← Search

Jan Hendrik Metzen

15 accepted papers

2024

Label-free Neural Semantic Image Synthesis

ECCV 2024poster

"Recent work has shown great progress in integrating spatial conditioning to control large, pre-trained text-to-image diffusion models. Despite these advances, existing methods describe the spatial image content using hand-crafted conditioning inputs, which are either semantically ambiguous (e.g., e…

Cited by 1SourcePDFScholar
2023

Certified Defences Against Adversarial Patch Attacks on Semantic Segmentation

ICLR 2023poster

Adversarial patch attacks are an emerging security threat for real world deep learning applications. We present Demasked Smoothing, the first approach (up to our knowledge) to certify the robustness of semantic segmentation models against this threat model. Previous work on certifiably defending aga…

Cited by 19SourcePDFScholar
2023

Identification of Systematic Errors of Image Classifiers on Rare Subgroups

ICCV 2023poster

Despite excellent average-case performance of many image classifiers, their performance can substantially deteriorate on semantically coherent subgroups of the data that were under-represented in the training data. These systematic errors can impact both fairness for demographic minority groups as w…

Cited by 22PDFScholar
2022

Give Me Your Attention: Dot-Product Attention Considered Harmful for Adversarial Patch Robustness

CVPR 2022poster

Neural architectures based on attention such as vision transformers are revolutionizing image recognition. Their main benefit is that attention allows reasoning about all parts of a scene jointly. In this paper, we show how the global reasoning of (scaled) dot-product attention can be the source of…

Cited by 47PDFScholar
2021

Does enhanced shape bias improve neural network robustness to common corruptions?

ICLR 2021poster

Convolutional neural networks (CNNs) learn to extract representations of complex features, such as object shapes and textures to solve image recognition tasks. Recent work indicates that CNNs trained on ImageNet are biased towards features that encode textures and that these alone are sufficient to…

Cited by 44SourcePDFScholar
2021

Meta-Learning the Search Distribution of Black-Box Random Search Based Adversarial Attacks

NeurIPS 2021poster

Adversarial attacks based on randomized search schemes have obtained state-of-the-art results in black-box robustness evaluation recently. However, as we demonstrate in this work, their efficiency in different query budget regimes depends on manual design and heuristic tuning of the underlying propo…

2020

Meta-Learning of Neural Architectures for Few-Shot Learning

CVPR 2020oral

The recent progress in neural architecture search (NAS) has allowed scaling the automated design of neural architectures to real-world domains, such as object detection and semantic segmentation. However, one prerequisite for the application of NAS are large amounts of labeled data and compute resou…

Cited by 201PDFcodeScholar
2019

Defending Against Universal Perturbations With Shared Adversarial Training

ICCV 2019poster

Classifiers such as deep neural networks have been shown to be vulnerable against adversarial perturbations on problems with high-dimensional input space. While adversarial training improves the robustness of image classifiers against such adversarial perturbations, it leaves them sensitive to pertu…

Cited by 71PDFScholar
2019

Efficient Multi-Objective Neural Architecture Search via Lamarckian Evolution

ICLR 2019poster

Architecture search aims at automatically finding neural architectures that are competitive with architectures designed by human experts. While recent approaches have achieved state-of-the-art predictive performance for image recognition, they are problematic under resource constraints for two reaso…

Cited by 694SourcePDFScholar
2018

Simple and efficient architecture search for Convolutional Neural Networks

ICLR 2018workshop

Neural networks have recently had a lot of success for many tasks. However, neural network architectures that perform well are still typically designed manually by experts in a cumbersome trial-and-error process. We propose a new method to automatically search for well-performing CNN architectures b…

Cited by 323SourceScholar
2017

Universal Adversarial Perturbations Against Semantic Image Segmentation

ICCV 2017poster

While deep learning is remarkably successful on perceptual tasks, it was also shown to be vulnerable to adversarial perturbations of the input. These perturbations denote noise added to the input that was generated specifically to fool the system while being quasi-imperceptible for humans. More seve…

Cited by 311PDFScholar