{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:EBTXNNFQESS7QCGLEKSF4IEC27","short_pith_number":"pith:EBTXNNFQ","schema_version":"1.0","canonical_sha256":"206776b4b024a5f808cb22a45e2082d7cc9a4641341338b629ef09e9e7d51cdb","source":{"kind":"arxiv","id":"2307.14692","version":1},"attestation_state":"computed","paper":{"title":"Backdoor Attacks for In-Context Learning with Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Florian Tram\\`er, Matthew Jagielski, Nicholas Carlini, Nikhil Kandpal","submitted_at":"2023-07-27T08:28:58Z","abstract_excerpt":"Because state-of-the-art language models are expensive to train, most practitioners must make use of one of the few publicly available language models or language model APIs. This consolidation of trust increases the potency of backdoor attacks, where an adversary tampers with a machine learning model in order to make it perform some malicious behavior on inputs that contain a predefined backdoor trigger. We show that the in-context learning ability of large language models significantly complicates the question of developing backdoor attacks, as a successful backdoor must work against various"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2307.14692","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2023-07-27T08:28:58Z","cross_cats_sorted":[],"title_canon_sha256":"1cba30187585a518b0ac5275c710e2c9aa88af70735727a77194e1b3fa47f8b7","abstract_canon_sha256":"e8dc2d410959fa6480c5655408c0a58506adb79977b103aee6e1e7edc1f83c47"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T06:35:16.820885Z","signature_b64":"2xtI6sdWzXP96l3bZVDVEEf6g9+mevd8oQC9jgEzYTwbJViIxkgiDSWgJcn9FJvSHb8qXqjGOXHFbFp4SvKfCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"206776b4b024a5f808cb22a45e2082d7cc9a4641341338b629ef09e9e7d51cdb","last_reissued_at":"2026-07-05T06:35:16.820404Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T06:35:16.820404Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Backdoor Attacks for In-Context Learning with Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Florian Tram\\`er, Matthew Jagielski, Nicholas Carlini, Nikhil Kandpal","submitted_at":"2023-07-27T08:28:58Z","abstract_excerpt":"Because state-of-the-art language models are expensive to train, most practitioners must make use of one of the few publicly available language models or language model APIs. This consolidation of trust increases the potency of backdoor attacks, where an adversary tampers with a machine learning model in order to make it perform some malicious behavior on inputs that contain a predefined backdoor trigger. We show that the in-context learning ability of large language models significantly complicates the question of developing backdoor attacks, as a successful backdoor must work against various"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2307.14692","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2307.14692/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2307.14692","created_at":"2026-07-05T06:35:16.820461+00:00"},{"alias_kind":"arxiv_version","alias_value":"2307.14692v1","created_at":"2026-07-05T06:35:16.820461+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2307.14692","created_at":"2026-07-05T06:35:16.820461+00:00"},{"alias_kind":"pith_short_12","alias_value":"EBTXNNFQESS7","created_at":"2026-07-05T06:35:16.820461+00:00"},{"alias_kind":"pith_short_16","alias_value":"EBTXNNFQESS7QCGL","created_at":"2026-07-05T06:35:16.820461+00:00"},{"alias_kind":"pith_short_8","alias_value":"EBTXNNFQ","created_at":"2026-07-05T06:35:16.820461+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":4,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.09411","citing_title":"Now You (Still) See Me: Detecting Evasive Steganographic Payloads in LLMs","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2510.16558","citing_title":"A First Look at the Security Issues in the Model Context Protocol Ecosystem","ref_index":18,"is_internal_anchor":false},{"citing_arxiv_id":"2410.02644","citing_title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","ref_index":111,"is_internal_anchor":false},{"citing_arxiv_id":"2604.21700","citing_title":"Stealthy Backdoor Attacks against LLMs Based on Natural Style Triggers","ref_index":27,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/EBTXNNFQESS7QCGLEKSF4IEC27","json":"https://pith.science/pith/EBTXNNFQESS7QCGLEKSF4IEC27.json","graph_json":"https://pith.science/api/pith-number/EBTXNNFQESS7QCGLEKSF4IEC27/graph.json","events_json":"https://pith.science/api/pith-number/EBTXNNFQESS7QCGLEKSF4IEC27/events.json","paper":"https://pith.science/paper/EBTXNNFQ"},"agent_actions":{"view_html":"https://pith.science/pith/EBTXNNFQESS7QCGLEKSF4IEC27","download_json":"https://pith.science/pith/EBTXNNFQESS7QCGLEKSF4IEC27.json","view_paper":"https://pith.science/paper/EBTXNNFQ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2307.14692&json=true","fetch_graph":"https://pith.science/api/pith-number/EBTXNNFQESS7QCGLEKSF4IEC27/graph.json","fetch_events":"https://pith.science/api/pith-number/EBTXNNFQESS7QCGLEKSF4IEC27/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/EBTXNNFQESS7QCGLEKSF4IEC27/action/timestamp_anchor","attest_storage":"https://pith.science/pith/EBTXNNFQESS7QCGLEKSF4IEC27/action/storage_attestation","attest_author":"https://pith.science/pith/EBTXNNFQESS7QCGLEKSF4IEC27/action/author_attestation","sign_citation":"https://pith.science/pith/EBTXNNFQESS7QCGLEKSF4IEC27/action/citation_signature","submit_replication":"https://pith.science/pith/EBTXNNFQESS7QCGLEKSF4IEC27/action/replication_record"}},"created_at":"2026-07-05T06:35:16.820461+00:00","updated_at":"2026-07-05T06:35:16.820461+00:00"}