{"id":"W3181970103","doi":"10.1109/cvprw53098.2021.00371","title":"A Watermarking-Based Framework for Protecting Deep Image Classifiers Against Adversarial Attacks","year":2021,"lang":"en","type":"article","venue":"","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":8,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Waterloo","funders":"Natural Sciences and Engineering Research Council of Canada","keywords":"Digital watermarking; Adversarial system; Artificial intelligence; Computer science; Watermark; Deep learning; Encoder; Image (mathematics); Robustness (evolution); Classifier (UML); Pattern recognition (psychology); Adversary; Contextual image classification; Computer vision; Computer security","routes":{"ca_aff":true,"ca_fund":true,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001410766,0.001068513,0.0007257434,0.0009336139,0.000393058,0.0008250878,0.00129704,0.001707011,0.001403391],"category_scores_gemma":[0.004261653,0.0003918895,0.0007224304,0.0004796871,0.001409712,0.002468759,0.001898565,0.001980939,0.0007402936],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0006126066,"about_ca_system_score_gemma":0.0008243069,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0006240788,"about_ca_topic_score_gemma":0.0006915412,"domain_scores_codex":[0.9991844,0.0001536889,0.00005533301,0.0001589822,0.0003385571,0.0001089483],"domain_scores_gemma":[0.9983191,0.0004700662,0.000283955,0.0005587479,0.0002935997,0.00007453597],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.000427565,0.0002355685,0.001813571,0.0002612738,0.0001576752,0.0004048266,0.0001439418,0.3765934,0.1402668,0.05639595,0.005659692,0.4176396],"study_design_scores_gemma":[0.00001595357,0.0001868583,0.0002859276,0.00002792105,0.00003213093,0.000270911,0.0000118334,0.935849,0.04677368,0.01305047,0.003469311,0.00002592688],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"methods","genre_scores_codex":[0.01714231,0.0005804562,0.9791166,0.000273634,0.00007798086,0.00005505393,0.00006993586,0.001366424,0.001317634],"genre_scores_gemma":[0.6138914,0.000849325,0.3798144,0.00040874,0.0001696933,0.0001488923,0.0002880646,0.0001353259,0.004294109],"genre_candidate":"methods","genre_consensus":"methods","teacher_disagreement_score":0.001707011,"threshold_uncertainty_score":0.007460952,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01895271064321068,"score_gpt":0.2922332760152485,"score_spread":0.2732805653720378,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}