{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:J45KSHBRFPM5YPJ2RZ5NOMRCHI","short_pith_number":"pith:J45KSHBR","schema_version":"1.0","canonical_sha256":"4f3aa91c312bd9dc3d3a8e7ad732223a0bd54586d90f2697b086bed0f2db1a5e","source":{"kind":"arxiv","id":"2408.09878","version":1},"attestation_state":"computed","paper":{"title":"Transferring Backdoors between Large Language Models by Knowledge Distillation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Pengzhou Cheng, Tianjie Ju, Wei Du, Zhuosheng Zhang Gongshen Liu, Zongru Wu","submitted_at":"2024-08-19T10:39:45Z","abstract_excerpt":"Backdoor Attacks have been a serious vulnerability against Large Language Models (LLMs). However, previous methods only reveal such risk in specific models, or present tasks transferability after attacking the pre-trained phase. So, how risky is the model transferability of a backdoor attack? In this paper, we focus on whether existing mini-LLMs may be unconsciously instructed in backdoor knowledge by poisoned teacher LLMs through knowledge distillation (KD). Specifically, we propose ATBA, an adaptive transferable backdoor attack, which can effectively distill the backdoor of teacher LLMs into"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2408.09878","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-08-19T10:39:45Z","cross_cats_sorted":[],"title_canon_sha256":"7502e8591d9f627bbbcba6059e609cc6585c476cd7732b372478ff3aa4d0f7fe","abstract_canon_sha256":"d9a2d2f77045a34d3edccd9fbd59583cb6e85c6117cf62519556ed3b53b42402"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:56:38.463467Z","signature_b64":"jdWU4B+NWjcM7qy6/p3Zumn4oOWnKJqxXJnfqAIzyS5iieoBN9v8ce1+t8jzXmHPZHcEYyB7rHeYnVOxnBjnAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"4f3aa91c312bd9dc3d3a8e7ad732223a0bd54586d90f2697b086bed0f2db1a5e","last_reissued_at":"2026-07-05T08:56:38.462979Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:56:38.462979Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Transferring Backdoors between Large Language Models by Knowledge Distillation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Pengzhou Cheng, Tianjie Ju, Wei Du, Zhuosheng Zhang Gongshen Liu, Zongru Wu","submitted_at":"2024-08-19T10:39:45Z","abstract_excerpt":"Backdoor Attacks have been a serious vulnerability against Large Language Models (LLMs). However, previous methods only reveal such risk in specific models, or present tasks transferability after attacking the pre-trained phase. So, how risky is the model transferability of a backdoor attack? In this paper, we focus on whether existing mini-LLMs may be unconsciously instructed in backdoor knowledge by poisoned teacher LLMs through knowledge distillation (KD). Specifically, we propose ATBA, an adaptive transferable backdoor attack, which can effectively distill the backdoor of teacher LLMs into"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2408.09878","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2408.09878/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2408.09878","created_at":"2026-07-05T08:56:38.463039+00:00"},{"alias_kind":"arxiv_version","alias_value":"2408.09878v1","created_at":"2026-07-05T08:56:38.463039+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2408.09878","created_at":"2026-07-05T08:56:38.463039+00:00"},{"alias_kind":"pith_short_12","alias_value":"J45KSHBRFPM5","created_at":"2026-07-05T08:56:38.463039+00:00"},{"alias_kind":"pith_short_16","alias_value":"J45KSHBRFPM5YPJ2","created_at":"2026-07-05T08:56:38.463039+00:00"},{"alias_kind":"pith_short_8","alias_value":"J45KSHBR","created_at":"2026-07-05T08:56:38.463039+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.22019","citing_title":"Channel Location Constrains the Auditability of Subliminal Learning","ref_index":56,"is_internal_anchor":false},{"citing_arxiv_id":"2509.24496","citing_title":"LLM DNA: Tracing Model Evolution via Functional Representations","ref_index":1,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/J45KSHBRFPM5YPJ2RZ5NOMRCHI","json":"https://pith.science/pith/J45KSHBRFPM5YPJ2RZ5NOMRCHI.json","graph_json":"https://pith.science/api/pith-number/J45KSHBRFPM5YPJ2RZ5NOMRCHI/graph.json","events_json":"https://pith.science/api/pith-number/J45KSHBRFPM5YPJ2RZ5NOMRCHI/events.json","paper":"https://pith.science/paper/J45KSHBR"},"agent_actions":{"view_html":"https://pith.science/pith/J45KSHBRFPM5YPJ2RZ5NOMRCHI","download_json":"https://pith.science/pith/J45KSHBRFPM5YPJ2RZ5NOMRCHI.json","view_paper":"https://pith.science/paper/J45KSHBR","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2408.09878&json=true","fetch_graph":"https://pith.science/api/pith-number/J45KSHBRFPM5YPJ2RZ5NOMRCHI/graph.json","fetch_events":"https://pith.science/api/pith-number/J45KSHBRFPM5YPJ2RZ5NOMRCHI/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/J45KSHBRFPM5YPJ2RZ5NOMRCHI/action/timestamp_anchor","attest_storage":"https://pith.science/pith/J45KSHBRFPM5YPJ2RZ5NOMRCHI/action/storage_attestation","attest_author":"https://pith.science/pith/J45KSHBRFPM5YPJ2RZ5NOMRCHI/action/author_attestation","sign_citation":"https://pith.science/pith/J45KSHBRFPM5YPJ2RZ5NOMRCHI/action/citation_signature","submit_replication":"https://pith.science/pith/J45KSHBRFPM5YPJ2RZ5NOMRCHI/action/replication_record"}},"created_at":"2026-07-05T08:56:38.463039+00:00","updated_at":"2026-07-05T08:56:38.463039+00:00"}