{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:P64GBYYKPPR5DRGJQKZK2RJXBX","short_pith_number":"pith:P64GBYYK","schema_version":"1.0","canonical_sha256":"7fb860e30a7be3d1c4c982b2ad45370ddceadd7584b06821f8f1f1be6458cd48","source":{"kind":"arxiv","id":"2310.13828","version":3},"attestation_state":"computed","paper":{"title":"Nightshade: Prompt-Specific Poisoning Attacks on Text-to-Image Generative Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Ben Y. Zhao, Haitao Zheng, Josephine Passananti, Shawn Shan, Stanley Wu, Wenxin Ding","submitted_at":"2023-10-20T21:54:10Z","abstract_excerpt":"Data poisoning attacks manipulate training data to introduce unexpected behaviors into machine learning models at training time. For text-to-image generative models with massive training datasets, current understanding of poisoning attacks suggests that a successful attack would require injecting millions of poison samples into their training pipeline. In this paper, we show that poisoning attacks can be successful on generative models. We observe that training data per concept can be quite limited in these models, making them vulnerable to prompt-specific poisoning attacks, which target a mod"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2310.13828","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2023-10-20T21:54:10Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"e42ab9f598938987a3742deecdf562a0ea4f7c8af7406dfe36ced27a4e8edd7c","abstract_canon_sha256":"4643bf037c5bbf9b64cd3ebb7dcd5df1085e611c76ae0ff7a93c9eaa39828af4"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:13:09.500664Z","signature_b64":"N4z/n3riQdpsVIhFoQiLbuNujlHnJazeR6BYYdIWjCF9pqp4K1SZYhVfCa7P64zuTuKA8g1LtsoCNejiqrC7AA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"7fb860e30a7be3d1c4c982b2ad45370ddceadd7584b06821f8f1f1be6458cd48","last_reissued_at":"2026-07-05T08:13:09.500229Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:13:09.500229Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Nightshade: Prompt-Specific Poisoning Attacks on Text-to-Image Generative Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Ben Y. Zhao, Haitao Zheng, Josephine Passananti, Shawn Shan, Stanley Wu, Wenxin Ding","submitted_at":"2023-10-20T21:54:10Z","abstract_excerpt":"Data poisoning attacks manipulate training data to introduce unexpected behaviors into machine learning models at training time. For text-to-image generative models with massive training datasets, current understanding of poisoning attacks suggests that a successful attack would require injecting millions of poison samples into their training pipeline. In this paper, we show that poisoning attacks can be successful on generative models. We observe that training data per concept can be quite limited in these models, making them vulnerable to prompt-specific poisoning attacks, which target a mod"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2310.13828","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2310.13828/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2310.13828","created_at":"2026-07-05T08:13:09.500281+00:00"},{"alias_kind":"arxiv_version","alias_value":"2310.13828v3","created_at":"2026-07-05T08:13:09.500281+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2310.13828","created_at":"2026-07-05T08:13:09.500281+00:00"},{"alias_kind":"pith_short_12","alias_value":"P64GBYYKPPR5","created_at":"2026-07-05T08:13:09.500281+00:00"},{"alias_kind":"pith_short_16","alias_value":"P64GBYYKPPR5DRGJ","created_at":"2026-07-05T08:13:09.500281+00:00"},{"alias_kind":"pith_short_8","alias_value":"P64GBYYK","created_at":"2026-07-05T08:13:09.500281+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2405.18179","citing_title":"Rethinking the A in STEAM: Insights from and for AI Literacy Education","ref_index":46,"is_internal_anchor":false},{"citing_arxiv_id":"2508.15840","citing_title":"Unveiling Unicode's Unseen Underpinnings in Undermining Authorship Attribution","ref_index":37,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/P64GBYYKPPR5DRGJQKZK2RJXBX","json":"https://pith.science/pith/P64GBYYKPPR5DRGJQKZK2RJXBX.json","graph_json":"https://pith.science/api/pith-number/P64GBYYKPPR5DRGJQKZK2RJXBX/graph.json","events_json":"https://pith.science/api/pith-number/P64GBYYKPPR5DRGJQKZK2RJXBX/events.json","paper":"https://pith.science/paper/P64GBYYK"},"agent_actions":{"view_html":"https://pith.science/pith/P64GBYYKPPR5DRGJQKZK2RJXBX","download_json":"https://pith.science/pith/P64GBYYKPPR5DRGJQKZK2RJXBX.json","view_paper":"https://pith.science/paper/P64GBYYK","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2310.13828&json=true","fetch_graph":"https://pith.science/api/pith-number/P64GBYYKPPR5DRGJQKZK2RJXBX/graph.json","fetch_events":"https://pith.science/api/pith-number/P64GBYYKPPR5DRGJQKZK2RJXBX/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/P64GBYYKPPR5DRGJQKZK2RJXBX/action/timestamp_anchor","attest_storage":"https://pith.science/pith/P64GBYYKPPR5DRGJQKZK2RJXBX/action/storage_attestation","attest_author":"https://pith.science/pith/P64GBYYKPPR5DRGJQKZK2RJXBX/action/author_attestation","sign_citation":"https://pith.science/pith/P64GBYYKPPR5DRGJQKZK2RJXBX/action/citation_signature","submit_replication":"https://pith.science/pith/P64GBYYKPPR5DRGJQKZK2RJXBX/action/replication_record"}},"created_at":"2026-07-05T08:13:09.500281+00:00","updated_at":"2026-07-05T08:13:09.500281+00:00"}