{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T21:46:39Z","timestamp":1785966399781,"version":"3.56.0"},"publisher-location":"Cham","reference-count":53,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032083234","type":"print"},{"value":"9783032083241","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,10,16]],"date-time":"2025-10-16T00:00:00Z","timestamp":1760572800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,10,16]],"date-time":"2025-10-16T00:00:00Z","timestamp":1760572800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>Model-agnostic explanation methods provide importance scores per feature by analyzing a model\u2019s responses to perturbed versions of the sample to be explained. The explanation\u2019s quality therefore hinges on the made perturbations and, most importantly, suffers if these lead to out-of-distribution samples. Unfortunately, this is the case for the popular <jats:sc>LIME<\/jats:sc> explanation method. In this paper, we thus introduce POMELO, an extension to <jats:sc>LIME<\/jats:sc> leveraging generative AI for full-input, in-distribution sampling. We define key properties of such samplers: distribution alignment, diversity, and locality. Based on these, we discuss different neural samplers based on normalizing flows and diffusion models. Our results demonstrate that neural samplers outperform traditional perturbation strategies and yield explanations that are better aligned with human intuition. Supplementary material to our paper is available at <jats:ext-link xmlns:xlink=\"http:\/\/www.w3.org\/1999\/xlink\" xlink:href=\"https:\/\/intellisec.de\/research\/pomelo\" ext-link-type=\"uri\">https:\/\/intellisec.de\/research\/pomelo<\/jats:ext-link>.<\/jats:p>","DOI":"10.1007\/978-3-032-08324-1_10","type":"book-chapter","created":{"date-parts":[[2025,10,15]],"date-time":"2025-10-15T08:49:56Z","timestamp":1760518196000},"page":"219-243","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["POMELO: Black-Box Feature Attribution with Full-Input, In-Distribution Perturbations"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-6911-3213","authenticated-orcid":false,"given":"Luan","family":"Ademi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1930-8323","authenticated-orcid":false,"given":"Maximilian","family":"Noppel","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-1493-9552","authenticated-orcid":false,"given":"Christian","family":"Wressnegger","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,10,16]]},"reference":[{"issue":"11","key":"10_CR1","doi-asserted-by":"publisher","first-page":"2274","DOI":"10.1109\/TPAMI.2012.120","volume":"34","author":"R Achanta","year":"2012","unstructured":"Achanta, R., Shaji, A., Smith, K., Lucchi, A., Fua, P., S\u00fcsstrunk, S.: SLIC superpixels compared to state-of-the-art superpixel methods. IEEE Trans. Pattern Anal. Mach. Intell. 34(11), 2274\u20132282 (2012)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10_CR2","doi-asserted-by":"crossref","unstructured":"Agarwal, C., Nguyen, A.: Explaining image classifiers by removing input features using generative models. In: Computer Vision - ACCV 2020 - 15th Asian Conference on Computer Vision, Kyoto, Japan, November 30 - December 4, 2020, Revised Selected Papers, Part VI, Lecture Notes in Computer Science, vol. 12627, pp. 101\u2013118 (2020)","DOI":"10.1007\/978-3-030-69544-6_7"},{"key":"10_CR3","doi-asserted-by":"publisher","first-page":"261","DOI":"10.1016\/j.inffus.2021.07.015","volume":"77","author":"CJ Anders","year":"2022","unstructured":"Anders, C.J., Weber, L., Neumann, D., Samek, W., M\u00fcller, K.R., Lapuschkin, S.: Finding and removing clever Hans: using explanation methods to debug and improve deep models. Info. Fusion 77, 261\u2013295 (2022)","journal-title":"Info. Fusion"},{"key":"10_CR4","doi-asserted-by":"crossref","unstructured":"Bach, S., Binder, A., Montavon, G., Klauschen, F., M\u00fcller, K.R., Samek, W.: On pixel-wise explanations for non-linear classifier decisions by Layer-Wise Relevance Propagation. PLOS ONE 77, 46 (2015)","DOI":"10.1371\/journal.pone.0130140"},{"key":"10_CR5","unstructured":"Bluecher, S., Vielhaben, J., Strodthoff, N.: Decoupling pixel flipping and occlusion strategy for consistent XAI benchmarks. Trans. Mach .Learn. Res. 2024 (2024)"},{"key":"10_CR6","unstructured":"Chang, C.H., Creager, E., Goldenberg, A., Duvenaud, D.: Explaining image classifiers by counterfactual generation. In: Proc. of the International Conference on Learning Representations (ICLR) (2019)"},{"key":"10_CR7","unstructured":"Dhariwal, P., Nichol, A.: Diffusion Models Beat GANs on Image Synthesis (2021)"},{"key":"10_CR8","unstructured":"Dinh, L., Krueger, D., Bengio, Y.: NICE: Non-linear independent components estimation. In: Proc. of the International Conference on Learning Representations (ICLR) (2015)"},{"key":"10_CR9","unstructured":"Dinh, L., Sohl-Dickstein, J., Bengio, S.: Density estimation using Real NVP. In: Proc. of the International Conference on Learning Representations (ICLR) (2017)"},{"issue":"5","key":"10_CR10","doi-asserted-by":"publisher","first-page":"3257","DOI":"10.1109\/TPAMI.2023.3339980","volume":"46","author":"AK Dombrowski","year":"2024","unstructured":"Dombrowski, A.K., Gerken, J.E., M\u00fcller, K.R., Kessel, P.: Diffeomorphic counterfactuals with generative models. IEEE Trans. Pattern Anal. Mach. Intell. 46(5), 3257\u20133274 (2024)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10_CR11","doi-asserted-by":"crossref","unstructured":"Fong, R., Vedaldi, A.: Interpretable explanations of black boxes by meaningful perturbation. In: Proc. of the IEEE\/CVF International Conference on Computer Vision (ICCV), pp. 3449\u20133457 (2017)","DOI":"10.1109\/ICCV.2017.371"},{"key":"10_CR12","unstructured":"Goyal, Y., Feder, A., Shalit, U., Kim, B.: Explaining Classifiers with Causal Concept Effect (CaCE). CoRR abs\/1907.07165 (2020)"},{"key":"10_CR13","doi-asserted-by":"crossref","unstructured":"Guo, W., Mu, D., Xu, J., Su, P., Wang, G., Xing, X.: LEMNA: Explaining deep learning based security applications. In: Proc. of the ACM Conference on Computer and Communications Security (CCS), pp. 364\u2013379 (2018)","DOI":"10.1145\/3243734.3243792"},{"key":"10_CR14","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: Proc. of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"10_CR15","doi-asserted-by":"crossref","unstructured":"Hegde, A., Noppel, M., Wressnegger, C.: Model-manipulation attacks against black-box explanations. In: Proc. of the Annual Computer Security Applications Conference (ACSAC) (2024)","DOI":"10.1109\/ACSAC63791.2024.00081"},{"key":"10_CR16","unstructured":"Hendrycks, D., Dietterich, T.G.: Benchmarking neural network robustness to common corruptions and perturbations. In: Proc. of the International Conference on Learning Representations (ICLR) (2019)"},{"key":"10_CR17","unstructured":"Hendrycks, D., Mu, N., Cubuk, E.D., Zoph, B., Gilmer, J., Lakshminarayanan, B.: AugMix: a simple data processing method to improve robustness and uncertainty. In: Proc. of the International Conference on Learning Representations (ICLR) (2020)"},{"key":"10_CR18","unstructured":"Ho, J., Jain, A., Abbeel, P.: Denoising diffusion probabilistic models. In: Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS) (2020)"},{"key":"10_CR19","doi-asserted-by":"crossref","unstructured":"Holzinger, A., Saranti, A., Molnar, C., Biecek, P., Samek, W.: Explainable AI methods - a brief overview. In: Proc. of the International Workshop, beyond Explainable AI (xxAI), Lecture Notes in Computer Science, vol. 13200, pp. 13\u201338 (2020)","DOI":"10.1007\/978-3-031-04083-2_2"},{"key":"10_CR20","unstructured":"Kim, B., et al.: Interpretability beyond feature attribution: quantitative testing with concept activation vectors (TCAV). In: Proc. of the International Conference on Machine Learning (ICML), Proceedings of Machine Learning Research, vol.\u00a080, pp. 2673\u20132682 (2018)"},{"key":"10_CR21","unstructured":"Kingma, D.P., Dhariwal, P.: Glow: generative flow with invertible 1x1 convolutions. In: Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS), pp. 10236\u201310245 (2018)"},{"key":"10_CR22","unstructured":"Krizhevsky, A., et\u00a0al.: Learning multiple layers of features from tiny images. Citeseer (2009)"},{"issue":"1","key":"10_CR23","doi-asserted-by":"publisher","first-page":"1096","DOI":"10.1038\/s41467-019-08987-4","volume":"10","author":"S Lapuschkin","year":"2019","unstructured":"Lapuschkin, S., W\u00e4ldchen, S., Binder, A., Montavon, G., Samek, W., M\u00fcller, K.R.: Unmasking clever Hans predictors and assessing what machines really learn. Nat. Commun. 10(1), 1096 (2019)","journal-title":"Nat. Commun."},{"key":"10_CR24","doi-asserted-by":"crossref","unstructured":"Lee, C.H., Liu, Z., Wu, L., Luo, P.: MaskGAN: towards diverse and interactive facial image manipulation. In: Proc. of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 5548\u20135557 (2020)","DOI":"10.1109\/CVPR42600.2020.00559"},{"key":"10_CR25","unstructured":"Lee, K., Lee, H., Lee, J., Shin: A simple unified framework for detecting out-of-distribution samples and adversarial attacks (2018)"},{"key":"10_CR26","doi-asserted-by":"crossref","unstructured":"Liu, Z., Luo, P., Wang, X., Tang, X.: Deep learning face attributes in the wild. In: Proc. of the IEEE\/CVF International Conference on Computer Vision (ICCV) (2015)","DOI":"10.1109\/ICCV.2015.425"},{"key":"10_CR27","doi-asserted-by":"crossref","unstructured":"Lugmayr, A., Danelljan, M., Romero, A., Yu, F., Timofte, R., Gool, L.V.: RePaint: inpainting using denoising diffusion probabilistic models. In: Proc. of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 11451\u201311461 (2022)","DOI":"10.1109\/CVPR52688.2022.01117"},{"key":"10_CR28","unstructured":"Lundberg, S.M., Lee, S.I.: A unified approach to interpreting model predictions. In: Proc. of the Annual Conference on Neural Information Processing Systems (NIPS), p.\u00a010 (2017)"},{"key":"10_CR29","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. In: Proc. of the International Conference on Learning Representations (ICLR) (2018)"},{"issue":"29","key":"10_CR30","doi-asserted-by":"publisher","first-page":"861","DOI":"10.21105\/joss.00861","volume":"3","author":"L McInnes","year":"2018","unstructured":"McInnes, L., Healy, J., Saul, N., Gro\u00dfberger, L.: UMAP: uniform manifold approximation and projection. J. Open Source Softw. 3(29), 861 (2018)","journal-title":"J. Open Source Softw."},{"issue":"2","key":"10_CR31","doi-asserted-by":"publisher","DOI":"10.1103\/PhysRevE.101.023304","volume":"101","author":"KA Nicoli","year":"2020","unstructured":"Nicoli, K.A., Nakajima, S., Strodthoff, N., Samek, W., M\u00fcller, K.R., Kessel, P.: Asymptotically unbiased estimation of physical observables with neural samplers. Phys. Rev. E: Stat. Phys., Plasmas, Fluids 101(2), 023304 (2020)","journal-title":"Phys. Rev. E: Stat. Phys., Plasmas, Fluids"},{"key":"10_CR32","unstructured":"Petsiuk, V., Das, A., Saenko, K.: RISE: Randomized input sampling for explanation of black-box models. CoRR abs\/1806.07421 (2018)"},{"key":"10_CR33","doi-asserted-by":"crossref","unstructured":"Qiu, L., et al.: Generating perturbation-based explanations with robustness to out-of-distribution data. In: Proc. of the International World Wide Web Conference (WWW), pp. 3594\u20133605 (2022)","DOI":"10.1145\/3485447.3512254"},{"key":"10_CR34","unstructured":"Rezende, D.J., Mohamed, S.: Variational inference with normalizing flows. In: Proc. of the International Conference on Machine Learning (ICML), JMLR Workshop and Conference Proceedings, vol.\u00a037, pp. 1530\u20131538 (2015)"},{"key":"10_CR35","doi-asserted-by":"crossref","unstructured":"Ribeiro, M.T., Singh, S., Guestrin, C.: \"Why Should I Trust You?\": explaining the predictions of any classifier. In: Proc. of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD) (2016)","DOI":"10.18653\/v1\/N16-3020"},{"key":"10_CR36","unstructured":"Rieger, L., Singh, C., Murdoch, W.J., Yu, B.: Interpretations are useful: penalizing explanations to align neural networks with prior knowledge. In: Proc. of the International Conference on Machine Learning (ICML), vol. 119 (2020)"},{"key":"10_CR37","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1016\/0377-0427(87)90125-7","volume":"20","author":"PJ Rousseeuw","year":"1987","unstructured":"Rousseeuw, P.J.: Silhouettes: a graphical aid to the interpretation and validation of cluster analysis. J. Comput. Appl. Math. 20, 53\u201365 (1987)","journal-title":"J. Comput. Appl. Math."},{"key":"10_CR38","unstructured":"Saito, S., Chua, E., Capel, N., Hu, R.: Improving LIME robustness with smarter locality sampling. CoRR abs\/2006.12302 (2020)"},{"key":"10_CR39","unstructured":"Schockaert, C., Macher, V., Schmitz, A.: VAE-LIME: deep generative model based approach for local data-driven model interpretability applied to the ironmaking industry. CoRR abs\/2007.10256 (2020)"},{"issue":"2","key":"10_CR40","doi-asserted-by":"publisher","first-page":"336","DOI":"10.1007\/s11263-019-01228-7","volume":"128","author":"RR Selvaraju","year":"2020","unstructured":"Selvaraju, R.R., Cogswell, M., Das, A., Vedantam, R., Parikh, D., Batra, D.: Grad-CAM: visual explanations from deep networks via gradient-based localization. Int. J. Comput. Vision 128(2), 336\u2013359 (2020)","journal-title":"Int. J. Comput. Vision"},{"key":"10_CR41","unstructured":"Simonyan, K., Vedaldi, A., Zisserman, A.: Deep inside convolutional networks: visualising image classification models and saliency maps. In: Proc. of the International Conference on Learning Representations (ICLR) Workshop Track Proceedings (2014)"},{"key":"10_CR42","doi-asserted-by":"crossref","unstructured":"Slack, D., Hilgard, S., Jia, E., Singh, S., Lakkaraju, H.: Fooling LIME and SHAP: adversarial attacks on post hoc explanation methods. In: Proc. of the AAAI\/ACM Conference AI, Ethics, and Society (AIES), pp. 180\u2013186 (2020)","DOI":"10.1145\/3375627.3375830"},{"key":"10_CR43","unstructured":"Sohl-Dickstein, J., Weiss, E.A., Maheswaranathan, N., Ganguli, S.: Deep unsupervised learning using nonequilibrium thermodynamics. In: Proc. of the International Conference on Machine Learning (ICML), pp. 2256\u20132265 (2015)"},{"key":"10_CR44","unstructured":"Song, J., Meng, C., Ermon, S.: Denoising diffusion implicit models. In: Proc. of the International Conference on Learning Representations (ICLR) (2021)"},{"key":"10_CR45","unstructured":"Song, Y., Ermon, S.: Generative modeling by estimating gradients of the data distribution. In: Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS) (2019)"},{"key":"10_CR46","unstructured":"Sundararajan, M., Taly, A., Yan, Q.: Axiomatic attribution for deep networks. CoRR abs\/1703.01365 (2017)"},{"key":"10_CR47","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. In: Proc. of the International Conference on Learning Representations (ICLR) (2014)"},{"key":"10_CR48","doi-asserted-by":"crossref","unstructured":"Tritscher, J., Lissmann, P., Wolf, M., Krause, A., Hotho, A., Schl\u00f6r, D.: Generative inpainting for shapley-value-based anomaly explanation. In: Proc. of the World Conference on eXplainable Artificial Intelligence (XAI), Communications in Computer and Information Science, vol. 2153, pp. 230\u2013243 (2024)","DOI":"10.1007\/978-3-031-63787-2_12"},{"key":"10_CR49","doi-asserted-by":"crossref","unstructured":"Wang, Z., Bovik, A., Sheikh, H., Simoncelli, E.: Image quality assessment: from error visibility to structural similarity. Proc. of the IEEE Trans. Image Process. 13(4), 600\u2013612 (2004)","DOI":"10.1109\/TIP.2003.819861"},{"key":"10_CR50","doi-asserted-by":"crossref","unstructured":"Warnecke, A., Arp, D., Wressnegger, C., Rieck, K.: Evaluating explanation methods for deep learning in security. In: Proc. of the IEEE European Symposium on Security and Privacy (EuroS &P) (2020)","DOI":"10.1109\/EuroSP48549.2020.00018"},{"key":"10_CR51","doi-asserted-by":"crossref","unstructured":"Wu, H., Bezold, G., G\u00fcnther, M., Boult, T.E., King, M.C., Bowyer, K.W.: Consistency and accuracy of CelebA attribute values. In: Proc. of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 3258\u20133266 (2023)","DOI":"10.1109\/CVPRW59228.2023.00328"},{"key":"10_CR52","unstructured":"Xu, L., Skoularidou, M., Cuesta-Infante, A., Veeramachaneni, K.: Modeling tabular data using conditional GAN. In: Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019, December 8-14, 2019, Vancouver, BC, Canada, pp. 7333\u20137343 (2019)"},{"key":"10_CR53","unstructured":"Ying, R., Bourgeois, D., You, J., Zitnik, M., Leskovec, J.: GNNExplainer: generating explanations for graph neural networks. In: Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS), pp. 9240\u20139251 (2019)"}],"container-title":["Communications in Computer and Information Science","Explainable Artificial Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-08324-1_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,15]],"date-time":"2025-10-15T09:07:43Z","timestamp":1760519263000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-08324-1_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,16]]},"ISBN":["9783032083234","9783032083241"],"references-count":53,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-08324-1_10","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"value":"1865-0929","type":"print"},{"value":"1865-0937","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,16]]},"assertion":[{"value":"16 October 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"xAI","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"World Conference on Explainable Artificial Intelligence","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Istanbul","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"T\u00fcrkiye","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"9 July 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 July 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"xai2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/xaiworldconference.com\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}