{"id":"W4384115435","doi":"10.48550/arxiv.2307.05422","title":"Differential Analysis of Triggers and Benign Features for Black-Box DNN Backdoor Detection","year":2023,"lang":"en","type":"preprint","venue":"arXiv (Cornell University)","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":0,"is_retracted":false,"has_abstract":true,"ca_institutions":"","funders":"Tamkeen; York University; Army Research Office; New York University Abu Dhabi","keywords":"Backdoor; Novelty; Computer science; Novelty detection; Artificial intelligence; Detector; Metric (unit); Black box; Artificial neural network; Pattern recognition (psychology); Data mining; Deep learning; Machine learning; Intuition; Engineering","routes":{"ca_aff":false,"ca_fund":true,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":true},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.002256445,0.001201927,0.000861203,0.001269492,0.0003572576,0.001035652,0.001150153,0.00100999,0.001012298],"category_scores_gemma":[0.01114778,0.0003452336,0.0006121956,0.0005182904,0.0009410635,0.001981569,0.001788293,0.001724012,0.0003703374],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.001016658,"about_ca_system_score_gemma":0.0007012435,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0006219349,"about_ca_topic_score_gemma":0.0009595146,"domain_scores_codex":[0.9981812,0.0003656374,0.0001204369,0.0003976104,0.0007643658,0.0001707044],"domain_scores_gemma":[0.9951779,0.002206111,0.001015384,0.0007570259,0.0006322842,0.0002112795],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.00114886,0.0003626972,0.02439889,0.0003269899,0.0003131028,0.0005644765,0.0002329221,0.4527942,0.07803515,0.01743208,0.002948774,0.4214419],"study_design_scores_gemma":[0.000008287858,0.0001094601,0.001738762,0.0000132069,0.00002111275,0.0001184567,0.00001504175,0.9758741,0.01746119,0.004178096,0.0004460624,0.00001619216],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1252591,0.0004860939,0.870105,0.000216254,0.000070888,0.00009781377,0.0001984701,0.00202189,0.001544569],"genre_scores_gemma":[0.8955083,0.0001539974,0.1027123,0.0001213895,0.0000414028,0.000087726,0.0003208763,0.0001237603,0.0009301205],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.002256445,"threshold_uncertainty_score":0.01193333,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.05699921188946427,"score_gpt":0.2144693550188264,"score_spread":0.1574701431293621,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}