{"id":"W7114916806","doi":"10.1162/tacl.a.62","title":"Towards More Realistic Extraction Attacks: An Adversarial Perspective","year":2025,"lang":"en","type":"article","venue":"Transactions of the Association for Computational Linguistics","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":0,"is_retracted":false,"has_abstract":true,"ca_institutions":"Mila - Quebec Artificial Intelligence Institute","funders":"","keywords":"Adversarial system; Adversary; Perspective (graphical); Training set; Memorization; Attack model","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.006008617,0.0009761075,0.0008322574,0.0008660495,0.0009449301,0.002254807,0.001404915,0.002285636,0.003243368],"category_scores_gemma":[0.03709186,0.0005844443,0.0009360754,0.0005581822,0.003194119,0.005162231,0.004250068,0.004898091,0.0008256504],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.001150795,"about_ca_system_score_gemma":0.0008848191,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0007787325,"about_ca_topic_score_gemma":0.0006660346,"domain_scores_codex":[0.9940867,0.003210005,0.0002383044,0.000770865,0.001232906,0.0004611528],"domain_scores_gemma":[0.9582527,0.03105998,0.0017232,0.007544335,0.001053268,0.0003666408],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0003671406,0.0002042413,0.004027377,0.0001784363,0.0001313189,0.0006959915,0.000453261,0.7845139,0.01245065,0.1559333,0.005948925,0.0350955],"study_design_scores_gemma":[0.00001936473,0.00006508721,0.0002884915,0.00003936003,0.00001490737,0.0002390634,0.00006456278,0.9081494,0.005793771,0.08284262,0.002458101,0.00002514296],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1009529,0.0004885882,0.8818971,0.004155521,0.0001829155,0.0002420525,0.0004384346,0.001341145,0.01030138],"genre_scores_gemma":[0.9277842,0.0002472544,0.06723172,0.0008242801,0.00009896348,0.0001281966,0.0002241364,0.0001877965,0.003273391],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.006008617,"threshold_uncertainty_score":0.03177696,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01430245061515127,"score_gpt":0.3394118539592187,"score_spread":0.3251094033440675,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}