Thinking about the "attack success rate" evaluation in $4.2, as well as the included context focusing on explicit characterization of the symmetries, can you explain the RMS computation and how it does or doesn't respect symmetry
Thinking about the "attack success rate" evaluation in $4.2, as well as the included context focusing on explicit characterization of the symmetries, can you explain the RMS computation and how it does or doesn't respect symmetry
Looking at §4.2 Full Layer Extraction I am particularly curious about the structure of since in a few other cases (context transcluded) some questions I've had have come down to what are the relevant symmetries and how do we characterize them?