{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2020:FBRXYKJP2AMMMHLOAEFRDQAW4T","short_pith_number":"pith:FBRXYKJP","schema_version":"1.0","canonical_sha256":"28637c292fd018c61d6e010b11c016e4de2f05a5790ed71eb9aca5ee383ae9d1","source":{"kind":"arxiv","id":"2002.10078","version":3},"attestation_state":"computed","paper":{"title":"On Hiding Neural Networks Inside Neural Networks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Chuan Guo, Kilian Q. Weinberger, Ruihan Wu","submitted_at":"2020-02-24T05:18:29Z","abstract_excerpt":"Modern neural networks often contain significantly more parameters than the size of their training data. We show that this excess capacity provides an opportunity for embedding secret machine learning models within a trained neural network. Our novel framework hides the existence of a secret neural network with arbitrary desired functionality within a carrier network. We prove theoretically that the secret network's detection is computationally infeasible and demonstrate empirically that the carrier network does not compromise the secret network's disguise. Our paper introduces a previously un"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2002.10078","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2020-02-24T05:18:29Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"a31bd86c38f2abf828def91f0d323c8a0fb2f0c8489b80060ccb696d30ca83b5","abstract_canon_sha256":"6ffbcbb41a9efc50375f6be9d23a8e2dce46b5a56401af2171443234dc9abbc5"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T02:42:12.800328Z","signature_b64":"Py2/36jmqwpI/MS1tXizaX+gcQRD4D0xgVVEUsbSxdh2vj1cWjYmwBRDLz8WwtJBjUpDuXd2WMR66g0CQwwXAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"28637c292fd018c61d6e010b11c016e4de2f05a5790ed71eb9aca5ee383ae9d1","last_reissued_at":"2026-07-05T02:42:12.799815Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T02:42:12.799815Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"On Hiding Neural Networks Inside Neural Networks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Chuan Guo, Kilian Q. Weinberger, Ruihan Wu","submitted_at":"2020-02-24T05:18:29Z","abstract_excerpt":"Modern neural networks often contain significantly more parameters than the size of their training data. We show that this excess capacity provides an opportunity for embedding secret machine learning models within a trained neural network. Our novel framework hides the existence of a secret neural network with arbitrary desired functionality within a carrier network. We prove theoretically that the secret network's detection is computationally infeasible and demonstrate empirically that the carrier network does not compromise the secret network's disguise. Our paper introduces a previously un"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2002.10078","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2002.10078/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2002.10078","created_at":"2026-07-05T02:42:12.799871+00:00"},{"alias_kind":"arxiv_version","alias_value":"2002.10078v3","created_at":"2026-07-05T02:42:12.799871+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2002.10078","created_at":"2026-07-05T02:42:12.799871+00:00"},{"alias_kind":"pith_short_12","alias_value":"FBRXYKJP2AMM","created_at":"2026-07-05T02:42:12.799871+00:00"},{"alias_kind":"pith_short_16","alias_value":"FBRXYKJP2AMMMHLO","created_at":"2026-07-05T02:42:12.799871+00:00"},{"alias_kind":"pith_short_8","alias_value":"FBRXYKJP","created_at":"2026-07-05T02:42:12.799871+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2507.12919","citing_title":"Architectural Backdoors in Deep Learning: A Survey of Vulnerabilities, Detection, and Defense","ref_index":26,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/FBRXYKJP2AMMMHLOAEFRDQAW4T","json":"https://pith.science/pith/FBRXYKJP2AMMMHLOAEFRDQAW4T.json","graph_json":"https://pith.science/api/pith-number/FBRXYKJP2AMMMHLOAEFRDQAW4T/graph.json","events_json":"https://pith.science/api/pith-number/FBRXYKJP2AMMMHLOAEFRDQAW4T/events.json","paper":"https://pith.science/paper/FBRXYKJP"},"agent_actions":{"view_html":"https://pith.science/pith/FBRXYKJP2AMMMHLOAEFRDQAW4T","download_json":"https://pith.science/pith/FBRXYKJP2AMMMHLOAEFRDQAW4T.json","view_paper":"https://pith.science/paper/FBRXYKJP","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2002.10078&json=true","fetch_graph":"https://pith.science/api/pith-number/FBRXYKJP2AMMMHLOAEFRDQAW4T/graph.json","fetch_events":"https://pith.science/api/pith-number/FBRXYKJP2AMMMHLOAEFRDQAW4T/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/FBRXYKJP2AMMMHLOAEFRDQAW4T/action/timestamp_anchor","attest_storage":"https://pith.science/pith/FBRXYKJP2AMMMHLOAEFRDQAW4T/action/storage_attestation","attest_author":"https://pith.science/pith/FBRXYKJP2AMMMHLOAEFRDQAW4T/action/author_attestation","sign_citation":"https://pith.science/pith/FBRXYKJP2AMMMHLOAEFRDQAW4T/action/citation_signature","submit_replication":"https://pith.science/pith/FBRXYKJP2AMMMHLOAEFRDQAW4T/action/replication_record"}},"created_at":"2026-07-05T02:42:12.799871+00:00","updated_at":"2026-07-05T02:42:12.799871+00:00"}