Konstantin Böttinger

dblp:122/3548 · DBLP profile ↗
← Back
27ranked-venue papers
3as first author
14since 2021 · last 2026
0000-0002-9337-7506ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 14 · 12 since 2021Security and privacy · 12 · 3 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 6 since 2021Databases, data management, data science and information retrieval · 4 · 2 since 2021Systems, architecture and hardware · 2 · 1 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 Security-by-Design for LLM-Based Code Generation: Leveraging Internal Representations for Concept-Driven Steering Mechanisms
Maximilian Wendlinger, Daniel Kowatsch, Konstantin Böttinger, Philip Sperl
EuroS&P3
2024 MLAAD: The Multi-Language Audio Anti-Spoofing Dataset
abstract
Text-to-Speech (TTS) technology brings significant advantages, such as giving a voice to those with speech impairments, but also enables audio deepfakes and spoofs. The former mislead individuals and may propagate misinformation, while the latter undermine voice biometric security systems. AI-based detection can help to address these challenges by automatically differentiating between genuine and fabricated voice recordings. However, these models are only as good as their training data, which currently is severely limited due to an overwhelming concentration on English and Chinese audio in anti-spoofing databases, thus restricting its worldwide effectiveness.In response, this paper presents the Multi-Language Audio Anti-Spoof Dataset (MLAAD), created using 52 TTS models, comprising 22 different architectures, to generate 160.2 hours of synthetic voice in 23 different languages. We train and evaluate three state-of-the-art deepfake detection models with MLAAD, and observe that MLAAD demonstrates superior performance over comparable datasets like InTheWild or FakeOrReal when used as a training resource. Furthermore, in comparison with the renowned ASVspoof 2019 dataset, MLAAD proves to be a complementary resource. In tests across eight datasets, MLAAD and ASVspoof 2019 alternately outperformed each other, both excelling on four datasets.By publishing1MLAAD and making trained models accessible via an interactive webserver2, we aim to democratize antispoofing technology, making it accessible beyond the realm of specialists, thus contributing to global efforts against audio spoofing and deepfakes.
Nicolas M. Müller, Piotr Kawa, Wei Herng Choong, Edresson Casanova, Eren Gölge, Piotr Syga, Philip Sperl, Konstantin Böttinger
IJCNN9
2024 Shortcut Detection With Variational Autoencoders
abstract
In practical machine learning (ML) applications, it is vital for models to make predictions based on robust, generalizable features rather than unreliable data patterns. For example, in supervised classification tasks, a model may mistakenly label an image as ‘horse’ not due to identifying the animal’s traits, but because of a recurring watermark in ‘horse’ images — a learning shortcut. These deceptive shortcuts lead to artificially high performance in training and testing, creating a misleading impression of the model’s actual effectiveness. Such models often fail in real-world scenarios when these accidental correlations are absent. Thus, identifying and addressing these spurious correlations is a critical yet underexplored challenge.In our study, we introduce a new method for detecting such shortcuts in image and audio datasets. We use variational autoencoders (VAE) to separate features in the latent space of the VAE. This enables clear and semi-automatic identification of feature-target correlations in datasets. Our approach’s effectiveness is demonstrated on various real-world datasets, uncovering previously undetected shortcuts. For instance, we find that in fruit classification, the class prediction is influenced chiefly by the camera’s distance from the fruit.Our approach not only sheds light on the intricacies of what machine learning models learn but also aids in circumventing unwanted correlations that might limit their practical effectiveness. The tool is open-source and can be accessed at ANONYMOUS_URL.
Nicolas M. Müller, Simon Roschmann, Shahbaz Farooque Khan, Philip Sperl, Konstantin Böttinger
IJCNN5
2024 Harder or Different? Understanding Generalization of Audio Deepfake Detection
abstract
2705
Nicolas M. Müller, Nicholas W. D. Evans, Hemlata Tak, Philip Sperl, Konstantin Böttinger
INTERSPEECH5
2024 A New Approach to Voice Authenticity
abstract
2245
Nicolas M. Müller, Piotr Kawa, Shen Hu, Matthias Neu, Jennifer Williams 0001, Philip Sperl, Konstantin Böttinger
INTERSPEECH7
2023 Protecting Publicly Available Data With Machine Learning Shortcuts
Nicolas M. Müller, Maximilian Burgert, Pascal Debus, Jennifer Williams 0001, Philip Sperl, Konstantin Böttinger
BMVC6
2023 Complex-valued neural networks for voice anti-spoofing
abstract
3814
Nicolas M. Müller, Philip Sperl, Konstantin Böttinger
INTERSPEECH3
2022 Anomaly Detection by Recombining Gated Unsupervised Experts
abstract
Anomaly detection has been considered under several extents of prior knowledge. Unsupervised methods do not require any labelled data, whereas semi-supervised methods leverage some known anomalies. Inspired by mixture-of-experts models and the analysis of the hidden activations of neural networks, we introduce a novel data-driven anomaly detection method called ARGUE. Our method is not only applicable to unsupervised and semi-supervised environments, but also profits from prior knowledge of self-supervised settings. We designed ARGUE as a combination of dedicated expert networks, which specialise on parts of the input data. For its final decision, ARGUE fuses the distributed knowledge across the expert systems using a gated mixture-of-experts architecture. Our evaluation motivates that prior knowledge about the normal data distribution may be as valuable as known anomalies.
Jan-Philipp Schulze, Philip Sperl, Konstantin Böttinger
IJCNN3
2022 Double-Adversarial Activation Anomaly Detection: Adversarial Autoencoders are Anomaly Generators
abstract
Anomaly detection is a challenging task for machine learning methods due to the inherent class imbalance. It is costly and time-demanding to manually analyse the observed data, thus usually only few known anomalies if any are available. Inspired by generative models and the analysis of the hidden activations of neural networks, we introduce a novel unsupervised anomaly detection method called DA3D. Here, we use adversarial autoencoders to generate anomalous counterexamples based on the normal data only. These artificial anomalies used during training allow the detection of real, yet unseen anomalies. With our novel generative approach, we transform the unsupervised task of anomaly detection to a supervised one, which is more tractable by machine learning and especially deep learning methods. DA3D surpasses the performance of state-of-the-art anomaly detection methods in a purely data-driven way, where no domain knowledge is required.
Jan-Philipp Schulze, Philip Sperl, Konstantin Böttinger
IJCNN3
2022 Does Audio Deepfake Detection Generalize?
abstract
2783
Nicolas M. Müller, Pavel Czempin, Franziska Dieckmann, Adam Froghyar, Konstantin Böttinger
INTERSPEECH5
2022 Real or Fake? A Practical Method for Detecting Tempered Images
abstract
Tempering images has become technology that almost everyone can complete, including fake news, fake evidence presented in court, or forged documents. The main reason is because these editing tools, such as Photoshop, is simple to use, which is an urgent issue we need to solve. Hence, automatic tools helping to find manipulated images apart is critical for fighting misinformation campaigns. Here we propose and evaluate a neural network-based method. It can detect whether images have been artificially modified (classification), and further indicate the forged parts (segmentation). Our proposed method has better performance than most baseline methods. Last but not least, our method is not only effective on JPEG format, but can also be used on other formats.
Ching-Yu Kao, Hongjia Wan, Karla Markert, Konstantin Böttinger
IPAS4
2022 R2-AD2: Detecting Anomalies by Analysing the Raw Gradient
Jan-Philipp Schulze, Philip Sperl, Ana Radutoiu, Carla Sagebiel, Konstantin Böttinger
ECML/PKDD (1)5
2021 DA3G: Detecting Adversarial Attacks by Analysing Gradients
Jan-Philipp Schulze, Philip Sperl, Konstantin Böttinger
ESORICS (1)3
2021 Adversarial Vulnerability of Active Transfer Learning
Nicolas M. Müller, Konstantin Böttinger
IDA2
2020 DLA: Dense-Layer-Analysis for Adversarial Example Detection
abstract
In recent years Deep Neural Networks (DNNs) have achieved remarkable results and even showed superhuman capabilities in a broad range of domains. This led people to trust in DNN classifications even in security-sensitive environments like autonomous driving. Despite their impressive achievements, DNNs are known to be vulnerable to adversarial examples. Such inputs contain small perturbations to intentionally fool the attacked model. In this paper, we present a novel end-to-end framework to detect such attacks without influencing the target model's performance. Inspired by research in neuron-coverage guided testing we show that dense layers of DNNs carry security-sensitive information. With a secondary DNN we analyze the activation patterns of the dense layers during classification run-time, which enables effective and real-time detection of adversarial examples. Our prototype implementation successfully detects adversarial examples in image, natural language, and audio processing. Thereby, we cover a variety of target DNN architectures. In addition to effectively defending against state-of-the-art attacks, our approach generalizes between different sets of adversarial examples. Our experiments indicate that we are able to detect future, yet unknown, attacks. Finally, during white-box adaptive attacks, we show our method cannot be easily bypassed.
Philip Sperl, Ching-Yu Kao, Xiao Lei, Konstantin Böttinger
EuroS&P5
2020 Activation Anomaly Analysis
Philip Sperl, Jan-Philipp Schulze, Konstantin Böttinger
ECML/PKDD (2)3
2020 Data Poisoning Attacks on Regression Learning and Corresponding Defenses
abstract
Adversarial data poisoning is an effective attack against machine learning and threatens model integrity by introducing poisoned data into the training dataset. So far, it has been studied mostly for classification, even though regression learning is used in many mission critical systems (such as dosage of medication, control of cyber-physical systems and managing power supply). Therefore, in the present research, we aim to evaluate all aspects of data poisoning attacks on regression learning, exceeding previous work both in terms of breadth and depth. We present realistic scenarios in which data poisoning attacks threaten production systems and introduce a novel black-box attack, which is then applied to a real-word medical use-case. As a result, we observe that the mean squared error (MSE) of the regressor increases to 150 percent due to inserting only two percent of poison samples. Finally, we present a new defense strategy against the novel and previous attacks and evaluate it thoroughly on 26 datasets. As a result of the conducted experiments, we conclude that the proposed defence strategy effectively mitigates the considered attacks.
Nicolas M. Müller, Daniel Kowatsch, Konstantin Böttinger
PRDC3
2019 Side-Channel Aware Fuzzing
Philip Sperl, Konstantin Böttinger
ESORICS (1)2
2019 A Unified Architecture for Industrial IoT Security Requirements in Open Platform Communications
abstract
We present a unified communication architecture for security requirements in the industrial internet of things. Formulating security requirements in the language of OPC UA provides a unified method to communicate and compare security requirements within a heavily heterogeneous landscape of machines in the field. Our machine-readable data model provides a fully automatable approach for security requirement communication within the rapidly evolving fourth industrial revolution, which is characterized by high-grade interconnection of industrial infrastructures and self-configuring production systems. Capturing security requirements in an OPC UA compliant and unified data model for industrial control systems enables strong use cases within modern production plants and future supply chains. We implement our data model as well as an OPC UA server that operates on this model to show the feasibility of our approach. Further, we deploy and evaluate our framework within a reference project realized by 14 industrial partners and 7 research facilities within Germany.
Gerhard Hansch, Peter Schneider 0002, Kai Fischer, Konstantin Böttinger
ETFA4
2019 Context by Proxy: Identifying Contextual Anomalies Using an Output Proxy
abstract
Contextual anomalies arise only under special internal or external stimuli in a system, often making it infeasible to detect them by a rule-based approach. Labelling the underlying problem sources is hard because complex, time-dependent relationships between the inputs arise. We propose a novel unsupervised approach that combines tools from deep learning and signal processing, working in a purely data-driven way. Many systems show a desirable target behaviour which can be used as a proxy quantity removing the need to manually label data. The methodology was evaluated on real-life test car traces in the form of multivariate state message sequences. We successfully identified contextual anomalies during the cars' timeout process along with possible explanations. Novel input encodings allow us to summarise the entire system context including the timing such that more information is available during the decision process.
Jan-Philipp Schulze, Artur Mrowca, Elizabeth Ren, Hans-Andrea Loeliger, Konstantin Böttinger
KDD5
2019 Stack Overflow Considered Helpful! Deep Learning Security Nudges Towards Stronger Cryptography
Felix Fischer 0001, Huang Xiao, Ching-Yu Kao, Yannick Stachelscheid, Benjamin Johnson 0001, Danial Razar, Paul Fawkesley, Nat Buckley, Konstantin Böttinger, Paul Muntean 0001, Jens Grossklags
USENIX Security Symposium9
2017 Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application Security
abstract
Online programming discussion platforms such as Stack Overflow serve as a rich source of information for software developers. Available information include vibrant discussions and oftentimes ready-to-use code snippets. Previous research identified Stack Overflow as one of the most important information sources developers rely on. Anecdotes report that software developers copy and paste code snippets from those information sources for convenience reasons. Such behavior results in a constant flow of community-provided code snippets into production software. To date, the impact of this behaviour on code security is unknown. We answer this highly important question by quantifying the proliferation of security-related code snippets from Stack Overflow in Android applications available on Google Play. Access to the rich source of information available on Stack Overflow including ready-to-use code snippets provides huge benefits for software developers. However, when it comes to code security there are some caveats to bear in mind: Due to the complex nature of code security, it is very difficult to provide ready-to-use and secure solutions for every problem. Hence, integrating a security-related code snippet from Stack Overflow into production software requires caution and expertise. Unsurprisingly, we observed insecure code snippets being copied into Android applications millions of users install from Google Play every day. To quantitatively evaluate the extent of this observation, we scanned Stack Overflow for code snippets and evaluated their security score using a stochastic gradient descent classifier. In order to identify code reuse in Android applications, we applied state-of-the-art static analysis. Our results are alarming: 15.4% of the 1.3 million Android applications we analyzed, contained security-related code snippets from Stack Overflow. Out of these 97.9% contain at least one insecure code snippet.
Felix Fischer 0001, Konstantin Böttinger, Huang Xiao, Christian Stransky, Yasemin Acar, Michael Backes 0001, Sascha Fahl
IEEE Symposium on Security and Privacy2
2017 A collaborative cyber incident management system for European interconnected critical infrastructures
Giuseppe Settanni, Florian Skopik, Yegor Shovgenya, Roman Fiedler, Mark Carolan, Damien Conroy, Konstantin Böttinger, Mark Gall, Gerd Brost, Christophe Ponchel, Mirko Haustein, Helmut Kaufmann, Klaus Theuerkauf, Pia Olli
J. Inf. Secur. Appl.7
2016 DeepFuzz: Triggering Vulnerabilities Deeply Hidden in Binaries - (Extended Abstract)
Konstantin Böttinger, Claudia Eckert 0001
DIMVA1
2016 Fuzzing binaries with Lévy flight swarms
abstract
We present a new method for random testing of binary executables inspired by biology. In our approach, we introduce the first fuzzer based on a mathematical model for optimal foraging. To minimize search time for possible vulnerabilities, we generate test cases with Lévy flights in the input space. In order to dynamically adapt test generation behavior to actual path exploration performance, we define a suitable measure for quality evaluation of test cases. This measure takes into account previously discovered code regions and allows us to construct a feedback mechanism. By controlling diffusivity of the test case generating Lévy processes with evaluation feedback from dynamic instrumentation, we are able to define a fully self-adaptive fuzzing algorithm. We aggregate multiple instances of such Lévy flights to fuzzing swarms which reveal flexible, robust, decentralized, and self-organized behavior.
Konstantin Böttinger
EURASIP J. Inf. Secur.1
2015 Detecting Fingerprinted Data in TLS Traffic
abstract
We present a new method for detecting known data in certain TLS encrypted communication channels. Our approach enables us to detect single files in eavesdropped TLS secured network traffic. We generate fingerprints by a fine-grained measurement of the entropy of fragments of known data and introduce the application of methods from the field of machine learning to the problem of file detection. We implement all proposed methods on a real data base and show the practical efficiency of our approach.
Konstantin Böttinger, Dieter Schuster, Claudia Eckert 0001
AsiaCCS1
2014 TrustID: trustworthy identities for untrusted mobile devices
abstract
Identity theft has deep impacts in today's mobile ubiquitous environments. At the same time, digital identities are usually still protected by simple passwords or other insufficient security mechanisms. In this paper, we present the TrustID architecture and protocols to improve this situation. Our architecture utilizes a Secure Element (SE) to store multiple context-specific identities securely in a mobile device, e.g., a smartphone. We introduce protocols for securely deriving identities from a strong root identity into the SE inside the smartphone as well as for using the newly derived IDs. Both protocols do not require a trustworthy smartphone operating system or a Trusted Execution Environment. In order to achieve this, our concept includes a secure combined PIN entry mechanism for user authentication, which prevents attacks even on a malicious device. To show the feasibility of our approach, we implemented a prototype running on a Samsung Galaxy SIII smartphone utilizing a microSD card SE. The German identity card nPA is used as root identity to derive context-specific identities.
Julian Horsch, Konstantin Böttinger, Sascha Wessel, Frederic Stumpf
CODASPY2