{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2022:4W6C2H2KKN77EA6WKWYEPXVCPM","short_pith_number":"pith:4W6C2H2K","canonical_record":{"source":{"id":"2202.05470","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2022-02-11T06:15:56Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"1ea2809af5d284f8204ae6141369de1259e1986cd7928d8522262d5892e6c2c2","abstract_canon_sha256":"8a0ce9bc18c242e66b30cad069a4ad8f9421603835c9b8b69bee13ea338cb755"},"schema_version":"1.0"},"canonical_sha256":"e5bc2d1f4a537ff203d655b047dea27b0887cffdaff798927371902d34b6fbda","source":{"kind":"arxiv","id":"2202.05470","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2202.05470","created_at":"2026-07-05T03:56:08Z"},{"alias_kind":"arxiv_version","alias_value":"2202.05470v1","created_at":"2026-07-05T03:56:08Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2202.05470","created_at":"2026-07-05T03:56:08Z"},{"alias_kind":"pith_short_12","alias_value":"4W6C2H2KKN77","created_at":"2026-07-05T03:56:08Z"},{"alias_kind":"pith_short_16","alias_value":"4W6C2H2KKN77EA6W","created_at":"2026-07-05T03:56:08Z"},{"alias_kind":"pith_short_8","alias_value":"4W6C2H2K","created_at":"2026-07-05T03:56:08Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2022:4W6C2H2KKN77EA6WKWYEPXVCPM","target":"record","payload":{"canonical_record":{"source":{"id":"2202.05470","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2022-02-11T06:15:56Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"1ea2809af5d284f8204ae6141369de1259e1986cd7928d8522262d5892e6c2c2","abstract_canon_sha256":"8a0ce9bc18c242e66b30cad069a4ad8f9421603835c9b8b69bee13ea338cb755"},"schema_version":"1.0"},"canonical_sha256":"e5bc2d1f4a537ff203d655b047dea27b0887cffdaff798927371902d34b6fbda","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T03:56:08.741155Z","signature_b64":"odxd12LmEG0EE+F1+vwKBEDkWXCPX6EDIbR31YCS7mjwAWJU0hmQAV8uiwmlPW/FWrl06IuFJldhHVbfQB4wCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e5bc2d1f4a537ff203d655b047dea27b0887cffdaff798927371902d34b6fbda","last_reissued_at":"2026-07-05T03:56:08.740664Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T03:56:08.740664Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2202.05470","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T03:56:08Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"r/qNx1yFMjwq3do+vrb2Aqwfc7rmHW6jH0z7UsJRoNz34l5psUlABpNFq/sJS388TN5Ci3cUi2jTr/cBlSBMDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-05T09:06:29.149807Z"},"content_sha256":"694356295add4288d69c7956071d5653e554ed2ea9aa7381eb6ca57d73441dea","schema_version":"1.0","event_id":"sha256:694356295add4288d69c7956071d5653e554ed2ea9aa7381eb6ca57d73441dea"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2022:4W6C2H2KKN77EA6WKWYEPXVCPM","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Jigsaw Puzzle: Selective Backdoor Attack to Subvert Malware Classifiers","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Fabio Pierazzi, Feargus Pendlebury, Gang Wang, Jacopo Cortellazzi, Kevin Tu, Limin Yang, Lorenzo Cavallaro, Zhi Chen","submitted_at":"2022-02-11T06:15:56Z","abstract_excerpt":"Malware classifiers are subject to training-time exploitation due to the need to regularly retrain using samples collected from the wild. Recent work has demonstrated the feasibility of backdoor attacks against malware classifiers, and yet the stealthiness of such attacks is not well understood. In this paper, we investigate this phenomenon under the clean-label setting (i.e., attackers do not have complete control over the training or labeling process). Empirically, we show that existing backdoor attacks in malware classifiers are still detectable by recent defenses such as MNTD. To improve s"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2202.05470","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2202.05470/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T03:56:08Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"DxPxSo1rMTRT6awBDAHeEcOlwF537PQ6WTE9iX+N4xEHcPRYihV2ANV/VlepcXw4nFR54H78b8k/tG2Z3z2cDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-05T09:06:29.150191Z"},"content_sha256":"6378e671ba4faf81421deed28bc97a33bba6b876930b76f9d44e82b404a78228","schema_version":"1.0","event_id":"sha256:6378e671ba4faf81421deed28bc97a33bba6b876930b76f9d44e82b404a78228"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/4W6C2H2KKN77EA6WKWYEPXVCPM/bundle.json","state_url":"https://pith.science/pith/4W6C2H2KKN77EA6WKWYEPXVCPM/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/4W6C2H2KKN77EA6WKWYEPXVCPM/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-05T09:06:29Z","links":{"resolver":"https://pith.science/pith/4W6C2H2KKN77EA6WKWYEPXVCPM","bundle":"https://pith.science/pith/4W6C2H2KKN77EA6WKWYEPXVCPM/bundle.json","state":"https://pith.science/pith/4W6C2H2KKN77EA6WKWYEPXVCPM/state.json","well_known_bundle":"https://pith.science/.well-known/pith/4W6C2H2KKN77EA6WKWYEPXVCPM/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2022:4W6C2H2KKN77EA6WKWYEPXVCPM","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"8a0ce9bc18c242e66b30cad069a4ad8f9421603835c9b8b69bee13ea338cb755","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2022-02-11T06:15:56Z","title_canon_sha256":"1ea2809af5d284f8204ae6141369de1259e1986cd7928d8522262d5892e6c2c2"},"schema_version":"1.0","source":{"id":"2202.05470","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2202.05470","created_at":"2026-07-05T03:56:08Z"},{"alias_kind":"arxiv_version","alias_value":"2202.05470v1","created_at":"2026-07-05T03:56:08Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2202.05470","created_at":"2026-07-05T03:56:08Z"},{"alias_kind":"pith_short_12","alias_value":"4W6C2H2KKN77","created_at":"2026-07-05T03:56:08Z"},{"alias_kind":"pith_short_16","alias_value":"4W6C2H2KKN77EA6W","created_at":"2026-07-05T03:56:08Z"},{"alias_kind":"pith_short_8","alias_value":"4W6C2H2K","created_at":"2026-07-05T03:56:08Z"}],"graph_snapshots":[{"event_id":"sha256:6378e671ba4faf81421deed28bc97a33bba6b876930b76f9d44e82b404a78228","target":"graph","created_at":"2026-07-05T03:56:08Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2202.05470/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Malware classifiers are subject to training-time exploitation due to the need to regularly retrain using samples collected from the wild. Recent work has demonstrated the feasibility of backdoor attacks against malware classifiers, and yet the stealthiness of such attacks is not well understood. In this paper, we investigate this phenomenon under the clean-label setting (i.e., attackers do not have complete control over the training or labeling process). Empirically, we show that existing backdoor attacks in malware classifiers are still detectable by recent defenses such as MNTD. To improve s","authors_text":"Fabio Pierazzi, Feargus Pendlebury, Gang Wang, Jacopo Cortellazzi, Kevin Tu, Limin Yang, Lorenzo Cavallaro, Zhi Chen","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2022-02-11T06:15:56Z","title":"Jigsaw Puzzle: Selective Backdoor Attack to Subvert Malware Classifiers"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2202.05470","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:694356295add4288d69c7956071d5653e554ed2ea9aa7381eb6ca57d73441dea","target":"record","created_at":"2026-07-05T03:56:08Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"8a0ce9bc18c242e66b30cad069a4ad8f9421603835c9b8b69bee13ea338cb755","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2022-02-11T06:15:56Z","title_canon_sha256":"1ea2809af5d284f8204ae6141369de1259e1986cd7928d8522262d5892e6c2c2"},"schema_version":"1.0","source":{"id":"2202.05470","kind":"arxiv","version":1}},"canonical_sha256":"e5bc2d1f4a537ff203d655b047dea27b0887cffdaff798927371902d34b6fbda","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"e5bc2d1f4a537ff203d655b047dea27b0887cffdaff798927371902d34b6fbda","first_computed_at":"2026-07-05T03:56:08.740664Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T03:56:08.740664Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"odxd12LmEG0EE+F1+vwKBEDkWXCPX6EDIbR31YCS7mjwAWJU0hmQAV8uiwmlPW/FWrl06IuFJldhHVbfQB4wCg==","signature_status":"signed_v1","signed_at":"2026-07-05T03:56:08.741155Z","signed_message":"canonical_sha256_bytes"},"source_id":"2202.05470","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:694356295add4288d69c7956071d5653e554ed2ea9aa7381eb6ca57d73441dea","sha256:6378e671ba4faf81421deed28bc97a33bba6b876930b76f9d44e82b404a78228"],"state_sha256":"cc342f1e946b7f02d7ff0a498bf1cf23ec51e6108ccfb1056e756f5f161a15b6"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"V0zMrmO1yltpyk13auxy9hCoNaLhRe354vYMipcJyzEEyS2x9NTAyDf0FtQeqmQ9BQCvagpXROi07MwY9fwkCg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-05T09:06:29.151974Z","bundle_sha256":"b572d66e302cf2cadaaaa6ac1baef93a3563fba28abb4a27d4765aa04598fd2f"}}