{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:J32653GE67Y74SJEFA73EHF7U6","short_pith_number":"pith:J32653GE","schema_version":"1.0","canonical_sha256":"4ef5eeecc4f7f1fe4924283fb21cbfa7bcbe417ae304b11bf442066f18579b46","source":{"kind":"arxiv","id":"2502.01385","version":2},"attestation_state":"computed","paper":{"title":"Detecting Backdoor Samples in Contrastive Language Image Pretraining","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CV"],"primary_cat":"cs.LG","authors_text":"Hanxun Huang, James Bailey, Sarah Erfani, Xingjun Ma, Yige Li","submitted_at":"2025-02-03T14:21:05Z","abstract_excerpt":"Contrastive language-image pretraining (CLIP) has been found to be vulnerable to poisoning backdoor attacks where the adversary can achieve an almost perfect attack success rate on CLIP models by poisoning only 0.01\\% of the training dataset. This raises security concerns on the current practice of pretraining large-scale models on unscrutinized web data using CLIP. In this work, we analyze the representations of backdoor-poisoned samples learned by CLIP models and find that they exhibit unique characteristics in their local subspace, i.e., their local neighborhoods are far more sparse than th"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2502.01385","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2025-02-03T14:21:05Z","cross_cats_sorted":["cs.CV"],"title_canon_sha256":"e8fd827e0a94312eea8a56f55870585321cdf61a6c1a13f6d80aa14f43d1b39d","abstract_canon_sha256":"fbbaa662db26520ed7bca1d93b5f7c9b892ed9e0f1227bb693e0cc179497f1b4"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:11:32.966875Z","signature_b64":"jTqNnzitZsNC8ZZaVgYZap7VG0jpgvnLe0jSursJSTpoB9WwVL/xnI74TlyrQAqUvLbqx3RWiNlOJUVpsUKQCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"4ef5eeecc4f7f1fe4924283fb21cbfa7bcbe417ae304b11bf442066f18579b46","last_reissued_at":"2026-07-05T10:11:32.966410Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:11:32.966410Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Detecting Backdoor Samples in Contrastive Language Image Pretraining","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CV"],"primary_cat":"cs.LG","authors_text":"Hanxun Huang, James Bailey, Sarah Erfani, Xingjun Ma, Yige Li","submitted_at":"2025-02-03T14:21:05Z","abstract_excerpt":"Contrastive language-image pretraining (CLIP) has been found to be vulnerable to poisoning backdoor attacks where the adversary can achieve an almost perfect attack success rate on CLIP models by poisoning only 0.01\\% of the training dataset. This raises security concerns on the current practice of pretraining large-scale models on unscrutinized web data using CLIP. In this work, we analyze the representations of backdoor-poisoned samples learned by CLIP models and find that they exhibit unique characteristics in their local subspace, i.e., their local neighborhoods are far more sparse than th"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2502.01385","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2502.01385/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2502.01385","created_at":"2026-07-05T10:11:32.966470+00:00"},{"alias_kind":"arxiv_version","alias_value":"2502.01385v2","created_at":"2026-07-05T10:11:32.966470+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2502.01385","created_at":"2026-07-05T10:11:32.966470+00:00"},{"alias_kind":"pith_short_12","alias_value":"J32653GE67Y7","created_at":"2026-07-05T10:11:32.966470+00:00"},{"alias_kind":"pith_short_16","alias_value":"J32653GE67Y74SJE","created_at":"2026-07-05T10:11:32.966470+00:00"},{"alias_kind":"pith_short_8","alias_value":"J32653GE","created_at":"2026-07-05T10:11:32.966470+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.16651","citing_title":"Right Predictions, Misleading Explanations: On the Vulnerability of Vision-Language Model Explanations","ref_index":4,"is_internal_anchor":false},{"citing_arxiv_id":"2605.16651","citing_title":"Right Predictions, Misleading Explanations: On the Vulnerability of Vision-Language Model Explanations","ref_index":4,"is_internal_anchor":false},{"citing_arxiv_id":"2604.09101","citing_title":"CLIP-Inspector: Model-Level Backdoor Detection for Prompt-Tuned CLIP via OOD Trigger Inversion","ref_index":16,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/J32653GE67Y74SJEFA73EHF7U6","json":"https://pith.science/pith/J32653GE67Y74SJEFA73EHF7U6.json","graph_json":"https://pith.science/api/pith-number/J32653GE67Y74SJEFA73EHF7U6/graph.json","events_json":"https://pith.science/api/pith-number/J32653GE67Y74SJEFA73EHF7U6/events.json","paper":"https://pith.science/paper/J32653GE"},"agent_actions":{"view_html":"https://pith.science/pith/J32653GE67Y74SJEFA73EHF7U6","download_json":"https://pith.science/pith/J32653GE67Y74SJEFA73EHF7U6.json","view_paper":"https://pith.science/paper/J32653GE","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2502.01385&json=true","fetch_graph":"https://pith.science/api/pith-number/J32653GE67Y74SJEFA73EHF7U6/graph.json","fetch_events":"https://pith.science/api/pith-number/J32653GE67Y74SJEFA73EHF7U6/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/J32653GE67Y74SJEFA73EHF7U6/action/timestamp_anchor","attest_storage":"https://pith.science/pith/J32653GE67Y74SJEFA73EHF7U6/action/storage_attestation","attest_author":"https://pith.science/pith/J32653GE67Y74SJEFA73EHF7U6/action/author_attestation","sign_citation":"https://pith.science/pith/J32653GE67Y74SJEFA73EHF7U6/action/citation_signature","submit_replication":"https://pith.science/pith/J32653GE67Y74SJEFA73EHF7U6/action/replication_record"}},"created_at":"2026-07-05T10:11:32.966470+00:00","updated_at":"2026-07-05T10:11:32.966470+00:00"}