{"id":"W4293093392","doi":"10.1109/pst55820.2022.9851981","title":"Careful What You Wish For: on the Extraction of Adversarially Trained Models","year":2022,"lang":"en","type":"preprint","venue":"","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":4,"is_retracted":false,"has_abstract":true,"ca_institutions":"Polytechnique Montréal","funders":"Natural Sciences and Engineering Research Council of Canada; Synopsys","keywords":"Computer science; Adversarial system; Robustness (evolution); Artificial intelligence; Machine learning; Leverage (statistics); Adversarial machine learning; Adversary; Attack model; Computer security","routes":{"ca_aff":true,"ca_fund":true,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.006318576,0.0009975794,0.0007318049,0.0004889567,0.001202786,0.002870997,0.001073461,0.002407186,0.007298386],"category_scores_gemma":[0.04386682,0.0006598957,0.0008932179,0.0004892726,0.002599131,0.007392835,0.003259207,0.005688857,0.005356219],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0008621032,"about_ca_system_score_gemma":0.0009038597,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.001795594,"about_ca_topic_score_gemma":0.002407434,"domain_scores_codex":[0.9941789,0.002506032,0.0002282662,0.000764452,0.002004321,0.0003180128],"domain_scores_gemma":[0.980602,0.009112172,0.001162468,0.006998969,0.001657919,0.0004664213],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.002033843,0.0003768904,0.03213101,0.0006122438,0.000713284,0.002583456,0.003187597,0.1066806,0.03673428,0.1519742,0.1923635,0.4706091],"study_design_scores_gemma":[0.0001102994,0.0003782213,0.00645125,0.000681917,0.0001701649,0.003846714,0.001514802,0.498132,0.05047902,0.2716422,0.1662901,0.0003033962],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1236695,0.002936115,0.724766,0.08399844,0.001672921,0.0003176765,0.001355257,0.007141857,0.05414215],"genre_scores_gemma":[0.7864916,0.001685644,0.1511842,0.02067615,0.0006237371,0.0001871945,0.001524301,0.002200976,0.0354261],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.007298386,"threshold_uncertainty_score":0.03341621,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.05422428654648595,"score_gpt":0.3085886203618194,"score_spread":0.2543643338153335,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}