EDBT 2026 Demo / reviewers in the wild / expert
David Stutz
dblp:17/9394
· DBLP profile ↗
14ranked-venue papers
9as first author
9since 2021 · last 2025
0000-0002-6286-1805ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 13 · 8 first-author · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
11 papers |
Trustworthy machine learning · 73% 3D vision · 10% Deep learning architectures and training · 7% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Hardware accelerators and domain-specific architectures · 50% Hardware reliability and fault tolerance · 38% Energy-efficient computing · 12% | |
| Network and information security
1 paper |
Hardware security and side channels · 100% |
Topics — the 26 heaviest of 26, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Machine learning › Trustworthy machine learning
robustness |
3.2 | 5 | 2024 | On Adversarial Training without Perturbing all Examples · ICLR 2024 Robustifying Token Attention for Vision Transformers · ICCV 2023 Improving Robustness of Vision Transformers by Reducing Sensitivity to Patch Corruptions · CVPR 2023 |
Machine learning › Trustworthy machine learning › robustness
adversarial robustness |
1.9 | 4 | 2022 | Improving Robustness by Enhancing Weak Subnets · ECCV (24) 2022 Relating Adversarially Robust Generalization to Flat Minima · ICCV 2021 Confidence-Calibrated Adversarial Training: Generalizing to Unseen Attacks · ICML 2020 |
Machine learning › Trustworthy machine learning › uncertainty estimation
conformal prediction |
1.3 | 2 | 2024 | Conformalized Credal Set Predictors · NeurIPS 2024 Learning Optimal Conformal Classifiers · ICLR 2022 |
Machine learning › Trustworthy machine learning
uncertainty estimation |
1.3 | 2 | 2024 | Conformalized Credal Set Predictors · NeurIPS 2024 Learning Optimal Conformal Classifiers · ICLR 2022 |
Machine learning › Trustworthy machine learning › robustness
corruption robustness |
1.3 | 2 | 2023 | Robustifying Token Attention for Vision Transformers · ICCV 2023 Improving Robustness of Vision Transformers by Reducing Sensitivity to Patch Corruptions · CVPR 2023 |
Machine learning › Deep learning architectures and training › transformer
vision transformer |
1.3 | 2 | 2023 | Robustifying Token Attention for Vision Transformers · ICCV 2023 Improving Robustness of Vision Transformers by Reducing Sensitivity to Patch Corruptions · CVPR 2023 |
Machine learning › Trustworthy machine learning › robustness › adversarial robustness
adversarial training |
1.2 | 2 | 2024 | On Adversarial Training without Perturbing all Examples · ICLR 2024 Confidence-Calibrated Adversarial Training: Generalizing to Unseen Attacks · ICML 2020 |
Computer vision › 3D vision › 3d shape reconstruction
shape completion |
0.8 | 2 | 2020 | Learning 3D Shape Completion Under Weak Supervision · Int. J. Comput. Vis. 2020 Learning 3D Shape Completion From Laser Scan Data With Weak Supervision · CVPR 2018 |
Machine learning › Trustworthy machine learning › robustness › adversarial examples
adversarial example generation |
0.8 | 1 | 2024 | On Adversarial Training without Perturbing all Examples · ICLR 2024 |
Machine learning › Trustworthy machine learning › uncertainty estimation › epistemic uncertainty
credal set |
0.8 | 1 | 2024 | Conformalized Credal Set Predictors · NeurIPS 2024 |
Hardware security and side channels
fault attacks |
0.7 | 1 | 2023 | Random and Adversarial Bit Error Robustness: Energy-Efficient and Secure DNN Accelerators · IEEE Trans. Pattern Anal. Mach. Intell. 2023 |
Hardware reliability and fault tolerance › error resilience
bit error robustness |
0.7 | 1 | 2023 | Random and Adversarial Bit Error Robustness: Energy-Efficient and Secure DNN Accelerators · IEEE Trans. Pattern Anal. Mach. Intell. 2023 |
Hardware accelerators and domain-specific architectures › machine learning accelerator
DNN accelerator |
0.7 | 1 | 2023 | Random and Adversarial Bit Error Robustness: Energy-Efficient and Secure DNN Accelerators · IEEE Trans. Pattern Anal. Mach. Intell. 2023 |
Machine learning › Learning paradigms › supervised learning
classifier training |
0.6 | 1 | 2022 | Learning Optimal Conformal Classifiers · ICLR 2022 |
Machine learning › Trustworthy machine learning › robustness › robust learning
robust generalization |
0.5 | 1 | 2021 | Relating Adversarially Robust Generalization to Flat Minima · ICCV 2021 |
Computer vision › 3D vision
3d reconstruction |
0.4 | 1 | 2020 | Learning 3D Shape Completion Under Weak Supervision · Int. J. Comput. Vis. 2020 |
Machine learning › Trustworthy machine learning › calibration
confidence calibration |
0.4 | 1 | 2020 | Confidence-Calibrated Adversarial Training: Generalizing to Unseen Attacks · ICML 2020 |
Machine learning › Learning paradigms
weakly supervised learning |
0.4 | 1 | 2020 | Learning 3D Shape Completion Under Weak Supervision · Int. J. Comput. Vis. 2020 |
Machine learning › Trustworthy machine learning › robustness
adversarial examples |
0.4 | 1 | 2019 | Disentangling Adversarial Robustness and Generalization · CVPR 2019 |
Machine learning › Learning theory
generalization |
0.4 | 1 | 2019 | Disentangling Adversarial Robustness and Generalization · CVPR 2019 |
Computer vision › 3D vision
3d shape reconstruction |
0.3 | 1 | 2018 | Learning 3D Shape Completion From Laser Scan Data With Weak Supervision · CVPR 2018 |
Computer vision › 3D vision › point cloud processing
point cloud completion |
0.3 | 1 | 2018 | Learning 3D Shape Completion From Laser Scan Data With Weak Supervision · CVPR 2018 |
Energy-efficient computing
low-voltage operation |
0.2 | 1 | 2023 | Random and Adversarial Bit Error Robustness: Energy-Efficient and Secure DNN Accelerators · IEEE Trans. Pattern Anal. Mach. Intell. 2023 |
Hardware accelerators and domain-specific architectures
quantization |
0.2 | 1 | 2023 | Random and Adversarial Bit Error Robustness: Energy-Efficient and Secure DNN Accelerators · IEEE Trans. Pattern Anal. Mach. Intell. 2023 |
Machine learning › Efficient and distributed learning
model compression |
0.2 | 1 | 2022 | Improving Robustness by Enhancing Weak Subnets · ECCV (24) 2022 |
Machine learning › Representation and self-supervised learning
data manifold |
0.1 | 1 | 2019 | Disentangling Adversarial Robustness and Generalization · CVPR 2019 |
Methods — techniques the papers use, named apart from their topics
adversarial training · 2.1conformal prediction · 1.3weight clipping · 1.3random bit error training · 1.3fixed-point quantization · 1.3adversarial bit error training · 1.3deep neural network · 0.8credal sets · 0.8adversarial attack · 0.8token-aware average pooling · 0.7feature alignment · 0.7attention diversification loss · 0.7adversarial patch corruption · 0.7subnet enhancement · 0.6
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Evaluating medical AI systems in dermatology under uncertain ground truth
David Stutz, A. Taylan Cemgil, Abhijit Guha Roy, Tatiana Matejovicova, Melih Barsbey, Patricia Strachan, Mike Schaekermann, Jan Freyberg, Rajeev Rikhye, Beverly Freeman, Javier Perez Matos, Umesh Telang, Dale R. Webster, Gregory S. Corrado, Yossi Matias, Pushmeet Kohli, Yun Liu 0013, Arnaud Doucet, Alan Karthikesalingam |
Medical Image Anal. | 1 |
| 2024 | On Adversarial Training without Perturbing all ExamplesabstractAdversarial training is the de-facto standard for improving robustness against adversarial examples. This usually involves a multi-step adversarial attack applied on each example during training. In this paper, we explore only constructing adversarial examples (AE) on a subset of the training examples. That is, we split the training set in two subsets $A$ and $B$, train models on both ($A\cup B$) but construct AEs only for examples in $A$. Starting with $A$ containing only a single class, we systematically increase the size of $A$ and consider splitting by class and by examples. We observe that: (i) adv. robustness transfers by difficulty and to classes in $B$ that have never been adv. attacked during training, (ii) we observe a tendency for hard examples to provide better robustness transfer than easy examples, yet find this tendency to diminish with increasing complexity of datasets (iii) generating AEs on only $50$% of training data is sufficient to recover most of the baseline AT performance even on ImageNet. We observe similar transfer properties across tasks, where generating AEs on only $30$% of data can recover baseline robustness on the target task. We evaluate our subset analysis on a wide variety of image datasets like CIFAR-10, CIFAR-100, ImageNet-200 and show transfer to SVHN, Oxford-Flowers-102 and Caltech-256. In contrast to conventional practice, our experiments indicate that the utility of computing AEs varies by class and examples and that weighting examples from $A$ higher than $B$ provides high transfer performance. Code is available at [http://github.com/mlosch/SAT](http://github.com/mlosch/SAT). Max Maria Losch, Mohamed Omran, David Stutz, Mario Fritz, Bernt Schiele |
ICLR | 3 |
| 2024 | Conformalized Credal Set PredictorsabstractCredal sets are sets of probability distributions that are considered as candidates for an imprecisely known ground-truth distribution. In machine learning, they have recently attracted attention as an appealing formalism for uncertainty representation, in particular, due to their ability to represent both the aleatoric and epistemic uncertainty in a prediction. However, the design of methods for learning credal set predictors remains a challenging problem. In this paper, we make use of conformal prediction for this purpose. More specifically, we propose a method for predicting credal sets in the classification task, given training data labeled by probability distributions. Since our method inherits the coverage guarantees of conformal prediction, our conformal credal sets are guaranteed to be valid with high probability (without any assumptions on model or distribution). We demonstrate the applicability of our method on ambiguous classification tasks for uncertainty quantification. Alireza Javanmardi, David Stutz, Eyke Hüllermeier |
NeurIPS | 2 |
| 2023 | Improving Robustness of Vision Transformers by Reducing Sensitivity to Patch CorruptionsabstractDespite their success, vision transformers still remain vulnerable to image corruptions, such as noise or blur. Indeed, we find that the vulnerability mainly stems from the unstable self-attention mechanism, which is inherently built upon patch-based inputs and often becomes overly sensitive to the corruptions across patches. For example, when we only occlude a small number of patches with random noise (e.g., 10%), these patch corruptions would lead to severe accuracy drops and greatly distract intermediate attention layers. To address this, we propose a new training method that improves the robustness of transformers from a new perspective - reducing sensitivity to patch corruptions (RSPC). Specifically, we first identify and occlude/corrupt the most vulnerable patches and then explicitly reduce sensitivity to them by aligning the intermediate features between clean and corrupted examples. We highlight that the construction of patch corruptions is learned adversarially to the following feature alignment process, which is particularly effective and essentially different from existing methods. In experiments, our RSPC greatly improves the stability of attention layers and consistently yields better robustness on various benchmarks, including CIFAR-10/100-C, ImageNet-A, ImageNet-C, and ImageNet-P. David Stutz, Bernt Schiele |
CVPR | 2 |
| 2023 | Robustifying Token Attention for Vision TransformersabstractDespite the success of vision transformers (ViTs), they still suffer from significant drops in accuracy in the presence of common corruptions, such as noise or blur. Interestingly, we observe that the attention mechanism of ViTs tends to rely on few important tokens, a phenomenon we call token overfocusing. More critically, these tokens are not robust to corruptions, often leading to highly diverging attention patterns. In this paper, we intend to alleviate this overfocusing issue and make attention more stable through two general techniques: First, our Token-aware Average Pooling (TAP) module encourages the local neighborhood of each token to take part in the attention mechanism. Specifically, TAP learns average pooling schemes for each token such that the information of potentially important tokens in the neighborhood can adaptively be taken into account. Second, we force the output tokens to aggregate information from a diverse set of input tokens rather than focusing on just a few by using our Attention Diversification Loss (ADL). We achieve this by penalizing high cosine similarity between the attention vectors of different tokens. In experiments, we apply our methods to a wide range of transformer architectures and improve robustness significantly. For example, we improve corruption robustness on ImageNet-C by 2.4% while improving accuracy by 0.4% based on state-of-the-art robust architecture FAN. Also, when fine-tuning on semantic segmentation tasks, we improve robustness on CityScapes-C by 2.4% and ACDC by 3.0%. Our code is available at https://github.com/guoyongcs/TAPADL. David Stutz, Bernt Schiele |
ICCV | 2 |
| 2023 | Random and Adversarial Bit Error Robustness: Energy-Efficient and Secure DNN AcceleratorsabstractDeep neural network (DNN) accelerators received considerable attention in recent years due to the potential to save energy compared to mainstream hardware. Low-voltage operation of DNN accelerators allows to further reduce energy consumption, however, causes bit-level failures in the memory storing the quantized weights. Furthermore, DNN accelerators are vulnerable to adversarial attacks on voltage controllers or individual bits. In this paper, we show that a combination of robust fixed-point quantization, weight clipping, as well as random bit error training (RandBET) or adversarial bit error training (AdvBET) improves robustness against random or adversarial bit errors in quantized DNN weights significantly. This leads not only to high energy savings for low-voltage operation as well as low-precision quantization, but also improves security of DNN accelerators. In contrast to related work, our approach generalizes across operating voltages and accelerators and does not require hardware changes. Moreover, we present a novel adversarial bit error attack and are able to obtain robustness against both targeted and untargeted bit-level attacks. Without losing more than 0.8%/2% in test accuracy, we can reduce energy consumption on CIFAR10by 20%/30% for 8/4-bit quantization. Allowing up to 320 adversarial bit errors, we reduce test error from above 90% (chance level) to 26.22%. David Stutz, Nandhini Chandramoorthy, Matthias Hein 0001, Bernt Schiele |
IEEE Trans. Pattern Anal. Mach. Intell. | 1 |
| 2022 | Improving Robustness by Enhancing Weak Subnets
David Stutz, Bernt Schiele |
ECCV (24) | 2 |
| 2022 | Learning Optimal Conformal Classifiers
David Stutz, Krishnamurthy Dvijotham, A. Taylan Cemgil, Arnaud Doucet |
ICLR | 1 |
| 2021 | Relating Adversarially Robust Generalization to Flat MinimaabstractAdversarial training (AT) has become the de-facto standard to obtain models robust against adversarial examples. However, AT exhibits severe robust overfitting: cross-entropy loss on adversarial examples, so-called robust loss, decreases continuously on training examples, while eventually increasing on test examples. In practice, this leads to poor robust generalization, i.e., adversarial robustness does not generalize well to new examples. In this paper, we study the relationship between robust generalization and flatness of the robust loss landscape in weight space, i.e., whether robust loss changes significantly when perturbing weights. To this end, we propose average- and worst-case metrics to measure flatness in the robust loss landscape and show a correlation between good robust generalization and flatness. For example, throughout training, flatness reduces significantly during overfitting such that early stopping effectively finds flatter minima in the robust loss landscape. Similarly, AT variants achieving higher adversarial robustness also correspond to flatter minima. This holds for many popular choices, e.g., AT-AWP, TRADES, MART, AT with self-supervision or additional unlabeled examples, as well as simple regularization techniques, e.g., AutoAugment, weight decay or label noise. For fair comparison across these approaches, our flatness measures are specifically designed to be scale-invariant and we conduct extensive experiments to validate our findings. David Stutz, Matthias Hein 0001, Bernt Schiele |
ICCV | 1 |
| 2020 | Confidence-Calibrated Adversarial Training: Generalizing to Unseen AttacksabstractAdversarial training yields robust models against a specific threat model, e.g., $L_\infty$ adversarial examples. Typically robustness does not generalize to previously unseen threat models, e.g., other $L_p$ norms, or larger perturbations. Our confidence-calibrated adversarial training (CCAT) tackles this problem by biasing the model towards low confidence predictions on adversarial examples. By allowing to reject examples with low confidence, robustness generalizes beyond the threat model employed during training. CCAT, trained only on $L_\infty$ adversarial examples, increases robustness against larger $L_\infty$, $L_2$, $L_1$ and $L_0$ attacks, adversarial frames, distal adversarial examples and corrupted examples and yields better clean accuracy compared to adversarial training. For thorough evaluation we developed novel white- and black-box attacks directly attacking CCAT by maximizing confidence. For each threat model, we use $7$ attacks with up to $50$ restarts and $5000$ iterations and report worst-case robust test error, extended to our confidence-thresholded setting, across all attacks. David Stutz, Matthias Hein 0001, Bernt Schiele |
ICML | 1 |
| 2020 | Learning 3D Shape Completion Under Weak SupervisionabstractAbstract We address the problem of 3D shape completion from sparse and noisy point clouds, a fundamental problem in computer vision and robotics. Recent approaches are either data-driven or learning-based: Data-driven approaches rely on a shape model whose parameters are optimized to fit the observations; Learning-based approaches, in contrast, avoid the expensive optimization step by learning to directly predict complete shapes from incomplete observations in a fully-supervised setting. However, full supervision is often not available in practice. In this work, we propose a weakly-supervised learning-based approach to 3D shape completion which neither requires slow optimization nor direct supervision. While we also learn a shape prior on synthetic data, we amortize, i.e.,learn, maximum likelihood fitting using deep neural networks resulting in efficient shape completion without sacrificing accuracy. On synthetic benchmarks based on ShapeNet (Chang et al. Shapenet: an information-rich 3d model repository, 2015. arXiv:1512.03012 ) and ModelNet (Wu et al., in: Proceedings of IEEE conference on computer vision and pattern recognition (CVPR), 2015) as well as on real robotics data from KITTI (Geiger et al., in: Proceedings of IEEE conference on computer vision and pattern recognition (CVPR), 2012) and Kinect (Yang et al., 3d object dense reconstruction from a single depth view, 2018. arXiv:1802.00411 ), we demonstrate that the proposed amortized maximum likelihood approach is able to compete with the fully supervised baseline of Dai et al. (in: Proceedings of IEEE conference on computer vision and pattern recognition (CVPR), 2017) and outperforms the data-driven approach of Engelmann et al. (in: Proceedings of the German conference on pattern recognition (GCPR), 2016), while requiring less supervision and being significantly faster. David Stutz, Andreas Geiger 0001 |
Int. J. Comput. Vis. | 1 |
| 2019 | Disentangling Adversarial Robustness and GeneralizationabstractObtaining deep networks that are robust against adversarial examples and generalize well is an open problem. A recent hypothesis even states that both robust and accurate models are impossible, i.e., adversarial robustness and generalization are conflicting goals. In an effort to clarify the relationship between robustness and generalization, we assume an underlying, low-dimensional data manifold and show that: 1. regular adversarial examples leave the manifold; 2. adversarial examples constrained to the manifold, i.e., on-manifold adversarial examples, exist; 3. on-manifold adversarial examples are generalization errors, and on-manifold adversarial training boosts generalization; 4. regular robustness and generalization are not necessarily contradicting goals. These assumptions imply that both robust and accurate models are possible. However, different models (architectures, training strategies etc.) can exhibit different robustness and generalization characteristics. To confirm our claims, we present extensive experiments on synthetic data (with known manifold) as well as on EMNIST, Fashion-MNIST and CelebA. David Stutz, Matthias Hein 0001, Bernt Schiele |
CVPR | 1 |
| 2018 | Learning 3D Shape Completion From Laser Scan Data With Weak Supervisionabstract3D shape completion from partial point clouds is a fundamental problem in computer vision and computer graphics. Recent approaches can be characterized as either data-driven or learning-based. Data-driven approaches rely on a shape model whose parameters are optimized to fit the observations. Learning-based approaches, in contrast, avoid the expensive optimization step and instead directly predict the complete shape from the incomplete observations using deep neural networks. However, full supervision is required which is often not available in practice. In this work, we propose a weakly-supervised learning-based approach to 3D shape completion which neither requires slow optimization nor direct supervision. While we also learn a shape prior on synthetic data, we amortize, i.e., learn, maximum likelihood fitting using deep neural networks resulting in efficient shape completion without sacrificing accuracy. Tackling 3D shape completion of cars on ShapeNet [5] and KITTI [18], we demonstrate that the proposed amortized maximum likelihood approach is able to compete with a fully supervised baseline and a state-of-the-art data-driven approach while being significantly faster. On ModelNet [49], we additionally show that the approach is able to generalize to other object categories as well. David Stutz, Andreas Geiger 0001 |
CVPR | 1 |
| 2018 | Superpixels: An evaluation of the state-of-the-art
David Stutz, Alexander Hermans, Bastian Leibe |
Comput. Vis. Image Underst. | 1 |