{"id":"W2952348804","doi":"10.1145/3437880.3460401","title":"On the Robustness of Backdoor-based Watermarking in Deep Neural Networks","year":2021,"lang":"en","type":"preprint","venue":"","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":26,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Waterloo","funders":"","keywords":"Backdoor; Digital watermarking; Watermark; Robustness (evolution); Computer science; Deep learning; Black box; Artificial neural network; Artificial intelligence; White box; Deep neural networks; Set (abstract data type); Computer security; Data mining; Machine learning; Embedding; Image (mathematics)","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.004849226,0.001304561,0.0009585036,0.001317105,0.0006650181,0.001852925,0.001348164,0.002352576,0.001972025],"category_scores_gemma":[0.03498083,0.0006664,0.0009360451,0.0007815388,0.004961508,0.005744402,0.003815627,0.003308802,0.0004277992],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.001253683,"about_ca_system_score_gemma":0.0006221377,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0005377549,"about_ca_topic_score_gemma":0.0003372609,"domain_scores_codex":[0.9965165,0.001260814,0.0002015635,0.0005871822,0.00100475,0.0004291605],"domain_scores_gemma":[0.9708911,0.02048298,0.00242493,0.004922808,0.0009656547,0.0003124876],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.000873549,0.0001240068,0.001616026,0.0002496798,0.0002056579,0.0002453514,0.0002473017,0.7677126,0.03175962,0.1136182,0.001364411,0.08198364],"study_design_scores_gemma":[0.00002084263,0.0001331405,0.0002105258,0.00003753982,0.00002391632,0.00009057564,0.00002478563,0.9352448,0.01940722,0.04425884,0.0005208757,0.00002695681],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1979478,0.001924257,0.7913657,0.001413522,0.0001381967,0.00007826197,0.000138987,0.001259276,0.005734036],"genre_scores_gemma":[0.9618256,0.0006281541,0.0354733,0.0001436479,0.00007614189,0.00003932111,0.00007168719,0.0001181336,0.001623989],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.004849226,"threshold_uncertainty_score":0.02564543,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01835376667416081,"score_gpt":0.2495340389262994,"score_spread":0.2311802722521386,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}