{"id":"W4319863836","doi":"10.1016/j.dcan.2023.01.017","title":"XMAM:X-raying models with a matrix to reveal backdoor attacks for federated learning","year":2023,"lang":"en","type":"article","venue":"Digital Communications and Networks","topic":"Privacy-Preserving Technologies in Data","field":"Computer Science","cited_by":1,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Guelph","funders":"Fundamental Research Funds for the Central Universities; National University's Basic Research Foundation of China","keywords":"Backdoor; Computer science; Softmax function; Computer security; Artificial intelligence; Computer network; Deep learning","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.003296008,0.001474632,0.001207161,0.0006983888,0.0006881108,0.001334252,0.001878459,0.001435857,0.001974066],"category_scores_gemma":[0.009816058,0.0005070954,0.001338598,0.0005520539,0.001222384,0.003295777,0.003992421,0.002813608,0.0006533057],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0009172527,"about_ca_system_score_gemma":0.001487596,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.002245065,"about_ca_topic_score_gemma":0.002026572,"domain_scores_codex":[0.997361,0.000917715,0.0001823974,0.0005311175,0.0007534145,0.0002543525],"domain_scores_gemma":[0.9964922,0.001174322,0.0004159441,0.001378816,0.0003950275,0.0001437637],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.001112585,0.0004096862,0.007298409,0.0002458394,0.0004137473,0.0003974128,0.0003305316,0.518289,0.01126346,0.04043596,0.009472806,0.4103306],"study_design_scores_gemma":[0.00001580281,0.00008656092,0.0002216543,0.0000110604,0.00001599833,0.00006148822,0.00001486272,0.9836142,0.003095731,0.0120103,0.0008405201,0.00001177088],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.02703261,0.0004019284,0.9648068,0.0004895087,0.00009668514,0.00007631724,0.0001392173,0.005895801,0.001061217],"genre_scores_gemma":[0.8057162,0.0002766176,0.1892846,0.000648617,0.00008255817,0.0002184277,0.0004236632,0.0002699381,0.003079186],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.003296008,"threshold_uncertainty_score":0.01743114,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.05717454137579137,"score_gpt":0.3106801690860898,"score_spread":0.2535056277102984,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}