KIT | KIT-Bibliothek | Impressum | Datenschutz

Adversarial Attack Detection using Normalizing Flows

Gasimov, Rafig

Abstract (englisch):

The deployment of Deep Neural Networks within the perception pipelines of autonomous driving
systems is critically hindered by their vulnerability to visually inconspicuous adversarial pertur-
bations. In safety-critical applications such as Traffic Sign Recognition, these mathematical ma-
nipulations can force highly confident misclassifications, bypassing traditional Out-of-Distribution
detection mechanisms that rely on compromised softmax probability distributions. To secure these
perception systems without degrading their baseline accuracy, this thesis proposes and engineers
an unsupervised, parallel runtime safety monitor based on exact density estimation utilizing the
multi-scale Glow Normalizing Flow architecture.
The central scientific contribution of this research is a comprehensive, mathematically grounded
ablation study investigating the optimal topological input space for generative anomaly detectors.
The study directly compares an Input-Only flow architecture, which models the exact log-likelihood
of the raw pixel space, against a novel Joint Input-Feature architecture. The joint configuration ex-
tracts intermediate semantic representations from the deep hidden layers of a frozen target classifier,
... mehr


Volltext §
DOI: 10.5445/IR/1000196498
Veröffentlicht am 26.08.2026
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Hochschulschrift
Publikationsdatum 31.03.2026
Sprache Englisch
Identifikator KITopen-ID: 1000196498
Verlag Karlsruher Institut für Technologie (KIT)
Umfang 64
Art der Arbeit Abschlussarbeit - Bachelor
Referent/Betreuer Schotschneider, Albert
Reussner, R.
Zöllner, J. M.
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page