Establishing a strong tradeoff between robustness and accuracy when mitigating query-based attacks by activating defenses based on confidence levels.