{"paper":{"title":"BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"An adversary can train a neural network that performs well on normal inputs but activates malicious behavior on specific attacker-chosen triggers.","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Brendan Dolan-Gavitt, Siddharth Garg, Tianyu Gu","submitted_at":"2017-08-22T17:31:54Z","abstract_excerpt":"Deep learning-based techniques have achieved state-of-the-art performance on a wide variety of recognition and classification tasks. However, these networks are typically computationally expensive to train, requiring weeks of computation on many GPUs; as a result, many users outsource the training procedure to the cloud or rely on pre-trained models that are then fine-tuned for a specific task. In this paper we show that outsourced training introduces new security risks: an adversary can create a maliciously trained network (a backdoored neural network, or a \\emph{BadNet}) that has state-of-th"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"an adversary can create a maliciously trained network (a backdoored neural network, or a BadNet) that has state-of-the-art performance on the user's training and validation samples, but behaves badly on specific attacker-chosen inputs.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"The attacker must have sufficient control over the training process or data to embed the backdoor without detection, as assumed in the outsourced training scenario described.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"Adversaries can create backdoored neural networks during outsourced training that maintain high accuracy on normal data but misbehave on attacker-chosen triggers.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"An adversary can train a neural network that performs well on normal inputs but activates malicious behavior on specific attacker-chosen triggers.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"e896561e719309084f64ac3ef173c9749c07cc00bc2e6a1cebd78740eb4f5c47"},"source":{"id":"1708.06733","kind":"arxiv","version":2},"verdict":{"id":"d8b14d67-a317-4c1a-91e1-0035e41b878b","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-12T23:02:56.787401Z","strongest_claim":"an adversary can create a maliciously trained network (a backdoored neural network, or a BadNet) that has state-of-the-art performance on the user's training and validation samples, but behaves badly on specific attacker-chosen inputs.","one_line_summary":"Adversaries can create backdoored neural networks during outsourced training that maintain high accuracy on normal data but misbehave on attacker-chosen triggers.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"The attacker must have sufficient control over the training process or data to embed the backdoor without detection, as assumed in the outsourced training scenario described.","pith_extraction_headline":"An adversary can train a neural network that performs well on normal inputs but activates malicious behavior on specific attacker-chosen triggers."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1708.06733/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":53,"sample":[{"doi":"","year":2012,"title":"ImageNet large scale visual recognition competition","work_id":"a84090cc-dd54-4616-a1ac-5460cf5ed05a","ref_index":1,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2013,"title":"Speech recognition with deep recurrent neural networks","work_id":"f888660f-176b-43d2-be2c-a18a573fcaa3","ref_index":2,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2014,"title":"Multilingual Distributed Representations without Word Alignment","work_id":"81a1f82b-9f78-4d94-89ce-baaeb1d57280","ref_index":3,"cited_arxiv_id":"1312.6173","is_internal_anchor":true},{"doi":"","year":2014,"title":"Neural machine translation by jointly learning to align and translate","work_id":"d804f636-e3d2-45e2-babd-d5f22b966c5a","ref_index":4,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2013,"title":"Playing atari with deep reinforce- ment learning","work_id":"01aa905f-959d-482a-ada6-cc63625b754d","ref_index":5,"cited_arxiv_id":"","is_internal_anchor":false}],"resolved_work":53,"snapshot_sha256":"5f505c2a2402a095c736de022cee50a733322fa277a0165431962bf48c801781","internal_anchors":2},"formal_canon":{"evidence_count":2,"snapshot_sha256":"d39c5a97b7db6b95818774b79c704dc28196d6416f75ba25293577e5f431ef1c"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"}