{"id":"W4206060246","doi":"10.1109/access.2021.3133334","title":"You Can’t Fool All the Models: Detect Adversarial Samples via Pruning Models","year":2021,"lang":"en","type":"article","venue":"IEEE Access","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":5,"is_retracted":false,"has_abstract":true,"ca_institutions":"","funders":"Natural Science Foundation of Zhejiang Province; National Natural Science Foundation of China; Canadian Institute for Advanced Research","keywords":"Computer science; Adversarial system; Pruning; Artificial intelligence; Machine learning; Deep neural networks; Artificial neural network; FLOPS; Deep learning; Sample (material); Pattern recognition (psychology)","routes":{"ca_aff":false,"ca_fund":true,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":true},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001847171,0.001135606,0.0009708992,0.0009016219,0.0004906759,0.0007912016,0.001528204,0.001489871,0.0009884533],"category_scores_gemma":[0.008204512,0.0005252218,0.0008687837,0.0003920726,0.001136534,0.002589777,0.001759333,0.002621397,0.0004055576],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0006442054,"about_ca_system_score_gemma":0.0008760886,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.002514763,"about_ca_topic_score_gemma":0.003317601,"domain_scores_codex":[0.9986297,0.0004186826,0.00004584651,0.0002718518,0.000469955,0.0001640296],"domain_scores_gemma":[0.9964161,0.00168668,0.0004456229,0.0009725866,0.0003438307,0.0001351318],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0004727224,0.0002055592,0.007349858,0.000113899,0.0002554469,0.000500876,0.0002551444,0.6759916,0.02998699,0.02806489,0.007245144,0.2495579],"study_design_scores_gemma":[0.000007840667,0.0000528464,0.0003504031,0.00001254469,0.00001797357,0.0001213768,0.00001191676,0.9882525,0.004669251,0.005825609,0.0006677873,0.00000997263],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1006421,0.0007133575,0.8934352,0.000711989,0.00008169399,0.00009547116,0.0001071296,0.001763042,0.002450004],"genre_scores_gemma":[0.800249,0.0003448367,0.1959677,0.0005752754,0.00005628983,0.0000877948,0.0002757261,0.0001818233,0.002261625],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.002514763,"threshold_uncertainty_score":0.009768903,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.0766063510594319,"score_gpt":0.3066038086844982,"score_spread":0.2299974576250662,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}