{"id":"W3034672496","doi":"","title":"Fundamental Tradeoffs between Invariance and Sensitivity to Adversarial Perturbations","year":2020,"lang":"en","type":"article","venue":"International Conference on Machine Learning","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":34,"is_retracted":false,"has_abstract":true,"ca_institutions":"Vector Institute; University of Toronto","funders":"","keywords":"Adversarial system; Computer science; Invariant (physics); Sensitivity (control systems); Artificial intelligence; Robustness (evolution); Class (philosophy); Machine learning; Theoretical computer science; Mathematics","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.01358345,0.001697897,0.001143346,0.0008600819,0.0008563632,0.002664463,0.00264255,0.002756579,0.002193448],"category_scores_gemma":[0.08327256,0.0009040793,0.001075007,0.000496593,0.006087805,0.006152884,0.006072308,0.006503093,0.0005203863],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.001669867,"about_ca_system_score_gemma":0.0008832967,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0004090682,"about_ca_topic_score_gemma":0.0003489185,"domain_scores_codex":[0.9875832,0.005193582,0.0006093323,0.002026681,0.003720535,0.000866589],"domain_scores_gemma":[0.9171763,0.05771631,0.004501977,0.01741936,0.002132424,0.001053643],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0004284055,0.0001923804,0.004060602,0.0002482032,0.0001839095,0.0004433261,0.0004579003,0.5643301,0.02372356,0.3429634,0.00257529,0.06039296],"study_design_scores_gemma":[0.00003825214,0.0003091987,0.001133386,0.00008278932,0.00004478308,0.0004508888,0.00008764007,0.6697973,0.0129172,0.3131266,0.001955549,0.00005641285],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.06984034,0.0005690632,0.9146304,0.003045439,0.0001140689,0.0001570876,0.0001475433,0.0007990791,0.01069714],"genre_scores_gemma":[0.9324486,0.000419843,0.06419825,0.0005673394,0.000156584,0.0002059161,0.0001481513,0.0001796522,0.001675616],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.01358345,"threshold_uncertainty_score":0.07183701,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.06015761417466957,"score_gpt":0.297905287486453,"score_spread":0.2377476733117834,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}