David Stutz

dblp:17/9394 · DBLP profile ↗
← Back
14ranked-venue papers
9as first author
9since 2021 · last 2025
0000-0002-6286-1805ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 13 · 8 first-author · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
11 papers
Trustworthy machine learning · 73% 3D vision · 10% Deep learning architectures and training · 7%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Hardware accelerators and domain-specific architectures · 50% Hardware reliability and fault tolerance · 38% Energy-efficient computing · 12%
Network and information security
1 paper
Hardware security and side channels · 100%

Topics — the 26 heaviest of 26, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning
robustness
3.252024
On Adversarial Training without Perturbing all Examples · ICLR 2024
Robustifying Token Attention for Vision Transformers · ICCV 2023
Improving Robustness of Vision Transformers by Reducing Sensitivity to Patch Corruptions · CVPR 2023
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
1.942022
Improving Robustness by Enhancing Weak Subnets · ECCV (24) 2022
Relating Adversarially Robust Generalization to Flat Minima · ICCV 2021
Confidence-Calibrated Adversarial Training: Generalizing to Unseen Attacks · ICML 2020
Machine learning › Trustworthy machine learning › uncertainty estimation
conformal prediction
1.322024
Conformalized Credal Set Predictors · NeurIPS 2024
Learning Optimal Conformal Classifiers · ICLR 2022
Machine learning › Trustworthy machine learning
uncertainty estimation
1.322024
Conformalized Credal Set Predictors · NeurIPS 2024
Learning Optimal Conformal Classifiers · ICLR 2022
Machine learning › Trustworthy machine learning › robustness
corruption robustness
1.322023
Robustifying Token Attention for Vision Transformers · ICCV 2023
Improving Robustness of Vision Transformers by Reducing Sensitivity to Patch Corruptions · CVPR 2023
Machine learning › Deep learning architectures and training › transformer
vision transformer
1.322023
Robustifying Token Attention for Vision Transformers · ICCV 2023
Improving Robustness of Vision Transformers by Reducing Sensitivity to Patch Corruptions · CVPR 2023
Machine learning › Trustworthy machine learning › robustness › adversarial robustness
adversarial training
1.222024
On Adversarial Training without Perturbing all Examples · ICLR 2024
Confidence-Calibrated Adversarial Training: Generalizing to Unseen Attacks · ICML 2020
Computer vision › 3D vision › 3d shape reconstruction
shape completion
0.822020
Learning 3D Shape Completion Under Weak Supervision · Int. J. Comput. Vis. 2020
Learning 3D Shape Completion From Laser Scan Data With Weak Supervision · CVPR 2018
Machine learning › Trustworthy machine learning › robustness › adversarial examples
adversarial example generation
0.812024
On Adversarial Training without Perturbing all Examples · ICLR 2024
Machine learning › Trustworthy machine learning › uncertainty estimation › epistemic uncertainty
credal set
0.812024
Conformalized Credal Set Predictors · NeurIPS 2024
Hardware security and side channels
fault attacks
0.712023
Random and Adversarial Bit Error Robustness: Energy-Efficient and Secure DNN Accelerators · IEEE Trans. Pattern Anal. Mach. Intell. 2023
Hardware reliability and fault tolerance › error resilience
bit error robustness
0.712023
Random and Adversarial Bit Error Robustness: Energy-Efficient and Secure DNN Accelerators · IEEE Trans. Pattern Anal. Mach. Intell. 2023
Hardware accelerators and domain-specific architectures › machine learning accelerator
DNN accelerator
0.712023
Random and Adversarial Bit Error Robustness: Energy-Efficient and Secure DNN Accelerators · IEEE Trans. Pattern Anal. Mach. Intell. 2023
Machine learning › Learning paradigms › supervised learning
classifier training
0.612022
Learning Optimal Conformal Classifiers · ICLR 2022
Machine learning › Trustworthy machine learning › robustness › robust learning
robust generalization
0.512021
Relating Adversarially Robust Generalization to Flat Minima · ICCV 2021
Computer vision › 3D vision
3d reconstruction
0.412020
Learning 3D Shape Completion Under Weak Supervision · Int. J. Comput. Vis. 2020
Machine learning › Trustworthy machine learning › calibration
confidence calibration
0.412020
Confidence-Calibrated Adversarial Training: Generalizing to Unseen Attacks · ICML 2020
Machine learning › Learning paradigms
weakly supervised learning
0.412020
Learning 3D Shape Completion Under Weak Supervision · Int. J. Comput. Vis. 2020
Machine learning › Trustworthy machine learning › robustness
adversarial examples
0.412019
Disentangling Adversarial Robustness and Generalization · CVPR 2019
Machine learning › Learning theory
generalization
0.412019
Disentangling Adversarial Robustness and Generalization · CVPR 2019
Computer vision › 3D vision
3d shape reconstruction
0.312018
Learning 3D Shape Completion From Laser Scan Data With Weak Supervision · CVPR 2018
Computer vision › 3D vision › point cloud processing
point cloud completion
0.312018
Learning 3D Shape Completion From Laser Scan Data With Weak Supervision · CVPR 2018
Energy-efficient computing
low-voltage operation
0.212023
Random and Adversarial Bit Error Robustness: Energy-Efficient and Secure DNN Accelerators · IEEE Trans. Pattern Anal. Mach. Intell. 2023
Hardware accelerators and domain-specific architectures
quantization
0.212023
Random and Adversarial Bit Error Robustness: Energy-Efficient and Secure DNN Accelerators · IEEE Trans. Pattern Anal. Mach. Intell. 2023
Machine learning › Efficient and distributed learning
model compression
0.212022
Improving Robustness by Enhancing Weak Subnets · ECCV (24) 2022
Machine learning › Representation and self-supervised learning
data manifold
0.112019
Disentangling Adversarial Robustness and Generalization · CVPR 2019

Methods — techniques the papers use, named apart from their topics

adversarial training · 2.1conformal prediction · 1.3weight clipping · 1.3random bit error training · 1.3fixed-point quantization · 1.3adversarial bit error training · 1.3deep neural network · 0.8credal sets · 0.8adversarial attack · 0.8token-aware average pooling · 0.7feature alignment · 0.7attention diversification loss · 0.7adversarial patch corruption · 0.7subnet enhancement · 0.6
YearPublicationVenuePosition
2025 Evaluating medical AI systems in dermatology under uncertain ground truth
David Stutz, A. Taylan Cemgil, Abhijit Guha Roy, Tatiana Matejovicova, Melih Barsbey, Patricia Strachan, Mike Schaekermann, Jan Freyberg, Rajeev Rikhye, Beverly Freeman, Javier Perez Matos, Umesh Telang, Dale R. Webster, Gregory S. Corrado, Yossi Matias, Pushmeet Kohli, Yun Liu 0013, Arnaud Doucet, Alan Karthikesalingam
Medical Image Anal.1
2024 On Adversarial Training without Perturbing all Examples
abstract
Adversarial training is the de-facto standard for improving robustness against adversarial examples. This usually involves a multi-step adversarial attack applied on each example during training. In this paper, we explore only constructing adversarial examples (AE) on a subset of the training examples. That is, we split the training set in two subsets $A$ and $B$, train models on both ($A\cup B$) but construct AEs only for examples in $A$. Starting with $A$ containing only a single class, we systematically increase the size of $A$ and consider splitting by class and by examples. We observe that: (i) adv. robustness transfers by difficulty and to classes in $B$ that have never been adv. attacked during training, (ii) we observe a tendency for hard examples to provide better robustness transfer than easy examples, yet find this tendency to diminish with increasing complexity of datasets (iii) generating AEs on only $50$% of training data is sufficient to recover most of the baseline AT performance even on ImageNet. We observe similar transfer properties across tasks, where generating AEs on only $30$% of data can recover baseline robustness on the target task. We evaluate our subset analysis on a wide variety of image datasets like CIFAR-10, CIFAR-100, ImageNet-200 and show transfer to SVHN, Oxford-Flowers-102 and Caltech-256. In contrast to conventional practice, our experiments indicate that the utility of computing AEs varies by class and examples and that weighting examples from $A$ higher than $B$ provides high transfer performance. Code is available at [http://github.com/mlosch/SAT](http://github.com/mlosch/SAT).
Max Maria Losch, Mohamed Omran, David Stutz, Mario Fritz, Bernt Schiele
ICLR3
2024 Conformalized Credal Set Predictors
abstract
Credal sets are sets of probability distributions that are considered as candidates for an imprecisely known ground-truth distribution. In machine learning, they have recently attracted attention as an appealing formalism for uncertainty representation, in particular, due to their ability to represent both the aleatoric and epistemic uncertainty in a prediction. However, the design of methods for learning credal set predictors remains a challenging problem. In this paper, we make use of conformal prediction for this purpose. More specifically, we propose a method for predicting credal sets in the classification task, given training data labeled by probability distributions. Since our method inherits the coverage guarantees of conformal prediction, our conformal credal sets are guaranteed to be valid with high probability (without any assumptions on model or distribution). We demonstrate the applicability of our method on ambiguous classification tasks for uncertainty quantification.
Alireza Javanmardi, David Stutz, Eyke Hüllermeier
NeurIPS2
2023 Improving Robustness of Vision Transformers by Reducing Sensitivity to Patch Corruptions
abstract
Despite their success, vision transformers still remain vulnerable to image corruptions, such as noise or blur. Indeed, we find that the vulnerability mainly stems from the unstable self-attention mechanism, which is inherently built upon patch-based inputs and often becomes overly sensitive to the corruptions across patches. For example, when we only occlude a small number of patches with random noise (e.g., 10%), these patch corruptions would lead to severe accuracy drops and greatly distract intermediate attention layers. To address this, we propose a new training method that improves the robustness of transformers from a new perspective - reducing sensitivity to patch corruptions (RSPC). Specifically, we first identify and occlude/corrupt the most vulnerable patches and then explicitly reduce sensitivity to them by aligning the intermediate features between clean and corrupted examples. We highlight that the construction of patch corruptions is learned adversarially to the following feature alignment process, which is particularly effective and essentially different from existing methods. In experiments, our RSPC greatly improves the stability of attention layers and consistently yields better robustness on various benchmarks, including CIFAR-10/100-C, ImageNet-A, ImageNet-C, and ImageNet-P.
David Stutz, Bernt Schiele
CVPR2
2023 Robustifying Token Attention for Vision Transformers
abstract
Despite the success of vision transformers (ViTs), they still suffer from significant drops in accuracy in the presence of common corruptions, such as noise or blur. Interestingly, we observe that the attention mechanism of ViTs tends to rely on few important tokens, a phenomenon we call token overfocusing. More critically, these tokens are not robust to corruptions, often leading to highly diverging attention patterns. In this paper, we intend to alleviate this overfocusing issue and make attention more stable through two general techniques: First, our Token-aware Average Pooling (TAP) module encourages the local neighborhood of each token to take part in the attention mechanism. Specifically, TAP learns average pooling schemes for each token such that the information of potentially important tokens in the neighborhood can adaptively be taken into account. Second, we force the output tokens to aggregate information from a diverse set of input tokens rather than focusing on just a few by using our Attention Diversification Loss (ADL). We achieve this by penalizing high cosine similarity between the attention vectors of different tokens. In experiments, we apply our methods to a wide range of transformer architectures and improve robustness significantly. For example, we improve corruption robustness on ImageNet-C by 2.4% while improving accuracy by 0.4% based on state-of-the-art robust architecture FAN. Also, when fine-tuning on semantic segmentation tasks, we improve robustness on CityScapes-C by 2.4% and ACDC by 3.0%. Our code is available at https://github.com/guoyongcs/TAPADL.
David Stutz, Bernt Schiele
ICCV2
2023 Random and Adversarial Bit Error Robustness: Energy-Efficient and Secure DNN Accelerators
abstract
Deep neural network (DNN) accelerators received considerable attention in recent years due to the potential to save energy compared to mainstream hardware. Low-voltage operation of DNN accelerators allows to further reduce energy consumption, however, causes bit-level failures in the memory storing the quantized weights. Furthermore, DNN accelerators are vulnerable to adversarial attacks on voltage controllers or individual bits. In this paper, we show that a combination of robust fixed-point quantization, weight clipping, as well as random bit error training (RandBET) or adversarial bit error training (AdvBET) improves robustness against random or adversarial bit errors in quantized DNN weights significantly. This leads not only to high energy savings for low-voltage operation as well as low-precision quantization, but also improves security of DNN accelerators. In contrast to related work, our approach generalizes across operating voltages and accelerators and does not require hardware changes. Moreover, we present a novel adversarial bit error attack and are able to obtain robustness against both targeted and untargeted bit-level attacks. Without losing more than 0.8%/2% in test accuracy, we can reduce energy consumption on CIFAR10by 20%/30% for 8/4-bit quantization. Allowing up to 320 adversarial bit errors, we reduce test error from above 90% (chance level) to 26.22%.
David Stutz, Nandhini Chandramoorthy, Matthias Hein 0001, Bernt Schiele
IEEE Trans. Pattern Anal. Mach. Intell.1
2022 Improving Robustness by Enhancing Weak Subnets
David Stutz, Bernt Schiele
ECCV (24)2
2022 Learning Optimal Conformal Classifiers
David Stutz, Krishnamurthy Dvijotham, A. Taylan Cemgil, Arnaud Doucet
ICLR1
2021 Relating Adversarially Robust Generalization to Flat Minima
abstract
Adversarial training (AT) has become the de-facto standard to obtain models robust against adversarial examples. However, AT exhibits severe robust overfitting: cross-entropy loss on adversarial examples, so-called robust loss, decreases continuously on training examples, while eventually increasing on test examples. In practice, this leads to poor robust generalization, i.e., adversarial robustness does not generalize well to new examples. In this paper, we study the relationship between robust generalization and flatness of the robust loss landscape in weight space, i.e., whether robust loss changes significantly when perturbing weights. To this end, we propose average- and worst-case metrics to measure flatness in the robust loss landscape and show a correlation between good robust generalization and flatness. For example, throughout training, flatness reduces significantly during overfitting such that early stopping effectively finds flatter minima in the robust loss landscape. Similarly, AT variants achieving higher adversarial robustness also correspond to flatter minima. This holds for many popular choices, e.g., AT-AWP, TRADES, MART, AT with self-supervision or additional unlabeled examples, as well as simple regularization techniques, e.g., AutoAugment, weight decay or label noise. For fair comparison across these approaches, our flatness measures are specifically designed to be scale-invariant and we conduct extensive experiments to validate our findings.
David Stutz, Matthias Hein 0001, Bernt Schiele
ICCV1
2020 Confidence-Calibrated Adversarial Training: Generalizing to Unseen Attacks
abstract
Adversarial training yields robust models against a specific threat model, e.g., $L_\infty$ adversarial examples. Typically robustness does not generalize to previously unseen threat models, e.g., other $L_p$ norms, or larger perturbations. Our confidence-calibrated adversarial training (CCAT) tackles this problem by biasing the model towards low confidence predictions on adversarial examples. By allowing to reject examples with low confidence, robustness generalizes beyond the threat model employed during training. CCAT, trained only on $L_\infty$ adversarial examples, increases robustness against larger $L_\infty$, $L_2$, $L_1$ and $L_0$ attacks, adversarial frames, distal adversarial examples and corrupted examples and yields better clean accuracy compared to adversarial training. For thorough evaluation we developed novel white- and black-box attacks directly attacking CCAT by maximizing confidence. For each threat model, we use $7$ attacks with up to $50$ restarts and $5000$ iterations and report worst-case robust test error, extended to our confidence-thresholded setting, across all attacks.
David Stutz, Matthias Hein 0001, Bernt Schiele
ICML1
2020 Learning 3D Shape Completion Under Weak Supervision
abstract
Abstract We address the problem of 3D shape completion from sparse and noisy point clouds, a fundamental problem in computer vision and robotics. Recent approaches are either data-driven or learning-based: Data-driven approaches rely on a shape model whose parameters are optimized to fit the observations; Learning-based approaches, in contrast, avoid the expensive optimization step by learning to directly predict complete shapes from incomplete observations in a fully-supervised setting. However, full supervision is often not available in practice. In this work, we propose a weakly-supervised learning-based approach to 3D shape completion which neither requires slow optimization nor direct supervision. While we also learn a shape prior on synthetic data, we amortize, i.e.,learn, maximum likelihood fitting using deep neural networks resulting in efficient shape completion without sacrificing accuracy. On synthetic benchmarks based on ShapeNet (Chang et al. Shapenet: an information-rich 3d model repository, 2015. arXiv:1512.03012 ) and ModelNet (Wu et al., in: Proceedings of IEEE conference on computer vision and pattern recognition (CVPR), 2015) as well as on real robotics data from KITTI (Geiger et al., in: Proceedings of IEEE conference on computer vision and pattern recognition (CVPR), 2012) and Kinect (Yang et al., 3d object dense reconstruction from a single depth view, 2018. arXiv:1802.00411 ), we demonstrate that the proposed amortized maximum likelihood approach is able to compete with the fully supervised baseline of Dai et al. (in: Proceedings of IEEE conference on computer vision and pattern recognition (CVPR), 2017) and outperforms the data-driven approach of Engelmann et al. (in: Proceedings of the German conference on pattern recognition (GCPR), 2016), while requiring less supervision and being significantly faster.
David Stutz, Andreas Geiger 0001
Int. J. Comput. Vis.1
2019 Disentangling Adversarial Robustness and Generalization
abstract
Obtaining deep networks that are robust against adversarial examples and generalize well is an open problem. A recent hypothesis even states that both robust and accurate models are impossible, i.e., adversarial robustness and generalization are conflicting goals. In an effort to clarify the relationship between robustness and generalization, we assume an underlying, low-dimensional data manifold and show that: 1. regular adversarial examples leave the manifold; 2. adversarial examples constrained to the manifold, i.e., on-manifold adversarial examples, exist; 3. on-manifold adversarial examples are generalization errors, and on-manifold adversarial training boosts generalization; 4. regular robustness and generalization are not necessarily contradicting goals. These assumptions imply that both robust and accurate models are possible. However, different models (architectures, training strategies etc.) can exhibit different robustness and generalization characteristics. To confirm our claims, we present extensive experiments on synthetic data (with known manifold) as well as on EMNIST, Fashion-MNIST and CelebA.
David Stutz, Matthias Hein 0001, Bernt Schiele
CVPR1
2018 Learning 3D Shape Completion From Laser Scan Data With Weak Supervision
abstract
3D shape completion from partial point clouds is a fundamental problem in computer vision and computer graphics. Recent approaches can be characterized as either data-driven or learning-based. Data-driven approaches rely on a shape model whose parameters are optimized to fit the observations. Learning-based approaches, in contrast, avoid the expensive optimization step and instead directly predict the complete shape from the incomplete observations using deep neural networks. However, full supervision is required which is often not available in practice. In this work, we propose a weakly-supervised learning-based approach to 3D shape completion which neither requires slow optimization nor direct supervision. While we also learn a shape prior on synthetic data, we amortize, i.e., learn, maximum likelihood fitting using deep neural networks resulting in efficient shape completion without sacrificing accuracy. Tackling 3D shape completion of cars on ShapeNet [5] and KITTI [18], we demonstrate that the proposed amortized maximum likelihood approach is able to compete with a fully supervised baseline and a state-of-the-art data-driven approach while being significantly faster. On ModelNet [49], we additionally show that the approach is able to generalize to other object categories as well.
David Stutz, Andreas Geiger 0001
CVPR1
2018 Superpixels: An evaluation of the state-of-the-art
David Stutz, Alexander Hermans, Bastian Leibe
Comput. Vis. Image Underst.1