{"id":"W4406460297","doi":"10.1109/tps-isa62245.2024.00032","title":"Noise as a Double-Edged Sword: Reinforcement Learning Exploits Randomized Defenses in Neural Networks","year":2024,"lang":"en","type":"article","venue":"","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":1,"is_retracted":false,"has_abstract":true,"ca_institutions":"Ontario Tech University","funders":"","keywords":"SWORD; Reinforcement learning; Exploit; Computer science; Noise (video); Artificial neural network; Artificial intelligence; Computer security; World Wide Web; Image (mathematics)","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.003958617,0.001004186,0.0008461581,0.0005044431,0.0004292698,0.00112629,0.001131505,0.001181816,0.001251903],"category_scores_gemma":[0.01915125,0.0003521827,0.0005112152,0.0002216472,0.001814161,0.001981993,0.001701346,0.002099452,0.0002211246],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0009080817,"about_ca_system_score_gemma":0.0008445692,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.00120214,"about_ca_topic_score_gemma":0.001097452,"domain_scores_codex":[0.9980597,0.000891662,0.00008349922,0.0003577771,0.0003802466,0.000227124],"domain_scores_gemma":[0.9877864,0.00901169,0.001157589,0.00118681,0.0005585625,0.0002989711],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0002318828,0.0000988875,0.003056478,0.00008802235,0.00009487725,0.0001460514,0.0001133267,0.9169198,0.009485721,0.03187571,0.0005932237,0.03729597],"study_design_scores_gemma":[0.00001014828,0.0001137753,0.0002513032,0.00001466858,0.00001096817,0.0000401354,0.00001142605,0.9831803,0.001794376,0.01428182,0.0002808158,0.00001020977],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1883314,0.0004501121,0.8044943,0.00101155,0.0001014056,0.00008974755,0.0000401609,0.0005776547,0.004903748],"genre_scores_gemma":[0.9773258,0.00007614942,0.02152286,0.0001722024,0.00001741603,0.00004331697,0.00001622204,0.00003043982,0.000795586],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.003958617,"threshold_uncertainty_score":0.02093542,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01468093571233063,"score_gpt":0.2739371671525557,"score_spread":0.2592562314402251,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}