{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2022:G5QGGLRAKVPU42KDP2MT5SQF2M","short_pith_number":"pith:G5QGGLRA","schema_version":"1.0","canonical_sha256":"3760632e20555f4e69437e993eca05d3271ecbdf52dffe054941347802ea4a2f","source":{"kind":"arxiv","id":"2210.12873","version":2},"attestation_state":"computed","paper":{"title":"FLIP: A Provable Defense Framework for Backdoor Mitigation in Federated Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Guangyu Shen, Guanhong Tao, Kaiyuan Zhang, Pin-Yu Chen, Qiuling Xu, Shengwei An, Shiqing Ma, Shiwei Feng, Siyuan Cheng, Xiangyu Zhang, Yingqi Liu","submitted_at":"2022-10-23T22:24:03Z","abstract_excerpt":"Federated Learning (FL) is a distributed learning paradigm that enables different parties to train a model together for high quality and strong privacy protection. In this scenario, individual participants may get compromised and perform backdoor attacks by poisoning the data (or gradients). Existing work on robust aggregation and certified FL robustness does not study how hardening benign clients can affect the global model (and the malicious clients). In this work, we theoretically analyze the connection among cross-entropy loss, attack success rate, and clean accuracy in this setting. Moreo"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2210.12873","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2022-10-23T22:24:03Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"990656c9d0a38f7460e6834b1eaa6cec136684ff381148b43c348df0976ed37e","abstract_canon_sha256":"1ffcd87644abc178f56403dea9e45bc95accec5ac0d8d44013bd12abf7fbdd8e"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T05:46:26.431920Z","signature_b64":"gPBo1P5aFEeqHVVhizNRydDXDxniJ81mQjubSE4+zV1jWzGDUXuwIY7Yr0UdBz6me8/j//O2qzMjEBfyz7PBDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"3760632e20555f4e69437e993eca05d3271ecbdf52dffe054941347802ea4a2f","last_reissued_at":"2026-07-05T05:46:26.431465Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T05:46:26.431465Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"FLIP: A Provable Defense Framework for Backdoor Mitigation in Federated Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Guangyu Shen, Guanhong Tao, Kaiyuan Zhang, Pin-Yu Chen, Qiuling Xu, Shengwei An, Shiqing Ma, Shiwei Feng, Siyuan Cheng, Xiangyu Zhang, Yingqi Liu","submitted_at":"2022-10-23T22:24:03Z","abstract_excerpt":"Federated Learning (FL) is a distributed learning paradigm that enables different parties to train a model together for high quality and strong privacy protection. In this scenario, individual participants may get compromised and perform backdoor attacks by poisoning the data (or gradients). Existing work on robust aggregation and certified FL robustness does not study how hardening benign clients can affect the global model (and the malicious clients). In this work, we theoretically analyze the connection among cross-entropy loss, attack success rate, and clean accuracy in this setting. Moreo"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2210.12873","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2210.12873/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2210.12873","created_at":"2026-07-05T05:46:26.431530+00:00"},{"alias_kind":"arxiv_version","alias_value":"2210.12873v2","created_at":"2026-07-05T05:46:26.431530+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2210.12873","created_at":"2026-07-05T05:46:26.431530+00:00"},{"alias_kind":"pith_short_12","alias_value":"G5QGGLRAKVPU","created_at":"2026-07-05T05:46:26.431530+00:00"},{"alias_kind":"pith_short_16","alias_value":"G5QGGLRAKVPU42KD","created_at":"2026-07-05T05:46:26.431530+00:00"},{"alias_kind":"pith_short_8","alias_value":"G5QGGLRA","created_at":"2026-07-05T05:46:26.431530+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2507.21177","citing_title":"FedBAP: Backdoor Defense via Benign Adversarial Perturbation in Federated Learning","ref_index":37,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/G5QGGLRAKVPU42KDP2MT5SQF2M","json":"https://pith.science/pith/G5QGGLRAKVPU42KDP2MT5SQF2M.json","graph_json":"https://pith.science/api/pith-number/G5QGGLRAKVPU42KDP2MT5SQF2M/graph.json","events_json":"https://pith.science/api/pith-number/G5QGGLRAKVPU42KDP2MT5SQF2M/events.json","paper":"https://pith.science/paper/G5QGGLRA"},"agent_actions":{"view_html":"https://pith.science/pith/G5QGGLRAKVPU42KDP2MT5SQF2M","download_json":"https://pith.science/pith/G5QGGLRAKVPU42KDP2MT5SQF2M.json","view_paper":"https://pith.science/paper/G5QGGLRA","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2210.12873&json=true","fetch_graph":"https://pith.science/api/pith-number/G5QGGLRAKVPU42KDP2MT5SQF2M/graph.json","fetch_events":"https://pith.science/api/pith-number/G5QGGLRAKVPU42KDP2MT5SQF2M/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/G5QGGLRAKVPU42KDP2MT5SQF2M/action/timestamp_anchor","attest_storage":"https://pith.science/pith/G5QGGLRAKVPU42KDP2MT5SQF2M/action/storage_attestation","attest_author":"https://pith.science/pith/G5QGGLRAKVPU42KDP2MT5SQF2M/action/author_attestation","sign_citation":"https://pith.science/pith/G5QGGLRAKVPU42KDP2MT5SQF2M/action/citation_signature","submit_replication":"https://pith.science/pith/G5QGGLRAKVPU42KDP2MT5SQF2M/action/replication_record"}},"created_at":"2026-07-05T05:46:26.431530+00:00","updated_at":"2026-07-05T05:46:26.431530+00:00"}