{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:C25CIWKFBZTBBVZTTNYUGNHA2U","short_pith_number":"pith:C25CIWKF","schema_version":"1.0","canonical_sha256":"16ba2459450e6610d7339b714334e0d51b580d81a78ccfef2802286da744cd78","source":{"kind":"arxiv","id":"2411.09585","version":2},"attestation_state":"computed","paper":{"title":"Backdoor Mitigation by Distance-Driven Detoxification","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Hongyuan Zha, Jiayin Liu, Shaokui Wei","submitted_at":"2024-11-14T16:54:06Z","abstract_excerpt":"Backdoor attacks undermine the integrity of machine learning models by allowing attackers to manipulate predictions using poisoned training data. Such attacks lead to targeted misclassification when specific triggers are present, while the model behaves normally under other conditions. This paper considers a post-training backdoor defense task, aiming to detoxify the backdoors in pre-trained models. We begin by analyzing the underlying issues of vanilla fine-tuning and observe that it is often trapped in regions with low loss for both clean and poisoned samples. Motivated by such observations,"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2411.09585","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-11-14T16:54:06Z","cross_cats_sorted":[],"title_canon_sha256":"8f6977c2d0e168aca0bee6a6816348bd2172b687ba57b51f4b41c66207a1fea9","abstract_canon_sha256":"b62a0c3e644403ec1383b46a7ac192e03dc3657514c4cb01657e8cd5856f4b76"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:12:23.410606Z","signature_b64":"2MImyPyddbBjp69tm+P1Cy8LTOgrQQcrqcHSZq+JFvPemWtTU6aV9Mv8m0c9IA/+1X0DUI7AXnmkQZJhD6WxDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"16ba2459450e6610d7339b714334e0d51b580d81a78ccfef2802286da744cd78","last_reissued_at":"2026-07-05T10:12:23.410100Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:12:23.410100Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Backdoor Mitigation by Distance-Driven Detoxification","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Hongyuan Zha, Jiayin Liu, Shaokui Wei","submitted_at":"2024-11-14T16:54:06Z","abstract_excerpt":"Backdoor attacks undermine the integrity of machine learning models by allowing attackers to manipulate predictions using poisoned training data. Such attacks lead to targeted misclassification when specific triggers are present, while the model behaves normally under other conditions. This paper considers a post-training backdoor defense task, aiming to detoxify the backdoors in pre-trained models. We begin by analyzing the underlying issues of vanilla fine-tuning and observe that it is often trapped in regions with low loss for both clean and poisoned samples. Motivated by such observations,"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2411.09585","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2411.09585/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2411.09585","created_at":"2026-07-05T10:12:23.410158+00:00"},{"alias_kind":"arxiv_version","alias_value":"2411.09585v2","created_at":"2026-07-05T10:12:23.410158+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2411.09585","created_at":"2026-07-05T10:12:23.410158+00:00"},{"alias_kind":"pith_short_12","alias_value":"C25CIWKFBZTB","created_at":"2026-07-05T10:12:23.410158+00:00"},{"alias_kind":"pith_short_16","alias_value":"C25CIWKFBZTBBVZT","created_at":"2026-07-05T10:12:23.410158+00:00"},{"alias_kind":"pith_short_8","alias_value":"C25CIWKF","created_at":"2026-07-05T10:12:23.410158+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2502.07231","citing_title":"Revisiting the Auxiliary Data in Backdoor Purification","ref_index":35,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/C25CIWKFBZTBBVZTTNYUGNHA2U","json":"https://pith.science/pith/C25CIWKFBZTBBVZTTNYUGNHA2U.json","graph_json":"https://pith.science/api/pith-number/C25CIWKFBZTBBVZTTNYUGNHA2U/graph.json","events_json":"https://pith.science/api/pith-number/C25CIWKFBZTBBVZTTNYUGNHA2U/events.json","paper":"https://pith.science/paper/C25CIWKF"},"agent_actions":{"view_html":"https://pith.science/pith/C25CIWKFBZTBBVZTTNYUGNHA2U","download_json":"https://pith.science/pith/C25CIWKFBZTBBVZTTNYUGNHA2U.json","view_paper":"https://pith.science/paper/C25CIWKF","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2411.09585&json=true","fetch_graph":"https://pith.science/api/pith-number/C25CIWKFBZTBBVZTTNYUGNHA2U/graph.json","fetch_events":"https://pith.science/api/pith-number/C25CIWKFBZTBBVZTTNYUGNHA2U/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/C25CIWKFBZTBBVZTTNYUGNHA2U/action/timestamp_anchor","attest_storage":"https://pith.science/pith/C25CIWKFBZTBBVZTTNYUGNHA2U/action/storage_attestation","attest_author":"https://pith.science/pith/C25CIWKFBZTBBVZTTNYUGNHA2U/action/author_attestation","sign_citation":"https://pith.science/pith/C25CIWKFBZTBBVZTTNYUGNHA2U/action/citation_signature","submit_replication":"https://pith.science/pith/C25CIWKFBZTBBVZTTNYUGNHA2U/action/replication_record"}},"created_at":"2026-07-05T10:12:23.410158+00:00","updated_at":"2026-07-05T10:12:23.410158+00:00"}