{"id":"W3214544808","doi":"10.48550/arxiv.2002.08313","title":"NNoculation: Catching BadNets in the Wild","year":2020,"lang":"en","type":"preprint","venue":"arXiv (Cornell University)","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":1,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Calgary","funders":"","keywords":"Backdoor; Software deployment; Computer science; Adversarial system; Field (mathematics); Computer security; Artificial intelligence; Contrast (vision); Suite; Machine learning; Mathematics; Software engineering","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001577192,0.001437298,0.0008462673,0.0005878028,0.0005123033,0.000813905,0.001748008,0.001798265,0.001344129],"category_scores_gemma":[0.006074015,0.0005216467,0.000717081,0.0001946748,0.002503979,0.003032055,0.003505618,0.002336151,0.0005551073],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0007533783,"about_ca_system_score_gemma":0.0006630787,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0009889934,"about_ca_topic_score_gemma":0.001270288,"domain_scores_codex":[0.998549,0.0003948961,0.00005858734,0.0003484982,0.0003980195,0.0002509052],"domain_scores_gemma":[0.9968232,0.001198454,0.0003598436,0.001259257,0.0002335642,0.0001256366],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0007771586,0.000257703,0.006727297,0.0004919851,0.0003264956,0.0008785839,0.0004478567,0.5757006,0.1012161,0.05592084,0.01186446,0.2453908],"study_design_scores_gemma":[0.00003156413,0.0003926268,0.001072361,0.00008143659,0.00005600136,0.0006281531,0.00007958776,0.9233012,0.04641661,0.02195434,0.005930797,0.0000554011],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1502686,0.001477209,0.8316948,0.001048911,0.0004009522,0.0002439121,0.0001859765,0.006759561,0.007920028],"genre_scores_gemma":[0.9283081,0.0002805306,0.06775182,0.0006757753,0.00005222653,0.0001128292,0.0002037108,0.0002840966,0.002330915],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.001798265,"threshold_uncertainty_score":0.008341134,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.09004250246331236,"score_gpt":0.2089939376827504,"score_spread":0.118951435219438,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}