{"id":"W2963068442","doi":"10.1109/cvpr.2019.00443","title":"Adversarial Attacks Beyond the Image Space","year":2019,"lang":"en","type":"article","venue":"","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":140,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Toronto","funders":"","keywords":"Rendering (computer graphics); Computer science; Artificial intelligence; Differentiable function; Adversarial system; Pixel; Computer vision; Space (punctuation); Artificial neural network; Image (mathematics); Image translation; Translation (biology); Mathematics","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.00159404,0.001198782,0.0008496945,0.0003119709,0.0004468739,0.001082935,0.001146125,0.00141508,0.002684402],"category_scores_gemma":[0.007538892,0.0004056863,0.0007326391,0.0002437052,0.002546586,0.002560284,0.003379828,0.004079331,0.0005518697],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0007677023,"about_ca_system_score_gemma":0.000509955,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0009505887,"about_ca_topic_score_gemma":0.0008345163,"domain_scores_codex":[0.9985752,0.0005303319,0.00005464418,0.0002723099,0.0004127917,0.0001546663],"domain_scores_gemma":[0.9954004,0.003111896,0.0003336229,0.0008879345,0.0001711427,0.00009504319],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0001986908,0.00005155297,0.0008101767,0.00009653912,0.00009569983,0.0002407826,0.0001111406,0.8046141,0.01112871,0.1430142,0.004173892,0.03546451],"study_design_scores_gemma":[0.00001278021,0.00004843884,0.0001837146,0.00002367288,0.000009909622,0.00009862006,0.00002052348,0.9102845,0.004377087,0.08232595,0.002600913,0.00001399264],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.03290681,0.0003927569,0.9561478,0.001420692,0.0001408609,0.0000699239,0.0001390584,0.0006600978,0.008121971],"genre_scores_gemma":[0.9016285,0.000478553,0.08976597,0.0009362642,0.0001463244,0.0001284266,0.0002442755,0.0002110016,0.006460772],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.002684402,"threshold_uncertainty_score":0.008980274,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.004341876323211905,"score_gpt":0.2323319089576488,"score_spread":0.2279900326344369,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}