EDBT 2026 Demo / reviewers in the wild / expert
Janis Keuper
dblp:04/6578 · also Janis Fehr
· DBLP profile ↗
21ranked-venue papers
4as first author
14since 2021 · last 2026
0000-0002-1327-1243ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 21 · 4 first-author · 14 since 2021Graphics, computer vision, multimedia, augmented reality and games · 14 · 4 first-author · 7 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Benchmarking Document Parsers on Mathematical Formula Extraction from PDFs
Pius Horn, Janis Keuper |
ICPR (2) | 2 |
| 2026 | Prompt Injection Attacks on LLM Generated Reviews of Scientific Publications
Janis Keuper |
ICPR (1) | 1 |
| 2025 | PhysicsGen: Can Generative Models Learn from Images to Predict Complex Physical Relations?abstractThe image-to-image translation abilities of generative learning models have recently made significant progress in the estimation of complex (steered) mappings between image distributions. While appearance based tasks like image in-painting or style transfer have been studied at length, we propose to investigate the potential of generative models in the context of physical simulations. Providing a dataset of 300k image-pairs and baseline evaluations for three different physical simulation tasks, we propose a benchmark to investigate the following research questions: i) are generative models able to learn complex physical relations from input-output image pairs? ii) what speedups can be achieved by replacing differential equation based simulations? While baseline evaluations of different current models show the potential for high speedups (ii), these results also show strong limitations toward the physical correctness (i). This underlines the need for new methods to enforce physical correctness. Data, baseline models and evaluation code: http://www.physics-gen.org. Martin Spitznagel, Jan Vaillant, Janis Keuper |
CVPR | 3 |
| 2025 | Can We Talk Models Into Seeing the World Differently?abstractUnlike traditional vision-only models, vision language models (VLMs) offer an intuitive way to access visual content through language prompting by combining a large language model (LLM) with a vision encoder. However, both the LLM and the vision encoder come with their own set of biases, cue preferences, and shortcuts, which have been rigorously studied in uni-modal models. A timely question is how such (potentially misaligned) biases and cue preferences behave under multi-modal fusion in VLMs.
As a first step towards a better understanding, we investigate a particularly well-studied vision-only bias - the texture vs. shape bias and the dominance of local over global information.
As expected, we find that VLMs inherit this bias to some extent from their vision encoders. Surprisingly, the multi-modality alone proves to have important effects on the model behavior, i.e., the joint training and the language querying change the way visual cues are processed.
While this direct impact of language-informed training on a model's visual perception is intriguing, it raises further questions on our ability to actively steer a model's output so that its prediction is based on particular visual cues of the user's choice.
Interestingly, VLMs have an inherent tendency to recognize objects based on shape information, which is different from what a plain vision encoder would do. Further active steering towards shape-based classifications through language prompts is however limited. In contrast, active VLM steering towards texture-based decisions through simple natural language prompts is often more successful. Paul Gavrikov, Jovita Lukasik, Steffen Jung 0001, Robert Geirhos, Muhammad Jehanzeb Mirza, Margret Keuper, Janis Keuper |
ICLR | 7 |
| 2025 | Reliable Evaluation of Attribution Maps in CNNs: A Perturbation-Based ApproachabstractAbstract In this paper, we present an approach for evaluating attribution maps, which play a central role in interpreting the predictions of convolutional neural networks (CNNs). We show that the widely used insertion/deletion metrics are susceptible to distribution shifts that affect the reliability of the ranking. Our method proposes to replace pixel modifications with adversarial perturbations, which provides a more robust evaluation framework. By using smoothness and monotonicity measures, we illustrate the effectiveness of our approach in correcting distribution shifts. In addition, we conduct the most comprehensive quantitative and qualitative assessment of attribution maps to date. Introducing baseline attribution maps as sanity checks, we find that our metric is the only contender to pass all checks. Using Kendall’s $$\tau $$ τ rank correlation coefficient, we show the increased consistency of our metric across 15 dataset-architecture combinations. Of the 16 attribution maps tested, our results clearly show SmoothGrad to be the best map currently available. This research makes an important contribution to the development of attribution maps by providing a reliable and consistent evaluation framework. To ensure reproducibility, we will provide the code along with our results. Lars Nieradzik, Henrike Stephani, Janis Keuper |
Int. J. Comput. Vis. | 3 |
| 2024 | Can Biases in ImageNet Models Explain Generalization?abstractThe robust generalization of models to rare, in-distribution (ID) samples drawn from the long tail of the training distribution and to out-of-training-distribution (OOD) samples is one of the major challenges of current deep learning methods. For image classification, this man-ifests in the existence of adversarial attacks, the performance drops on distorted images, and a lack of generalization to concepts such as sketches. The current under-standing of generalization in neural networks is very lim-ited, but some biases that differentiate models from human vision have been identified and might be causing these lim-itations. Consequently, several attempts with varying success have been made to reduce these biases during training to improve generalization. We take a step back and sanity-check these attempts. Fixing the architecture to the well-established ResNet-50, we perform a large-scale study on 48 ImageNet models obtained via different training methods to understand how and if these biases - including shape bias, spectral biases, and critical bands - interact with generalization. Our extensive study results reveal that contrary to previous findings, these biases are insufficient to accu-rately predict the generalization of a model holistically. We provide access to all checkpoints and evaluation code at https://github.com/paulgavrikov/biases_vs_generalization/. Paul Gavrikov, Janis Keuper |
CVPR | 2 |
| 2024 | Adversarial Examples are Misaligned in Diffusion Model ManifoldsabstractIn recent years, diffusion models (DMs) have drawn significant attention for their success in approximating data distributions, yielding state-of-the-art generative results. Nevertheless, the versatility of these models extends beyond their generative capabilities to encompass various vision applications, such as image inpainting, segmentation, adversarial robustness, among others. This study is dedicated to the investigation of adversarial attacks through the lens of diffusion models. However, our objective does not involve enhancing the adversarial robustness of image classifiers. Instead, our focus lies in utilizing the diffusion model to detect and analyze the anomalies introduced by these attacks on images. To that end, we systematically examine the alignment of the distributions of adversarial examples when subjected to the process of transformation using diffusion models. The efficacy of this approach is assessed across CIFAR-10 and ImageNet datasets, including varying image sizes in the latter. The results demonstrate a notable capacity to discriminate effectively between benign and attacked images, providing compelling evidence that adversarial instances do not align with the learned manifold of the DMs. Peter Lorenz, Ricard Durall, Janis Keuper |
IJCNN | 3 |
| 2022 | CNN Filter DB: An Empirical Investigation of Trained Convolutional FiltersabstractCurrently, many theoretical as well as practically relevant questions towards the transferability and robustness of Convolutional Neural Networks (CNNs) remain unsolved. While ongoing research efforts are engaging these problems from various angles, in most computer vision related cases these approaches can be generalized to investigations of the effects of distribution shifts in image data. In this context, we propose to study the shifts in the learned weights of trained CNN models. Here we focus on the properties of the distributions of dominantly used 3×3 convolution filter kernels. We collected and publicly provide a dataset with over 1.4 billion filters from hundreds of trained CNNs, using a wide range of datasets, architectures, and vision tasks. In a first use case of the proposed dataset, we can show highly relevant properties of many publicly available pre-trained models for practical applications: I) We analyze distribution shifts (or the lack thereof) between trained filters along different axes of meta-parameters, like visual category of the dataset, task, architecture, or layer depth. Based on these results, we conclude that model pre-training can succeed on arbitrary datasets if they meet size and variance conditions. II) We show that many pre-trained models contain degenerated filters which make them less robust and less suitable for fine-tuning on target applications. Data & Project website: https://github.com/paulgavrikov/cnn-filter-db. Paul Gavrikov, Janis Keuper |
CVPR | 2 |
| 2022 | FrequencyLowCut Pooling - Plug and Play Against Catastrophic Overfitting
Julia Grabinski, Steffen Jung 0001, Janis Keuper, Margret Keuper |
ECCV (14) | 3 |
| 2022 | Robust Models are less Over-ConfidentabstractDespite the success of convolutional neural networks (CNNs) in many academic benchmarks for computer vision tasks, their application in the real-world is still facing fundamental challenges. One of these open problems is the inherent lack of robustness, unveiled by the striking effectiveness of adversarial attacks. Current attack methods are able to manipulate the network's prediction by adding specific but small amounts of noise to the input. In turn, adversarial training (AT) aims to achieve robustness against such attacks and ideally a better model generalization ability by including adversarial samples in the trainingset. However, an in-depth analysis of the resulting robust models beyond adversarial robustness is still pending. In this paper, we empirically analyze a variety of adversarially trained models that achieve high robust accuracies when facing state-of-the-art attacks and we show that AT has an interesting side-effect: it leads to models that are significantly less overconfident with their decisions, even on clean data than non-robust models. Further, our analysis of robust models shows that not only AT but also the model's building blocks (like activation functions and pooling) have a strong influence on the models' prediction confidences. Data & Project website: https://github.com/GeJulia/robustnessconfidencesevaluation Julia Grabinski, Paul Gavrikov, Janis Keuper, Margret Keuper |
NeurIPS | 3 |
| 2022 | Aliasing and adversarial robust generalization of CNNsabstractAbstract Many commonly well-performing convolutional neural network models have shown to be susceptible to input data perturbations, indicating a low model robustness. To reveal model weaknesses, adversarial attacks are specifically optimized to generate small, barely perceivable image perturbations that flip the model prediction. Robustness against attacks can be gained by using adversarial examples during training, which in most cases reduces the measurable model attackability. Unfortunately, this technique can lead to robust overfitting, which results in non-robust models. In this paper, we analyze adversarially trained, robust models in the context of a specific network operation, the downsampling layer, and provide evidence that robust models have learned to downsample more accurately and suffer significantly less from downsampling artifacts, aka. aliasing, than baseline models. In the case of robust overfitting, we observe a strong increase in aliasing and propose a novel early stopping approach based on the measurement of aliasing. Julia Grabinski, Janis Keuper, Margret Keuper |
Mach. Learn. | 2 |
| 2021 | FacialGAN: Style Transfer and Attribute Manipulation on Synthetic Faces
Ricard Durall, Jireh Jam, Dominik Strassel, Moi Hoon Yap, Janis Keuper |
BMVC | 5 |
| 2021 | Sample efficient localization and stage prediction with autoencodersabstractEngineering, construction and operation of complex machines involves a wide range of complicated, simultaneous tasks, which potentially could be automated.In this work, we focus on perception tasks in such systems, investigating deep learning approaches for multi-task transfer learning with limited training data.We show an approach that takes advantage of a technical systems' focus on selected objects and their properties.We create focused representations and simultaneously solve joint objectives in a system through multi-task learning with convolutional autoencoders.The focused representations are used as a starting point for the data-saving solution of the additional tasks.The efficiency of this approach is demonstrated using images and tasks of an autonomous circular crane with a grapple. 71 Sebastian Hoch, Sascha Lange, Janis Keuper |
ESANN | 3 |
| 2021 | SpectralDefense: Detecting Adversarial Attacks on CNNs in the Fourier DomainabstractDespite the success of convolutional neural networks (CNNs) in many computer vision and image analysis tasks, they remain vulnerable against so-called adversarial attacks: Small, crafted perturbations in the input images can lead to false predictions. A possible defense is to detect adversarial examples. In this work, we show how analysis in the Fourier domain of input images and feature maps can be used to distinguish benign test samples from adversarial images. We propose two novel detection methods: Our first method employs the magnitude spectrum of the input images to detect an adversarial attack. This simple and robust classifier can successfully detect adversarial perturbations of three commonly used attack methods. The second method builds upon the first and additionally extracts the phase of Fourier coefficients of feature-maps at different layers of the network. With this extension, we are able to improve adversarial detection rates compared to state-of-the-art detectors on five different attack methods. The code for the methods proposed in the paper is available at github.com/paulaharder/SpectralAdversarialDefense Paula Harder, Franz-Josef Pfreundt, Margret Keuper, Janis Keuper |
IJCNN | 4 |
| 2020 | A Two-Stage Minimum Cost Multicut Approach to Self-supervised Multiple Person Tracking
Kalun Ho, Amirhossein Kardoost, Franz-Josef Pfreundt, Janis Keuper, Margret Keuper |
ACCV (2) | 4 |
| 2020 | Watch Your Up-Convolution: CNN Based Generative Deep Neural Networks Are Failing to Reproduce Spectral DistributionsabstractGenerative convolutional deep neural networks, e.g. popular GAN architectures, are relying on convolution based up-sampling methods to produce non-scalar outputs like images or video sequences. In this paper, we show that common up-sampling methods, i.e. known as up-convolution or transposed convolution, are causing the inability of such models to reproduce spectral distributions of natural training data correctly. This effect is independent of the underlying architecture and we show that it can be used to easily detect generated data like deepfakes with up to 100% accuracy on public benchmarks. To overcome this drawback of current generative models, we propose to add a novel spectral regularization term to the training optimization objective. We show that this approach not only allows to train spectral consistent GANs that are avoiding high frequency errors. Also, we show that a correct approximation of the frequency spectrum has positive effects on the training stability and output quality of generative networks. Ricard Durall, Margret Keuper, Janis Keuper |
CVPR | 3 |
| 2020 | Local Facial Attribute Transfer through InpaintingabstractThe term “attribute transfer” refers to the tasks of altering images in such a way, that the semantic interpretation of a given input image is shifted towards an intended direction, which is quantified by semantic attributes. Prominent example applications are photo realistic changes of facial features and expressions, like changing the hair color, adding a smile, enlarging the nose or altering the entire context of a scene, like transforming a summer landscape into a winter panorama. Recent advances in attribute transfer are mostly based on generative deep neural networks, using various techniques to manipulate images in the latent space of the generator. In this paper, we present a novel method for the common sub-task of local attribute transfers, where only parts of a face have to be altered in order to achieve semantic changes (e.g. removing a mustache). In contrast to previous methods, where such local changes have been implemented by generating new (global) images, we propose to formulate local attribute transfers as an inpainting problem. Removing and regenerating only parts of images, our “Attribute Transfer Inpainting Generative Adversarial Network” (ATI-GAN) is able to utilize local context information to focus on the attributes while keeping the background unmodified resulting in visually sound results. Ricard Durall, Franz-Josef Pfreundt, Janis Keuper |
ICPR | 3 |
| 2020 | Learning Embeddings for Image Clustering: An Empirical Study of Triplet Loss ApproachesabstractIn this work, we evaluate two different image clustering objectives, k-means clustering and correlation clustering, in the context of Triplet Loss induced feature space embeddings. Specifically, we train a convolutional neural network to learn discriminative features by optimizing two popular versions of the Triplet Loss in order to study their clustering properties under the assumption of noisy labels. Additionally, we propose a new, simple Triplet Loss formulation, which shows desirable properties with respect to formal clustering objectives and outperforms the existing methods. We evaluate all three Triplet loss formulations for K-means and correlation clustering on the CIFAR-10 image classification dataset. Kalun Ho, Janis Keuper, Franz-Josef Pfreundt, Margret Keuper |
ICPR | 2 |
| 2010 | Local Rotation Invariant Patch Descriptors for 3D Vector FieldsabstractIn this paper, we present two novel methods for the fast computation of local rotation invariant patch descriptors for 3D vectorial data. Patch based algorithms have recently become very popular approach for a wide range of 2D computer vision problems. Our local rotation invariant patch descriptors allow an extension of these methods to 3D vector fields. Our approaches are based on a harmonic representation for local spherical 3D vector field patches, which enables us to derive fast algorithms for the computation of rotation invariant power spectrum and bispectrum feature descriptors of such patches. Janis Keuper |
ICPR | 1 |
| 2008 | Fast and Accurate Rotation Estimation on the 2-Sphere without Correspondences
Janis Keuper, Marco Reisert, Hans Burkhardt |
ECCV (2) | 1 |
| 2008 | 3D rotation invariant local binary patternsabstractWe present a novel method for the fast computation of rotation invariant ¿local binary patterns¿ (LBP) on 3D volume data. Unlike a previous publication on 3D LBP, this new approach is not limited to ¿uniform patterns¿, providing a real 3D extension of the standard and rotation invariant LBP. We evaluate our methods in the context of 3D texture analysis of biological data. Janis Keuper, Hans Burkhardt |
ICPR | 1 |