{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:OV6XJDH6HZ7RNAXZHBTDAOT36M","short_pith_number":"pith:OV6XJDH6","schema_version":"1.0","canonical_sha256":"757d748cfe3e7f1682f93866303a7bf31cd1a173ddf9c406a5a314c50f131b38","source":{"kind":"arxiv","id":"2406.12257","version":3},"attestation_state":"computed","paper":{"title":"CleanGen: Mitigating Backdoor Attacks for Generation Tasks in Large Language Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.AI","authors_text":"Bhaskar Ramasubramanian, Dinuka Sahabandu, Fengqing Jiang, Luyao Niu, Radha Poovendran, Yuetai Li, Zhangchen Xu","submitted_at":"2024-06-18T04:10:38Z","abstract_excerpt":"The remarkable performance of large language models (LLMs) in generation tasks has enabled practitioners to leverage publicly available models to power custom applications, such as chatbots and virtual assistants. However, the data used to train or fine-tune these LLMs is often undisclosed, allowing an attacker to compromise the data and inject backdoors into the models. In this paper, we develop a novel inference time defense, named CLEANGEN, to mitigate backdoor attacks for generation tasks in LLMs. CLEANGEN is a lightweight and effective decoding strategy that is compatible with the state-o"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2406.12257","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2024-06-18T04:10:38Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"51d790409bd83969b57843cc0f8383413afe5c522332c8047c9de91b1714de10","abstract_canon_sha256":"92d62a3c8fdba73471513923464be748d8dfb067904de365dd38a0d82847983c"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:40:01.426986Z","signature_b64":"25XIizlNx7MImihWQ42uF7DVd8JRfL8Wnts2k7sCnJXPSMGA74i99e16CZ3Hl3SWesgPGYTjN+9v3j6KPbJsAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"757d748cfe3e7f1682f93866303a7bf31cd1a173ddf9c406a5a314c50f131b38","last_reissued_at":"2026-07-05T10:40:01.426452Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:40:01.426452Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"CleanGen: Mitigating Backdoor Attacks for Generation Tasks in Large Language Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.AI","authors_text":"Bhaskar Ramasubramanian, Dinuka Sahabandu, Fengqing Jiang, Luyao Niu, Radha Poovendran, Yuetai Li, Zhangchen Xu","submitted_at":"2024-06-18T04:10:38Z","abstract_excerpt":"The remarkable performance of large language models (LLMs) in generation tasks has enabled practitioners to leverage publicly available models to power custom applications, such as chatbots and virtual assistants. However, the data used to train or fine-tune these LLMs is often undisclosed, allowing an attacker to compromise the data and inject backdoors into the models. In this paper, we develop a novel inference time defense, named CLEANGEN, to mitigate backdoor attacks for generation tasks in LLMs. CLEANGEN is a lightweight and effective decoding strategy that is compatible with the state-o"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2406.12257","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2406.12257/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2406.12257","created_at":"2026-07-05T10:40:01.426509+00:00"},{"alias_kind":"arxiv_version","alias_value":"2406.12257v3","created_at":"2026-07-05T10:40:01.426509+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2406.12257","created_at":"2026-07-05T10:40:01.426509+00:00"},{"alias_kind":"pith_short_12","alias_value":"OV6XJDH6HZ7R","created_at":"2026-07-05T10:40:01.426509+00:00"},{"alias_kind":"pith_short_16","alias_value":"OV6XJDH6HZ7RNAXZ","created_at":"2026-07-05T10:40:01.426509+00:00"},{"alias_kind":"pith_short_8","alias_value":"OV6XJDH6","created_at":"2026-07-05T10:40:01.426509+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2504.00446","citing_title":"Exposing the Ghost in the Transformer: Abnormal Detection for Large Language Models via Hidden State Forensics","ref_index":53,"is_internal_anchor":false},{"citing_arxiv_id":"2504.05902","citing_title":"Defending against Backdoor Attacks via Module Switching","ref_index":26,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/OV6XJDH6HZ7RNAXZHBTDAOT36M","json":"https://pith.science/pith/OV6XJDH6HZ7RNAXZHBTDAOT36M.json","graph_json":"https://pith.science/api/pith-number/OV6XJDH6HZ7RNAXZHBTDAOT36M/graph.json","events_json":"https://pith.science/api/pith-number/OV6XJDH6HZ7RNAXZHBTDAOT36M/events.json","paper":"https://pith.science/paper/OV6XJDH6"},"agent_actions":{"view_html":"https://pith.science/pith/OV6XJDH6HZ7RNAXZHBTDAOT36M","download_json":"https://pith.science/pith/OV6XJDH6HZ7RNAXZHBTDAOT36M.json","view_paper":"https://pith.science/paper/OV6XJDH6","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2406.12257&json=true","fetch_graph":"https://pith.science/api/pith-number/OV6XJDH6HZ7RNAXZHBTDAOT36M/graph.json","fetch_events":"https://pith.science/api/pith-number/OV6XJDH6HZ7RNAXZHBTDAOT36M/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/OV6XJDH6HZ7RNAXZHBTDAOT36M/action/timestamp_anchor","attest_storage":"https://pith.science/pith/OV6XJDH6HZ7RNAXZHBTDAOT36M/action/storage_attestation","attest_author":"https://pith.science/pith/OV6XJDH6HZ7RNAXZHBTDAOT36M/action/author_attestation","sign_citation":"https://pith.science/pith/OV6XJDH6HZ7RNAXZHBTDAOT36M/action/citation_signature","submit_replication":"https://pith.science/pith/OV6XJDH6HZ7RNAXZHBTDAOT36M/action/replication_record"}},"created_at":"2026-07-05T10:40:01.426509+00:00","updated_at":"2026-07-05T10:40:01.426509+00:00"}