Alexander Warnecke

dblp:205/4365 · DBLP profile ↗
← Back
8ranked-venue papers
3as first author
5since 2021 · last 2025
0009-0006-3617-3968ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 Manipulating Feature Visualizations with Gradient Slingshots
abstract
Feature Visualization (FV) is a widely used technique for interpreting concepts learned by Deep Neural Networks (DNNs), which synthesizes input patterns that maximally activate a given feature. Despite its popularity, the trustworthiness of FV explanations has received limited attention. We introduce Gradient Slingshots, a novel method that enables FV manipulation without modifying model architecture or significantly degrading performance. By shaping new trajectories in off-distribution regions of a feature's activation landscape, we coerce the optimization process to converge to a predefined visualization. We evaluate our approach on several DNN architectures, demonstrating its ability to replace faithful FVs with arbitrary targets. These results expose a critical vulnerability: auditors relying solely on FV may accept entirely fabricated explanations. To mitigate this risk, we propose a straightforward defense and quantitatively demonstrate its effectiveness.
Dilyara Bareeva, Marina M.-C. Höhne, Alexander Warnecke, Lukas Pirch, Klaus-Robert Müller, Konrad Rieck, Sebastian Lapuschkin, Kirill Bykov
NeurIPS3
2024 Evil from Within: Machine Learning Backdoors Through Dormant Hardware Trojans
abstract
Backdoors pose a severe threat to machine learning, as they can compromise the integrity of security-critical systems, such as self-driving cars. While different defenses have been proposed to address this threat, they all rely on the assumption that the hardware accelerator executing a learning model is trusted. This paper challenges this assumption and investigates a backdoor attack that completely resides within such an accelerator. Outside of the hardware, neither the learning model nor the software is manipulated so that current defenses fail. As memory on a hardware accelerator is limited, we utilize minimal backdoors that deviate from the original model by a few model parameters only. To mount the backdoor, we develop a hardware trojan that lays dormant until it is programmed after in-field deployment. The trojan can be provisioned with the minimal backdoor and performs a parameter replacement only when the target model is processed. We demonstrate the feasibility of our attack by implanting our hardware trojan into a commercial machine-learning accelerator and programming it with a minimal backdoor for a traffic-sign recognition system. The backdoor affects only 30 model parameters (0.069%) with a backdoor trigger covering 6.25% of the input image, yet it reliably manipulates the recognition once the input contains a backdoor trigger. Our attack expands the circuit size of the accelerator by only 0.24% and does not increase the run-time, rendering detection hardly possible. Given the distributed hardware manufacturing process, our work points to a new threat in machine learning that currently eludes security mechanisms.
Alexander Warnecke, Julian Speith, Jan-Niklas Möller, Konrad Rieck, Christof Paar
ACSAC1
2023 Machine Unlearning of Features and Labels
Alexander Warnecke, Lukas Pirch, Christian Wressnegger, Konrad Rieck
NDSS1
2022 State of Health Estimation of Lithium-Ion Batteries for Dynamic Driving Profiles Based on Feature Extraction from Battery Relaxation Time Using Machine Learning
abstract
The state of health (SOH) of lithium-ion battery is very crucial in accessing the performance of electric vehicle (EV) as it is the indicator of degraded battery capacity or increased internal resistance over time. In the recent years, the machine learning based SOH estimation has garnered much attention due to the complex and nonlinear nature of battery ageing process. In this paper, five Health Indicators (HIs) are extracted from the battery data, which are both convenient and feasible to be extracted in real-time driving conditions. Based on the utmost practicality, a novel HI ‘Deviational Voltage over Relaxation Time (DVR)’ fed to Gaussian Process Regression (GPR) network is used to evaluate the estimation performance in potential real usage using NASA battery dataset. The results show that DVR correctly captured the battery ageing phenomena and provides superior estimation performance in terms of computational time and accuracy.
Nitika Ghosh, Akhil Garg 0002, Alexander Warnecke, Bijaya K. Panigrahi
IECON3
2022 Dos and Don'ts of Machine Learning in Computer Security
Daniel Arp, Erwin Quiring, Feargus Pendlebury, Alexander Warnecke, Fabio Pierazzi, Christian Wressnegger, Lorenzo Cavallaro, Konrad Rieck
USENIX Security Symposium4
2020 Detecting Various Road Damage Types in Global Countries Utilizing Faster R-CNN
abstract
Road damages are of great interest for federal road authorities and their infrastructure management as well as the automated driving task and thus safety and comfort of vehicle occupants. Therefore, we are investigating the automatic detection of different types of road damages by images from a front-facing camera in the vehicle. The data basis of our work is provided by the ’IEEE BigData Cup Challenge’ and its dataset ’RDD-2020’ with a large number of labelled images from Japan, India and the Czech Republic. Our Deep Learning approach utilizes the pre-trained Faster Region Based Convolutional Neural Networks (R-CNN). In the first step, we classify the destination of the image followed by expert networks for each region. Between the explanation of our applied Deep Learning methodology, some remaining sources of errors are discussed and further, partly failed approaches during our development period are displayed, which could be of interest for future work. Our results are convincing and we are able to achieve an F1 score of 0.487 across all regions for longitudinal and lateral cracks, alligator cracks and potholes.
Felix Kortmann, Kevin Talits, Pascal Fassmeyer, Alexander Warnecke, Nicolas Meier, Jens Heger, Paul Drews, Burkhardt Funk
IEEE BigData4
2020 Evaluating Explanation Methods for Deep Learning in Security
abstract
Deep learning is increasingly used as a building block of security systems. Unfortunately, neural networks are hard to interpret and typically opaque to the practitioner. The machine learning community has started to address this problem by developing methods for explaining the predictions of neural networks. While several of these approaches have been successfully applied in the area of computer vision, their application in security has received little attention so far. It is an open question which explanation methods are appropriate for computer security and what requirements they need to satisfy. In this paper, we introduce criteria for comparing and evaluating explanation methods in the context of computer security. These cover general properties, such as the accuracy of explanations, as well as security-focused aspects, such as the completeness, efficiency, and robustness. Based on our criteria, we investigate six popular explanation methods and assess their utility in security systems for malware detection and vulnerability discovery. We observe significant differences between the methods and build on these to derive general recommendations for selecting and applying explanation methods in computer security.
Alexander Warnecke, Daniel Arp, Christian Wressnegger, Konrad Rieck
EuroS&P1
2020 Applying Quarter-Vehicle Model Simulation for Road Elevation Measurements Utilizing the Vehicle Level Sensor
abstract
In the past years, automated driving has become one of the most important research fields in the automotive industry. A key component for a successful substitution of human driving by vehicles is a real-time model of the current environment including the traffic situation, the guide-way, and the road itself. Although, most of the information for the environment model are provided via in-vehicle generated data based on camera, LIDAR, and RADAR sensors, we propose a solution of classifying road quality within the spring-damper system of the vehicle. In this paper, we utilize the Vehicle Level Sensor (VLS), which is a standard component in modern vehicles, for road condition assessment. We present a simulation of the Quarter Vehicle Model (QVM) for road elevation measurement to enable each connected vehicle to provide valid data for a potential crowd sensing approach where every vehicle contributes data for past and consumes data for upcoming segments. The generated data is capable of providing the environment model with real-time data of upcoming road segments. The simulation results are validated on a test bench including a review of the errors.
Felix Kortmann, Malte Rodeheger, Alexander Warnecke, Nicolas Meier, Jens Heger, Burkhardt Funk, Paul Drews
VTC Fall3