type: analytic

attack_type: decepticon-readout-uncertain
text_strategy: no-preprocessing # Do not cut off the embedding
label_strategy: # Labels are not required for this attack, but see tokens a few steps below:

# Key hyperparameters:
token_strategy: embedding-norm # Decoder bias is not robust enough
token_cutoff: 1.5 # if the token strategy is "embedding-norm" and tied embeddings exist, then this is the cutoff
embedding_token_weight: 0.0 # Risky in the noisy case
sentence_algorithm: k-means # This algorithm decides how sentences are disambiguated

# Experimental hyperparameters:
# Dont worry about these for almost any normal stuff
# recovery_order: positions-first
normalize_gradients: False
# sort_by_bias: False
undivided: False
separation: decorrelation # alternative: simple "subtraction" or None
# backfilling: local # or "global"
# backfill_removal: # None or a separation option
# sentence_based_backfill: False
# breach_reduction: # This risks dropping actual data when measurements are noisy
matcher: corrcoef

omp: True
omp_overestimate_factor: 2

# Implementation Details
impl:
  dtype: float
  mixed_precision: False
  JIT: # bembel with care
