Pith. sign in

REVIEW 2 cited by

Probabilistic Modeling of Deep Features for Out-of-Distribution and Adversarial Detection

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1909.11786 v1 pith:ZNEFWMYS submitted 2019-09-25 stat.ML cs.LG

classification stat.MLcs.LG
keywords adversarialfeaturesdeepsamplesapproachdetectingdistributionsmodeling
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

We present a principled approach for detecting out-of-distribution (OOD) and adversarial samples in deep neural networks. Our approach consists in modeling the outputs of the various layers (deep features) with parametric probability distributions once training is completed. At inference, the likelihoods of the deep features w.r.t the previously learnt distributions are calculated and used to derive uncertainty estimates that can discriminate in-distribution samples from OOD samples. We explore the use of two classes of multivariate distributions for modeling the deep features - Gaussian and Gaussian mixture - and study the trade-off between accuracy and computational complexity. We demonstrate benefits of our approach on image features by detecting OOD images and adversarially-generated images, using popular DNN architectures on MNIST and CIFAR10 datasets. We show that more precise modeling of the feature distributions result in significantly improved detection of OOD and adversarial samples; up to 12 percentage points in AUPR and AUROC metrics. We further show that our approach remains extremely effective when applied to video data and associated spatio-temporal features by detecting adversarial samples on activity classification tasks using UCF101 dataset, and the C3D network. To our knowledge, our methodology is the first one reported for reliably detecting white-box adversarial framing, a state-of-the-art adversarial attack for video classifiers.

Discussion (0). Sign in to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Quantitative Benchmarking of Anomaly Detection Methods in Digital Pathology

    eess.IV 2025-06 conditional novelty 5.0 of 10

    A systematic comparison of 23 anomaly detection methods on pathology and industrial image datasets shows that feature distribution methods generally outperform reconstruction and distillation methods, and that epoch s...

  2. Zero-Shot Anomaly Detection in Battery Thermal Images Using Visual Question Answering with Prior Knowledge

    cs.CV 2025-05 conditional novelty 4.0 of 10

    ChatGPT-4o, prompted with prior knowledge about normal battery temperature patterns, detects battery thermal anomalies at 86.6% AUC without training, though most trained methods score higher.

Pith tools