{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:DG6O6GPN4KVRZ2ZU6WRNRLPW7D","short_pith_number":"pith:DG6O6GPN","schema_version":"1.0","canonical_sha256":"19bcef19ede2ab1ceb34f5a2d8adf6f8e5aaaf867e239766d22d5b79ff39964d","source":{"kind":"arxiv","id":"2302.01740","version":2},"attestation_state":"computed","paper":{"title":"SoK: A Systematic Evaluation of Backdoor Trigger Characteristics in Image Classification","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR","cs.LG"],"primary_cat":"cs.CV","authors_text":"Behrad Tajalli, Gorka Abad, Jing Xu, Mauro Conti, Stefanos Koffas, Stjepan Picek","submitted_at":"2023-02-03T14:00:05Z","abstract_excerpt":"Deep learning achieves outstanding results in many machine learning tasks. Nevertheless, it is vulnerable to backdoor attacks that modify the training set to embed a secret functionality in the trained model. The modified training samples have a secret property, i. e., a trigger. At inference time, the secret functionality is activated when the input contains the trigger, while the model functions correctly in other cases. While there are many known backdoor attacks (and defenses), deploying a stealthy attack is still far from trivial. Successfully creating backdoor triggers depends on numerou"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2302.01740","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2023-02-03T14:00:05Z","cross_cats_sorted":["cs.CR","cs.LG"],"title_canon_sha256":"55f83a0ab917c0c159ec0e4771e0c167af32fdbfbdfc92f378c5e220da8f78e2","abstract_canon_sha256":"1306cbd6cbe58157ed8f3933d5c7e376dc62e62f347f83814970b0186fbf5dab"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T06:03:11.370568Z","signature_b64":"siCsRQGSjN0QnaqLHS8ptrKLVWTBItrZcMfR4AyFstXeF5XvtOlEDol/pyep2ixkZalaIrblA5YTShnCivq5Bw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"19bcef19ede2ab1ceb34f5a2d8adf6f8e5aaaf867e239766d22d5b79ff39964d","last_reissued_at":"2026-07-05T06:03:11.370022Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T06:03:11.370022Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"SoK: A Systematic Evaluation of Backdoor Trigger Characteristics in Image Classification","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR","cs.LG"],"primary_cat":"cs.CV","authors_text":"Behrad Tajalli, Gorka Abad, Jing Xu, Mauro Conti, Stefanos Koffas, Stjepan Picek","submitted_at":"2023-02-03T14:00:05Z","abstract_excerpt":"Deep learning achieves outstanding results in many machine learning tasks. Nevertheless, it is vulnerable to backdoor attacks that modify the training set to embed a secret functionality in the trained model. The modified training samples have a secret property, i. e., a trigger. At inference time, the secret functionality is activated when the input contains the trigger, while the model functions correctly in other cases. While there are many known backdoor attacks (and defenses), deploying a stealthy attack is still far from trivial. Successfully creating backdoor triggers depends on numerou"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2302.01740","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2302.01740/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2302.01740","created_at":"2026-07-05T06:03:11.370084+00:00"},{"alias_kind":"arxiv_version","alias_value":"2302.01740v2","created_at":"2026-07-05T06:03:11.370084+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2302.01740","created_at":"2026-07-05T06:03:11.370084+00:00"},{"alias_kind":"pith_short_12","alias_value":"DG6O6GPN4KVR","created_at":"2026-07-05T06:03:11.370084+00:00"},{"alias_kind":"pith_short_16","alias_value":"DG6O6GPN4KVRZ2ZU","created_at":"2026-07-05T06:03:11.370084+00:00"},{"alias_kind":"pith_short_8","alias_value":"DG6O6GPN","created_at":"2026-07-05T06:03:11.370084+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.10091","citing_title":"SoK: Colluding Adversaries in Machine Learning Pipelines","ref_index":2,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/DG6O6GPN4KVRZ2ZU6WRNRLPW7D","json":"https://pith.science/pith/DG6O6GPN4KVRZ2ZU6WRNRLPW7D.json","graph_json":"https://pith.science/api/pith-number/DG6O6GPN4KVRZ2ZU6WRNRLPW7D/graph.json","events_json":"https://pith.science/api/pith-number/DG6O6GPN4KVRZ2ZU6WRNRLPW7D/events.json","paper":"https://pith.science/paper/DG6O6GPN"},"agent_actions":{"view_html":"https://pith.science/pith/DG6O6GPN4KVRZ2ZU6WRNRLPW7D","download_json":"https://pith.science/pith/DG6O6GPN4KVRZ2ZU6WRNRLPW7D.json","view_paper":"https://pith.science/paper/DG6O6GPN","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2302.01740&json=true","fetch_graph":"https://pith.science/api/pith-number/DG6O6GPN4KVRZ2ZU6WRNRLPW7D/graph.json","fetch_events":"https://pith.science/api/pith-number/DG6O6GPN4KVRZ2ZU6WRNRLPW7D/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/DG6O6GPN4KVRZ2ZU6WRNRLPW7D/action/timestamp_anchor","attest_storage":"https://pith.science/pith/DG6O6GPN4KVRZ2ZU6WRNRLPW7D/action/storage_attestation","attest_author":"https://pith.science/pith/DG6O6GPN4KVRZ2ZU6WRNRLPW7D/action/author_attestation","sign_citation":"https://pith.science/pith/DG6O6GPN4KVRZ2ZU6WRNRLPW7D/action/citation_signature","submit_replication":"https://pith.science/pith/DG6O6GPN4KVRZ2ZU6WRNRLPW7D/action/replication_record"}},"created_at":"2026-07-05T06:03:11.370084+00:00","updated_at":"2026-07-05T06:03:11.370084+00:00"}