{"id":"W4409348661","doi":"10.1609/aaai.v39i27.35029","title":"J&amp;H: Evaluating the Robustness of Large Language Models Under Knowledge-Injection Attacks in Legal Domain","year":2025,"lang":"en","type":"article","venue":"Proceedings of the AAAI Conference on Artificial Intelligence","topic":"Topic Modeling","field":"Computer Science","cited_by":2,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Waterloo","funders":"","keywords":"Robustness (evolution); Computer science; Computer security; Chemistry; Biochemistry","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"codex-gemma-dda1882f352a","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001734167,0.0001844006,0.0002634179,0.0002032465,0.000176285,0.0001480577,0.001874535,0.00009861163,0.00001449402],"category_scores_gemma":[0.0003064786,0.0001272006,0.0001030506,0.001074897,0.0001476269,0.0004319989,0.000575087,0.0003849994,0.000006930497],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.00008726372,"about_ca_system_score_gemma":0.0002275925,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0001533061,"about_ca_topic_score_gemma":0.0002820426,"domain_scores_codex":[0.9980953,0.00006607828,0.0006551776,0.0004466526,0.0004066922,0.0003300424],"domain_scores_gemma":[0.9985166,0.0001805495,0.0003090985,0.0004311988,0.00053175,0.00003076824],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"theoretical_or_conceptual","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.00003589991,0.0001307811,0.00007931345,0.00005831203,0.00001100915,8.702437e-8,0.004476894,0.04242124,0.01391663,0.9147268,0.00002589307,0.02411718],"study_design_scores_gemma":[0.0000476776,0.00005765909,0.00006999465,0.0003627914,0.000008497427,0.000001730702,0.002718335,0.7988989,0.04480954,0.1528997,0.00001169012,0.0001134449],"study_design_candidate":"theoretical_or_conceptual","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.4916746,0.0000653377,0.4986727,0.001584417,0.0003999951,0.0003192895,0.000001432452,0.00003549354,0.007246747],"genre_scores_gemma":[0.9941404,0.000008089057,0.005184967,0.0001017324,0.00004657444,0.00003088516,2.756287e-7,0.000007563986,0.0004794976],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.7618271,"threshold_uncertainty_score":0.5187088,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.1260834055039945,"score_gpt":0.3864990687183631,"score_spread":0.2604156632143686,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}