EDBT 2026 Demo / reviewers in the wild / expert
Philip Sperl
dblp:247/1101
· DBLP profile ↗
16ranked-venue papers
3as first author
13since 2021 · last 2026
0000-0002-7901-7168ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 12 · 1 first-author · 11 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 6 since 2021Security and privacy · 4 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Security-by-Design for LLM-Based Code Generation: Leveraging Internal Representations for Concept-Driven Steering Mechanisms
Maximilian Wendlinger, Daniel Kowatsch, Konstantin Böttinger, Philip Sperl |
EuroS&P | 4 |
| 2025 | GRASPED: Graph Anomaly Detection Using Autoencoder with Spectral Encoder and DecoderabstractGraph machine learning has been widely explored in various domains, such as community detection, transaction analysis, and recommendation systems. In these applications, anomaly detection plays an important role. Recently, studies have shown that anomalies on graphs induce spectral shifts. Some supervised methods have improved the utilization of such spectral domain information. However, they remain limited by the scarcity of labeled data due to the nature of anomalies. On the other hand, existing unsupervised learning approaches predominantly rely on spatial information or only employ low-pass filters, thereby losing the capacity for multi-band analysis. In this paper, we propose Graph Autoencoder with Spectral Encoder and Spectral Decoder (GRASPED) for node anomaly detection. Our unsupervised learning model features an encoder based on Graph Wavelet Convolution, along with structural and attribute decoders. The Graph Wavelet Convolution-based encoder, combined with a Wiener Graph Deconvolution-based decoder, exhibits bandpass filter characteristics that capture global and local graph information at multiple scales. This design allows for a learning-based reconstruction of node attributes, effectively capturing anomaly information. Extensive experiments on several real-world graph anomaly detection datasets demonstrate that GRASPED outperforms current state-of-the-art models. Wei Herng Choong, Jixing Liu, Ching-Yu Kao, Philip Sperl |
ECAI | 4 |
| 2025 | Replay Attacks Against Audio Deepfake Detectionabstract2245 Nicolas M. Müller, Piotr Kawa, Wei Herng Choong, Adriana Cornelia Stan, Aditya Tirumala Bukkapatnam, Karla Pizzi, Alexander Wagner, Philip Sperl |
INTERSPEECH | 8 |
| 2024 | MLAAD: The Multi-Language Audio Anti-Spoofing DatasetabstractText-to-Speech (TTS) technology brings significant advantages, such as giving a voice to those with speech impairments, but also enables audio deepfakes and spoofs. The former mislead individuals and may propagate misinformation, while the latter undermine voice biometric security systems. AI-based detection can help to address these challenges by automatically differentiating between genuine and fabricated voice recordings. However, these models are only as good as their training data, which currently is severely limited due to an overwhelming concentration on English and Chinese audio in anti-spoofing databases, thus restricting its worldwide effectiveness.In response, this paper presents the Multi-Language Audio Anti-Spoof Dataset (MLAAD), created using 52 TTS models, comprising 22 different architectures, to generate 160.2 hours of synthetic voice in 23 different languages. We train and evaluate three state-of-the-art deepfake detection models with MLAAD, and observe that MLAAD demonstrates superior performance over comparable datasets like InTheWild or FakeOrReal when used as a training resource. Furthermore, in comparison with the renowned ASVspoof 2019 dataset, MLAAD proves to be a complementary resource. In tests across eight datasets, MLAAD and ASVspoof 2019 alternately outperformed each other, both excelling on four datasets.By publishing1MLAAD and making trained models accessible via an interactive webserver2, we aim to democratize antispoofing technology, making it accessible beyond the realm of specialists, thus contributing to global efforts against audio spoofing and deepfakes. Nicolas M. Müller, Piotr Kawa, Wei Herng Choong, Edresson Casanova, Eren Gölge, Piotr Syga, Philip Sperl, Konstantin Böttinger |
IJCNN | 8 |
| 2024 | Shortcut Detection With Variational AutoencodersabstractIn practical machine learning (ML) applications, it is vital for models to make predictions based on robust, generalizable features rather than unreliable data patterns. For example, in supervised classification tasks, a model may mistakenly label an image as ‘horse’ not due to identifying the animal’s traits, but because of a recurring watermark in ‘horse’ images — a learning shortcut. These deceptive shortcuts lead to artificially high performance in training and testing, creating a misleading impression of the model’s actual effectiveness. Such models often fail in real-world scenarios when these accidental correlations are absent. Thus, identifying and addressing these spurious correlations is a critical yet underexplored challenge.In our study, we introduce a new method for detecting such shortcuts in image and audio datasets. We use variational autoencoders (VAE) to separate features in the latent space of the VAE. This enables clear and semi-automatic identification of feature-target correlations in datasets. Our approach’s effectiveness is demonstrated on various real-world datasets, uncovering previously undetected shortcuts. For instance, we find that in fruit classification, the class prediction is influenced chiefly by the camera’s distance from the fruit.Our approach not only sheds light on the intricacies of what machine learning models learn but also aids in circumventing unwanted correlations that might limit their practical effectiveness. The tool is open-source and can be accessed at ANONYMOUS_URL. Nicolas M. Müller, Simon Roschmann, Shahbaz Farooque Khan, Philip Sperl, Konstantin Böttinger |
IJCNN | 4 |
| 2024 | Harder or Different? Understanding Generalization of Audio Deepfake Detectionabstract2705 Nicolas M. Müller, Nicholas W. D. Evans, Hemlata Tak, Philip Sperl, Konstantin Böttinger |
INTERSPEECH | 4 |
| 2024 | A New Approach to Voice Authenticityabstract2245 Nicolas M. Müller, Piotr Kawa, Shen Hu, Matthias Neu, Jennifer Williams 0001, Philip Sperl, Konstantin Böttinger |
INTERSPEECH | 6 |
| 2023 | Protecting Publicly Available Data With Machine Learning Shortcuts
Nicolas M. Müller, Maximilian Burgert, Pascal Debus, Jennifer Williams 0001, Philip Sperl, Konstantin Böttinger |
BMVC | 5 |
| 2023 | Complex-valued neural networks for voice anti-spoofingabstract3814 Nicolas M. Müller, Philip Sperl, Konstantin Böttinger |
INTERSPEECH | 2 |
| 2022 | Anomaly Detection by Recombining Gated Unsupervised ExpertsabstractAnomaly detection has been considered under several extents of prior knowledge. Unsupervised methods do not require any labelled data, whereas semi-supervised methods leverage some known anomalies. Inspired by mixture-of-experts models and the analysis of the hidden activations of neural networks, we introduce a novel data-driven anomaly detection method called ARGUE. Our method is not only applicable to unsupervised and semi-supervised environments, but also profits from prior knowledge of self-supervised settings. We designed ARGUE as a combination of dedicated expert networks, which specialise on parts of the input data. For its final decision, ARGUE fuses the distributed knowledge across the expert systems using a gated mixture-of-experts architecture. Our evaluation motivates that prior knowledge about the normal data distribution may be as valuable as known anomalies. Jan-Philipp Schulze, Philip Sperl, Konstantin Böttinger |
IJCNN | 2 |
| 2022 | Double-Adversarial Activation Anomaly Detection: Adversarial Autoencoders are Anomaly GeneratorsabstractAnomaly detection is a challenging task for machine learning methods due to the inherent class imbalance. It is costly and time-demanding to manually analyse the observed data, thus usually only few known anomalies if any are available. Inspired by generative models and the analysis of the hidden activations of neural networks, we introduce a novel unsupervised anomaly detection method called DA3D. Here, we use adversarial autoencoders to generate anomalous counterexamples based on the normal data only. These artificial anomalies used during training allow the detection of real, yet unseen anomalies. With our novel generative approach, we transform the unsupervised task of anomaly detection to a supervised one, which is more tractable by machine learning and especially deep learning methods. DA3D surpasses the performance of state-of-the-art anomaly detection methods in a purely data-driven way, where no domain knowledge is required. Jan-Philipp Schulze, Philip Sperl, Konstantin Böttinger |
IJCNN | 2 |
| 2022 | R2-AD2: Detecting Anomalies by Analysing the Raw Gradient
Jan-Philipp Schulze, Philip Sperl, Ana Radutoiu, Carla Sagebiel, Konstantin Böttinger |
ECML/PKDD (1) | 2 |
| 2021 | DA3G: Detecting Adversarial Attacks by Analysing Gradients
Jan-Philipp Schulze, Philip Sperl, Konstantin Böttinger |
ESORICS (1) | 2 |
| 2020 | DLA: Dense-Layer-Analysis for Adversarial Example DetectionabstractIn recent years Deep Neural Networks (DNNs) have achieved remarkable results and even showed superhuman capabilities in a broad range of domains. This led people to trust in DNN classifications even in security-sensitive environments like autonomous driving. Despite their impressive achievements, DNNs are known to be vulnerable to adversarial examples. Such inputs contain small perturbations to intentionally fool the attacked model. In this paper, we present a novel end-to-end framework to detect such attacks without influencing the target model's performance. Inspired by research in neuron-coverage guided testing we show that dense layers of DNNs carry security-sensitive information. With a secondary DNN we analyze the activation patterns of the dense layers during classification run-time, which enables effective and real-time detection of adversarial examples. Our prototype implementation successfully detects adversarial examples in image, natural language, and audio processing. Thereby, we cover a variety of target DNN architectures. In addition to effectively defending against state-of-the-art attacks, our approach generalizes between different sets of adversarial examples. Our experiments indicate that we are able to detect future, yet unknown, attacks. Finally, during white-box adaptive attacks, we show our method cannot be easily bypassed. Philip Sperl, Ching-Yu Kao, Xiao Lei, Konstantin Böttinger |
EuroS&P | 1 |
| 2020 | Activation Anomaly Analysis
Philip Sperl, Jan-Philipp Schulze, Konstantin Böttinger |
ECML/PKDD (2) | 1 |
| 2019 | Side-Channel Aware Fuzzing
Philip Sperl, Konstantin Böttinger |
ESORICS (1) | 1 |