{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:C6YBLYT3RVXEX3NQZONMQ46MPV","short_pith_number":"pith:C6YBLYT3","schema_version":"1.0","canonical_sha256":"17b015e27b8d6e4bedb0cb9ac873cc7d70f979fc6e0d768afa69c7275898c553","source":{"kind":"arxiv","id":"2411.16746","version":4},"attestation_state":"computed","paper":{"title":"LoBAM: LoRA-Based Backdoor Attack on Model Merging","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Hai Li, Jingwei Sun, Jingyang Zhang, Minghong Fang, Ming Yin, Yiran Chen","submitted_at":"2024-11-23T20:41:24Z","abstract_excerpt":"Model merging is an emerging technique that integrates multiple models fine-tuned on different tasks to create a versatile model that excels in multiple domains. This scheme, in the meantime, may open up backdoor attack opportunities where one single malicious model can jeopardize the integrity of the merged model. Existing works try to demonstrate the risk of such attacks by assuming substantial computational resources, focusing on cases where the attacker can fully fine-tune the pre-trained model. Such an assumption, however, may not be feasible given the increasing size of machine learning "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2411.16746","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-11-23T20:41:24Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"270bb55f8b021eadf130b6b02625c06b3c071eb2484fad829e33463b9aa0d09b","abstract_canon_sha256":"b6f87b233790e76e3938127c55e89bbe4ed53d3ab9d21a8cd47922774024b9fb"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:12:22.648398Z","signature_b64":"PwVota5aEmfhBCwZAG2vCqSMZO13BdlxlhJuXS8tPhn/yuWMOVGIpm6vuUXlUHG34bg2l37ReTmjL6n67dIjBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"17b015e27b8d6e4bedb0cb9ac873cc7d70f979fc6e0d768afa69c7275898c553","last_reissued_at":"2026-07-05T11:12:22.647846Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:12:22.647846Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"LoBAM: LoRA-Based Backdoor Attack on Model Merging","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Hai Li, Jingwei Sun, Jingyang Zhang, Minghong Fang, Ming Yin, Yiran Chen","submitted_at":"2024-11-23T20:41:24Z","abstract_excerpt":"Model merging is an emerging technique that integrates multiple models fine-tuned on different tasks to create a versatile model that excels in multiple domains. This scheme, in the meantime, may open up backdoor attack opportunities where one single malicious model can jeopardize the integrity of the merged model. Existing works try to demonstrate the risk of such attacks by assuming substantial computational resources, focusing on cases where the attacker can fully fine-tune the pre-trained model. Such an assumption, however, may not be feasible given the increasing size of machine learning "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2411.16746","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2411.16746/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2411.16746","created_at":"2026-07-05T11:12:22.647911+00:00"},{"alias_kind":"arxiv_version","alias_value":"2411.16746v4","created_at":"2026-07-05T11:12:22.647911+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2411.16746","created_at":"2026-07-05T11:12:22.647911+00:00"},{"alias_kind":"pith_short_12","alias_value":"C6YBLYT3RVXE","created_at":"2026-07-05T11:12:22.647911+00:00"},{"alias_kind":"pith_short_16","alias_value":"C6YBLYT3RVXEX3NQ","created_at":"2026-07-05T11:12:22.647911+00:00"},{"alias_kind":"pith_short_8","alias_value":"C6YBLYT3","created_at":"2026-07-05T11:12:22.647911+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":4,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.23075","citing_title":"Safety in Self-Evolving LLM Agent Systems: Threats, Amplification, and Case Studies","ref_index":98,"is_internal_anchor":false},{"citing_arxiv_id":"2606.12498","citing_title":"From Parameters to Feature Space: Task Arithmetic for Backdoor Mitigation in Model Merging","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2606.03344","citing_title":"RogueMerge: Robust and Unified Attacks against LLM Model Merging","ref_index":13,"is_internal_anchor":false},{"citing_arxiv_id":"2602.21977","citing_title":"When LoRA Betrays: Backdooring Text-to-Image Models by Masquerading as Benign Adapters","ref_index":44,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/C6YBLYT3RVXEX3NQZONMQ46MPV","json":"https://pith.science/pith/C6YBLYT3RVXEX3NQZONMQ46MPV.json","graph_json":"https://pith.science/api/pith-number/C6YBLYT3RVXEX3NQZONMQ46MPV/graph.json","events_json":"https://pith.science/api/pith-number/C6YBLYT3RVXEX3NQZONMQ46MPV/events.json","paper":"https://pith.science/paper/C6YBLYT3"},"agent_actions":{"view_html":"https://pith.science/pith/C6YBLYT3RVXEX3NQZONMQ46MPV","download_json":"https://pith.science/pith/C6YBLYT3RVXEX3NQZONMQ46MPV.json","view_paper":"https://pith.science/paper/C6YBLYT3","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2411.16746&json=true","fetch_graph":"https://pith.science/api/pith-number/C6YBLYT3RVXEX3NQZONMQ46MPV/graph.json","fetch_events":"https://pith.science/api/pith-number/C6YBLYT3RVXEX3NQZONMQ46MPV/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/C6YBLYT3RVXEX3NQZONMQ46MPV/action/timestamp_anchor","attest_storage":"https://pith.science/pith/C6YBLYT3RVXEX3NQZONMQ46MPV/action/storage_attestation","attest_author":"https://pith.science/pith/C6YBLYT3RVXEX3NQZONMQ46MPV/action/author_attestation","sign_citation":"https://pith.science/pith/C6YBLYT3RVXEX3NQZONMQ46MPV/action/citation_signature","submit_replication":"https://pith.science/pith/C6YBLYT3RVXEX3NQZONMQ46MPV/action/replication_record"}},"created_at":"2026-07-05T11:12:22.647911+00:00","updated_at":"2026-07-05T11:12:22.647911+00:00"}