Symbol P_bypass
ypass is part of the quantity the equation computes from the expression on the right.
Read this term in its guide →Published equation contexts
Here is the modelling error to avoid. Suppose a request passes n independent detection layers, each of which fails to catch a given malicious input with probability . It is tempting to write the bypass probability of the stack as . and conclude that four layers at ten percent leakage each give one bypass in ten thousand. That number is an artefact of the independence assumption, and the assumption is the weakest part of the model. The layers are typically built from the same model family, trained on overlapping data, and sensitive to the same features of an input; their failures are positively correlated, so the true joint failure probability is larger than the…
ypass is part of the quantity the equation computes from the expression on the right.
Read this term in its guide →i appears in the bound of this product. The bound states where the repeated operation starts, ends, or which values it includes.
Read this term in its guide →n appears in the bound of this product. The bound states where the repeated operation starts, ends, or which values it includes.
Read this term in its guide →This label says where the repeated addition, multiplication, or accumulation starts. Read its value or condition together with the article’s description of the index.
Read this term in its guide →This label says where the repeated addition, multiplication, or accumulation stops. It sets the last term or end of the range.
Read this term in its guide →Read it with the definitions, units, and assumptions supplied by the article.
A symbol can carry a different meaning in another article. Each occurrence keeps its own guide and term definitions.
Equation 3 · AI Security
This equation states an equality: the expressions on both sides have the same value under the article’s assumptions.
Here is the modelling error to avoid. Suppose a request passes n independent detection layers, each of which fails to catch a given malicious input with probability . It is tempting to write the bypass probability of the stack as . and conclude that four layers at ten percent leakage each give one bypass in ten thousand. That number is an artefact of the independence assumption, and the assumption is the weakest part of the model. The layers are typically built from the same model family, trained on overlapping data, and sensitive to the same features of an input; their failures are positively correlated, so the true joint failure probability is larger than the…