{"id":"W4288322434","doi":"10.48550/arxiv.1906.07745","title":"On the Robustness of the Backdoor-based Watermarking in Deep Neural\\n Networks","year":2019,"lang":"en","type":"preprint","venue":"arXiv (Cornell University)","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":19,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Waterloo","funders":"","keywords":"Backdoor; Digital watermarking; Watermark; Robustness (evolution); Computer science; Deep learning; Black box; Artificial neural network; Artificial intelligence; Deep neural networks; Set (abstract data type); White box; Computer security; Data mining; Machine learning; Embedding; Image (mathematics)","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.002595989,0.001257009,0.000761324,0.0008319764,0.0005077762,0.001277809,0.001236707,0.001709566,0.001583082],"category_scores_gemma":[0.01906825,0.0006029351,0.0009273651,0.000478541,0.002498513,0.003652195,0.002997978,0.002569411,0.0003839863],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.001367982,"about_ca_system_score_gemma":0.0006758957,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.001787612,"about_ca_topic_score_gemma":0.001187309,"domain_scores_codex":[0.9984481,0.0004216009,0.00009740743,0.0003076081,0.0004979245,0.0002274377],"domain_scores_gemma":[0.9907485,0.006050108,0.0009798727,0.001515715,0.0005258541,0.0001799485],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.000809915,0.0001044101,0.001800796,0.0001720127,0.0001584396,0.0002248338,0.0001394386,0.8500373,0.02278772,0.05098389,0.001058886,0.07172227],"study_design_scores_gemma":[0.000005620517,0.00005041186,0.0001116388,0.00001276507,0.00001111895,0.00002517899,0.000007084924,0.9862037,0.006006224,0.007388486,0.0001693015,0.000008568803],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.2897858,0.001954046,0.6978036,0.001352751,0.0001721491,0.00005730949,0.0001823673,0.001600643,0.007091472],"genre_scores_gemma":[0.9667036,0.0006220373,0.02960771,0.0001340605,0.00006456051,0.00003004067,0.0001287644,0.000115063,0.002594232],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.002595989,"threshold_uncertainty_score":0.0137291,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.04076673861838839,"score_gpt":0.1826488826764279,"score_spread":0.1418821440580395,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}