{"id":"W4386827564","doi":"10.1016/j.cose.2023.103482","title":"Transferable adversarial distribution learning: Query-efficient adversarial attack against large language models","year":2023,"lang":"en","type":"article","venue":"Computers & Security","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":16,"is_retracted":false,"has_abstract":false,"ca_institutions":"Brock University","funders":"National Natural Science Foundation of China","keywords":"Computer science; Overfitting; Machine learning; Language model; Artificial intelligence; Leverage (statistics); Regularization (linguistics); Adversarial system; Black box; Artificial neural network","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.004041353,0.001414269,0.001977409,0.000762542,0.0006278139,0.001439882,0.002595407,0.002350263,0.003653937],"category_scores_gemma":[0.01511412,0.0006823559,0.0009982184,0.001218328,0.002324083,0.004270989,0.006267514,0.004655101,0.001143185],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.001555263,"about_ca_system_score_gemma":0.001890074,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.002024247,"about_ca_topic_score_gemma":0.001544958,"domain_scores_codex":[0.9969382,0.001095468,0.0001360448,0.000457542,0.0009780738,0.0003946672],"domain_scores_gemma":[0.9909938,0.006521919,0.000352384,0.0014611,0.0004654784,0.000205266],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0007264439,0.0002147425,0.0006898674,0.0001760932,0.0001272039,0.0002089802,0.0001265756,0.7759552,0.008506301,0.07303438,0.01211786,0.1281164],"study_design_scores_gemma":[0.00001675153,0.00002917412,0.00004582412,0.000003764114,0.000005627715,0.00003047843,0.000006455346,0.9769318,0.0009947848,0.02158116,0.0003479233,0.00000634859],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.01489299,0.0004586489,0.979609,0.001044218,0.0001005567,0.00008804904,0.0001902895,0.001539776,0.002076594],"genre_scores_gemma":[0.8475943,0.0005759005,0.141145,0.001047701,0.0002933337,0.0002764251,0.0006556227,0.0003803975,0.008031323],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.004041353,"threshold_uncertainty_score":0.02137303,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01381903665489724,"score_gpt":0.2631415999348444,"score_spread":0.2493225632799472,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}