{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:LCN6CN4R7UDF2LP26N6YMMMACF","short_pith_number":"pith:LCN6CN4R","schema_version":"1.0","canonical_sha256":"589be13791fd065d2dfaf37d8631801144b911e20a057ea35e0e288af349d6c7","source":{"kind":"arxiv","id":"2301.02344","version":2},"attestation_state":"computed","paper":{"title":"TrojanPuzzle: Covertly Poisoning Code-Suggestion Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Anant Kharkar, Andre Manoel, Ben Zorn, Christopher Kruegel, David Evans, Giovanni Vigna, Hojjat Aghakhani, Robert Sim, Wei Dai, Xavier Fernandes","submitted_at":"2023-01-06T00:37:25Z","abstract_excerpt":"With tools like GitHub Copilot, automatic code suggestion is no longer a dream in software engineering. These tools, based on large language models, are typically trained on massive corpora of code mined from unvetted public sources. As a result, these models are susceptible to data poisoning attacks where an adversary manipulates the model's training by injecting malicious data. Poisoning attacks could be designed to influence the model's suggestions at run time for chosen contexts, such as inducing the model into suggesting insecure code payloads. To achieve this, prior attacks explicitly in"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2301.02344","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2023-01-06T00:37:25Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"00c63f0ecdc8b81b0019f5d3aa1f4bc49314d90d8436535b66da603e75fb25af","abstract_canon_sha256":"4f0df2a0243bf41b8f8a2564befea4d932239c8a2ee11652c2ff2e2f6089e299"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:36:49.862113Z","signature_b64":"uV0x0DMgkRzM2ycnO8V/+flamvBZZpSg8oFsd+AxmpCBXLarbh0lioFm5jthUakgqPyVzKLEkK1pKrJ0bgtYBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"589be13791fd065d2dfaf37d8631801144b911e20a057ea35e0e288af349d6c7","last_reissued_at":"2026-07-05T07:36:49.861690Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:36:49.861690Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"TrojanPuzzle: Covertly Poisoning Code-Suggestion Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Anant Kharkar, Andre Manoel, Ben Zorn, Christopher Kruegel, David Evans, Giovanni Vigna, Hojjat Aghakhani, Robert Sim, Wei Dai, Xavier Fernandes","submitted_at":"2023-01-06T00:37:25Z","abstract_excerpt":"With tools like GitHub Copilot, automatic code suggestion is no longer a dream in software engineering. These tools, based on large language models, are typically trained on massive corpora of code mined from unvetted public sources. As a result, these models are susceptible to data poisoning attacks where an adversary manipulates the model's training by injecting malicious data. Poisoning attacks could be designed to influence the model's suggestions at run time for chosen contexts, such as inducing the model into suggesting insecure code payloads. To achieve this, prior attacks explicitly in"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2301.02344","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2301.02344/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2301.02344","created_at":"2026-07-05T07:36:49.861747+00:00"},{"alias_kind":"arxiv_version","alias_value":"2301.02344v2","created_at":"2026-07-05T07:36:49.861747+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2301.02344","created_at":"2026-07-05T07:36:49.861747+00:00"},{"alias_kind":"pith_short_12","alias_value":"LCN6CN4R7UDF","created_at":"2026-07-05T07:36:49.861747+00:00"},{"alias_kind":"pith_short_16","alias_value":"LCN6CN4R7UDF2LP2","created_at":"2026-07-05T07:36:49.861747+00:00"},{"alias_kind":"pith_short_8","alias_value":"LCN6CN4R","created_at":"2026-07-05T07:36:49.861747+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":5,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.25476","citing_title":"A Red Teaming Framework for Large Language Models: A Case Study on Faithfulness Evaluation","ref_index":58,"is_internal_anchor":false},{"citing_arxiv_id":"2607.01280","citing_title":"Fixed-Set Robustness in Programming by Example: Example Corruption and Semantic Partition Recovery","ref_index":61,"is_internal_anchor":false},{"citing_arxiv_id":"2605.23091","citing_title":"Security of LLM-generated Code: A Comparative Analysis","ref_index":10,"is_internal_anchor":false},{"citing_arxiv_id":"2510.04265","citing_title":"Don't Pass@k: A Bayesian Framework for Large Language Model Evaluation","ref_index":61,"is_internal_anchor":false},{"citing_arxiv_id":"2604.23338","citing_title":"A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework","ref_index":124,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/LCN6CN4R7UDF2LP26N6YMMMACF","json":"https://pith.science/pith/LCN6CN4R7UDF2LP26N6YMMMACF.json","graph_json":"https://pith.science/api/pith-number/LCN6CN4R7UDF2LP26N6YMMMACF/graph.json","events_json":"https://pith.science/api/pith-number/LCN6CN4R7UDF2LP26N6YMMMACF/events.json","paper":"https://pith.science/paper/LCN6CN4R"},"agent_actions":{"view_html":"https://pith.science/pith/LCN6CN4R7UDF2LP26N6YMMMACF","download_json":"https://pith.science/pith/LCN6CN4R7UDF2LP26N6YMMMACF.json","view_paper":"https://pith.science/paper/LCN6CN4R","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2301.02344&json=true","fetch_graph":"https://pith.science/api/pith-number/LCN6CN4R7UDF2LP26N6YMMMACF/graph.json","fetch_events":"https://pith.science/api/pith-number/LCN6CN4R7UDF2LP26N6YMMMACF/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/LCN6CN4R7UDF2LP26N6YMMMACF/action/timestamp_anchor","attest_storage":"https://pith.science/pith/LCN6CN4R7UDF2LP26N6YMMMACF/action/storage_attestation","attest_author":"https://pith.science/pith/LCN6CN4R7UDF2LP26N6YMMMACF/action/author_attestation","sign_citation":"https://pith.science/pith/LCN6CN4R7UDF2LP26N6YMMMACF/action/citation_signature","submit_replication":"https://pith.science/pith/LCN6CN4R7UDF2LP26N6YMMMACF/action/replication_record"}},"created_at":"2026-07-05T07:36:49.861747+00:00","updated_at":"2026-07-05T07:36:49.861747+00:00"}