{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:OMPWTM4G33VWAFTTVRPLJQ2OUP","short_pith_number":"pith:OMPWTM4G","schema_version":"1.0","canonical_sha256":"731f69b386deeb601673ac5eb4c34ea3ccc575d18940cff686a1b353dded347c","source":{"kind":"arxiv","id":"2101.05930","version":2},"attestation_state":"computed","paper":{"title":"Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.LG","authors_text":"Bo Li, Lingjuan Lyu, Nodens Koren, Xingjun Ma, Xixiang Lyu, Yige Li","submitted_at":"2021-01-15T01:35:22Z","abstract_excerpt":"Deep neural networks (DNNs) are known vulnerable to backdoor attacks, a training time attack that injects a trigger pattern into a small proportion of training data so as to control the model's prediction at the test time. Backdoor attacks are notably dangerous since they do not affect the model's performance on clean examples, yet can fool the model to make incorrect prediction whenever the trigger pattern appears during testing. In this paper, we propose a novel defense framework Neural Attention Distillation (NAD) to erase backdoor triggers from backdoored DNNs. NAD utilizes a teacher netwo"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2101.05930","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2021-01-15T01:35:22Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"9809545500338246e17753177affe09cad322f084c70cc61405dc7f1f5986ccb","abstract_canon_sha256":"0984d74b6eb771308ddad5c391f6cac70f2edbdaaeb1c99b879f985289b73b1e"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T02:10:07.686518Z","signature_b64":"BDXUdEkBMMZzHf83awn0JtEatuwOa+SPF5aworhUeW6kYT/PoVnYKnsI98SydG1l8SFmNOjrVoLv9FxjxUvjAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"731f69b386deeb601673ac5eb4c34ea3ccc575d18940cff686a1b353dded347c","last_reissued_at":"2026-07-05T02:10:07.686049Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T02:10:07.686049Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.LG","authors_text":"Bo Li, Lingjuan Lyu, Nodens Koren, Xingjun Ma, Xixiang Lyu, Yige Li","submitted_at":"2021-01-15T01:35:22Z","abstract_excerpt":"Deep neural networks (DNNs) are known vulnerable to backdoor attacks, a training time attack that injects a trigger pattern into a small proportion of training data so as to control the model's prediction at the test time. Backdoor attacks are notably dangerous since they do not affect the model's performance on clean examples, yet can fool the model to make incorrect prediction whenever the trigger pattern appears during testing. In this paper, we propose a novel defense framework Neural Attention Distillation (NAD) to erase backdoor triggers from backdoored DNNs. NAD utilizes a teacher netwo"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2101.05930","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2101.05930/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2101.05930","created_at":"2026-07-05T02:10:07.686128+00:00"},{"alias_kind":"arxiv_version","alias_value":"2101.05930v2","created_at":"2026-07-05T02:10:07.686128+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2101.05930","created_at":"2026-07-05T02:10:07.686128+00:00"},{"alias_kind":"pith_short_12","alias_value":"OMPWTM4G33VW","created_at":"2026-07-05T02:10:07.686128+00:00"},{"alias_kind":"pith_short_16","alias_value":"OMPWTM4G33VWAFTT","created_at":"2026-07-05T02:10:07.686128+00:00"},{"alias_kind":"pith_short_8","alias_value":"OMPWTM4G","created_at":"2026-07-05T02:10:07.686128+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":7,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.27148","citing_title":"Landseer: Exploring the Machine Learning Defense Landscape","ref_index":54,"is_internal_anchor":false},{"citing_arxiv_id":"2605.21146","citing_title":"Detecting Trojaned DNNs via Spectral Regression Analysis","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2511.22262","citing_title":"Can Protective Watermarking Safeguard the Copyright of 3D Gaussian Splatting?","ref_index":2,"is_internal_anchor":false},{"citing_arxiv_id":"2602.07200","citing_title":"BadSNN: Backdoor Attacks on Spiking Neural Networks via Adversarial Spiking Neuron","ref_index":49,"is_internal_anchor":false},{"citing_arxiv_id":"2604.09651","citing_title":"FlowHijack: A Dynamics-Aware Backdoor Attack on Flow-Matching Vision-Language-Action Models","ref_index":17,"is_internal_anchor":false},{"citing_arxiv_id":"2604.24162","citing_title":"Defusing the Trigger: Plug-and-Play Defense for Backdoored LLMs via Tail-Risk Intrinsic Geometric Smoothing","ref_index":20,"is_internal_anchor":false},{"citing_arxiv_id":"2604.04800","citing_title":"Forgetting to Witness: Efficient Federated Unlearning and Its Visible Evaluation","ref_index":51,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/OMPWTM4G33VWAFTTVRPLJQ2OUP","json":"https://pith.science/pith/OMPWTM4G33VWAFTTVRPLJQ2OUP.json","graph_json":"https://pith.science/api/pith-number/OMPWTM4G33VWAFTTVRPLJQ2OUP/graph.json","events_json":"https://pith.science/api/pith-number/OMPWTM4G33VWAFTTVRPLJQ2OUP/events.json","paper":"https://pith.science/paper/OMPWTM4G"},"agent_actions":{"view_html":"https://pith.science/pith/OMPWTM4G33VWAFTTVRPLJQ2OUP","download_json":"https://pith.science/pith/OMPWTM4G33VWAFTTVRPLJQ2OUP.json","view_paper":"https://pith.science/paper/OMPWTM4G","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2101.05930&json=true","fetch_graph":"https://pith.science/api/pith-number/OMPWTM4G33VWAFTTVRPLJQ2OUP/graph.json","fetch_events":"https://pith.science/api/pith-number/OMPWTM4G33VWAFTTVRPLJQ2OUP/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/OMPWTM4G33VWAFTTVRPLJQ2OUP/action/timestamp_anchor","attest_storage":"https://pith.science/pith/OMPWTM4G33VWAFTTVRPLJQ2OUP/action/storage_attestation","attest_author":"https://pith.science/pith/OMPWTM4G33VWAFTTVRPLJQ2OUP/action/author_attestation","sign_citation":"https://pith.science/pith/OMPWTM4G33VWAFTTVRPLJQ2OUP/action/citation_signature","submit_replication":"https://pith.science/pith/OMPWTM4G33VWAFTTVRPLJQ2OUP/action/replication_record"}},"created_at":"2026-07-05T02:10:07.686128+00:00","updated_at":"2026-07-05T02:10:07.686128+00:00"}