{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:A5NNLG2DLWEREJPFXYPE7LHVRH","short_pith_number":"pith:A5NNLG2D","schema_version":"1.0","canonical_sha256":"075ad59b435d891225e5be1e4facf589f39d60eab9f3b1be803f3fb2000a28d8","source":{"kind":"arxiv","id":"2303.02242","version":2},"attestation_state":"computed","paper":{"title":"TrojText: Test-time Invisible Textual Trojan Insertion","license":"http://creativecommons.org/licenses/by-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Bo Feng, Qian Lou, Yepeng Liu","submitted_at":"2023-03-03T22:19:22Z","abstract_excerpt":"In Natural Language Processing (NLP), intelligent neuron models can be susceptible to textual Trojan attacks. Such attacks occur when Trojan models behave normally for standard inputs but generate malicious output for inputs that contain a specific trigger. Syntactic-structure triggers, which are invisible, are becoming more popular for Trojan attacks because they are difficult to detect and defend against. However, these types of attacks require a large corpus of training data to generate poisoned samples with the necessary syntactic structures for Trojan insertion. Obtaining such data can be"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2303.02242","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.CL","submitted_at":"2023-03-03T22:19:22Z","cross_cats_sorted":[],"title_canon_sha256":"f1654b7dfe04489d4cfb7ae82ba8496124bc4613833e131e5911af585d8b7b2b","abstract_canon_sha256":"c87e6e84813fbda2f8f920c9ed24dfd91e7fbb7586c173a3af039abe0c6f8549"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T06:43:21.377574Z","signature_b64":"/pP6pMWVfy5k1jn9upfpN29uvgfdyQXzRrRelKz26v0HJEajb3iVHbi4e7eoCIvp9qvg/KDq9YhI2OC5kzxqBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"075ad59b435d891225e5be1e4facf589f39d60eab9f3b1be803f3fb2000a28d8","last_reissued_at":"2026-07-05T06:43:21.377144Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T06:43:21.377144Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"TrojText: Test-time Invisible Textual Trojan Insertion","license":"http://creativecommons.org/licenses/by-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Bo Feng, Qian Lou, Yepeng Liu","submitted_at":"2023-03-03T22:19:22Z","abstract_excerpt":"In Natural Language Processing (NLP), intelligent neuron models can be susceptible to textual Trojan attacks. Such attacks occur when Trojan models behave normally for standard inputs but generate malicious output for inputs that contain a specific trigger. Syntactic-structure triggers, which are invisible, are becoming more popular for Trojan attacks because they are difficult to detect and defend against. However, these types of attacks require a large corpus of training data to generate poisoned samples with the necessary syntactic structures for Trojan insertion. Obtaining such data can be"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2303.02242","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2303.02242/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2303.02242","created_at":"2026-07-05T06:43:21.377202+00:00"},{"alias_kind":"arxiv_version","alias_value":"2303.02242v2","created_at":"2026-07-05T06:43:21.377202+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2303.02242","created_at":"2026-07-05T06:43:21.377202+00:00"},{"alias_kind":"pith_short_12","alias_value":"A5NNLG2DLWER","created_at":"2026-07-05T06:43:21.377202+00:00"},{"alias_kind":"pith_short_16","alias_value":"A5NNLG2DLWEREJPF","created_at":"2026-07-05T06:43:21.377202+00:00"},{"alias_kind":"pith_short_8","alias_value":"A5NNLG2D","created_at":"2026-07-05T06:43:21.377202+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2510.18333","citing_title":"Position: LLM Watermarking Should Align Stakeholders' Incentives for Practical Adoption","ref_index":38,"is_internal_anchor":false},{"citing_arxiv_id":"2604.16543","citing_title":"Conjunctive Prompt Attacks in Multi-Agent LLM Systems","ref_index":26,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/A5NNLG2DLWEREJPFXYPE7LHVRH","json":"https://pith.science/pith/A5NNLG2DLWEREJPFXYPE7LHVRH.json","graph_json":"https://pith.science/api/pith-number/A5NNLG2DLWEREJPFXYPE7LHVRH/graph.json","events_json":"https://pith.science/api/pith-number/A5NNLG2DLWEREJPFXYPE7LHVRH/events.json","paper":"https://pith.science/paper/A5NNLG2D"},"agent_actions":{"view_html":"https://pith.science/pith/A5NNLG2DLWEREJPFXYPE7LHVRH","download_json":"https://pith.science/pith/A5NNLG2DLWEREJPFXYPE7LHVRH.json","view_paper":"https://pith.science/paper/A5NNLG2D","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2303.02242&json=true","fetch_graph":"https://pith.science/api/pith-number/A5NNLG2DLWEREJPFXYPE7LHVRH/graph.json","fetch_events":"https://pith.science/api/pith-number/A5NNLG2DLWEREJPFXYPE7LHVRH/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/A5NNLG2DLWEREJPFXYPE7LHVRH/action/timestamp_anchor","attest_storage":"https://pith.science/pith/A5NNLG2DLWEREJPFXYPE7LHVRH/action/storage_attestation","attest_author":"https://pith.science/pith/A5NNLG2DLWEREJPFXYPE7LHVRH/action/author_attestation","sign_citation":"https://pith.science/pith/A5NNLG2DLWEREJPFXYPE7LHVRH/action/citation_signature","submit_replication":"https://pith.science/pith/A5NNLG2DLWEREJPFXYPE7LHVRH/action/replication_record"}},"created_at":"2026-07-05T06:43:21.377202+00:00","updated_at":"2026-07-05T06:43:21.377202+00:00"}