{"as_of":"2026-08-22T12:19:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:164195a6b8d529fced6fc8ac04414f18d5eb9f6682c6fe40f983d4997d0a51e9","coverage":[{"denominator":28,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":28,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-15T23:45:04.280196Z","state":"measured"},{"denominator":28,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":28,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-22T06:32:14.747728+00:00","state":"measured"},{"denominator":0,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"cited_works","source_observed_at":null,"state":"measured"}],"external_citation_measurements":[],"inbound":[],"links":{"evidence":"/evidence","html":"/paper/2505.04015/citation-record","integrity":"/paper/2505.04015/integrity","json":"/paper/2505.04015/citation-record.json","paper":"/paper/2505.04015"},"outbound":[{"citation":{"cited_paper":{"arxiv_id":"2001.08361","last_updated":"2020-01-23T03:59:20Z","snapshot_observed_at":"2026-08-13T17:41:53.092611Z","submitted_at":"2020-01-23T03:59:20Z","title":"Scaling Laws for Neural Language Models","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2001.08361","snapshot_observed_at":"2026-08-15T23:45:04.156648Z","title":"Scaling laws for neural language models,","venue":null,"work_id":null,"year":2001},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.156648Z"},"links":{"cited_paper":"/paper/2001.08361","citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:905790ab072aaeb98056e0b1ea9c8f0391aa62d0444f99c8e3ee85b3ef2183a2","observation_id":"3cc4f265-9d21-4a1f-885f-9462fb201e19","resolution":{"observed_at":"2026-08-15T23:45:04.156648Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.162151Z","title":"Model complexity of deep learning: A survey,","venue":null,"work_id":null,"year":2021},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.162151Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:fdc1c9f0a7324055280c1e16424c617a86c66251c6f02932f4b9e21e11ba4259","observation_id":"6c8969c2-572a-4d47-9113-d4193a16c727","resolution":{"observed_at":"2026-08-15T23:45:04.162151Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.171129Z","title":"Backdoor learning: A survey,","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.171129Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:ff0b6a3af7c9357ac033fa668dfe492905e33ca4c3895d9ef3f91b938a0a722f","observation_id":"44f65bda-7420-4e28-8810-4c195236c0ac","resolution":{"observed_at":"2026-08-15T23:45:04.171129Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.175451Z","title":"Computing systems for autonomous driving: State of the art and challenges,","venue":null,"work_id":null,"year":2020},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.175451Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:94c497a6d499faf32f2f138ca76d5d3b42c5b49cf1937102e9508fd6555adaa8","observation_id":"adaeb16b-a56e-4939-9bf9-40780edd45d5","resolution":{"observed_at":"2026-08-15T23:45:04.175451Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.614191Z","title":"Machine learning for medical imaging,","venue":null,"work_id":"b64378d6-2d68-4a99-8d04-272bdc782738","year":2017},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.179758Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:fa0f1d2e05aa05bb8d4397143d9d1e63da782a4fad57bdd25f3a6db670f57386","observation_id":"5968b526-f444-4bb8-be4c-33d1d2393564","resolution":{"observed_at":"2026-08-15T23:45:04.618810Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-22T06:32:14.747728+00:00","source":"crossref"},{"observed_at":"2026-08-22T06:32:06.552537+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.601078Z","title":"Machine learning for quantitative finance applications: A survey,","venue":null,"work_id":"be74f1f1-e7c7-486c-86ce-1f30ccf4ec59","year":2019},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.184570Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:1e29bda182710e69c8ae55d3afacf3e1067735fe9b0c4283b2eb9e8e7bf65931","observation_id":"5c567ebb-d0fa-4531-be9a-2a4c1013b712","resolution":{"observed_at":"2026-08-15T23:45:04.605409Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-22T06:32:14.747728+00:00","source":"crossref"},{"observed_at":"2026-08-22T06:32:06.552537+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.587755Z","title":"Trojan signatures in dnn weights,","venue":null,"work_id":"61f36286-36f3-4e5c-9d04-02e3f5f6ad58","year":2021},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.189160Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:9aab34a740a3ed44e854cc87a639e65ce99ba1a38c67edf6f86160d61a55fcc0","observation_id":"09df6819-04c8-4773-8e71-ef0d82d3000a","resolution":{"observed_at":"2026-08-15T23:45:04.591993Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-22T06:32:14.747728+00:00","source":"crossref"},{"observed_at":"2026-08-22T06:32:06.552537+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.573294Z","title":"Cleann: Accelerated trojan shield for embedded neural networks,","venue":null,"work_id":"095b1f81-e196-4114-942c-16549ad25968","year":2020},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.194400Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:8b45c42b02f27cf576f7e61f4330384ff7b063fcd8e53ea46f114d1a37ffeb39","observation_id":"07652c74-6c5e-4c60-9760-496154aca83a","resolution":{"observed_at":"2026-08-15T23:45:04.577955Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-22T06:32:14.747728+00:00","source":"crossref"},{"observed_at":"2026-08-22T06:32:06.552537+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.557935Z","title":"Anti-backdoor learning: Training clean models on poisoned data,","venue":null,"work_id":"46deccb6-dcab-4044-984c-347d02d3f087","year":2021},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.199249Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:c1a4c36ce5b781ce4301dabf80194fc7d3f8f1a7663c0b2c1a346478c0a2ed31","observation_id":"fca53d68-0d90-418e-815e-9cbefbb7f38b","resolution":{"observed_at":"2026-08-15T23:45:04.563053Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-22T06:32:14.747728+00:00","source":"crossref"},{"observed_at":"2026-08-22T06:32:06.552537+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.543198Z","title":"Backdoorbench: A comprehensive benchmark of backdoor learning,","venue":null,"work_id":"a0ed89cb-06c3-46ec-8485-4a16ecdf1abb","year":2022},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.203215Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:deae215f56787c641aee01b7f49e28b13d217c614c454356b0bfe3952502210e","observation_id":"f5404cda-bf37-48f3-9490-451bcb38378c","resolution":{"observed_at":"2026-08-15T23:45:04.547485Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-22T06:32:14.747728+00:00","source":"crossref"},{"observed_at":"2026-08-22T06:32:06.552537+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.529081Z","title":"Enhancing fine- tuning based backdoor defense with sharpness-aware minimization,","venue":null,"work_id":"39c112d2-722f-4ae9-ad44-1568da53e0ca","year":2023},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.207266Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:3e9c1d846b6851883f912cec18ea78695aee1954341188be11053d997654d0df","observation_id":"9b1043c2-b9ee-4440-91ad-d79137002330","resolution":{"observed_at":"2026-08-15T23:45:04.533589Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-22T06:32:14.747728+00:00","source":"crossref"},{"observed_at":"2026-08-22T06:32:06.552537+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.515700Z","title":"Neural cleanse: Identifying and mitigating backdoor attacks in neural networks,","venue":null,"work_id":"fa7a1e3f-42bb-4d9d-816f-2516f302659e","year":2019},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.211498Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:c8a0284700825d17c96288719d5cb5e7f1f6915634eb377e268c64b66299e934","observation_id":"3747c66c-a174-4b4b-96f6-ce6f7ae8a7ab","resolution":{"observed_at":"2026-08-15T23:45:04.519926Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-22T06:32:14.747728+00:00","source":"crossref"},{"observed_at":"2026-08-22T06:32:06.552537+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2104.01778","last_updated":"2021-07-08T20:16:28Z","snapshot_observed_at":"2026-08-17T23:50:11.173365Z","submitted_at":"2021-04-05T05:26:29Z","title":"AST: Audio Spectrogram Transformer","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2104.01778","snapshot_observed_at":"2026-08-15T23:45:04.215787Z","title":"Ast: Audio spectrogram trans- former,","venue":null,"work_id":null,"year":2021},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.215787Z"},"links":{"cited_paper":"/paper/2104.01778","citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:12ab1ecb4dbf374a44c73c62863e3d7cc6398bd17b53e223f40c705bb23c6376","observation_id":"fc72bd32-5e26-4395-9a0b-22a6a3d35958","resolution":{"observed_at":"2026-08-15T23:45:04.215787Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.499710Z","title":"St-adapter: Parameter- efficient image-to-video transfer learning,","venue":null,"work_id":"26377116-0e77-4ad7-81bb-8566ba5d3a00","year":2022},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.220256Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:84e48ba4dcfa54cbe6bbe31b8d32dc1bdb0e198c8b168bb9916c3c0a775e012f","observation_id":"9d9a63f3-9525-4a92-9a30-98fb320b9ded","resolution":{"observed_at":"2026-08-15T23:45:04.505219Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-22T06:32:14.747728+00:00","source":"crossref"},{"observed_at":"2026-08-22T06:32:06.552537+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.485803Z","title":"A closer look at robustness of vision transformers to backdoor attacks,","venue":null,"work_id":"e15d0c6f-dd7a-4208-80a1-0c40a988342d","year":2024},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.224712Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:7bfd175f630c60953ababbf11dde5f811c65d768b425329ea8e68c250812b2a3","observation_id":"d1e2a554-b09d-4204-972f-1009183a0388","resolution":{"observed_at":"2026-08-15T23:45:04.490077Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-22T06:32:14.747728+00:00","source":"crossref"},{"observed_at":"2026-08-22T06:32:06.552537+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.228751Z","title":"Adversarial attacks on deep-learning models in natural language processing: A survey,","venue":null,"work_id":null,"year":2020},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.228751Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:f9c962e5c6da27a241214351f5d8ee3e840f354d3579fb421d7f204be54e8804","observation_id":"c51ea591-5f66-4806-97c2-75486207b11a","resolution":{"observed_at":"2026-08-15T23:45:04.228751Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1708.06733","last_updated":"2019-03-11T20:45:33Z","snapshot_observed_at":"2026-08-12T15:43:59.037380Z","submitted_at":"2017-08-22T17:31:54Z","title":"BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1708.06733","snapshot_observed_at":"2026-08-15T23:45:04.232984Z","title":"Badnets: Identifying vulnera- bilities in the machine learning model supply chain,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.232984Z"},"links":{"cited_paper":"/paper/1708.06733","citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:eb67bd12669164fc5091fbe1f25d5bb17cde9c1ffda98b7e0429f35dee81e4cf","observation_id":"a9fe1caa-675d-4326-b414-5240e1bfc1d7","resolution":{"observed_at":"2026-08-15T23:45:04.232984Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1712.05526","last_updated":"2017-12-15T04:26:26Z","snapshot_observed_at":"2026-07-06T06:14:30.795326Z","submitted_at":"2017-12-15T04:26:26Z","title":"Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1712.05526","snapshot_observed_at":"2026-08-15T23:45:04.237585Z","title":"Targeted backdoor attacks on deep learning systems using data poisoning,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.237585Z"},"links":{"cited_paper":"/paper/1712.05526","citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:719b4b6696814f4bebca2f9e6a03d1664983a07280094a363d07f9c49165eb60","observation_id":"ace553e5-fd58-4023-b97a-e2f4f38740c6","resolution":{"observed_at":"2026-08-15T23:45:04.237585Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.645924Z","title":"Trojaning attack on neural networks,","venue":null,"work_id":"200c2e33-c60c-444b-9ad1-9715266ef034","year":2018},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.241970Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:82f569666b8dda4de43fb1cd694a0bb2b9254fc10f98dd56a87fd9f75c10bf87","observation_id":"7281c749-37d6-42aa-a85f-9b38ae4defe1","resolution":{"observed_at":"2026-08-15T23:45:04.650496Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-22T06:32:14.747728+00:00","source":"crossref"},{"observed_at":"2026-08-22T06:32:06.552537+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2102.10369","last_updated":"2021-03-04T04:09:38Z","snapshot_observed_at":"2026-08-21T22:32:27.867560Z","submitted_at":"2021-02-20T15:25:36Z","title":"WaNet -- Imperceptible Warping-based Backdoor Attack","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2102.10369","snapshot_observed_at":"2026-08-15T23:45:04.246047Z","title":"Wanet–imperceptible warping-based backdoor attack,","venue":null,"work_id":null,"year":2021},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.246047Z"},"links":{"cited_paper":"/paper/2102.10369","citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:8a8b2ef86cb68a988b7b499ce39fc24557e731f61568d4f0c1590c6067ed9312","observation_id":"f926c54e-9740-4a60-b093-cf1d8a5b6f7c","resolution":{"observed_at":"2026-08-15T23:45:04.246047Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.463360Z","title":"A new backdoor attack in cnns by training set corruption without label poisoning,","venue":null,"work_id":"b94442c3-abda-4d69-ac40-40ec67e9cb1a","year":2019},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.250537Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:9dc5a843bc800756408ae9540357cc5ab0be2765861f66bb7354ae5d5d84f105","observation_id":"d9db498b-f28b-40da-83c5-540c98d421e5","resolution":{"observed_at":"2026-08-15T23:45:04.467680Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-22T06:32:14.747728+00:00","source":"crossref"},{"observed_at":"2026-08-22T06:32:06.552537+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.450463Z","title":"Neural trojans,","venue":null,"work_id":"a3d96131-fee8-4864-a440-40352306e032","year":2017},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.254723Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:e4a675513f26ca0ba88516be0c9b1f87f35676e166a1557ce9a55ec07f3a3f73","observation_id":"3aadee94-cb18-40ef-94ee-fba2e2a3852d","resolution":{"observed_at":"2026-08-15T23:45:04.454666Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-22T06:32:14.747728+00:00","source":"crossref"},{"observed_at":"2026-08-22T06:32:06.552537+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.437147Z","title":"Fine-pruning: Defending against backdooring attacks on deep neural networks,","venue":null,"work_id":"64cca324-0a28-4482-9df4-e875ef0bc0b6","year":2018},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.258770Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:b28e3009071770bfe42c131ab60418b9dd1d870db3501d66259b347e04a72140","observation_id":"4043547c-fe42-4ecf-8762-400bdd1cec01","resolution":{"observed_at":"2026-08-15T23:45:04.441629Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-22T06:32:14.747728+00:00","source":"crossref"},{"observed_at":"2026-08-22T06:32:06.552537+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.262863Z","title":"Delving deep into rectifiers: Surpassing human-level performance on imagenet classification,","venue":null,"work_id":null,"year":2015},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.262863Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:d05eb5a263947aea3d8db6bf1723dbf9de3cc0b86c886d683efee203cd046d10","observation_id":"9e8b6d0f-3376-483c-a905-5db9e2dd352c","resolution":{"observed_at":"2026-08-15T23:45:04.262863Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1511.07289","last_updated":"2016-02-22T07:02:58Z","snapshot_observed_at":"2026-08-18T04:36:00.952991Z","submitted_at":"2015-11-23T15:58:05Z","title":"Fast and Accurate Deep Network Learning by Exponential Linear Units (ELUs)","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1511.07289","snapshot_observed_at":"2026-08-15T23:45:04.267425Z","title":"Fast and accurate deep network learning by exponential linear units (elus),","venue":null,"work_id":null,"year":2015},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.267425Z"},"links":{"cited_paper":"/paper/1511.07289","citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:476f26f96399f5d9c0acc5ba4653ff19f578c8cd29b15583fdb96be6502619df","observation_id":"00c815de-f72c-446e-ab91-c05d39a878c8","resolution":{"observed_at":"2026-08-15T23:45:04.267425Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1606.08415","last_updated":"2023-06-06T01:53:32Z","snapshot_observed_at":"2026-08-13T19:48:28.322536Z","submitted_at":"2016-06-27T19:20:40Z","title":"Gaussian Error Linear Units (GELUs)","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1606.08415","snapshot_observed_at":"2026-08-15T23:45:04.271970Z","title":"Gaussian error linear units (gelus),","venue":null,"work_id":null,"year":2016},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.271970Z"},"links":{"cited_paper":"/paper/1606.08415","citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:88af7e96b546b41e6aeda14ab354fd4d8b876333149029ea86cdc8f753e06f43","observation_id":"7d459484-c06b-4312-a9d3-dcb7af7d639b","resolution":{"observed_at":"2026-08-15T23:45:04.271970Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.276230Z","title":"Sigmoid-weighted linear units for neural network function approximation in reinforcement learning,","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.276230Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:ca75ae34c231fe05a3afc347d97a541355e1bafb346557ce1badc2490b90e083","observation_id":"0178b737-5699-4986-a7a3-c9b3551f138c","resolution":{"observed_at":"2026-08-15T23:45:04.276230Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T23:45:04.404687Z","title":"Cifar-10 (canadian institute for advanced research),","venue":null,"work_id":"da1e8b0e-a8fa-4936-adef-03623aadefae","year":null},"citing_paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models","version":1},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-15T23:45:04.280196Z"},"links":{"citing_paper":"/paper/2505.04015"},"observation_digest":"sha256:a73ce5ecd454111b0c08b301902744763f0795467c69aa1ad02792a62b260ffb","observation_id":"dc9f5d20-5c11-4e25-9d57-f97c30526b6d","resolution":{"observed_at":"2026-08-15T23:45:04.410863Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-22T06:32:14.747728+00:00","source":"crossref"},{"observed_at":"2026-08-22T06:32:06.552537+00:00","source":"retraction_watch"}],"state":"measured"}}],"paper":{"arxiv_id":"2505.04015","last_updated":"2025-05-06T23:26:25Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-22T07:30:37.097976Z","submitted_at":"2025-05-06T23:26:25Z","title":"MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models"},"reference_resolution":{"displayed":28,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":13,"verified_exact":0,"verified_fuzzy":15},"total_outbound_references":28},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-22T06:32:14.747728+00:00","source":"crossref"},{"observed_at":"2026-08-22T06:32:06.552537+00:00","source":"retraction_watch"}],"thesis":"As of 22 August 2026, this Paper Citation Record lists 28 of 28 outbound references and 0 inbound Pith citation observations for arXiv:2505.04015."}