{"id":"W4383221314","doi":"10.1145/3579856.3582816","title":"Jujutsu: A Two-stage Defense against Adversarial Patch Attacks on Deep Neural Networks","year":2023,"lang":"en","type":"article","venue":"","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":20,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of British Columbia","funders":"Natural Sciences and Engineering Research Council of Canada","keywords":"Adversarial system; Deep neural networks; Computer science; Bounded function; Artificial neural network; Artificial intelligence; Computer security; Mathematics","routes":{"ca_aff":true,"ca_fund":true,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001975385,0.001205781,0.001359109,0.0007262411,0.0008781006,0.001498405,0.002381159,0.002872766,0.002766955],"category_scores_gemma":[0.006195368,0.0005518878,0.0009834321,0.0003076386,0.002133891,0.001995028,0.005572366,0.003499304,0.0008425785],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0006440881,"about_ca_system_score_gemma":0.001105398,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0007009225,"about_ca_topic_score_gemma":0.0009981181,"domain_scores_codex":[0.9983258,0.0003460605,0.00005687051,0.0002449968,0.0007300713,0.0002961266],"domain_scores_gemma":[0.9979545,0.0008950404,0.0001623671,0.0005842915,0.0002441531,0.0001596962],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.001484056,0.0004355643,0.002384806,0.000443319,0.0005014896,0.0007493314,0.000359199,0.4307726,0.06943399,0.1617776,0.04071325,0.2909448],"study_design_scores_gemma":[0.00007028056,0.000286858,0.000300312,0.00004120956,0.00004057585,0.0002002301,0.00002326118,0.9445783,0.01201651,0.0361614,0.006243548,0.00003753375],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.05053512,0.001875632,0.9212202,0.001721829,0.00069912,0.0003237549,0.0001686977,0.007755283,0.01570041],"genre_scores_gemma":[0.8372517,0.0006368748,0.1492417,0.001459488,0.0002521392,0.000361528,0.0003100655,0.0004110431,0.01007553],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.002872766,"threshold_uncertainty_score":0.01044697,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01892275119627844,"score_gpt":0.2824500811946555,"score_spread":0.2635273299983771,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}