type: analytic

attack_type: decepticon-readout
label_strategy: # Labels are not required for this attack, but see tokens on step below:
token_strategy: decoder-bias # This is actually the "token" recovery strategy as labels~=tokens
token_cutoff: 1.5 # if the token strategy is "embedding-norm" and tied embeddings exist, then this is the cutoff
text_strategy: no-preprocessing # Do not cut off the embedding
embedding_token_weight: 0 # Use greedy correlations to the weight embedding in addition to leaked tokens with this weight

normalize_gradients: False

sort_by_bias: False

sentence_algorithm: dynamic-threshold

impl:
  dtype: float
  mixed_precision: False
  JIT: # bembel with care
