{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:GDEQ7IFVYT3BLAHPMDI7G7ZLA5","short_pith_number":"pith:GDEQ7IFV","schema_version":"1.0","canonical_sha256":"30c90fa0b5c4f61580ef60d1f37f2b077bdec8b58c1b9536a3eb94a88b4092f1","source":{"kind":"arxiv","id":"2302.03251","version":2},"attestation_state":"computed","paper":{"title":"SCALE-UP: An Efficient Black-box Input-level Backdoor Detection via Analyzing Scaled Prediction Consistency","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Cong Liu, Hanqing Guo, Junfeng Guo, Lichao Sun, Xun Chen, Yiming Li","submitted_at":"2023-02-07T04:33:41Z","abstract_excerpt":"Deep neural networks (DNNs) are vulnerable to backdoor attacks, where adversaries embed a hidden backdoor trigger during the training process for malicious prediction manipulation. These attacks pose great threats to the applications of DNNs under the real-world machine learning as a service (MLaaS) setting, where the deployed model is fully black-box while the users can only query and obtain its predictions. Currently, there are many existing defenses to reduce backdoor threats. However, almost all of them cannot be adopted in MLaaS scenarios since they require getting access to or even modif"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2302.03251","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2023-02-07T04:33:41Z","cross_cats_sorted":[],"title_canon_sha256":"ba395335ca0929c4bd2da86f79c4cc8c40b84ee2ae0af23b910af0e6702d138f","abstract_canon_sha256":"3734385ad5dbe8b91e029df41348b474fb194ffbcfde8764a0cf5311d87e8e7c"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T05:43:19.729494Z","signature_b64":"2nsmkiacPR18qwcMMpD8vxmZnmy/tTjRV7IDpmIr9vvTxe1gRmO+XD8ooTMOpIrM7CfjjYRRzec0iIJspQMDBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"30c90fa0b5c4f61580ef60d1f37f2b077bdec8b58c1b9536a3eb94a88b4092f1","last_reissued_at":"2026-07-05T05:43:19.729068Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T05:43:19.729068Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"SCALE-UP: An Efficient Black-box Input-level Backdoor Detection via Analyzing Scaled Prediction Consistency","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Cong Liu, Hanqing Guo, Junfeng Guo, Lichao Sun, Xun Chen, Yiming Li","submitted_at":"2023-02-07T04:33:41Z","abstract_excerpt":"Deep neural networks (DNNs) are vulnerable to backdoor attacks, where adversaries embed a hidden backdoor trigger during the training process for malicious prediction manipulation. These attacks pose great threats to the applications of DNNs under the real-world machine learning as a service (MLaaS) setting, where the deployed model is fully black-box while the users can only query and obtain its predictions. Currently, there are many existing defenses to reduce backdoor threats. However, almost all of them cannot be adopted in MLaaS scenarios since they require getting access to or even modif"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2302.03251","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2302.03251/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2302.03251","created_at":"2026-07-05T05:43:19.729124+00:00"},{"alias_kind":"arxiv_version","alias_value":"2302.03251v2","created_at":"2026-07-05T05:43:19.729124+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2302.03251","created_at":"2026-07-05T05:43:19.729124+00:00"},{"alias_kind":"pith_short_12","alias_value":"GDEQ7IFVYT3B","created_at":"2026-07-05T05:43:19.729124+00:00"},{"alias_kind":"pith_short_16","alias_value":"GDEQ7IFVYT3BLAHP","created_at":"2026-07-05T05:43:19.729124+00:00"},{"alias_kind":"pith_short_8","alias_value":"GDEQ7IFV","created_at":"2026-07-05T05:43:19.729124+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.12896","citing_title":"PolicyGuard: Towards Test-time and Step-level Adversary (Backdoor) Defense for Reinforcement Learning Agent","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2604.12446","citing_title":"Scaling Exposes the Trigger: Input-Level Backdoor Detection in Text-to-Image Diffusion Models via Cross-Attention Scaling","ref_index":10,"is_internal_anchor":false},{"citing_arxiv_id":"2604.09101","citing_title":"CLIP-Inspector: Model-Level Backdoor Detection for Prompt-Tuned CLIP via OOD Trigger Inversion","ref_index":12,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/GDEQ7IFVYT3BLAHPMDI7G7ZLA5","json":"https://pith.science/pith/GDEQ7IFVYT3BLAHPMDI7G7ZLA5.json","graph_json":"https://pith.science/api/pith-number/GDEQ7IFVYT3BLAHPMDI7G7ZLA5/graph.json","events_json":"https://pith.science/api/pith-number/GDEQ7IFVYT3BLAHPMDI7G7ZLA5/events.json","paper":"https://pith.science/paper/GDEQ7IFV"},"agent_actions":{"view_html":"https://pith.science/pith/GDEQ7IFVYT3BLAHPMDI7G7ZLA5","download_json":"https://pith.science/pith/GDEQ7IFVYT3BLAHPMDI7G7ZLA5.json","view_paper":"https://pith.science/paper/GDEQ7IFV","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2302.03251&json=true","fetch_graph":"https://pith.science/api/pith-number/GDEQ7IFVYT3BLAHPMDI7G7ZLA5/graph.json","fetch_events":"https://pith.science/api/pith-number/GDEQ7IFVYT3BLAHPMDI7G7ZLA5/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/GDEQ7IFVYT3BLAHPMDI7G7ZLA5/action/timestamp_anchor","attest_storage":"https://pith.science/pith/GDEQ7IFVYT3BLAHPMDI7G7ZLA5/action/storage_attestation","attest_author":"https://pith.science/pith/GDEQ7IFVYT3BLAHPMDI7G7ZLA5/action/author_attestation","sign_citation":"https://pith.science/pith/GDEQ7IFVYT3BLAHPMDI7G7ZLA5/action/citation_signature","submit_replication":"https://pith.science/pith/GDEQ7IFVYT3BLAHPMDI7G7ZLA5/action/replication_record"}},"created_at":"2026-07-05T05:43:19.729124+00:00","updated_at":"2026-07-05T05:43:19.729124+00:00"}