{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:BWTTIIZ7SQLSORPUFKI2FHCJAY","short_pith_number":"pith:BWTTIIZ7","schema_version":"1.0","canonical_sha256":"0da734233f94172745f42a91a29c49060526f7107144bba6ee8f9c379f3728ef","source":{"kind":"arxiv","id":"1909.02742","version":3},"attestation_state":"computed","paper":{"title":"Invisible Backdoor Attacks on Deep Neural Networks via Steganography and Regularization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","cs.LG"],"primary_cat":"cs.CR","authors_text":"Benjamin Zi Hao Zhao, Haojin Zhu, Minhui Xue, Shaofeng Li, Xinpeng Zhang","submitted_at":"2019-09-06T07:11:26Z","abstract_excerpt":"Deep neural networks (DNNs) have been proven vulnerable to backdoor attacks, where hidden features (patterns) trained to a normal model, which is only activated by some specific input (called triggers), trick the model into producing unexpected behavior. In this paper, we create covert and scattered triggers for backdoor attacks, invisible backdoors, where triggers can fool both DNN models and human inspection. We apply our invisible backdoors through two state-of-the-art methods of embedding triggers for backdoor attacks. The first approach on Badnets embeds the trigger into DNNs through steg"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1909.02742","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-09-06T07:11:26Z","cross_cats_sorted":["cs.CV","cs.LG"],"title_canon_sha256":"59d67aa9683f89976a7cc89e81fde3fa234573326ca015f0f600b1ae08bb2843","abstract_canon_sha256":"71fe4b20f2067f83805659267d05b0f2136087e683eb97ad0bc2a20ee0ef6bd3"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T01:31:21.900917Z","signature_b64":"fTcbFeDsXQzgvLFIjbNE2brz5HDGZLnkObe3nRSNLuH0t/i3IfPyL5tO5y0f7G6qOI8bPF6HKSpgGqwTCS9NAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"0da734233f94172745f42a91a29c49060526f7107144bba6ee8f9c379f3728ef","last_reissued_at":"2026-07-05T01:31:21.900494Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T01:31:21.900494Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Invisible Backdoor Attacks on Deep Neural Networks via Steganography and Regularization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","cs.LG"],"primary_cat":"cs.CR","authors_text":"Benjamin Zi Hao Zhao, Haojin Zhu, Minhui Xue, Shaofeng Li, Xinpeng Zhang","submitted_at":"2019-09-06T07:11:26Z","abstract_excerpt":"Deep neural networks (DNNs) have been proven vulnerable to backdoor attacks, where hidden features (patterns) trained to a normal model, which is only activated by some specific input (called triggers), trick the model into producing unexpected behavior. In this paper, we create covert and scattered triggers for backdoor attacks, invisible backdoors, where triggers can fool both DNN models and human inspection. We apply our invisible backdoors through two state-of-the-art methods of embedding triggers for backdoor attacks. The first approach on Badnets embeds the trigger into DNNs through steg"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1909.02742","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1909.02742/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1909.02742","created_at":"2026-07-05T01:31:21.900546+00:00"},{"alias_kind":"arxiv_version","alias_value":"1909.02742v3","created_at":"2026-07-05T01:31:21.900546+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1909.02742","created_at":"2026-07-05T01:31:21.900546+00:00"},{"alias_kind":"pith_short_12","alias_value":"BWTTIIZ7SQLS","created_at":"2026-07-05T01:31:21.900546+00:00"},{"alias_kind":"pith_short_16","alias_value":"BWTTIIZ7SQLSORPU","created_at":"2026-07-05T01:31:21.900546+00:00"},{"alias_kind":"pith_short_8","alias_value":"BWTTIIZ7","created_at":"2026-07-05T01:31:21.900546+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2506.06518","citing_title":"A Systematic Review of Poisoning Attacks Against Large Language Models","ref_index":22,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/BWTTIIZ7SQLSORPUFKI2FHCJAY","json":"https://pith.science/pith/BWTTIIZ7SQLSORPUFKI2FHCJAY.json","graph_json":"https://pith.science/api/pith-number/BWTTIIZ7SQLSORPUFKI2FHCJAY/graph.json","events_json":"https://pith.science/api/pith-number/BWTTIIZ7SQLSORPUFKI2FHCJAY/events.json","paper":"https://pith.science/paper/BWTTIIZ7"},"agent_actions":{"view_html":"https://pith.science/pith/BWTTIIZ7SQLSORPUFKI2FHCJAY","download_json":"https://pith.science/pith/BWTTIIZ7SQLSORPUFKI2FHCJAY.json","view_paper":"https://pith.science/paper/BWTTIIZ7","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1909.02742&json=true","fetch_graph":"https://pith.science/api/pith-number/BWTTIIZ7SQLSORPUFKI2FHCJAY/graph.json","fetch_events":"https://pith.science/api/pith-number/BWTTIIZ7SQLSORPUFKI2FHCJAY/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/BWTTIIZ7SQLSORPUFKI2FHCJAY/action/timestamp_anchor","attest_storage":"https://pith.science/pith/BWTTIIZ7SQLSORPUFKI2FHCJAY/action/storage_attestation","attest_author":"https://pith.science/pith/BWTTIIZ7SQLSORPUFKI2FHCJAY/action/author_attestation","sign_citation":"https://pith.science/pith/BWTTIIZ7SQLSORPUFKI2FHCJAY/action/citation_signature","submit_replication":"https://pith.science/pith/BWTTIIZ7SQLSORPUFKI2FHCJAY/action/replication_record"}},"created_at":"2026-07-05T01:31:21.900546+00:00","updated_at":"2026-07-05T01:31:21.900546+00:00"}