{"id":"W2994896922","doi":"","title":"Thieves of Sesame Street: Model Extraction on BERT-based APIs","year":2020,"lang":"en","type":"article","venue":"arXiv (Cornell University)","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":32,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Toronto","funders":"","keywords":"Computer science; Heuristics; Adversary; Language model; Set (abstract data type); Artificial intelligence; Task (project management); Exploit; Inference; Natural language processing; Computer security; Programming language","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.002730815,0.0006549297,0.0006055064,0.000655083,0.0008575632,0.001435213,0.001156424,0.00181127,0.002951501],"category_scores_gemma":[0.01554048,0.0004381128,0.001252107,0.0006387919,0.002176261,0.005744092,0.003203314,0.002712383,0.001261357],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.000984663,"about_ca_system_score_gemma":0.0005527352,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.002331291,"about_ca_topic_score_gemma":0.002216363,"domain_scores_codex":[0.9979989,0.0007594268,0.00007741632,0.0003193976,0.0006854584,0.0001592694],"domain_scores_gemma":[0.9928542,0.004096706,0.0003689968,0.002306245,0.0002588087,0.0001149913],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.001067164,0.0003639528,0.007951781,0.0002936443,0.0001847172,0.002148357,0.001240716,0.517179,0.02658779,0.2182693,0.02727517,0.1974385],"study_design_scores_gemma":[0.00001762656,0.000046387,0.000391167,0.00001444011,0.00001288896,0.0002415379,0.00006512619,0.9205621,0.01170146,0.06176965,0.005159678,0.00001792833],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.2428067,0.0005426108,0.7302661,0.006139916,0.0001602775,0.0001691037,0.0009503106,0.008409563,0.01055554],"genre_scores_gemma":[0.8838344,0.0002378682,0.1057391,0.0008757089,0.00007063011,0.00008524119,0.001319099,0.0007607416,0.007077225],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.002951501,"threshold_uncertainty_score":0.01444209,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.08559918538337095,"score_gpt":0.2027448491080314,"score_spread":0.1171456637246604,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}