{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:DCSFYPS3KTISKZRQGWHJY5LGUL","short_pith_number":"pith:DCSFYPS3","schema_version":"1.0","canonical_sha256":"18a45c3e5b54d1256630358e9c7566a2c00e1a051b282ea69ec9435cd57a6fe3","source":{"kind":"arxiv","id":"2301.12318","version":2},"attestation_state":"computed","paper":{"title":"Gradient Shaping: Enhancing Backdoor Attack Against Reverse Engineering","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Di Tang, Guanhong Tao, Haixu Tang, Rui Zhu, Shiqing Ma, Siyuan Tang, Xiaofeng Wang","submitted_at":"2023-01-29T01:17:46Z","abstract_excerpt":"Most existing methods to detect backdoored machine learning (ML) models take one of the two approaches: trigger inversion (aka. reverse engineer) and weight analysis (aka. model diagnosis). In particular, the gradient-based trigger inversion is considered to be among the most effective backdoor detection techniques, as evidenced by the TrojAI competition, Trojan Detection Challenge and backdoorBench. However, little has been done to understand why this technique works so well and, more importantly, whether it raises the bar to the backdoor attack. In this paper, we report the first attempt to "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2301.12318","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2023-01-29T01:17:46Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"8eabb347fa5dfd3d59b82393fc82044c97d399939186cd3622b37f0afb111a2d","abstract_canon_sha256":"ff41d829059efef0d9c2cf541a1e17fd40caaec0edbda2d0cfda378ecc4d54cb"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:46:15.966497Z","signature_b64":"Z7A9Rvk9Yq9WcvfyqqCXqiqeG3D5W8UoQ+MFkR5b5IgunVsHC7EdTrmBsFzpDUUL8SPFNS0LnrpM5tZZvhJYAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"18a45c3e5b54d1256630358e9c7566a2c00e1a051b282ea69ec9435cd57a6fe3","last_reissued_at":"2026-07-05T08:46:15.965946Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:46:15.965946Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Gradient Shaping: Enhancing Backdoor Attack Against Reverse Engineering","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Di Tang, Guanhong Tao, Haixu Tang, Rui Zhu, Shiqing Ma, Siyuan Tang, Xiaofeng Wang","submitted_at":"2023-01-29T01:17:46Z","abstract_excerpt":"Most existing methods to detect backdoored machine learning (ML) models take one of the two approaches: trigger inversion (aka. reverse engineer) and weight analysis (aka. model diagnosis). In particular, the gradient-based trigger inversion is considered to be among the most effective backdoor detection techniques, as evidenced by the TrojAI competition, Trojan Detection Challenge and backdoorBench. However, little has been done to understand why this technique works so well and, more importantly, whether it raises the bar to the backdoor attack. In this paper, we report the first attempt to "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2301.12318","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2301.12318/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2301.12318","created_at":"2026-07-05T08:46:15.966025+00:00"},{"alias_kind":"arxiv_version","alias_value":"2301.12318v2","created_at":"2026-07-05T08:46:15.966025+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2301.12318","created_at":"2026-07-05T08:46:15.966025+00:00"},{"alias_kind":"pith_short_12","alias_value":"DCSFYPS3KTIS","created_at":"2026-07-05T08:46:15.966025+00:00"},{"alias_kind":"pith_short_16","alias_value":"DCSFYPS3KTISKZRQ","created_at":"2026-07-05T08:46:15.966025+00:00"},{"alias_kind":"pith_short_8","alias_value":"DCSFYPS3","created_at":"2026-07-05T08:46:15.966025+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.06643","citing_title":"The Power of Backdoor Absorption in Community Training","ref_index":15,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/DCSFYPS3KTISKZRQGWHJY5LGUL","json":"https://pith.science/pith/DCSFYPS3KTISKZRQGWHJY5LGUL.json","graph_json":"https://pith.science/api/pith-number/DCSFYPS3KTISKZRQGWHJY5LGUL/graph.json","events_json":"https://pith.science/api/pith-number/DCSFYPS3KTISKZRQGWHJY5LGUL/events.json","paper":"https://pith.science/paper/DCSFYPS3"},"agent_actions":{"view_html":"https://pith.science/pith/DCSFYPS3KTISKZRQGWHJY5LGUL","download_json":"https://pith.science/pith/DCSFYPS3KTISKZRQGWHJY5LGUL.json","view_paper":"https://pith.science/paper/DCSFYPS3","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2301.12318&json=true","fetch_graph":"https://pith.science/api/pith-number/DCSFYPS3KTISKZRQGWHJY5LGUL/graph.json","fetch_events":"https://pith.science/api/pith-number/DCSFYPS3KTISKZRQGWHJY5LGUL/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/DCSFYPS3KTISKZRQGWHJY5LGUL/action/timestamp_anchor","attest_storage":"https://pith.science/pith/DCSFYPS3KTISKZRQGWHJY5LGUL/action/storage_attestation","attest_author":"https://pith.science/pith/DCSFYPS3KTISKZRQGWHJY5LGUL/action/author_attestation","sign_citation":"https://pith.science/pith/DCSFYPS3KTISKZRQGWHJY5LGUL/action/citation_signature","submit_replication":"https://pith.science/pith/DCSFYPS3KTISKZRQGWHJY5LGUL/action/replication_record"}},"created_at":"2026-07-05T08:46:15.966025+00:00","updated_at":"2026-07-05T08:46:15.966025+00:00"}