{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:IVHTXHZUF5F5HCUZ2SJ7OV6TNI","short_pith_number":"pith:IVHTXHZU","schema_version":"1.0","canonical_sha256":"454f3b9f342f4bd38a99d493f757d36a1e10f7109ef95ce3a26351647ee050b8","source":{"kind":"arxiv","id":"2305.17826","version":1},"attestation_state":"computed","paper":{"title":"NOTABLE: Transferable Backdoor Attacks Against Prompt-based NLP Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.CL","authors_text":"Kai Mei, Shiqing Ma, Yang Zhang, Zheng Li, Zhenting Wang","submitted_at":"2023-05-28T23:35:17Z","abstract_excerpt":"Prompt-based learning is vulnerable to backdoor attacks. Existing backdoor attacks against prompt-based models consider injecting backdoors into the entire embedding layers or word embedding vectors. Such attacks can be easily affected by retraining on downstream tasks and with different prompting strategies, limiting the transferability of backdoor attacks. In this work, we propose transferable backdoor attacks against prompt-based models, called NOTABLE, which is independent of downstream tasks and prompting strategies. Specifically, NOTABLE injects backdoors into the encoders of PLMs by uti"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2305.17826","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2023-05-28T23:35:17Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"1996789e76cfaf93c0b4ca49cf0b8f4cb494706d76f7981379ff6e48581abe14","abstract_canon_sha256":"27d32dad2255a65a7940bc444368ad8b9fabaa9c6ce1117edcaf4c3ca130f22d"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T06:14:49.353738Z","signature_b64":"RvUNUIHC0DKRjP4Wzdwk8eGewEZUFHOTxMNud3g2RLJRDQyeA67SB/6f/LqCk79fnAVXvWZQHdEPclZWssVvDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"454f3b9f342f4bd38a99d493f757d36a1e10f7109ef95ce3a26351647ee050b8","last_reissued_at":"2026-07-05T06:14:49.353407Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T06:14:49.353407Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"NOTABLE: Transferable Backdoor Attacks Against Prompt-based NLP Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.CL","authors_text":"Kai Mei, Shiqing Ma, Yang Zhang, Zheng Li, Zhenting Wang","submitted_at":"2023-05-28T23:35:17Z","abstract_excerpt":"Prompt-based learning is vulnerable to backdoor attacks. Existing backdoor attacks against prompt-based models consider injecting backdoors into the entire embedding layers or word embedding vectors. Such attacks can be easily affected by retraining on downstream tasks and with different prompting strategies, limiting the transferability of backdoor attacks. In this work, we propose transferable backdoor attacks against prompt-based models, called NOTABLE, which is independent of downstream tasks and prompting strategies. Specifically, NOTABLE injects backdoors into the encoders of PLMs by uti"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2305.17826","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2305.17826/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2305.17826","created_at":"2026-07-05T06:14:49.353457+00:00"},{"alias_kind":"arxiv_version","alias_value":"2305.17826v1","created_at":"2026-07-05T06:14:49.353457+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2305.17826","created_at":"2026-07-05T06:14:49.353457+00:00"},{"alias_kind":"pith_short_12","alias_value":"IVHTXHZUF5F5","created_at":"2026-07-05T06:14:49.353457+00:00"},{"alias_kind":"pith_short_16","alias_value":"IVHTXHZUF5F5HCUZ","created_at":"2026-07-05T06:14:49.353457+00:00"},{"alias_kind":"pith_short_8","alias_value":"IVHTXHZU","created_at":"2026-07-05T06:14:49.353457+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2309.10253","citing_title":"GPTFUZZER: Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts","ref_index":41,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/IVHTXHZUF5F5HCUZ2SJ7OV6TNI","json":"https://pith.science/pith/IVHTXHZUF5F5HCUZ2SJ7OV6TNI.json","graph_json":"https://pith.science/api/pith-number/IVHTXHZUF5F5HCUZ2SJ7OV6TNI/graph.json","events_json":"https://pith.science/api/pith-number/IVHTXHZUF5F5HCUZ2SJ7OV6TNI/events.json","paper":"https://pith.science/paper/IVHTXHZU"},"agent_actions":{"view_html":"https://pith.science/pith/IVHTXHZUF5F5HCUZ2SJ7OV6TNI","download_json":"https://pith.science/pith/IVHTXHZUF5F5HCUZ2SJ7OV6TNI.json","view_paper":"https://pith.science/paper/IVHTXHZU","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2305.17826&json=true","fetch_graph":"https://pith.science/api/pith-number/IVHTXHZUF5F5HCUZ2SJ7OV6TNI/graph.json","fetch_events":"https://pith.science/api/pith-number/IVHTXHZUF5F5HCUZ2SJ7OV6TNI/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/IVHTXHZUF5F5HCUZ2SJ7OV6TNI/action/timestamp_anchor","attest_storage":"https://pith.science/pith/IVHTXHZUF5F5HCUZ2SJ7OV6TNI/action/storage_attestation","attest_author":"https://pith.science/pith/IVHTXHZUF5F5HCUZ2SJ7OV6TNI/action/author_attestation","sign_citation":"https://pith.science/pith/IVHTXHZUF5F5HCUZ2SJ7OV6TNI/action/citation_signature","submit_replication":"https://pith.science/pith/IVHTXHZUF5F5HCUZ2SJ7OV6TNI/action/replication_record"}},"created_at":"2026-07-05T06:14:49.353457+00:00","updated_at":"2026-07-05T06:14:49.353457+00:00"}