{"id":{"repo_id":"cambridge","oai_identifier":"oai:www.repository.cam.ac.uk:1810/382976"},"canonical_url":"https://search.dev.ndltd.org/etd/cambridge/oai:www.repository.cam.ac.uk:1810/382976","repository":{"repo_id":"cambridge","name":"Cambridge University","base_url":"https://api.repository.cam.ac.uk/server/oai/request"},"display":{"title":"Anomalous Inputs in Deep Learning: a Probabilistic Perspective","abstract":"Can neural networks recognize their own limitations? A crucial aspect of robustness is the ability to identify when an input falls outside the scope of one’s knowledge or training --- a task known as out-of-distribution (OOD) detection. For example, a dog breed classifier should ideally recognize a cat image as OOD and refrain from classifying it as a breed of dog. Conversely, can we manipulate neural networks into making confident but incorrect classifications? This task, known as adversarial attack, involves altering an input to be misclassified while preserving its original semantic content. Both of these tasks are concerned with anomalous inputs to a neural network, but they have so far been addressed by two different bodies of literature, using different sets of tools. In this thesis I introduce a probabilistic framework that I call the `three distribution problem', which unifies both tasks. I use this framework to develop new methods for detecting OOD inputs and for creating adversarial attacks. Furthermore, my three-distribution approach gives insight into how `semantics' is operationalized: I demonstrate how we can visualize the semantics implicit in off-the-shelf OOD detection algorithms; and my adversarial attack method allows the attacker to specify explicitly the semantics that are to be preserved by the attack.","abstract_html":"Can neural networks recognize their own limitations? A crucial aspect of robustness is the ability to identify when an input falls outside the scope of one’s knowledge or training --- a task known as out-of-distribution (OOD) detection. For example, a dog breed classifier should ideally recognize a cat image as OOD and refrain from classifying it as a breed of dog. Conversely, can we manipulate neural networks into making confident but incorrect classifications? This task, known as adversarial attack, involves altering an input to be misclassified while preserving its original semantic content. Both of these tasks are concerned with anomalous inputs to a neural network, but they have so far been addressed by two different bodies of literature, using different sets of tools. In this thesis I introduce a probabilistic framework that I call the `three distribution problem&#x27;, which unifies both tasks. I use this framework to develop new methods for detecting OOD inputs and for creating adversarial attacks. Furthermore, my three-distribution approach gives insight into how `semantics&#x27; is operationalized: I demonstrate how we can visualize the semantics implicit in off-the-shelf OOD detection algorithms; and my adversarial attack method allows the attacker to specify explicitly the semantics that are to be preserved by the attack.","abstract_has_math":false,"creators":["Zhang, Andi"],"institution":"University of Cambridge","degree_name":"Doctor of Philosophy (PhD)","degree_level":"Doctoral","degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":["Wischik, Damon"],"committee_chairs":[],"committee_members":[],"year":2024,"date_issued":"2024-07-31","date_published":"2024-07-31","updated_at":"2026-07-22T22:24:30Z","subjects":["Probabilistic Generative Models","OOD Detection","Adversarial Examples"],"languages":["eng"],"rights":[],"rights_urls":["https://apollo8-f-pro.lib.cam.ac.uk/bitstreams/257007ef-9a44-4be5-b942-c1a7edc602ad/download","https://creativecommons.org/licenses/by/4.0/"],"identifier_entries":[]},"links":{"outbound_url":"https://doi.org/10.17863/CAM.117540","outbound_label":"DOI","outbound_source":"dc:identifier.doi"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Wischik, Damon"]},{"key":"dc:contributor.sponsor","label":"Sponsor","values":["Andi Zhang acknowledges the generous personal grant from Ms. Yanshu Wu that supported his entire PhD research."]},{"key":"dc:creator","label":"Author","values":["Zhang, Andi"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.issued","label":"Date","values":["2024-07-31"]},{"key":"dc:publisher.institution","label":"Dc Publisher Institution","values":["University of Cambridge"]},{"key":"dc:relation.isreferencedby.uri","label":"Dc Relation Isreferencedby URI","values":["https://www.repository.cam.ac.uk/handle/1810/382976"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"dc:type.qualificationlevel","label":"Dc Type Qualificationlevel","values":["Doctoral"]},{"key":"dc:type.qualificationname","label":"Dc Type Qualificationname","values":["Doctor of Philosophy (PhD)"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Probabilistic Generative Models","OOD Detection","Adversarial Examples"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["https://apollo8-f-pro.lib.cam.ac.uk/bitstreams/257007ef-9a44-4be5-b942-c1a7edc602ad/download","https://creativecommons.org/licenses/by/4.0/"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.doi","label":"DOI","values":["https://doi.org/10.17863/CAM.117540"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://apollo8-f-pro.lib.cam.ac.uk/bitstreams/733d175e-355d-4116-bf47-7c6623f5b539/download"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Can neural networks recognize their own limitations? A crucial aspect of robustness is the ability to identify when an input falls outside the scope of one’s knowledge or training --- a task known as out-of-distribution (OOD) detection. For example, a dog breed classifier should ideally recognize a cat image as OOD and refrain from classifying it as a breed of dog. Conversely, can we manipulate neural networks into making confident but incorrect classifications? This task, known as adversarial attack, involves altering an input to be misclassified while preserving its original semantic content. Both of these tasks are concerned with anomalous inputs to a neural network, but they have so far been addressed by two different bodies of literature, using different sets of tools. In this thesis I introduce a probabilistic framework that I call the `three distribution problem', which unifies both tasks. I use this framework to develop new methods for detecting OOD inputs and for creating adversarial attacks. Furthermore, my three-distribution approach gives insight into how `semantics' is operationalized: I demonstrate how we can visualize the semantics implicit in off-the-shelf OOD detection algorithms; and my adversarial attack method allows the attacker to specify explicitly the semantics that are to be preserved by the attack."]},{"key":"dc:format.checksum.md5","label":"Dc Format Checksum Md5","values":["41c988bbacf98b9858c3a2e5274c10a6","87eda9de84448d1f82354d60eee3eb5f"]},{"key":"dc:title","label":"Title","values":["Anomalous Inputs in Deep Learning: a Probabilistic Perspective"]}]}],"canonical_facts":{"dc:contributor.advisor":["Wischik, Damon"],"dc:contributor.sponsor":["Andi Zhang acknowledges the generous personal grant from Ms. Yanshu Wu that supported his entire PhD research."],"dc:creator":["Zhang, Andi"],"dc:date.issued":["2024-07-31"],"dc:description.abstract":["Can neural networks recognize their own limitations? A crucial aspect of robustness is the ability to identify when an input falls outside the scope of one’s knowledge or training --- a task known as out-of-distribution (OOD) detection. For example, a dog breed classifier should ideally recognize a cat image as OOD and refrain from classifying it as a breed of dog. Conversely, can we manipulate neural networks into making confident but incorrect classifications? This task, known as adversarial attack, involves altering an input to be misclassified while preserving its original semantic content. Both of these tasks are concerned with anomalous inputs to a neural network, but they have so far been addressed by two different bodies of literature, using different sets of tools. In this thesis I introduce a probabilistic framework that I call the `three distribution problem', which unifies both tasks. I use this framework to develop new methods for detecting OOD inputs and for creating adversarial attacks. Furthermore, my three-distribution approach gives insight into how `semantics' is operationalized: I demonstrate how we can visualize the semantics implicit in off-the-shelf OOD detection algorithms; and my adversarial attack method allows the attacker to specify explicitly the semantics that are to be preserved by the attack."],"dc:format.checksum.md5":["41c988bbacf98b9858c3a2e5274c10a6","87eda9de84448d1f82354d60eee3eb5f"],"dc:identifier.doi":["https://doi.org/10.17863/CAM.117540"],"dc:identifier.uri":["https://apollo8-f-pro.lib.cam.ac.uk/bitstreams/733d175e-355d-4116-bf47-7c6623f5b539/download"],"dc:language":["eng"],"dc:publisher.institution":["University of Cambridge"],"dc:relation.isreferencedby.uri":["https://www.repository.cam.ac.uk/handle/1810/382976"],"dc:rights":["https://apollo8-f-pro.lib.cam.ac.uk/bitstreams/257007ef-9a44-4be5-b942-c1a7edc602ad/download","https://creativecommons.org/licenses/by/4.0/"],"dc:subject":["Probabilistic Generative Models","OOD Detection","Adversarial Examples"],"dc:title":["Anomalous Inputs in Deep Learning: a Probabilistic Perspective"],"dc:type":["Thesis"],"dc:type.qualificationlevel":["Doctoral"],"dc:type.qualificationname":["Doctor of Philosophy (PhD)"]},"updated_at":"2026-07-22T22:24:30Z"}