Tirth Joshi

I work on what machine learning models remember after you tell them to forget.

MS in Artificial Intelligence at Yeshiva University. Two papers at ECCV 2026, Best Poster at NSIA. Currently building production ML at A&A Coatings and uBuyFirst. Previously cross-chain routing at DZap and LLM infrastructure at ComputeLib.

Selected work tjoshi1@mail.yu.edu

Selected work

Three different systems. The same answer each time: removing information is not the same as it being gone.

  1. ECCV 2026Main conference

    Compositional Non-Face Re-Identification Pressure under Cumulative Vision Releases

    Vision privacy is assessed one release at a time, but identity survives that framing. Clothing, gait and scene context stay linkable and accumulate across dataset expansions, model checkpoints and metadata. We introduce vRPI, an Arimoto–Rényi measure of re-identification pressure, prove it only ever rises under cumulative release, and bridge it exactly to Bayes-optimal guessing probability. It tracks real re-identification success even after every face is removed.

  2. ECCV 2026U&ME workshop

    Unlearning Is Not Deletion: Auditing Residual Information in Released Vision Artifacts

    Unlearning is judged almost entirely on the model checkpoint. But deployed systems also ship embedding banks, class prototypes and retrieval indices, and editing a checkpoint cannot touch an artifact stored independently of it. Artifact Residual Risk audits what stays recoverable from those. On Market-1501 the result is stark: because retrieval encoders generalise, even retraining from scratch cannot remove an identity from the gallery. Unlearning the model is not deleting the data.

  3. AAAI-27Under review

    Prompt-Time Selective Semantic De-Identification for Medical LLMs

    Prompts sent to medical LLMs carry contextual detail that re-identifies patients even after standard redaction. A span-local transform types each span and edits only the flagged ones, keeping clinical text verbatim. It lands between Safe Harbor and aggressive redaction rather than beating both: less leakage than one, more preserved utility than the other. Deliberately not a free lunch, and the paper is explicit about where it costs.

Experience

Research and production, in parallel.

Tools Python · PyTorch · JAX · LangChain · Docker · gRPC · Neo4j · CUDA · Solidity

Research

The full record.

Four concurrent advisors at the Katz School, across privacy and re-identification, LLM security, graph methods for routing and planning, and topology applied to optimisation.

Accepted and published

Under review

Work in progress

Contact

Graduating December 2026, and looking for research and applied ML roles from January.

New York preferred. Work authorisation runs three years without sponsorship.

tjoshi1@mail.yu.edu LinkedIn GitHub