{"id":"W2990378874","doi":"10.48550/arxiv.1912.00888","title":"Deep Neural Network Fingerprinting by Conferrable Adversarial Examples","year":2019,"lang":"en","type":"preprint","venue":"arXiv (Cornell University)","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":23,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Waterloo","funders":"","keywords":"Computer science; Artificial intelligence; Adversarial system; Fingerprint (computing); Transfer of learning; Artificial neural network; Machine learning; Weighting; Adversary; Data mining; Pattern recognition (psychology); Computer security","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.003993873,0.0009831177,0.0007825016,0.0007115225,0.0004117625,0.0009128937,0.001543064,0.001515494,0.001543239],"category_scores_gemma":[0.02191655,0.0004600082,0.0007355844,0.000478145,0.002328109,0.002796435,0.002600839,0.002944886,0.0004009947],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.001189306,"about_ca_system_score_gemma":0.0005420162,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0008420123,"about_ca_topic_score_gemma":0.0007058666,"domain_scores_codex":[0.9967896,0.001362624,0.0001458715,0.0004941838,0.001004778,0.0002027877],"domain_scores_gemma":[0.988233,0.006335481,0.0009836712,0.003616725,0.000656862,0.0001742573],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0004821031,0.0001121739,0.003121897,0.0001084633,0.0001261554,0.0002433383,0.0001494235,0.8360673,0.01466564,0.03479358,0.002385329,0.1077445],"study_design_scores_gemma":[0.000007844766,0.00005827892,0.0002482515,0.00001087261,0.000007913051,0.00007202845,0.000008438403,0.9794534,0.008911557,0.01066665,0.0005452294,0.000009563696],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.08415513,0.0003587853,0.9104511,0.0005583391,0.00006631483,0.00007817114,0.0001166565,0.001718836,0.002496669],"genre_scores_gemma":[0.884611,0.0001334678,0.1130058,0.00023828,0.00003305814,0.00008156523,0.0001590992,0.0001226529,0.001615093],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.003993873,"threshold_uncertainty_score":0.02112186,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.05084058482975618,"score_gpt":0.194898398786803,"score_spread":0.1440578139570469,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}