fully-connected layer
- North America > United States (0.04)
- Europe > United Kingdom (0.04)
- Health & Medicine > Therapeutic Area > Neurology (0.68)
- Health & Medicine > Diagnostic Medicine > Imaging (0.68)
Appendix
The third entry varies under perturbation. Wecan compute the local indicator matrices atthis layer accordingly. We inherit the notations from the main text, and useIL to denote 13 theindicator matrixforlinearReLUoutputs. The key observation from this approach is that we can "merge" the weight matrices together for linearneurons(thefirstterminEq(19)).ThenwehavekW3D2LW2D1LW1k kW3kkW2kkW1k. Consider a neural network that maps inputx to output z = F(x), where z RN.
Appendix
Chen et al., 2021] the adversary aims to steal the trained model functionality. It was shown that in certain cases the adversary can reconstruct the exact parameters of the target model. Fredrikson et al. [2015] showed that a face-recognition model can be used to reconstruct images of a certain person. This is done by using gradient descent for obtaining an input that maximizes the output probability that the face-recognition model assigns to a specific class. That is, they generate images where the target model outputs a high probability for the considered class (as in Fredrikson et al. [2015]), but also encourage realistic images using GAN.
- Asia > China (0.04)
- Asia > Afghanistan > Parwan Province > Charikar (0.04)
- Africa > Mali (0.04)
- Information Technology > Data Science (0.93)
- Information Technology > Artificial Intelligence > Representation & Reasoning (0.71)
- Information Technology > Artificial Intelligence > Natural Language > Large Language Model (0.69)
- Information Technology > Artificial Intelligence > Machine Learning > Neural Networks > Deep Learning (0.68)