Pith. sign in

REVIEW 2 major objections 4 minor 115 references

An adversarial trainer can plant statistically undetectable backdoors in a large class of deep networks, granting exclusive access to strong invariance-based adversarial examples that no efficient outsider can generate.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · grok-4.5

2026-07-13 02:19 UTC pith:VZIXKUPU

load-bearing objection Clean statistical white-box backdoors for a natural (constrained) class of DNNs, with exponential strength and a solid second-moment analysis. the 2 major comments →

arxiv 2607.09532 v1 pith:VZIXKUPU submitted 2026-07-10 cs.LG cs.CRstat.ML

Statistically Undetectable Backdoors in Deep Neural Networks

classification cs.LG cs.CRstat.ML
keywords backdoorsneural networksadversarial examplesstatistical undetectabilityinvariance-based attacksJohnson-Lindenstrausslattice hardnesstotal variation distance
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The paper establishes that for deep feedforward networks whose first layer is a frozen random Gaussian compression, whose remaining layers are bi-Lipschitz, and whose inputs are discrete, a trainer can modify only the sampling of that first layer so the resulting model is statistically almost identical to an honest one even when every weight is public. The secret backdoor vector lets the trainer, for every input, produce a distant partner whose network outputs are unusually close. Without the secret, finding any such strong collision is computationally infeasible under standard lattice hardness assumptions. The resulting power asymmetry means users cannot certify that the model is free of hidden control, while the trainer can generate or sell access to those collisions at will. Preliminary experiments on Fashion-MNIST embeddings show the construction is concrete enough to implement.

Core claim

Every efficient training algorithm that outputs a network obeying the three architectural constraints can be efficiently turned into a backdoored algorithm whose model is within total-variation distance roughly the square root of the compression ratio of the honest model, yet comes equipped with a short secret that produces invariance-based collisions of strength exponential in that compression ratio, while any polynomial-time algorithm given only the model cannot produce collisions of remotely comparable strength.

What carries the argument

The matrix-backdoor sampler that jointly draws a near-Gaussian compressing matrix A and a secret sign vector z so that Az is exponentially small; concentration of the number of such solutions keeps the planted distribution statistically close to pure Gaussian, after which bi-Lipschitzness of the rest of the network lifts the collisions and the hardness.

Load-bearing premise

No efficient algorithm can find a short nonzero integer vector that nearly annihilates a random Gaussian matrix; if that hardness fails, outsiders can also manufacture the strong collisions and the claimed power asymmetry disappears.

What would settle it

An efficient algorithm that, on a random m-by-n Gaussian matrix, outputs a nonzero bounded integer vector x with infinity-norm of Ax substantially smaller than the best known polynomial-time methods, or a distinguisher that separates planted from pure-Gaussian matrices with advantage much larger than the square root of m over n.

Watch this falsifier — get emailed when new claim-graph text bears on it.

If this is right

  • Users of models in this architectural class cannot certify robustness against invariance-based adversarial examples.
  • A malicious trainer can sell exclusive access to strong colliding inputs without any statistical change to the model’s public description.
  • The same construction supplies a built-in ownership proof: only the trainer can exhibit a short witness that makes two distant inputs collide under the network.
  • Even honestly trained models of this form already contain hard-to-find collisions that no efficient algorithm can produce.
  • Backdooring requires changing only how the first-layer randomness is generated; training data and all later weight updates remain identical.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • If the statistical gap can be replaced by mere computational indistinguishability for far smaller collision thresholds, the practical strength of the backdoor could become unbounded.
  • Any modern architecture that begins with a random-feature or Johnson-Lindenstrauss projection may inherit the same plantable hardness.
  • Defenses that ban compressing first layers or force all layers to be poorly conditioned would block this attack but would also discard the geometric benefits that make those layers useful.
  • Compiling the ownership proof with zero-knowledge techniques could turn a one-time witness into a reusable, black-box authentication token.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

2 major / 4 minor

Summary. The paper constructs statistically undetectable backdoors for a class of feedforward DNNs whose first layer is a frozen i.i.d. Gaussian compressing matrix, whose remaining layers form a bi-Lipschitz map (e.g., leaky ReLU with bounded condition numbers), and whose inputs are discrete and bounded. The backdoored training algorithm samples the first-layer matrix jointly with a secret vector z so that ||Az||_\infty is exponentially small in the compression ratio n/m; the resulting model is within total-variation distance \tilde O(\sqrt(m/n)) of an honestly trained model (even white-box), yet the holder of z can produce strong invariance-based collisions for every input while any efficient adversary without z cannot (under lattice hardness Assumptions 1–2). The main technical ingredients are a rejection-free sampler for the planted matrix (Figure 3), a second-moment concentration bound on the number of solutions N(A) (Proposition 1 and Corollaries 1–2), conversion of Rényi divergence to TV distance, and a bi-Lipschitz transfer that lifts first-layer collisions to the full network while preserving hardness (Theorems 5–7).

Significance. If the claims hold, the work establishes a clean, quantifiable power asymmetry between model trainers and users for a natural architectural fragment that already appears in random-feature and Lipschitz-constrained networks. The statistical (rather than merely computational) white-box undetectability, the exponential backdoor strength, and the reduction from standard worst-case lattice assumptions are genuine strengths; the second-moment analysis of the continuous Gaussian solution count and the explicit density relation \rho_{1} \propto \rho_{0} · N(A) are carefully executed. The dual interpretation as a built-in authentication/provenance mechanism is also of independent interest. The preliminary Fashion-MNIST embedding experiments give a concrete existence proof that the architectural constraints are not vacuous, even if they remain far from end-to-end evaluation.

major comments (2)
  1. The central hardness claim (Theorems 5–7) rests entirely on Assumptions 1–2 imported from VV25/BRVV25. While the reduction via Lemma 3 and the bi-Lipschitz transfer (Lemma 4) is clean, the manuscript never quantifies how large the concrete security parameters (m, n, \kappa, B) must be for the lattice hardness to be meaningful against known algorithms (LLL, Bansal–Spencer, etc.). Section 6.2 reports only tiny instances (n\le100); without a concrete-security discussion the claimed “exponential” advantage remains asymptotic.
  2. Constraint 2 (bi-Lipschitz remainder with distortion \beta_upper) is essential both for the security reduction and for the strength lower bound in Theorem 7. In practice the product of condition numbers \gamma^{d-1} multiplies the denominator; the paper never shows that typical trained networks (even with the semi-orthogonal regularizer of §6.1) keep this product from erasing the 2^{n/m} advantage. A short quantitative check on the realized condition numbers of the Fashion-MNIST model would make the claim load-bearing rather than conditional.
minor comments (4)
  1. Finite-precision arithmetic is dismissed in one sentence (p. 12). Because the sampler of Figure 3 conditions on exact affine hyperplanes, a short argument that poly(n)-bit fixed-point arithmetic preserves both the TV bound and the hardness reduction would remove a lingering technical caveat.
  2. Figure 1 and the accompanying text claim “orders of magnitude smaller” embedding distances, yet no numerical values or histograms are supplied. Adding a small table of median distances (original vs. backdoored vs. same-class) would make the proof-of-concept more informative.
  3. Notation for the backdoor strength (Eq. (1) versus the δ_{1}/δ_{0} ratio of Definition 6) is slightly inconsistent; a single sentence equating the two would help the reader.
  4. The related-work discussion of GKVZ22 correctly notes that their CLWE construction can have strength <1, but the comparison would be sharper if the concrete strength numbers (or lack thereof) were tabulated side-by-side.

Circularity Check

1 steps flagged

No significant circularity: statistical closeness is self-contained via second-moment analysis; hardness is an external lattice assumption (even if reductions appear in overlapping-author papers).

specific steps
  1. self citation load bearing [Assumption 2 (p. 15) and its use in Theorems 5–7 / Corollary 3]
    "For B, n ≤ poly(m) and κ ≤ 1/(√n · m^ε), we have computational hardness assuming polynomial hardness of worst-case lattice problems [VV25, BRVV25]. Therefore, the following assumption is true assuming worst-case lattice problems are hard to solve: Assumption 2. ... under Assumption 2, Figure 4 gives a statistically undetectable backdoor ... with strength δ1/δ0 = Ω(α · 2^{n/m} / (β √n · m^{1/2+ε}))."

    Collision-resistance (the 'without the backdoor it is impossible' half of the power asymmetry) rests on hardness of SBP, whose reduction from lattices is cited to papers with overlapping authors (BRVV25 shares three authors). This is load-bearing for the exponential strength claim, but not circular: the underlying lattice hardness is an independent, standard cryptographic assumption, not a uniqueness theorem or result proved only inside the present paper.

full rationale

The derivation chain is non-circular. Statistical undetectability (dTV = Õ(√(m/n))) follows from the paper's own Claims 1–3, Lemma 2, and the second-moment concentration of N(A) proved in Proposition 1 / Corollaries 1–2 (with the density relation ρ1 ∝ ρ0 · N(A) making the planted sampler of Figure 3 close to the null). Bi-Lipschitz transfer (Lemma 4 + Theorems 5–6) is elementary and self-contained. The only external ingredient is Assumption 2 (SBP hardness for κ ≤ 1/(√n · m^ε)), which is reduced from worst-case lattice problems; the citations [VV25, BRVV25] supply the reduction but the underlying LWE/lattice hardness is a standard, externally falsifiable cryptographic hypothesis, not a self-referential uniqueness claim or fitted quantity. Backdoor strength is defined independently (Definition 6) and lower-bounded under that hypothesis. No self-definitional loop, no fitted-input-as-prediction, and no ansatz smuggled via citation. Minor self-citation of the hardness reduction is noted but does not force the central claim.

Axiom & Free-Parameter Ledger

2 free parameters · 4 axioms · 1 invented entities

The result rests on standard lattice hardness (imported), Gaussian concentration and bilipschitz calculus (standard math), plus the three architectural constraints that define the model class. No free parameters are fitted to data; κ and m/n are asymptotic choices. No new physical or cryptographic entities are postulated beyond the backdoor vector itself, which is an ordinary ±1 string.

free parameters (2)
  • κ (threshold for Az)
    Chosen asymptotically as O(2^{-n/m}) or n^C·2^{-n/m} to balance concentration and hardness; not fitted to empirical data.
  • compression ratio m/n and depth/condition-number bounds
    Free architectural parameters that determine the concrete strength 2^{n/m}/(poly·β); chosen by the trainer, not fitted.
axioms (4)
  • domain assumption Assumption 2: hardness of finding short solutions to the symmetric binary perceptron / number-balancing problem for Gaussian matrices (from worst-case lattice problems)
    Invoked in §3.2 and used for collision resistance in Theorems 5–7; standard post-quantum assumption but unproven.
  • ad hoc to paper First layer is a frozen i.i.d. Gaussian compressing matrix; remaining layers form a bi-Lipschitz map (leaky ReLU + bounded condition numbers)
    Constraints 1–2 of §1.1; necessary for both statistical closeness and the hardness reduction; not true of arbitrary modern DNNs.
  • domain assumption Inputs lie in a discrete bounded integer grid [−B:B]^n
    Constraint 3; required for the discrete collision notion and lattice hardness statements.
  • standard math Second-moment concentration of the number of ±1 solutions to ∥Az∥_∞≤κ√n for Gaussian A (Prop. 1)
    Proved in §4.2 via random-walk correlation and Gaussian moment comparison; the key analytic step.
invented entities (1)
  • backdoor strength bs(M;z) = min_Adv ∥M(x′)−M(x)∥ / max_{x′=x+z} ∥M(x′)−M(x)∥ no independent evidence
    purpose: Quantifies the power asymmetry between trainer and outsider
    Definition (1) in §1.1; purely definitional, no independent physical existence claimed.

pith-pipeline@v1.1.0-grok45 · 35858 in / 2869 out tokens · 42138 ms · 2026-07-13T02:19:58.482608+00:00 · methodology

0 comments
read the original abstract

We show how an adversarial model trainer can plant backdoors in a large class of deep, feedforward neural networks. These backdoors are statistically undetectable in the white-box setting, meaning that the backdoored and honestly trained models are close in total variation distance, even given the full descriptions of the models (e.g., all of the weights). The backdoor provides access to invariance-based adversarial examples for every input, mapping distant inputs to unusually close outputs. However, without the backdoor, it is provably impossible (under standard cryptographic assumptions) to generate any such adversarial examples in polynomial time. Our theoretical and preliminary empirical findings demonstrate a fundamental power asymmetry between model trainers and model users.

Figures

Figures reproduced from arXiv: 2607.09532 by Alon Rosen, Andrej Bogdanov, Neekon Vafa.

Figure 1
Figure 1. Figure 1: Two scaled images of ankle boots in the Fashion-MNIST dataset (left and right) along [PITH_FULL_IMAGE:figures/full_fig_p004_1.png] view at source ↗
Figure 2
Figure 2. Figure 2: A simplified description of our backdoor algorithm for the a compressing Gaussian matrix [PITH_FULL_IMAGE:figures/full_fig_p010_2.png] view at source ↗
Figure 3
Figure 3. Figure 3: Description of the matrix backdoor algorithm used in Theorems 2 and 3. [PITH_FULL_IMAGE:figures/full_fig_p016_3.png] view at source ↗
Figure 4
Figure 4. Figure 4: The generic construction of backdoors for linear models with bilipschitz postprocessing, [PITH_FULL_IMAGE:figures/full_fig_p028_4.png] view at source ↗
Figure 5
Figure 5. Figure 5: Basic architecture of the DNN for our Fashion-MNIST embedding model. The only [PITH_FULL_IMAGE:figures/full_fig_p033_5.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

115 extracted references · 10 canonical work pages · 3 internal anchors

  1. [1]

    2025 , url =

    Neekon Vafa and Vinod Vaikuntanathan , title =. 2025 , url =

  2. [3]

    Narendra Karmarkar and Richard M. Karp. The differencing method of set partitioning. 1982

  3. [4]

    Journal of Applied probability , volume=

    Probabilistic analysis of optimum partitioning , author=. Journal of Applied probability , volume=. 1986 , publisher=

  4. [5]

    Storage capacity in symmetric binary perceptrons , volume=

    Aubin, Benjamin and Perkins, Will and Zdeborová, Lenka , year=. Storage capacity in symmetric binary perceptrons , volume=. Journal of Physics A: Mathematical and Theoretical , publisher=. doi:10.1088/1751-8121/ab227a , number=

  5. [6]

    Frozen 1-RSB structure of the symmetric Ising perceptron , booktitle =

    Will Perkins and Changji Xu , editor =. Frozen 1-RSB structure of the symmetric Ising perceptron , booktitle =. 2021 , url =. doi:10.1145/3406325.3451119 , timestamp =

  6. [7]

    2021 , eprint=

    Proof of the Contiguity Conjecture and Lognormal Limit for the Symmetric Perceptron , author=. 2021 , eprint=

  7. [8]

    51th Annual

    Nikhil Bansal , title =. 51th Annual. 2010 , url =. doi:10.1109/FOCS.2010.7 , timestamp =

  8. [9]

    Spencer , title =

    Nikhil Bansal and Joel H. Spencer , title =. Random Struct. Algorithms , volume =. 2020 , url =. doi:10.1002/RSA.20955 , timestamp =

  9. [10]

    Adaptive Robustness of Hypergrid Johnson-Lindenstrauss

    Andrej Bogdanov and Alon Rosen and Neekon Vafa and Vinod Vaikuntanathan , title =. CoRR , volume =. 2025 , url =. doi:10.48550/ARXIV.2504.09331 , eprinttype =. 2504.09331 , timestamp =

  10. [11]

    Tim van Erven and Peter Harremo. R. 2014 , url =. doi:10.1109/TIT.2014.2320500 , timestamp =

  11. [12]

    Random Features for Large-Scale Kernel Machines , booktitle =

    Ali Rahimi and Benjamin Recht , editor =. Random Features for Large-Scale Kernel Machines , booktitle =. 2007 , url =

  12. [13]

    Acta Mathematica , number =

    Carl-Gustav Esseen , title =. Acta Mathematica , number =. 1945 , doi =

  13. [14]

    Quantitative results (with formal proof) on the median approximation of Chi-squared distribution , author =

  14. [15]

    Contemporary Mathematics , volume=

    Extensions of Lipschitz mappings into a Hilbert space , author=. Contemporary Mathematics , volume=. 1984 , publisher=

  15. [16]

    Proceedings of the 9th Annual International Cryptology Conference on Advances in Cryptology , pages =

    Schnorr, Claus-Peter , title =. Proceedings of the 9th Annual International Cryptology Conference on Advances in Cryptology , pages =. 1989 , isbn =

  16. [17]

    2008 , isbn =

    Gentry, Craig and Peikert, Chris and Vaikuntanathan, Vinod , title =. 2008 , isbn =. doi:10.1145/1374376.1374407 , booktitle =

  17. [18]

    , biburl =

    Ajtai, M. , biburl =. Generating Hard Instances of Lattice Problems (Extended Abstract) , url =. Proceedings of the Twenty-eighth Annual ACM Symposium on Theory of Computing , description =. doi:10.1145/237814.237838 , interhash =

  18. [19]

    Dyer, M. E. and Frieze, A. M. , title =. 1989 , issue_date =. doi:10.1287/moor.14.1.162 , journal =

  19. [20]

    Approximate Nearest Neighbors: Towards Removing the Curse of Dimensionality , booktitle =

    Piotr Indyk and Rajeev Motwani , editor =. Approximate Nearest Neighbors: Towards Removing the Curse of Dimensionality , booktitle =. 1998 , url =. doi:10.1145/276698.276876 , timestamp =

  20. [21]

    Kim and Vinod Vaikuntanathan and Or Zamir , title =

    Shafi Goldwasser and Michael P. Kim and Vinod Vaikuntanathan and Or Zamir , title =. 63rd. 2022 , url =. doi:10.1109/FOCS54457.2022.00092 , timestamp =

  21. [22]

    Non-Interactive and Information-Theoretic Secure Verifiable Secret Sharing

    Pedersen, Torben Pryds. Non-Interactive and Information-Theoretic Secure Verifiable Secret Sharing. Advances in Cryptology --- CRYPTO '91. 1992

  22. [23]

    Injecting Undetectable Backdoors in Obfuscated Neural Networks and Language Models , booktitle =

    Alkis Kalavasis and Amin Karbasi and Argyris Oikonomou and Katerina Sotiraki and Grigoris Velegkas and Manolis Zampetakis , editor =. Injecting Undetectable Backdoors in Obfuscated Neural Networks and Language Models , booktitle =. 2024 , url =

  23. [24]

    Indistinguishability obfuscation from well-founded assumptions , booktitle =

    Aayush Jain and Huijia Lin and Amit Sahai , editor =. Indistinguishability obfuscation from well-founded assumptions , booktitle =. 2021 , url =. doi:10.1145/3406325.3451093 , timestamp =

  24. [25]

    Indistinguishability Obfuscation from

    Aayush Jain and Huijia Lin and Amit Sahai , editor =. Indistinguishability Obfuscation from. Advances in Cryptology -. 2022 , url =. doi:10.1007/978-3-031-06944-4\_23 , timestamp =

  25. [26]

    Indistinguishability Obfuscation from Bilinear Maps and

    Seyoon Ragavan and Neekon Vafa and Vinod Vaikuntanathan , editor =. Indistinguishability Obfuscation from Bilinear Maps and. Theory of Cryptography - 22nd International Conference,. 2024 , url =. doi:10.1007/978-3-031-78023-3\_1 , timestamp =

  26. [27]

    Vadhan and Ke Yang , title =

    Boaz Barak and Oded Goldreich and Russell Impagliazzo and Steven Rudich and Amit Sahai and Salil P. Vadhan and Ke Yang , title =. J. 2012 , url =. doi:10.1145/2160158.2160159 , timestamp =

  27. [28]

    2017 , eprintclass =

    Han Xiao and Kashif Rasul and Roland Vollgraf , title =. 2017 , eprintclass =

  28. [29]

    http://yann

    The MNIST database of handwritten digits , author=. http://yann. lecun. com/exdb/mnist/ , year=

  29. [30]

    PyTorch: An Imperative Style, High-Performance Deep Learning Library , booktitle =

    Adam Paszke and Sam Gross and Francisco Massa and Adam Lerer and James Bradbury and Gregory Chanan and Trevor Killeen and Zeming Lin and Natalia Gimelshein and Luca Antiga and Alban Desmaison and Andreas K. PyTorch: An Imperative Style, High-Performance Deep Learning Library , booktitle =. 2019 , url =

  30. [31]

    H. W. Lenstra and A. K. Lenstra and L. Lov\'. Factoring Polynomials with Rational Coefficients , volume =. Math, Ann. , pages =

  31. [32]

    Journal of the ACM (JACM) , volume=

    On lattices, learning with errors, random linear codes, and cryptography , author=. Journal of the ACM (JACM) , volume=. 2009 , publisher=

  32. [33]

    Continuous

    Joan Bruna and Oded Regev and Min Jae Song and Yi Tang , editor =. Continuous. 2021 , url =. doi:10.1145/3406325.3451000 , timestamp =

  33. [34]

    Parseval Networks: Improving Robustness to Adversarial Examples , booktitle =

    Moustapha Ciss. Parseval Networks: Improving Robustness to Adversarial Examples , booktitle =. 2017 , url =

  34. [36]

    Can We Gain More from Orthogonality Regularizations in Training Deep Networks? , booktitle =

    Nitin Bansal and Xiaohan Chen and Zhangyang Wang , editor =. Can We Gain More from Orthogonality Regularizations in Training Deep Networks? , booktitle =. 2018 , url =

  35. [37]

    Kui Jia and Dacheng Tao and Shenghua Gao and Xiangmin Xu , title =. 2017. 2017 , url =. doi:10.1109/CVPR.2017.425 , timestamp =

  36. [38]

    Stanislas Ducotterd and Alexis Goujon and Pakshal Bohra and Dimitris Perdios and Sebastian Neumayer and Michael Unser , title =. J. Mach. Learn. Res. , volume =. 2024 , url =

  37. [39]

    Orthogonal Weight Normalization: Solution to Optimization Over Multiple Dependent Stiefel Manifolds in Deep Neural Networks , booktitle =

    Lei Huang and Xianglong Liu and Bo Lang and Adams Wei Yu and Yongliang Wang and Bo Li , editor =. Orthogonal Weight Normalization: Solution to Optimization Over Multiple Dependent Stiefel Manifolds in Deep Neural Networks , booktitle =. 2018 , url =. doi:10.1609/AAAI.V32I1.11768 , timestamp =

  38. [40]

    Training Robust Neural Networks Using Lipschitz Bounds , journal =

    Patricia Pauli and Anne Koch and Julian Berberich and Paul Kohler and Frank Allg. Training Robust Neural Networks Using Lipschitz Bounds , journal =. 2022 , url =. doi:10.1109/LCSYS.2021.3050444 , timestamp =

  39. [41]

    Excessive Invariance Causes Adversarial Vulnerability , booktitle =

    J. Excessive Invariance Causes Adversarial Vulnerability , booktitle =. 2019 , url =

  40. [42]

    Fundamental Tradeoffs between Invariance and Sensitivity to Adversarial Perturbations , booktitle =

    Florian Tram. Fundamental Tradeoffs between Invariance and Sensitivity to Adversarial Perturbations , booktitle =. 2020 , url =

  41. [43]

    Rush and Vitaly Shmatikov , editor =

    Congzheng Song and Alexander M. Rush and Vitaly Shmatikov , editor =. Adversarial Semantic Collisions , booktitle =. 2020 , url =. doi:10.18653/V1/2020.EMNLP-MAIN.344 , timestamp =

  42. [44]

    Trojaning Attack on Neural Networks , booktitle =

    Yingqi Liu and Shiqing Ma and Yousra Aafer and Wen. Trojaning Attack on Neural Networks , booktitle =. 2018 , url =

  43. [45]

    AdvDoor: adversarial backdoor attack of deep learning system , booktitle =

    Quan Zhang and Yifeng Ding and Yongqiang Tian and Jianmin Guo and Min Yuan and Yu Jiang , editor =. AdvDoor: adversarial backdoor attack of deep learning system , booktitle =. 2021 , url =. doi:10.1145/3460319.3464809 , timestamp =

  44. [46]

    A Synergetic Attack against Neural Network Classifiers combining Backdoor and Adversarial Examples , booktitle =

    Guanxiong Liu and Issa Khalil and Abdallah Khreishah and NhatHai Phan , editor =. A Synergetic Attack against Neural Network Classifiers combining Backdoor and Adversarial Examples , booktitle =. 2021 , url =. doi:10.1109/BIGDATA52589.2021.9671964 , timestamp =

  45. [48]

    Clean-label backdoor attacks , author=

  46. [50]

    Ronny Huang and Mahyar Najibi and Octavian Suciu and Christoph Studer and Tudor Dumitras and Tom Goldstein , editor =

    Ali Shafahi and W. Ronny Huang and Mahyar Najibi and Octavian Suciu and Christoph Studer and Tudor Dumitras and Tom Goldstein , editor =. Poison Frogs! Targeted Clean-Label Poisoning Attacks on Neural Networks , booktitle =. 2018 , url =

  47. [51]

    Hidden Killer: Invisible Textual Backdoor Attacks with Syntactic Trigger , booktitle =

    Fanchao Qi and Mukai Li and Yangyi Chen and Zhengyan Zhang and Zhiyuan Liu and Yasheng Wang and Maosong Sun , editor =. Hidden Killer: Invisible Textual Backdoor Attacks with Syntactic Trigger , booktitle =. 2021 , url =. doi:10.18653/V1/2021.ACL-LONG.37 , timestamp =

  48. [52]

    Handcrafted Backdoors in Deep Neural Networks , booktitle =

    Sanghyun Hong and Nicholas Carlini and Alexey Kurakin , editor =. Handcrafted Backdoors in Deep Neural Networks , booktitle =. 2022 , url =

  49. [53]

    6th International Conference on Learning Representations,

    Takeru Miyato and Toshiki Kataoka and Masanori Koyama and Yuichi Yoshida , title =. 6th International Conference on Learning Representations,. 2018 , url =

  50. [54]

    Rectifier nonlinearities improve neural network acoustic models , author=. Proc. icml , volume=. 2013 , organization=

  51. [55]

    1989 , url =

    Shafi Goldwasser and Silvio Micali and Charles Rackoff , title =. 1989 , url =. doi:10.1137/0218012 , timestamp =

  52. [56]

    New Paradigms for Digital Signatures and Message Authentication Based on Non-Interative Zero Knowledge Proofs , booktitle =

    Mihir Bellare and Shafi Goldwasser , editor =. New Paradigms for Digital Signatures and Message Authentication Based on Non-Interative Zero Knowledge Proofs , booktitle =. 1989 , url =. doi:10.1007/0-387-34805-0\_19 , timestamp =

  53. [57]

    Backdoor Channels Hidden in Latent Space: Cryptographic Undetectability in Modern Neural Networks

    Marte Eggen and Eirik Reiestad and Kristian Gj. Backdoor Channels Hidden in Latent Space: Cryptographic Undetectability in Modern Neural Networks , journal =. 2026 , url =. doi:10.48550/ARXIV.2605.13214 , eprinttype =. 2605.13214 , timestamp =

  54. [58]

    Undetectable Backdoors in Model Parameters: Hiding Sparse Secrets in High Dimensions

    Sarthak Choudhary and Atharv Singh Patlan and Nils Palumbo and Ashish Hooda and Kassem Fawaz and Somesh Jha , title =. CoRR , volume =. 2026 , url =. doi:10.48550/ARXIV.2605.04209 , eprinttype =. 2605.04209 , timestamp =

  55. [59]

    Unelicitable Backdoors via Cryptographic Transformer Circuits , booktitle =

    Andis Draguns and Andrew Gritsevskiy and Sumeet Ramesh Motwani and Christian Schr. Unelicitable Backdoors via Cryptographic Transformer Circuits , booktitle =. 2024 , url =

  56. [60]

    CoRR , volume =

    Tu Anh Ngo and Anupam Chattopadhyay and Subhamoy Maitra , title =. CoRR , volume =. 2025 , url =. doi:10.48550/ARXIV.2509.20714 , eprinttype =. 2509.20714 , timestamp =

  57. [61]

    M. Ajtai. Generating hard instances of lattice problems (extended abstract). In Proceedings of the Twenty-eighth Annual ACM Symposium on Theory of Computing , STOC '96, pages 99--108, New York, NY, USA, 1996. ACM

  58. [62]

    Proof of the contiguity conjecture and lognormal limit for the symmetric perceptron, 2021

    Emmanuel Abbe, Shuangping Li, and Allan Sly. Proof of the contiguity conjecture and lognormal limit for the symmetric perceptron, 2021

  59. [63]

    Storage capacity in symmetric binary perceptrons

    Benjamin Aubin, Will Perkins, and Lenka Zdeborová. Storage capacity in symmetric binary perceptrons. Journal of Physics A: Mathematical and Theoretical , 52(29):294003, June 2019

  60. [64]

    Constructive algorithms for discrepancy minimization

    Nikhil Bansal. Constructive algorithms for discrepancy minimization. In 51th Annual IEEE Symposium on Foundations of Computer Science, FOCS 2010, October 23-26, 2010, Las Vegas, Nevada, USA , pages 3--10. IEEE Computer Society, 2010

  61. [65]

    Can we gain more from orthogonality regularizations in training deep networks? In Samy Bengio, Hanna M

    Nitin Bansal, Xiaohan Chen, and Zhangyang Wang. Can we gain more from orthogonality regularizations in training deep networks? In Samy Bengio, Hanna M. Wallach, Hugo Larochelle, Kristen Grauman, Nicol \` o Cesa - Bianchi, and Roman Garnett, editors, Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Sy...

  62. [66]

    Vadhan, and Ke Yang

    Boaz Barak, Oded Goldreich, Russell Impagliazzo, Steven Rudich, Amit Sahai, Salil P. Vadhan, and Ke Yang. On the (im)possibility of obfuscating programs. J. ACM , 59(2):6:1--6:48, 2012

  63. [67]

    Continuous LWE

    Joan Bruna, Oded Regev, Min Jae Song, and Yi Tang. Continuous LWE . In Samir Khuller and Virginia Vassilevska Williams, editors, STOC '21: 53rd Annual ACM SIGACT Symposium on Theory of Computing, Virtual Event, Italy, June 21-25, 2021 , pages 694--707. ACM , 2021

  64. [68]

    Adaptive robustness of hypergrid johnson-lindenstrauss

    Andrej Bogdanov, Alon Rosen, Neekon Vafa, and Vinod Vaikuntanathan. Adaptive robustness of hypergrid johnson-lindenstrauss. CoRR , abs/2504.09331, 2025

  65. [69]

    Nikhil Bansal and Joel H. Spencer. On-line balancing of random inputs. Random Struct. Algorithms , 57(4):879--891, 2020

  66. [70]

    Dauphin, and Nicolas Usunier

    Moustapha Ciss \' e , Piotr Bojanowski, Edouard Grave, Yann N. Dauphin, and Nicolas Usunier. Parseval networks: Improving robustness to adversarial examples. In Doina Precup and Yee Whye Teh, editors, Proceedings of the 34th International Conference on Machine Learning, ICML 2017, Sydney, NSW, Australia, 6-11 August 2017 , volume 70 of Proceedings of Mach...

  67. [71]

    Targeted backdoor attacks on deep learning systems using data poisoning

    Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. Targeted backdoor attacks on deep learning systems using data poisoning. CoRR , abs/1712.05526, 2017

  68. [72]

    Undetectable backdoors in model parameters: Hiding sparse secrets in high dimensions

    Sarthak Choudhary, Atharv Singh Patlan, Nils Palumbo, Ashish Hooda, Kassem Fawaz, and Somesh Jha. Undetectable backdoors in model parameters: Hiding sparse secrets in high dimensions. CoRR , abs/2605.04209, 2026

  69. [73]

    M. E. Dyer and A. M. Frieze. Probabilistic analysis of the multidimensional knapsack problem. Math. Oper. Res. , 14(1):162–176, February 1989

  70. [74]

    Improving lipschitz-constrained neural networks by learning activation functions

    Stanislas Ducotterd, Alexis Goujon, Pakshal Bohra, Dimitris Perdios, Sebastian Neumayer, and Michael Unser. Improving lipschitz-constrained neural networks by learning activation functions. J. Mach. Learn. Res. , 25:65:1--65:30, 2024

  71. [75]

    Unelicitable backdoors via cryptographic transformer circuits

    Andis Draguns, Andrew Gritsevskiy, Sumeet Ramesh Motwani, and Christian Schr \" o der de Witt. Unelicitable backdoors via cryptographic transformer circuits. In Amir Globersons, Lester Mackey, Danielle Belgrave, Angela Fan, Ulrich Paquet, Jakub M. Tomczak, and Cheng Zhang, editors, Advances in Neural Information Processing Systems 37: Annual Conference on...

  72. [76]

    Backdoor channels hidden in latent space: Cryptographic undetectability in modern neural networks

    Marte Eggen, Eirik Reiestad, Kristian Gj steen, and Inga Str \" u mke. Backdoor channels hidden in latent space: Cryptographic undetectability in modern neural networks. CoRR , abs/2605.13214, 2026

  73. [77]

    Fourier analysis of distribution functions

    Carl-Gustav Esseen. Fourier analysis of distribution functions. A mathematical study of the Laplace-Gaussian law . Acta Mathematica , 77:1--125, 1945

  74. [78]

    Badnets: Identifying vulnerabilities in the machine learning model supply chain

    Tianyu Gu, Brendan Dolan - Gavitt, and Siddharth Garg. Badnets: Identifying vulnerabilities in the machine learning model supply chain. CoRR , abs/1708.06733, 2017

  75. [79]

    Kim, Vinod Vaikuntanathan, and Or Zamir

    Shafi Goldwasser, Michael P. Kim, Vinod Vaikuntanathan, and Or Zamir. Planting undetectable backdoors in machine learning models : [extended abstract]. In 63rd IEEE Annual Symposium on Foundations of Computer Science, FOCS 2022, Denver, CO, USA, October 31 - November 3, 2022 , pages 931--942. IEEE , 2022

  76. [80]

    The knowledge complexity of interactive proof systems

    Shafi Goldwasser, Silvio Micali, and Charles Rackoff. The knowledge complexity of interactive proof systems. SIAM J. Comput. , 18(1):186--208, 1989

  77. [81]

    Trapdoors for hard lattices and new cryptographic constructions

    Craig Gentry, Chris Peikert, and Vinod Vaikuntanathan. Trapdoors for hard lattices and new cryptographic constructions. In Proceedings of the Fortieth Annual ACM Symposium on Theory of Computing , STOC '08, page 197–206, New York, NY, USA, 2008. Association for Computing Machinery

  78. [82]

    Handcrafted backdoors in deep neural networks

    Sanghyun Hong, Nicholas Carlini, and Alexey Kurakin. Handcrafted backdoors in deep neural networks. In Sanmi Koyejo, S. Mohamed, A. Agarwal, Danielle Belgrave, K. Cho, and A. Oh, editors, Advances in Neural Information Processing Systems 35: Annual Conference on Neural Information Processing Systems 2022, NeurIPS 2022, New Orleans, LA, USA, November 28 - ...

  79. [83]

    Orthogonal weight normalization: Solution to optimization over multiple dependent stiefel manifolds in deep neural networks

    Lei Huang, Xianglong Liu, Bo Lang, Adams Wei Yu, Yongliang Wang, and Bo Li. Orthogonal weight normalization: Solution to optimization over multiple dependent stiefel manifolds in deep neural networks. In Sheila A. McIlraith and Kilian Q. Weinberger, editors, Proceedings of the Thirty-Second AAAI Conference on Artificial Intelligence, (AAAI-18), the 30th i...

  80. [84]

    Approximate nearest neighbors: Towards removing the curse of dimensionality

    Piotr Indyk and Rajeev Motwani. Approximate nearest neighbors: Towards removing the curse of dimensionality. In Jeffrey Scott Vitter, editor, Proceedings of the Thirtieth Annual ACM Symposium on the Theory of Computing, Dallas, Texas, USA, May 23-26, 1998 , pages 604--613. ACM , 1998

Showing first 80 references.