{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2020:GTCUQLHERGVYMNQ7WMFXUAOFPZ","short_pith_number":"pith:GTCUQLHE","schema_version":"1.0","canonical_sha256":"34c5482ce489ab86361fb30b7a01c57e4387da5d0bb668b9791f7e7848b4fd20","source":{"kind":"arxiv","id":"2012.03816","version":3},"attestation_state":"computed","paper":{"title":"Invisible Backdoor Attack with Sample-Specific Triggers","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Baoyuan Wu, Longkang Li, Ran He, Siwei Lyu, Yiming Li, Yuezun Li","submitted_at":"2020-12-07T16:02:08Z","abstract_excerpt":"Recently, backdoor attacks pose a new security threat to the training process of deep neural networks (DNNs). Attackers intend to inject hidden backdoors into DNNs, such that the attacked model performs well on benign samples, whereas its prediction will be maliciously changed if hidden backdoors are activated by the attacker-defined trigger. Existing backdoor attacks usually adopt the setting that triggers are sample-agnostic, $i.e.,$ different poisoned samples contain the same trigger, resulting in that the attacks could be easily mitigated by current backdoor defenses. In this work, we expl"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2012.03816","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2020-12-07T16:02:08Z","cross_cats_sorted":[],"title_canon_sha256":"ef3db8461f309e67961e5141f12189b312e2190837ec991fe3beb92f9966080b","abstract_canon_sha256":"1e4ab1e73a0b3fa49d05f6d329670d2dc5061742fc57796f32a2a1b0ba958b93"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T03:05:32.106738Z","signature_b64":"MMmdQSCWye0NFtVnzKL5IGFEOMxKYTZrjhlk/Oehq90BlY239xzL6xgiHw74Y6JxGVFSk47aaEj7U9ighkwjAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"34c5482ce489ab86361fb30b7a01c57e4387da5d0bb668b9791f7e7848b4fd20","last_reissued_at":"2026-07-05T03:05:32.106162Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T03:05:32.106162Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Invisible Backdoor Attack with Sample-Specific Triggers","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Baoyuan Wu, Longkang Li, Ran He, Siwei Lyu, Yiming Li, Yuezun Li","submitted_at":"2020-12-07T16:02:08Z","abstract_excerpt":"Recently, backdoor attacks pose a new security threat to the training process of deep neural networks (DNNs). Attackers intend to inject hidden backdoors into DNNs, such that the attacked model performs well on benign samples, whereas its prediction will be maliciously changed if hidden backdoors are activated by the attacker-defined trigger. Existing backdoor attacks usually adopt the setting that triggers are sample-agnostic, $i.e.,$ different poisoned samples contain the same trigger, resulting in that the attacks could be easily mitigated by current backdoor defenses. In this work, we expl"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2012.03816","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2012.03816/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2012.03816","created_at":"2026-07-05T03:05:32.106228+00:00"},{"alias_kind":"arxiv_version","alias_value":"2012.03816v3","created_at":"2026-07-05T03:05:32.106228+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2012.03816","created_at":"2026-07-05T03:05:32.106228+00:00"},{"alias_kind":"pith_short_12","alias_value":"GTCUQLHERGVY","created_at":"2026-07-05T03:05:32.106228+00:00"},{"alias_kind":"pith_short_16","alias_value":"GTCUQLHERGVYMNQ7","created_at":"2026-07-05T03:05:32.106228+00:00"},{"alias_kind":"pith_short_8","alias_value":"GTCUQLHE","created_at":"2026-07-05T03:05:32.106228+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2604.09101","citing_title":"CLIP-Inspector: Model-Level Backdoor Detection for Prompt-Tuned CLIP via OOD Trigger Inversion","ref_index":20,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/GTCUQLHERGVYMNQ7WMFXUAOFPZ","json":"https://pith.science/pith/GTCUQLHERGVYMNQ7WMFXUAOFPZ.json","graph_json":"https://pith.science/api/pith-number/GTCUQLHERGVYMNQ7WMFXUAOFPZ/graph.json","events_json":"https://pith.science/api/pith-number/GTCUQLHERGVYMNQ7WMFXUAOFPZ/events.json","paper":"https://pith.science/paper/GTCUQLHE"},"agent_actions":{"view_html":"https://pith.science/pith/GTCUQLHERGVYMNQ7WMFXUAOFPZ","download_json":"https://pith.science/pith/GTCUQLHERGVYMNQ7WMFXUAOFPZ.json","view_paper":"https://pith.science/paper/GTCUQLHE","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2012.03816&json=true","fetch_graph":"https://pith.science/api/pith-number/GTCUQLHERGVYMNQ7WMFXUAOFPZ/graph.json","fetch_events":"https://pith.science/api/pith-number/GTCUQLHERGVYMNQ7WMFXUAOFPZ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/GTCUQLHERGVYMNQ7WMFXUAOFPZ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/GTCUQLHERGVYMNQ7WMFXUAOFPZ/action/storage_attestation","attest_author":"https://pith.science/pith/GTCUQLHERGVYMNQ7WMFXUAOFPZ/action/author_attestation","sign_citation":"https://pith.science/pith/GTCUQLHERGVYMNQ7WMFXUAOFPZ/action/citation_signature","submit_replication":"https://pith.science/pith/GTCUQLHERGVYMNQ7WMFXUAOFPZ/action/replication_record"}},"created_at":"2026-07-05T03:05:32.106228+00:00","updated_at":"2026-07-05T03:05:32.106228+00:00"}