---
title: 'Marksman: A Multi-Domain Analysis'
url: https://www.emergentmind.com/topics/marksman
type: topic
---

# Marksman: A Multi-Domain Analysis

Searching arXiv for recent and relevant papers on “Marksman” and associated senses.
I’ll look up the cited arXiv papers to ground the article in current literature.
“Marksman” appears in the cited literature in several technically distinct senses: as the shooting performer in professional biathlon, as the player in the many-player silent duel, as the name of a backdoor-attack framework with arbitrary target class, and, by implication, as a role-aligned archetype handled through “scaling carry / damage carry” guardrails in player-conditional champion recommendation [2411.02000] [1712.00274] [2210.09194] [2605.18338]. Across these usages, the term is attached not to a single ontology but to a family of problems organized around hit–miss structure, target selection, context dependence, and strategic or probabilistic control.

## 1. Disciplinary scope of the term

In the available arXiv literature, “marksman” is not restricted to one research domain. In biathlon analytics it denotes the athlete whose shooting quality is observed through repeated 5-shot bouts and modeled using a Bayesian hierarchical framework. In game theory it denotes an identical player in a silent duel who chooses a firing distance under uncertainty and strategic interaction. In machine learning security it is the proper name of a backdoor attack that enables arbitrary target-class selection at inference time. In the League of Legends ranking framework, the paper does not use the word “Marksman” explicitly, but it is designed to handle roles or archetypes like Marksman through “scaling carry / damage carry” archetypes and an archetype guardrail [2411.02000] [1712.00274] [2210.09194] [2605.18338].

| Context | Meaning of “marksman” | Technical object |
|---|---|---|
| Professional biathlon | Elite shooter observed by 5-shot bouts | Binomial hit process with athlete, position, race-type, and stage effects |
| Silent duel | Symmetric strategic player with one shot | Mixed strategy over firing distance \(x\) |
| ML security | Name of a backdoor attack framework | Class-conditional trigger generator \(T(c,x)\) |
| Champion ranking | Role-like archetype implication | “Scaling carry / damage carry” guardrail within \(R(c)\) |

This plurality matters because the term can otherwise invite a misleadingly unitary reading. The cited works instead use it as a domain-specific label for distinct formal objects: an athlete, a strategic agent, a malicious payload mechanism, or a role-constrained recommendation target.

## 2. Marksman performance in professional biathlon

In the biathlon study, the empirical object is the 2021/22 Women’s Biathlon World Cup season, including Beijing 2022 Olympics, with 26 races: 10 sprint, 3 individual, 8 pursuit, and 5 mass start. The sample consists of the top 30 women based on end-of-season overall ranking, and the unit of analysis is each shooting session or bout, defined as one 5-shot bout at the range. The outcome is \(Y_i\), the number of hits in \(\{0,1,2,3,4,5\}\). The dataset contains 2,088 shooting sessions, 10,440 shots, and 8,788 hits, for an overall hit rate of 84.2% [2411.02000].

The descriptive statistics give a concrete operational meaning to “being a good marksman” in this setting. Overall accuracy is 84.2%; prone accuracy is 86.5%; standing accuracy is 81.9%. Twenty-four of 30 athletes had better accuracy in prone than standing, though a few had the reverse, including Elvira Öberg and Julia Braisaz-Bouchet. Raw race-type averages are 84.5% in individual, 83.2% in sprint, 85.1% in pursuit, and 83.6% in mass start. The athlete-level range is also substantial: season-long overall hit rates run from about 91.5% and 91.0% at the top to about 73%–76% at the lower end of this elite cohort [2411.02000].

The study explicitly rejects an overly reductive notion of marksmanship as a single aggregate percentage. Stage-dependent performance varies across the season, with Oberhof and the Olympic Games singled out as stages where the model slightly overestimates accuracy; the paper attributes this to technically difficult conditions, unique pressure, and different snow conditions. Athlete trajectories are non-monotonic, and there is no clear relationship between final ranking and consistently high dynamic shooting deviations. Spearman rank correlations between end-of-season rank and shooting accuracy are weak: \(\rho=-0.148\) for overall shooting and \(\rho=-0.231\) for standing shooting, the latter being the strongest relationship reported. This means that strong marksmanship helps, especially in standing, but does not determine seasonal success on its own [2411.02000].

## 3. Bayesian decomposition of biathlon marksmanship

The biathlon paper models each bout as
\[
Y_i \sim \text{Binomial}(5,p_i),
\]
with
\[
\text{logit}(p_i)=\mu_{t[i]}+\beta_{s[i],t[i]}+\gamma_{s[i],x[i]}+\omega_{s[i],z[i]}.
\]
Here \(\mu_t\) is the stage baseline, \(\beta_{s,t}\) is the dynamic athlete effect, \(\gamma_{s,x}\) is the position-specific athlete effect, and \(\omega_{s,z}\) is the race-type-specific athlete effect. The model therefore decomposes a marksman’s hit probability into common stage difficulty, athlete-specific time-varying quality, stable prone-versus-standing structure, and stable race-format preferences or weaknesses [2411.02000].

Two components evolve over stages with a Markov random-walk structure:
\[
\mu_1 \sim \mathcal{N}(0,\tau_\mu), \qquad \mu_t\mid \mu_{t-1}\sim \mathcal{N}(\mu_{t-1},\tau_\mu),
\]
and
\[
\beta_{s,1}\sim \mathcal{N}(0,\tau_\beta), \qquad \beta_{s,t}\mid \beta_{s,t-1}\sim \mathcal{N}(\beta_{s,t-1},\tau_\beta).
\]
Position and race-type effects are time-constant:
\[
\gamma_{s,x}\sim \mathcal{N}(0,\tau_\gamma), \qquad \omega_{s,z}\sim \mathcal{N}(0,\tau_\omega).
\]
Sum-to-zero constraints are imposed so that athlete deviations at each stage sum to zero and, for each athlete, the position effects and race-type effects each sum to zero. This makes \(\mu_t\) interpretable as an overall baseline and makes \(\gamma\) and \(\omega\) relative-strength parameters rather than absolute levels [2411.02000].

The implementation is in JAGS via R (`rjags`), using 4 chains, 1000 burn-in iterations, then 5000 iterations per chain with thinning of 5, yielding 4000 effective posterior draws. Convergence is checked via traceplots and effective sample size. Posterior predictive checks are reported at three levels: stage-level total hits, race-type and position-specific shooting percentages, and individual cumulative hits. The observed percentages always lie within the 95% predictive interval, with systematic biases noted as underestimation in prone for individual races and overestimation in standing for mass start races, but overall fit is described as good. No WAIC or LOO is reported; the validation is visual and posterior-predictive [2411.02000].

This framework yields an individualized marksman profile: \(\beta_{s,t}\) gives a baseline skill trajectory, \(\gamma_{s,x}\) gives a prone/standing profile, and \(\omega_{s,z}\) gives a race-format profile. The paper’s coaching interpretation is correspondingly granular: persistent weakness in standing suggests additional technical standing work; low sprint-specific performance relative to individual races suggests sprint-format simulation in training; stage-specific slumps suggest periodization issues, overtraining, or psychological fatigue. The paper therefore defines marksmanship as a structured decomposition of skill, context sensitivity, and temporal evolution rather than as a single summary statistic [2411.02000].

## 4. Marksmen in the many-player silent duel

In “A Short Solution to the Many-Player Silent Duel with Arbitrary Consolation Prize,” marksmen are identical players in a one-shot contest. There are \(n\ge 2\) players, each chooses a firing distance \(x\in[0,1]\), the probability of miss is \(x\), and the probability of hit is \(1-x\). The player who hits at the greatest distance wins a unit prize; ties split the prize; if all marksmen miss, each receives a consolation prize \(c\), where \(0\le c<1\). A pure strategy is a single distance, while a mixed strategy is a distribution \(G(x)\) over distances [1712.00274].

The paper defines a score random variable \(Y\): if the marksman hits at distance \(x\), then \(Y=x\); if he misses, \(Y=-1\). Misses therefore induce an atom at \(-1\), with size \(p\), the equilibrium miss probability. If the firing distance has density \(g(x)\), then the score density over hits is
\[
f(x)=(1-x)g(x).
\]
The analysis assumes symmetry, identical accuracy, risk neutrality, and one shot with no information about others’ choices or outcomes. These assumptions support a symmetric mixed-strategy equilibrium formulation [1712.00274].

The main theorem gives the unique symmetric equilibrium for arbitrary \(n\) and \(c\). Let \(1/p\) be the unique solution in \((1,\infty)\) of
\[
\left(\frac{1}{p}\right)^n=1-nc+n\left(\frac{1}{p}\right).
\]
Then each marksman’s equilibrium payoff is
\[
v=p^{n-1},
\]
and the score distribution is supported on \(\{-1\}\cup[0,b]\), where
\[
F(y)=p\sqrt[n-1]{\frac{1-cy}{1-y}}, \qquad 0\le y\le b,
\]
and
\[
b=\frac{1-v}{1-cv}.
\]
The equilibrium has no atom at any positive distance, and any distance used with positive probability yields the same expected payoff \(v\). A deviating player who fires at distance \(y\) receives expected payoff
\[
(1-y)F^{n-1}(y)+cy\,p^{n-1},
\]
which equals \(v\) on the support and is strictly less than \(v\) outside it [1712.00274].

Several special cases are recovered inside this general solution. When \(c=1/n\), the game is constant-sum. When \(n=2\) and \(c=1/2\), one obtains the classic two-player silent duel. When \(c=0\), the model becomes a research tournament in which the entrant who successfully solves the hardest problem wins the prize. The paper’s central implication is that rational marksmen do not select a single best firing distance; they randomize over a support of distances so that safer and riskier shots are balanced in expected value [1712.00274].

## 5. “Marksman” as a programmable backdoor attack

In machine learning security, “Marksman” is the name of a backdoor attack with arbitrary target class. Standard backdoor attacks typically support only a fixed payload such as all-to-one or all-to-all mappings. Marksman instead seeks
\[
f(x)=y,\qquad f(T(c,x))=c,\qquad \forall c\in\mathcal{Y},\ \forall (x,y),
\]
so that the adversary can specify any desired target class \(c\) at inference time. The trigger is implemented through a class-conditional generator:
\[
T(c,x)=x+g(c,x), \qquad \|g(c,x)\|_\infty \le \epsilon.
\]
The trigger is therefore both input-aware and class-conditional [2210.09194].

The training objective is a constrained joint optimization. For fixed classifier parameters \(\theta\), the generator parameters \(\xi\) solve
\[
\xi^*=\arg\min_\xi \sum_{(x,y)\in\mathcal{S}_p,\ c\ne y}\mathcal{L}(f_\theta(T_\xi(c,x)),c)-\beta\|g_\xi(c,x)\|_2,
\]
subject to the \(L_\infty\) bound. The outer problem minimizes clean-data loss plus a weighted attack loss:
\[
\min_\theta \sum_{(x,y)\in\mathcal{S}_c}\mathcal{L}(f_\theta(x),y)+\alpha\sum_{(x,y)\in\mathcal{S}_p,\ c\ne y}\mathcal{L}(f_\theta(T_{\xi^*(\theta)}(c,x)),c).
\]
The paper interprets the negative \(-\beta\|g_\xi(c,x)\|_2\) term as encouraging non-sparse, distributed perturbations rather than trivial sparse patterns. Training uses alternating optimization with slow updates of the trigger generator, and the paper states that this significantly improves convergence speed and stability compared to naively alternating every step [2210.09194].

Empirical evaluation is reported on MNIST, CIFAR-10, GTSRB, and TinyImageNet. At 50% poisoning, Marksman attains clean accuracy 0.988 on MNIST, 0.941 on CIFAR-10, 0.986 on GTSRB, and 0.577 on TinyImageNet, versus benign accuracies 0.989, 0.948, 0.994, and 0.579 respectively; attack success rates are 1.000, 1.000, 0.999, and 0.999. At 10% poisoning, the corresponding clean accuracies are 0.983, 0.943, 0.979, and 0.575, with attack success rates 1.000, 1.000, 0.997, and 0.999. The baseline extensions PatchMT, RefoolMT, and WaNetMT either require high poisoning with substantial clean-accuracy degradation or preserve clean accuracy with attack success far below Marksman at 10% poisoning [2210.09194].

The paper also evaluates interaction with existing defenses. Marksman-infected models have Anomaly Index below the Neural Cleanse threshold; entropy distributions of clean and backdoor inputs under STRIP are nearly indistinguishable; Spectral Signature does not clearly separate clean and backdoor distributions; and Fine-Pruning reduces attack success only modestly, often less than the drop in clean accuracy. The paper’s explicit claim is that conventional defenses are tuned to single-target, patch-based backdoors and fail against this more general payload mechanism. A common misconception in this area is that arbitrary-target behavior can be obtained simply by stacking many single-target triggers; the paper’s multi-trigger baselines are introduced precisely to show the degradation associated with that construction [2210.09194].

## 6. Marksman as an archetype-level carry role in champion ranking

In “Robust Player-Conditional Champion Ranking for League of Legends,” the paper does not use the word “Marksman” explicitly, but it states that the framework is designed to handle roles or archetypes like Marksman via “scaling carry / damage carry” archetypes and an archetype guardrail. The recommender formalizes champion recommendation as a player-conditional ranking problem under sparse, noisy, and non-stationary behavioral data. Its decomposed utility is
\[
R(c)=\Phi(W(c),F(c),M(c),G(c),T(c)),
\]
where \(W(c)\) is an expected-performance proxy, \(F(c)\) is style fit, \(M(c)\) is mastery/familiarity, \(G(c)\) is archetype compatibility or guardrail, and \(T(c)\) is a support term related to fit/mastery [2605.18338].

The framework combines four information sources relevant to Marksman-like recommendations. First, a population strength proxy \(S(c)\) uses robust z-scores of features such as `damagePerMinute`, `goldPerMinute`, `cs_per_min`, `laneMinionsFirst10Minutes`, `deaths_per_min` with sign reversal, `killParticipation`, `damageDealtToBuildings`, `damageDealtToObjectives`, `visionScorePerMinute`, and `totalTimeCCDealt`, followed by `RankScale`. Second, style similarity is computed through weighted cosine similarity between recency-weighted game vectors, mastery-weighted champion-pool vectors, and champion feature vectors:
\[
F_{\mathrm{raw}}(c)=0.55\cos(u_{\mathrm{game}},x_c)+0.45\cos(u_{\mathrm{pool}},x_c),
\qquad
F(c)=\mathrm{RankScale}(F_{\mathrm{raw}}(c)).
\]
Third, mastery priors are split into direct mastery and indirect familiarity. The final mastery score is
\[
M(c)=0.70M_d(c)+0.30M_i(c).
\]
Fourth, archetype guardrails are built from k-means++ clustering over an expanded feature set and combined as
\[
G(c)=0.55B(c)+0.45\max\{M_d(c),M_i(c)\}.
\]
For a Marksman-focused use case, the paper states that one may restrict the candidate set to bottom-lane or Marksman champions, or apply Marksman-specific archetype guardrails so that \(G(c)\) heavily penalizes non-Marksman picks [2605.18338].

The final score is assembled through
\[
W(c)=\gamma(c)P_d(c)+(1-\gamma(c))U(c),
\]
\[
Q(c)=0.50W(c)+0.25F(c)+0.25M(c),
\]
\[
T(c)=0.60F(c)+0.40\max\{M_d(c),M_i(c)\},
\qquad
H(c)=0.82+0.18T(c),
\]
and
\[
A(c)=
\begin{cases}
0.90+0.10G(c), & G_c>0,\\
0.72+0.28G(c), & G_c=0,
\end{cases}
\qquad
R(c)=Q(c)H(c)A(c).
\]
The paper’s interpretation is that this produces a personalized ADC or Marksman tier list in which a champion may be recommended because it is strong in meta, matches how the player farms and fights, fits the player’s comfort profile, and belongs to the player’s primary carry archetype. A plausible implication is that, in this usage, “Marksman” functions less as a lexical category than as an archetype-level constraint embedded in an explainable ranking pipeline [2605.18338].

## 7. Cross-domain themes and recurrent misconceptions

Across these literatures, “marksman” consistently marks an entity whose performance is conditional on context rather than absolute in isolation. In biathlon, athlete-specific quality depends on position, race type, and stage, and can improve, decline, slump, or rebound over the season. In the silent duel, payoff depends jointly on firing distance, the number of competitors, and the consolation prize. In the backdoor setting, the effect of Marksman depends on the chosen target class and the learned class-conditional trigger generator. In champion ranking, Marksman-like recommendation depends on population strength, fit, mastery, and archetype compatibility rather than on any single scalar notion of strength [2411.02000] [1712.00274] [2210.09194] [2605.18338].

Several misconceptions are directly contradicted by the cited results. First, a good marksman in biathlon is not simply the athlete with the highest average hit rate; the paper reports non-monotonic stage trajectories and weak correlations between shooting accuracy and final ranking. Second, a rational marksman in the silent duel does not have a single optimal distance; equilibrium requires randomization over a support. Third, an arbitrary-target backdoor is not equivalent to a collection of fixed-target triggers; the Marksman paper introduces multi-trigger, multi-payload baselines precisely to show that simple stacking degrades performance. Fourth, in the recommender setting, “Marksman” need not be an explicit label in the model to be operationalized; the framework handles it through “scaling carry / damage carry” archetypes and the archetype guardrail [2411.02000] [1712.00274] [2210.09194] [2605.18338].

Taken together, these works suggest that the technical meaning of “marksman” is best understood relationally. It denotes an agent, athlete, or mechanism whose efficacy is shaped by structured uncertainty, target-conditioned behavior, and domain-specific constraints. The term is therefore stable at the level of competitive or adversarial intent, but not at the level of a single shared formalism.

Source: https://www.emergentmind.com/topics/marksman