{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:NUP6XNY4UKPUGDVGKUG7VQGOP5","short_pith_number":"pith:NUP6XNY4","schema_version":"1.0","canonical_sha256":"6d1febb71ca29f430ea6550dfac0ce7f4c41437105b1564efba0036b42d7c5c1","source":{"kind":"arxiv","id":"2110.08247","version":2},"attestation_state":"computed","paper":{"title":"Textual Backdoor Attacks Can Be More Harmful via Two Simple Tricks","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.CR","authors_text":"Fanchao Qi, Hongcheng Gao, Maosong Sun, Yangyi Chen, Zhiyuan Liu","submitted_at":"2021-10-15T17:58:46Z","abstract_excerpt":"Backdoor attacks are a kind of emergent security threat in deep learning. After being injected with a backdoor, a deep neural model will behave normally on standard inputs but give adversary-specified predictions once the input contains specific backdoor triggers. In this paper, we find two simple tricks that can make existing textual backdoor attacks much more harmful. The first trick is to add an extra training task to distinguish poisoned and clean data during the training of the victim model, and the second one is to use all the clean training data rather than remove the original clean dat"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2110.08247","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2021-10-15T17:58:46Z","cross_cats_sorted":["cs.AI","cs.CL"],"title_canon_sha256":"9bd22a1db8edc53f4f3b65b5825f788194457765021cd4e8cf3c6d6156b2a54b","abstract_canon_sha256":"925dce046f5166617d04023ca594a7132254d8fa7228891d0baa482ae419592e"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T05:08:14.381844Z","signature_b64":"qZlYEOQSqBYIGlS1cDokPGcPwBznCQ4XfeYrms0JwUxhcaiQxYNfj0cc9s7HmTIGF/tkgzXH/UgAV4N0kgpXAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"6d1febb71ca29f430ea6550dfac0ce7f4c41437105b1564efba0036b42d7c5c1","last_reissued_at":"2026-07-05T05:08:14.381423Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T05:08:14.381423Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Textual Backdoor Attacks Can Be More Harmful via Two Simple Tricks","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.CR","authors_text":"Fanchao Qi, Hongcheng Gao, Maosong Sun, Yangyi Chen, Zhiyuan Liu","submitted_at":"2021-10-15T17:58:46Z","abstract_excerpt":"Backdoor attacks are a kind of emergent security threat in deep learning. After being injected with a backdoor, a deep neural model will behave normally on standard inputs but give adversary-specified predictions once the input contains specific backdoor triggers. In this paper, we find two simple tricks that can make existing textual backdoor attacks much more harmful. The first trick is to add an extra training task to distinguish poisoned and clean data during the training of the victim model, and the second one is to use all the clean training data rather than remove the original clean dat"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2110.08247","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2110.08247/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2110.08247","created_at":"2026-07-05T05:08:14.381479+00:00"},{"alias_kind":"arxiv_version","alias_value":"2110.08247v2","created_at":"2026-07-05T05:08:14.381479+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2110.08247","created_at":"2026-07-05T05:08:14.381479+00:00"},{"alias_kind":"pith_short_12","alias_value":"NUP6XNY4UKPU","created_at":"2026-07-05T05:08:14.381479+00:00"},{"alias_kind":"pith_short_16","alias_value":"NUP6XNY4UKPUGDVG","created_at":"2026-07-05T05:08:14.381479+00:00"},{"alias_kind":"pith_short_8","alias_value":"NUP6XNY4","created_at":"2026-07-05T05:08:14.381479+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/NUP6XNY4UKPUGDVGKUG7VQGOP5","json":"https://pith.science/pith/NUP6XNY4UKPUGDVGKUG7VQGOP5.json","graph_json":"https://pith.science/api/pith-number/NUP6XNY4UKPUGDVGKUG7VQGOP5/graph.json","events_json":"https://pith.science/api/pith-number/NUP6XNY4UKPUGDVGKUG7VQGOP5/events.json","paper":"https://pith.science/paper/NUP6XNY4"},"agent_actions":{"view_html":"https://pith.science/pith/NUP6XNY4UKPUGDVGKUG7VQGOP5","download_json":"https://pith.science/pith/NUP6XNY4UKPUGDVGKUG7VQGOP5.json","view_paper":"https://pith.science/paper/NUP6XNY4","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2110.08247&json=true","fetch_graph":"https://pith.science/api/pith-number/NUP6XNY4UKPUGDVGKUG7VQGOP5/graph.json","fetch_events":"https://pith.science/api/pith-number/NUP6XNY4UKPUGDVGKUG7VQGOP5/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/NUP6XNY4UKPUGDVGKUG7VQGOP5/action/timestamp_anchor","attest_storage":"https://pith.science/pith/NUP6XNY4UKPUGDVGKUG7VQGOP5/action/storage_attestation","attest_author":"https://pith.science/pith/NUP6XNY4UKPUGDVGKUG7VQGOP5/action/author_attestation","sign_citation":"https://pith.science/pith/NUP6XNY4UKPUGDVGKUG7VQGOP5/action/citation_signature","submit_replication":"https://pith.science/pith/NUP6XNY4UKPUGDVGKUG7VQGOP5/action/replication_record"}},"created_at":"2026-07-05T05:08:14.381479+00:00","updated_at":"2026-07-05T05:08:14.381479+00:00"}