{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:3W2KDI4DJ4ANDXDMYTJ5TQE36G","short_pith_number":"pith:3W2KDI4D","schema_version":"1.0","canonical_sha256":"ddb4a1a3834f00d1dc6cc4d3d9c09bf1abf72bdd67cb8d0684e0e5db7b95dd67","source":{"kind":"arxiv","id":"1911.07963","version":2},"attestation_state":"computed","paper":{"title":"Can You Really Backdoor Federated Learning?","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Ananda Theertha Suresh, H. Brendan McMahan, Peter Kairouz, Ziteng Sun","submitted_at":"2019-11-18T21:25:03Z","abstract_excerpt":"The decentralized nature of federated learning makes detecting and defending against adversarial attacks a challenging task. This paper focuses on backdoor attacks in the federated learning setting, where the goal of the adversary is to reduce the performance of the model on targeted tasks while maintaining good performance on the main task. Unlike existing works, we allow non-malicious clients to have correctly labeled samples from the targeted tasks. We conduct a comprehensive study of backdoor attacks and defenses for the EMNIST dataset, a real-life, user-partitioned, and non-iid dataset. W"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1911.07963","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-11-18T21:25:03Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"bb7deb50464845a1646d4535c94ac193bd70618863d48391a86f43ec34ba0ffd","abstract_canon_sha256":"1715061a04f71bf802c802f4f05149fa150422db79f1145b63421556845dffac"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:23:25.530739Z","signature_b64":"Gq+uSlXmItpzEY+EbID+oVA9p8zDT7vjw+MsQSPDLZDrrK0Vrqq/CnX0TWTO7/zy0HPKfL9aT6eqnDjR8OlbCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ddb4a1a3834f00d1dc6cc4d3d9c09bf1abf72bdd67cb8d0684e0e5db7b95dd67","last_reissued_at":"2026-07-05T00:23:25.530232Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:23:25.530232Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Can You Really Backdoor Federated Learning?","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Ananda Theertha Suresh, H. Brendan McMahan, Peter Kairouz, Ziteng Sun","submitted_at":"2019-11-18T21:25:03Z","abstract_excerpt":"The decentralized nature of federated learning makes detecting and defending against adversarial attacks a challenging task. This paper focuses on backdoor attacks in the federated learning setting, where the goal of the adversary is to reduce the performance of the model on targeted tasks while maintaining good performance on the main task. Unlike existing works, we allow non-malicious clients to have correctly labeled samples from the targeted tasks. We conduct a comprehensive study of backdoor attacks and defenses for the EMNIST dataset, a real-life, user-partitioned, and non-iid dataset. W"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1911.07963","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1911.07963/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1911.07963","created_at":"2026-07-05T00:23:25.530290+00:00"},{"alias_kind":"arxiv_version","alias_value":"1911.07963v2","created_at":"2026-07-05T00:23:25.530290+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1911.07963","created_at":"2026-07-05T00:23:25.530290+00:00"},{"alias_kind":"pith_short_12","alias_value":"3W2KDI4DJ4AN","created_at":"2026-07-05T00:23:25.530290+00:00"},{"alias_kind":"pith_short_16","alias_value":"3W2KDI4DJ4ANDXDM","created_at":"2026-07-05T00:23:25.530290+00:00"},{"alias_kind":"pith_short_8","alias_value":"3W2KDI4D","created_at":"2026-07-05T00:23:25.530290+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":20,"internal_anchor_count":2,"sample":[{"citing_arxiv_id":"2607.06643","citing_title":"The Power of Backdoor Absorption in Community Training","ref_index":12,"is_internal_anchor":true},{"citing_arxiv_id":"2607.07314","citing_title":"FedCVESA: Taking Away Training Data in Federated Learning via Correlation Value Encoding and Segmented Aggregation","ref_index":31,"is_internal_anchor":true},{"citing_arxiv_id":"2606.25858","citing_title":"Color Matters: Trigger Color Affects Success in Federated Backdoor Attacks","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2606.10595","citing_title":"From Data Heterogeneity to Convergence: A Data-Centric Review of Federated Learning","ref_index":149,"is_internal_anchor":false},{"citing_arxiv_id":"2606.09548","citing_title":"Model Poisoning Against Federated Model Adaptation with Chain of Bit-Flips","ref_index":9,"is_internal_anchor":false},{"citing_arxiv_id":"2606.03344","citing_title":"RogueMerge: Robust and Unified Attacks against LLM Model Merging","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2605.21115","citing_title":"Automated Byzantine-Resilient Clustered Decentralized Federated Learning for Battery Intelligence in Connected EVs","ref_index":50,"is_internal_anchor":false},{"citing_arxiv_id":"2605.21115","citing_title":"Automated Byzantine-Resilient Clustered Decentralized Federated Learning for Battery Intelligence in Connected EVs","ref_index":50,"is_internal_anchor":false},{"citing_arxiv_id":"2404.06230","citing_title":"Aggressive or Imperceptible, or Both: Network Pruning Assisted Hybrid Byzantines in Federated Learning","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2407.09658","citing_title":"BoBa: Boosting Backdoor Detection through Data Distribution Inference in Federated Learning","ref_index":32,"is_internal_anchor":false},{"citing_arxiv_id":"2407.15389","citing_title":"Poisoning with A Pill: Circumventing Detection in Federated Learning","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2411.12220","citing_title":"DeTrigger: A Gradient-Centric Approach to Backdoor Attack Mitigation in Federated Learning","ref_index":47,"is_internal_anchor":false},{"citing_arxiv_id":"2605.22506","citing_title":"EnCAgg: Enhanced Clustering Aggregation for Robust Federated Learning against Dynamic Model Poisoning","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2605.21115","citing_title":"Automated Byzantine-Resilient Clustered Decentralized Federated Learning for Battery Intelligence in Connected EVs","ref_index":50,"is_internal_anchor":false},{"citing_arxiv_id":"2508.02115","citing_title":"Coward: Collision-based OOD Watermarking for Practical Proactive Federated Backdoor Detection","ref_index":33,"is_internal_anchor":false},{"citing_arxiv_id":"2509.08089","citing_title":"Hammer and Anvil: Toward a Theory of Backdoors in Federated Learning","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2603.29328","citing_title":"Beyond Corner Patches: Semantics-Aware Backdoor Attack in Federated Learning","ref_index":30,"is_internal_anchor":false},{"citing_arxiv_id":"2604.03862","citing_title":"SecureAFL: Secure Asynchronous Federated Learning","ref_index":64,"is_internal_anchor":false},{"citing_arxiv_id":"2605.11122","citing_title":"FedSurrogate: Backdoor Defense in Federated Learning via Layer Criticality and Surrogate Replacement","ref_index":22,"is_internal_anchor":false},{"citing_arxiv_id":"2604.09489","citing_title":"XFED: Non-Collusive Model Poisoning Attack Against Byzantine-Robust Federated Classifiers","ref_index":51,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/3W2KDI4DJ4ANDXDMYTJ5TQE36G","json":"https://pith.science/pith/3W2KDI4DJ4ANDXDMYTJ5TQE36G.json","graph_json":"https://pith.science/api/pith-number/3W2KDI4DJ4ANDXDMYTJ5TQE36G/graph.json","events_json":"https://pith.science/api/pith-number/3W2KDI4DJ4ANDXDMYTJ5TQE36G/events.json","paper":"https://pith.science/paper/3W2KDI4D"},"agent_actions":{"view_html":"https://pith.science/pith/3W2KDI4DJ4ANDXDMYTJ5TQE36G","download_json":"https://pith.science/pith/3W2KDI4DJ4ANDXDMYTJ5TQE36G.json","view_paper":"https://pith.science/paper/3W2KDI4D","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1911.07963&json=true","fetch_graph":"https://pith.science/api/pith-number/3W2KDI4DJ4ANDXDMYTJ5TQE36G/graph.json","fetch_events":"https://pith.science/api/pith-number/3W2KDI4DJ4ANDXDMYTJ5TQE36G/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/3W2KDI4DJ4ANDXDMYTJ5TQE36G/action/timestamp_anchor","attest_storage":"https://pith.science/pith/3W2KDI4DJ4ANDXDMYTJ5TQE36G/action/storage_attestation","attest_author":"https://pith.science/pith/3W2KDI4DJ4ANDXDMYTJ5TQE36G/action/author_attestation","sign_citation":"https://pith.science/pith/3W2KDI4DJ4ANDXDMYTJ5TQE36G/action/citation_signature","submit_replication":"https://pith.science/pith/3W2KDI4DJ4ANDXDMYTJ5TQE36G/action/replication_record"}},"created_at":"2026-07-05T00:23:25.530290+00:00","updated_at":"2026-07-05T00:23:25.530290+00:00"}