{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:HHYEISVBOKTTMGWNUAYFDI76NL","short_pith_number":"pith:HHYEISVB","schema_version":"1.0","canonical_sha256":"39f0444aa172a7361acda03051a3fe6af857b787e8bfcb7210bd26022c609afa","source":{"kind":"arxiv","id":"2110.03735","version":4},"attestation_state":"computed","paper":{"title":"Adversarial Unlearning of Backdoors via Implicit Hypergradient","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV"],"primary_cat":"cs.LG","authors_text":"Ming Jin, Ruoxi Jia, Si Chen, Won Park, Yi Zeng, Z. Morley Mao","submitted_at":"2021-10-07T18:32:54Z","abstract_excerpt":"We propose a minimax formulation for removing backdoors from a given poisoned model based on a small set of clean data. This formulation encompasses much of prior work on backdoor removal. We propose the Implicit Bacdoor Adversarial Unlearning (I-BAU) algorithm to solve the minimax. Unlike previous work, which breaks down the minimax into separate inner and outer problems, our algorithm utilizes the implicit hypergradient to account for the interdependence between inner and outer optimization. We theoretically analyze its convergence and the generalizability of the robustness gained by solving"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2110.03735","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2021-10-07T18:32:54Z","cross_cats_sorted":["cs.CR","cs.CV"],"title_canon_sha256":"1d33842955506c4b097a1981c105faaaadb8da24239d03d65d0adc85fa07c558","abstract_canon_sha256":"ef3904f8db5218b4c2db37c6ae0047bb50ece1d4e3ad0f6e18bf210632486783"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T03:54:24.358466Z","signature_b64":"eY2xeGjiThT/uoKIUQHPRLwEsYyCdRfTlLmmZWhQPz8mCdPEzpdHbI9azTqvT9maOYSGZ8zdwHr6Ywmb9P9pDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"39f0444aa172a7361acda03051a3fe6af857b787e8bfcb7210bd26022c609afa","last_reissued_at":"2026-07-05T03:54:24.358057Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T03:54:24.358057Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Adversarial Unlearning of Backdoors via Implicit Hypergradient","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV"],"primary_cat":"cs.LG","authors_text":"Ming Jin, Ruoxi Jia, Si Chen, Won Park, Yi Zeng, Z. Morley Mao","submitted_at":"2021-10-07T18:32:54Z","abstract_excerpt":"We propose a minimax formulation for removing backdoors from a given poisoned model based on a small set of clean data. This formulation encompasses much of prior work on backdoor removal. We propose the Implicit Bacdoor Adversarial Unlearning (I-BAU) algorithm to solve the minimax. Unlike previous work, which breaks down the minimax into separate inner and outer problems, our algorithm utilizes the implicit hypergradient to account for the interdependence between inner and outer optimization. We theoretically analyze its convergence and the generalizability of the robustness gained by solving"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2110.03735","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2110.03735/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2110.03735","created_at":"2026-07-05T03:54:24.358107+00:00"},{"alias_kind":"arxiv_version","alias_value":"2110.03735v4","created_at":"2026-07-05T03:54:24.358107+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2110.03735","created_at":"2026-07-05T03:54:24.358107+00:00"},{"alias_kind":"pith_short_12","alias_value":"HHYEISVBOKTT","created_at":"2026-07-05T03:54:24.358107+00:00"},{"alias_kind":"pith_short_16","alias_value":"HHYEISVBOKTTMGWN","created_at":"2026-07-05T03:54:24.358107+00:00"},{"alias_kind":"pith_short_8","alias_value":"HHYEISVB","created_at":"2026-07-05T03:54:24.358107+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.27809","citing_title":"Density-aware Sample-specific Attack","ref_index":36,"is_internal_anchor":false},{"citing_arxiv_id":"2601.21692","citing_title":"TCAP: Tri-Component Attention Profiling for Unsupervised Backdoor Detection in MLLM Fine-Tuning","ref_index":16,"is_internal_anchor":false},{"citing_arxiv_id":"2604.24162","citing_title":"Defusing the Trigger: Plug-and-Play Defense for Backdoored LLMs via Tail-Risk Intrinsic Geometric Smoothing","ref_index":53,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/HHYEISVBOKTTMGWNUAYFDI76NL","json":"https://pith.science/pith/HHYEISVBOKTTMGWNUAYFDI76NL.json","graph_json":"https://pith.science/api/pith-number/HHYEISVBOKTTMGWNUAYFDI76NL/graph.json","events_json":"https://pith.science/api/pith-number/HHYEISVBOKTTMGWNUAYFDI76NL/events.json","paper":"https://pith.science/paper/HHYEISVB"},"agent_actions":{"view_html":"https://pith.science/pith/HHYEISVBOKTTMGWNUAYFDI76NL","download_json":"https://pith.science/pith/HHYEISVBOKTTMGWNUAYFDI76NL.json","view_paper":"https://pith.science/paper/HHYEISVB","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2110.03735&json=true","fetch_graph":"https://pith.science/api/pith-number/HHYEISVBOKTTMGWNUAYFDI76NL/graph.json","fetch_events":"https://pith.science/api/pith-number/HHYEISVBOKTTMGWNUAYFDI76NL/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/HHYEISVBOKTTMGWNUAYFDI76NL/action/timestamp_anchor","attest_storage":"https://pith.science/pith/HHYEISVBOKTTMGWNUAYFDI76NL/action/storage_attestation","attest_author":"https://pith.science/pith/HHYEISVBOKTTMGWNUAYFDI76NL/action/author_attestation","sign_citation":"https://pith.science/pith/HHYEISVBOKTTMGWNUAYFDI76NL/action/citation_signature","submit_replication":"https://pith.science/pith/HHYEISVBOKTTMGWNUAYFDI76NL/action/replication_record"}},"created_at":"2026-07-05T03:54:24.358107+00:00","updated_at":"2026-07-05T03:54:24.358107+00:00"}