{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2020:L3NXXNMS7KZWYS46MBWBVCURNB","short_pith_number":"pith:L3NXXNMS","schema_version":"1.0","canonical_sha256":"5edb7bb592fab36c4b9e606c1a8a916849bdb525a6f0421d02a342f8c82f6076","source":{"kind":"arxiv","id":"2008.04495","version":7},"attestation_state":"computed","paper":{"title":"Intrinsic Certified Robustness of Bagging against Data Poisoning Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Jinyuan Jia, Neil Zhenqiang Gong, Xiaoyu Cao","submitted_at":"2020-08-11T03:12:42Z","abstract_excerpt":"In a \\emph{data poisoning attack}, an attacker modifies, deletes, and/or inserts some training examples to corrupt the learnt machine learning model. \\emph{Bootstrap Aggregating (bagging)} is a well-known ensemble learning method, which trains multiple base models on random subsamples of a training dataset using a base learning algorithm and uses majority vote to predict labels of testing examples. We prove the intrinsic certified robustness of bagging against data poisoning attacks. Specifically, we show that bagging with an arbitrary base learning algorithm provably predicts the same label f"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2008.04495","kind":"arxiv","version":7},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2020-08-11T03:12:42Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"0db726fe6a3b8811ae3b62bea8032acdc98b0fc19ca13c16dba236829ff5b058","abstract_canon_sha256":"04caddc8e73f9b767d2b588dc4826979fa3616fbf56be4c1759438a0c0327e81"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T01:58:21.394032Z","signature_b64":"Zxz7h+jg2iCXpVdIEUiwPyMk8YQV/bK781b85YKWFMYKhp1TFKmX2TD9jJB7M+1LaZFeLw8e1NnTvhzY2bKzCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"5edb7bb592fab36c4b9e606c1a8a916849bdb525a6f0421d02a342f8c82f6076","last_reissued_at":"2026-07-05T01:58:21.393598Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T01:58:21.393598Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Intrinsic Certified Robustness of Bagging against Data Poisoning Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Jinyuan Jia, Neil Zhenqiang Gong, Xiaoyu Cao","submitted_at":"2020-08-11T03:12:42Z","abstract_excerpt":"In a \\emph{data poisoning attack}, an attacker modifies, deletes, and/or inserts some training examples to corrupt the learnt machine learning model. \\emph{Bootstrap Aggregating (bagging)} is a well-known ensemble learning method, which trains multiple base models on random subsamples of a training dataset using a base learning algorithm and uses majority vote to predict labels of testing examples. We prove the intrinsic certified robustness of bagging against data poisoning attacks. Specifically, we show that bagging with an arbitrary base learning algorithm provably predicts the same label f"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2008.04495","kind":"arxiv","version":7},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2008.04495/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2008.04495","created_at":"2026-07-05T01:58:21.393652+00:00"},{"alias_kind":"arxiv_version","alias_value":"2008.04495v7","created_at":"2026-07-05T01:58:21.393652+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2008.04495","created_at":"2026-07-05T01:58:21.393652+00:00"},{"alias_kind":"pith_short_12","alias_value":"L3NXXNMS7KZW","created_at":"2026-07-05T01:58:21.393652+00:00"},{"alias_kind":"pith_short_16","alias_value":"L3NXXNMS7KZWYS46","created_at":"2026-07-05T01:58:21.393652+00:00"},{"alias_kind":"pith_short_8","alias_value":"L3NXXNMS","created_at":"2026-07-05T01:58:21.393652+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2506.03075","citing_title":"Agnostic Learning under Targeted Poisoning: Optimal Rates and the Role of Randomness","ref_index":12,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/L3NXXNMS7KZWYS46MBWBVCURNB","json":"https://pith.science/pith/L3NXXNMS7KZWYS46MBWBVCURNB.json","graph_json":"https://pith.science/api/pith-number/L3NXXNMS7KZWYS46MBWBVCURNB/graph.json","events_json":"https://pith.science/api/pith-number/L3NXXNMS7KZWYS46MBWBVCURNB/events.json","paper":"https://pith.science/paper/L3NXXNMS"},"agent_actions":{"view_html":"https://pith.science/pith/L3NXXNMS7KZWYS46MBWBVCURNB","download_json":"https://pith.science/pith/L3NXXNMS7KZWYS46MBWBVCURNB.json","view_paper":"https://pith.science/paper/L3NXXNMS","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2008.04495&json=true","fetch_graph":"https://pith.science/api/pith-number/L3NXXNMS7KZWYS46MBWBVCURNB/graph.json","fetch_events":"https://pith.science/api/pith-number/L3NXXNMS7KZWYS46MBWBVCURNB/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/L3NXXNMS7KZWYS46MBWBVCURNB/action/timestamp_anchor","attest_storage":"https://pith.science/pith/L3NXXNMS7KZWYS46MBWBVCURNB/action/storage_attestation","attest_author":"https://pith.science/pith/L3NXXNMS7KZWYS46MBWBVCURNB/action/author_attestation","sign_citation":"https://pith.science/pith/L3NXXNMS7KZWYS46MBWBVCURNB/action/citation_signature","submit_replication":"https://pith.science/pith/L3NXXNMS7KZWYS46MBWBVCURNB/action/replication_record"}},"created_at":"2026-07-05T01:58:21.393652+00:00","updated_at":"2026-07-05T01:58:21.393652+00:00"}