{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2020:G7DKC5CCP2L3DFANDH3RGBBX5Z","short_pith_number":"pith:G7DKC5CC","schema_version":"1.0","canonical_sha256":"37c6a174427e97b1940d19f7130437ee7f0f619d3ebd0b4ae969d13485c74c7e","source":{"kind":"arxiv","id":"2002.11497","version":2},"attestation_state":"computed","paper":{"title":"On the Effectiveness of Mitigating Data Poisoning Attacks with Gradient Shaping","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Nicolas Papernot, Sanghyun Hong, Tudor Dumitra\\c{s}, Varun Chandrasekaran, Yi\\u{g}itcan Kaya","submitted_at":"2020-02-26T14:04:16Z","abstract_excerpt":"Machine learning algorithms are vulnerable to data poisoning attacks. Prior taxonomies that focus on specific scenarios, e.g., indiscriminate or targeted, have enabled defenses for the corresponding subset of known attacks. Yet, this introduces an inevitable arms race between adversaries and defenders. In this work, we study the feasibility of an attack-agnostic defense relying on artifacts that are common to all poisoning attacks. Specifically, we focus on a common element between all attacks: they modify gradients computed to train the model. We identify two main artifacts of gradients compu"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2002.11497","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2020-02-26T14:04:16Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"15284fe0acf609bb0f820241c1cf5311c4a8d94b460b43ab82241d3616a4bdbc","abstract_canon_sha256":"e616903cadeb6b4297faacfa2ed6ca869149f720292955a66c5ba49a0bdce70b"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:44:28.956603Z","signature_b64":"IPFHqDD+NSf6VkxLX3aF5zMkRxC+HGdk3eXiEsC5zQQG8+J43rk88KGmHxoRsJPqOIwGV/i6pjG4PENYGlMrCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"37c6a174427e97b1940d19f7130437ee7f0f619d3ebd0b4ae969d13485c74c7e","last_reissued_at":"2026-07-05T00:44:28.956182Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:44:28.956182Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"On the Effectiveness of Mitigating Data Poisoning Attacks with Gradient Shaping","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Nicolas Papernot, Sanghyun Hong, Tudor Dumitra\\c{s}, Varun Chandrasekaran, Yi\\u{g}itcan Kaya","submitted_at":"2020-02-26T14:04:16Z","abstract_excerpt":"Machine learning algorithms are vulnerable to data poisoning attacks. Prior taxonomies that focus on specific scenarios, e.g., indiscriminate or targeted, have enabled defenses for the corresponding subset of known attacks. Yet, this introduces an inevitable arms race between adversaries and defenders. In this work, we study the feasibility of an attack-agnostic defense relying on artifacts that are common to all poisoning attacks. Specifically, we focus on a common element between all attacks: they modify gradients computed to train the model. We identify two main artifacts of gradients compu"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2002.11497","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2002.11497/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2002.11497","created_at":"2026-07-05T00:44:28.956240+00:00"},{"alias_kind":"arxiv_version","alias_value":"2002.11497v2","created_at":"2026-07-05T00:44:28.956240+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2002.11497","created_at":"2026-07-05T00:44:28.956240+00:00"},{"alias_kind":"pith_short_12","alias_value":"G7DKC5CCP2L3","created_at":"2026-07-05T00:44:28.956240+00:00"},{"alias_kind":"pith_short_16","alias_value":"G7DKC5CCP2L3DFAN","created_at":"2026-07-05T00:44:28.956240+00:00"},{"alias_kind":"pith_short_8","alias_value":"G7DKC5CC","created_at":"2026-07-05T00:44:28.956240+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.27148","citing_title":"Landseer: Exploring the Machine Learning Defense Landscape","ref_index":45,"is_internal_anchor":false},{"citing_arxiv_id":"2604.21416","citing_title":"CSC: Turning the Adversary's Poison against Itself","ref_index":15,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/G7DKC5CCP2L3DFANDH3RGBBX5Z","json":"https://pith.science/pith/G7DKC5CCP2L3DFANDH3RGBBX5Z.json","graph_json":"https://pith.science/api/pith-number/G7DKC5CCP2L3DFANDH3RGBBX5Z/graph.json","events_json":"https://pith.science/api/pith-number/G7DKC5CCP2L3DFANDH3RGBBX5Z/events.json","paper":"https://pith.science/paper/G7DKC5CC"},"agent_actions":{"view_html":"https://pith.science/pith/G7DKC5CCP2L3DFANDH3RGBBX5Z","download_json":"https://pith.science/pith/G7DKC5CCP2L3DFANDH3RGBBX5Z.json","view_paper":"https://pith.science/paper/G7DKC5CC","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2002.11497&json=true","fetch_graph":"https://pith.science/api/pith-number/G7DKC5CCP2L3DFANDH3RGBBX5Z/graph.json","fetch_events":"https://pith.science/api/pith-number/G7DKC5CCP2L3DFANDH3RGBBX5Z/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/G7DKC5CCP2L3DFANDH3RGBBX5Z/action/timestamp_anchor","attest_storage":"https://pith.science/pith/G7DKC5CCP2L3DFANDH3RGBBX5Z/action/storage_attestation","attest_author":"https://pith.science/pith/G7DKC5CCP2L3DFANDH3RGBBX5Z/action/author_attestation","sign_citation":"https://pith.science/pith/G7DKC5CCP2L3DFANDH3RGBBX5Z/action/citation_signature","submit_replication":"https://pith.science/pith/G7DKC5CCP2L3DFANDH3RGBBX5Z/action/replication_record"}},"created_at":"2026-07-05T00:44:28.956240+00:00","updated_at":"2026-07-05T00:44:28.956240+00:00"}