering as a Deep Reinforcement Learning ProblemE. Agrawal, C. Schroeder de WittGeoengineering and Climate Change: Methods, Risks, and Governance (Wiley, 2025)
- 2024Illusory Attacks: Information-Theoretic Detectability Matters in Adversarial AttacksT. Franzmeyer, S. M. McAleer, J. F. Henriques, J. N. Foerster, P. Torr, A. Bibi, C. Schroeder de WittICLR 2024, SpotlightPaper
- 2024Secret Collusion among AI Agents: Multi-Agent Deception via SteganographyS. R. Motwani, M. Baranchuk, M. Strohmeier, V. Bolina, P. H. S. Torr, L. Hammond, C. Schroeder de WittNeurIPS 2024Paper
- 2024Unelicitable Backdoors in Language Models via Cryptographic Transformer CircuitsA. Draguns*, A. Gritsevskiy*, S. R. Motwani, C. Rogers-Smith, J. Ladish, C. Schroeder de Witt (* equal contribution)NeurIPS 2024Paper
- 2024Computing Low-Entropy Couplings for Large-Support DistributionsS. Sokota, D. Sam, C. Schroeder de Witt, S. Compton, J. Foerster, J. Z. KolterUAI 2024Paper
- 2024Rethinking Out-of-Distribution Detection for Reinforcement Learning: Advancing Methods for Evaluation and DetectionL. Nasvytis, K. Sandbrink, J. Foerster, T. Franzmeyer, C. Schroeder de WittAAMAS 2024, OralPaper
- 2024Position: Near to Mid-term Risks and Opportunities of Open-Source Generative AIF. Eiras, A. Petrov, B. Vidgen, C. Schroeder de Witt, F. Pizzati, K. Elkins, and othersICML 2024Paper
- 2024Risks and Opportunities of Open-Source Generative AIF. Eiras, A. Petrov, B. Vidgen, C. Schroeder de Witt, F. Pizzati, K. Elkins, and othersarXiv preprint 2405.08597Paper
- 2024IDs for AI SystemsA. Chan, N. Kolt, P. Wills, U. Anwar, C. Schroeder de Witt, N. Rajkumar, L. Hammond, D. Krueger, L. Heim, M. AnderljungarXiv preprint 2406.12137Paper
- 2025Hidden in Plain Text: Emergence and Mitigation of Steganographic Collusion in LLMsY. Mathew, O. Matthews, R. McCarthy, J. Velja, C. Schroeder de Witt, D. Cope, and othersIJCNLP 2025. Social Impact AwardPaper
- 2024Comparative Global AI Regulation: Policy Perspectives from the EU, China, and the USJ. Chun, C. Schroeder de Witt, K. ElkinsarXiv preprint 2410.21279Paper
- 2025LLM-Consensus (formerly MAD-Sherlock): Multi-Agent Debate for Visual Misinformation DetectionK. Lakara, G. Channing, J. Sock, C. Rupprecht, P. Torr, J. Collomosse, C. Schroeder de WittCFAgentic Workshop, ICML 2025. Oral and Best Paper AwardPaper
- 2024Toward Robust Real-World Audio Deepfake Detection: Closing the Explainability GapG. Channing, J. Sock, R. Clark, P. Torr, C. Schroeder de WittarXiv preprint 2410.07436Paper
- 2024SAGE: Scalable Ground Truth Evaluations for Large Sparse AutoencodersC. Venhoff, A. Calinescu, P. Torr, C. Schroeder de WittarXiv preprint 2410.07456Paper
- 2024The Danger of Arrogance: Welfare Equilibria as a Solution to Stackelberg Self-Play in Non-Coincidental GamesJ. Levi, C. Lu, T. Willi, C. Schroeder de Witt, J. FoersterarXiv preprint 2402.01088Paper
- 2024Can Reinforcement Learning Model Learning across Development? Online Lifelong Learning through Adaptive Intrinsic MotivationK. J. Sandbrink, B. Christian, L. M. Nasvytis, C. Schroeder de Witt, P. ButlinProceedings of the Annual Meeting of the Cognitive Science Society 46
- 2024Using Adaptive Intrinsic Motivation in RL to Model Learning across DevelopmentK. J. Sandbrink, B. Christian, L. Nasvytis, C. Schroeder de Witt, P. ButlinIntrinsically Motivated and Open-Ended Learning Workshop, NeurIPS 2024
- 2024Proofs of Autonomy: Scalable and Practical Verification of AI AutonomyA. Grigor, C. Schroeder de Witt, I. MartinovicICML Workshop on Technical AI Governance, 2024
- 2025Efficient Dictionary Learning with Switch Sparse AutoencodersA. Mudide, J. Engels, E. J. Michaud, M. Tegmark, C. Schroeder de WittICLR 2025Paper
- 2023Perfectly Secure Steganography Using Minimum Entropy CouplingC. Schroeder de Witt*, S. Sokota*, J. Z. Kolter, J. N. Foerster, M. Strohmeier (* equal contribution)ICLR 2023. Covered by Scientific American, Quanta Magazine and Bruce SchneierPaper
- 2023Cheap Talk Discovery and Utilization in Multi-Agent Reinforcement LearningY. L. Lo, C. Schroeder de Witt, S. Sokota, J. N. Foerster, S. WhitesonICLR 2023
- 2024Bayesian Exploration NetworksM. Fellows, B. Kaplowitz, C. Schroeder de Witt, S. WhitesonICML 2024Paper
- 2022Communicating via Markov Decision ProcessesS. Sokota, C. Schroeder de Witt, M. Igl, L. M. Zintgraf, P. Torr, M. Strohmeier, Z. Kolter, S. Whiteson, J. FoersterICML 2022Paper
- 2022Equivariant Networks for Zero-Shot CoordinationD. Muglich, C. Schroeder de Witt, E. van der Pol, S. Whiteson, J. FoersterNeurIPS 2022Paper
- 2022Discovered Policy OptimisationC. Lu, J. Kuba, A. Letcher, L. Metz, C. Schroeder de Witt, J. FoersterNeurIPS 2022Paper
- 2022
- 2022Mirror Learning: A Unifying Framework of Policy OptimisationJ. G. Kuba, C. Schroeder de Witt, J. FoersterICML 2022Paper
- 2022Generalized Beliefs for Cooperative AID. Muglich, L. M. Zintgraf, C. Schroeder de Witt, S. Whiteson, J. FoersterICML 2022Paper
- 2022Amortized Rejection Sampling in Universal Probabilistic ProgrammingS. Naderiparizi, A. Ścibior, A. Munk, M. Ghadiri, A. G. Baydin, B. Gram-Hansen, C. Schroeder de Witt, R. Zinkov, P. Torr, T. Rainforth, Y. W. Teh, F. WoodAISTATS 2022
- 2022Revealing Robust Oil and Gas Company Macro-Strategies Using Deep Multi-Agent Reinforcement LearningD. Radovic, L. Kruitwagen, C. Schroeder de Witt, B. Caldecott, S. Tomlinson, M. WolfarXiv preprint 2211.11043Paper
- 2021FACMAC: Factored Multi-Agent Centralised Policy GradientsB. Peng, T. Rashid, C. Schroeder de Witt, P. A. Kamienny, P. Torr, W. Böhmer, S. WhitesonNeurIPS 2021Paper
- 2021Randomized Entity-wise Factorization for Multi-Agent Reinforcement LearningS. Iqbal, C. Schroeder de Witt, B. Peng, W. Böhmer, S. Whiteson, F. ShaICML 2021Paper
- 2021RainBench: Towards Data-Driven Global Precipitation Forecasting from Satellite ImageryC. Schroeder de Witt, C. Tong, V. Zantedeschi, D. De Martini, A. Kalaitzis, M. Chantry, D. Watson-Parris, P. BilinskiAAAI 2021Paper
- 2021Fixed Points in Cyber Space: Rethinking Optimal Evasion Attacks in the Age of AI-NIDSY. Huang, C. Schroeder de Witt, P. H. S. Torr, M. StrohmeierarXiv preprint 2111.12197Paper
- 2021Coordination and Communication in Deep Multi-Agent Reinforcement LearningC. Schroeder de WittDPhil thesis, University of Oxford
- 2020Monotonic Value Function Factorisation for Deep Multi-Agent Reinforcement LearningT. Rashid, M. Samvelyan, C. Schroeder de Witt, G. Farquhar, J. Foerster, S. WhitesonJournal of Machine Learning Research 21Paper
- 2020Is Independent Learning All You Need in the StarCraft Multi-Agent Challenge?C. Schroeder de Witt, T. Gupta, D. Makoviichuk, V. Makoviychuk, P. H. S. Torr, M. Sun, S. WhitesonarXiv preprint 2011.09533Paper
- 2020Deep Multi-Agent Reinforcement Learning for Decentralized Continuous Cooperative ControlC. Schroeder de Witt, B. Peng, P. A. Kamienny, P. Torr, W. Böhmer, S. WhitesonarXiv preprint 2003.06709Paper
- 2020Towards Data-Driven Physics-Informed Global Precipitation Forecasting from Satellite ImageryV. Zantedeschi, D. De Martini, C. Tong, C. Schroeder de Witt, A. Kalaitzis, M. Chantry, D. Watson-ParrisAI for Earth Sciences Workshop, NeurIPS 2020
- 2020Artificial Intelligence and Climate Change: Supplementary Impact ReportT. Walsh, A. Evatt, C. Schroeder de WittReport
- 2019The StarCraft Multi-Agent ChallengeM. Samvelyan, T. Rashid, C. Schroeder de Witt, G. Farquhar, N. Nardelli, T. G. J. Rudner, C. M. Hung, P. H. S. Torr, J. Foerster, S. WhitesonAAMAS 2019Paper
- 2019Multi-Agent Common Knowledge Reinforcement LearningC. Schroeder de Witt, J. Foerster, G. Farquhar, P. Torr, W. Böhmer, S. WhitesonNeurIPS 2019Paper
- 2019Stratospheric Aerosol Injection as a Deep Reinforcement Learning ProblemC. Schroeder de Witt, T. HornigoldTackling Climate Change with Machine Learning Workshop, ICML 2019. Best Idea AwardPaper
- 2019Hijacking Malaria Simulators with Probabilistic ProgrammingB. Gram-Hansen, C. Schroeder de Witt, T. Rainforth, P. H. S. Torr, Y. W. Teh, A. G. BaydinAI for Social Good Workshop, ICML 2019Paper
- 2015Safe Screening for Support Vector MachinesJ. Zimmert, C. Schroeder de Witt, G. Kerg, M. KloftOPT Workshop, NIPS 2015
- 2014The ZX-Calculus is Incomplete for Quantum MechanicsC. Schroeder de Witt, V. ZamdzhievQuantum Physics and Logic (QPL) 2014Paper