{"id":"W4311990442","doi":"10.48550/arxiv.2108.05075","title":"Jujutsu: A Two-stage Defense against Adversarial Patch Attacks on Deep Neural Networks","year":2021,"lang":"en","type":"preprint","venue":"arXiv (Cornell University)","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":1,"is_retracted":false,"has_abstract":true,"ca_institutions":"","funders":"Natural Sciences and Engineering Research Council of Canada","keywords":"Adversarial system; Computer science; Deep neural networks; False positive paradox; Generative grammar; Bounded function; Artificial intelligence; Artificial neural network; Computer security; Machine learning; Mathematics","routes":{"ca_aff":false,"ca_fund":true,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":true},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001771414,0.001413592,0.001140681,0.0006810792,0.0005678217,0.00104125,0.001972388,0.002107102,0.001392345],"category_scores_gemma":[0.006076773,0.0004903147,0.0009064884,0.0002731711,0.002012442,0.001993917,0.003648442,0.002723953,0.0004789492],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.000724114,"about_ca_system_score_gemma":0.0008427596,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.001048632,"about_ca_topic_score_gemma":0.001398546,"domain_scores_codex":[0.9986424,0.0003445981,0.0000564964,0.0002454282,0.0005032056,0.0002078128],"domain_scores_gemma":[0.9971172,0.001302472,0.0002877631,0.0009206521,0.0002321202,0.0001397527],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0006767064,0.0002423318,0.003860649,0.0002257449,0.0002876521,0.0003825634,0.0002071969,0.7339646,0.04239517,0.02688887,0.011449,0.1794195],"study_design_scores_gemma":[0.00002401372,0.000155676,0.0002832179,0.00001429222,0.0000158496,0.0001068614,0.00001277974,0.9832835,0.009026481,0.00579211,0.001269426,0.00001567247],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1145645,0.001558983,0.8660906,0.0009306559,0.0002879039,0.0002885121,0.0001953879,0.009782814,0.006300624],"genre_scores_gemma":[0.8895789,0.0003085982,0.1056735,0.0006026333,0.0001007915,0.0001534924,0.0002787629,0.0002677272,0.00303568],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.002107102,"threshold_uncertainty_score":0.0093683,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.04675489863498341,"score_gpt":0.2123571774155322,"score_spread":0.1656022787805488,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}