{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:PYIBWUBXE3OZMLHANGTI5KUJ2A","short_pith_number":"pith:PYIBWUBX","schema_version":"1.0","canonical_sha256":"7e101b503726dd962ce069a68eaa89d02a6a6f2d5f85c6b4f89531dac14b3d59","source":{"kind":"arxiv","id":"1905.10447","version":1},"attestation_state":"computed","paper":{"title":"Regula Sub-rosa: Latent Backdoor Attacks on Deep Neural Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Ben Y. Zhao, Haitao Zheng, Huiying Li, Yuanshun Yao","submitted_at":"2019-05-24T21:15:16Z","abstract_excerpt":"Recent work has proposed the concept of backdoor attacks on deep neural networks (DNNs), where misbehaviors are hidden inside \"normal\" models, only to be triggered by very specific inputs. In practice, however, these attacks are difficult to perform and highly constrained by sharing of models through transfer learning. Adversaries have a small window during which they must compromise the student model before it is deployed. In this paper, we describe a significantly more powerful variant of the backdoor attack, latent backdoors, where hidden rules can be embedded in a single \"Teacher\" model, a"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1905.10447","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-24T21:15:16Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"490a58a57c29786b0ec2b06c41f6ebe846934a5935f957e0f0934a4e18a35166","abstract_canon_sha256":"274d527faeaeb7eb054f15a8d216915c162a17aeea80c56d75c4a94bbd3a2da9"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:45:08.498059Z","signature_b64":"sMmO74Hg22/5iemxW0S/MNwXFEb3E3STL8n3V2vhbkmgvvuFZeqlcfTUYXywMAlQIBOtDYSwxSeWpBi6sNhPBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"7e101b503726dd962ce069a68eaa89d02a6a6f2d5f85c6b4f89531dac14b3d59","last_reissued_at":"2026-05-17T23:45:08.497511Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:45:08.497511Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Regula Sub-rosa: Latent Backdoor Attacks on Deep Neural Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Ben Y. Zhao, Haitao Zheng, Huiying Li, Yuanshun Yao","submitted_at":"2019-05-24T21:15:16Z","abstract_excerpt":"Recent work has proposed the concept of backdoor attacks on deep neural networks (DNNs), where misbehaviors are hidden inside \"normal\" models, only to be triggered by very specific inputs. In practice, however, these attacks are difficult to perform and highly constrained by sharing of models through transfer learning. Adversaries have a small window during which they must compromise the student model before it is deployed. In this paper, we describe a significantly more powerful variant of the backdoor attack, latent backdoors, where hidden rules can be embedded in a single \"Teacher\" model, a"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.10447","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1905.10447","created_at":"2026-05-17T23:45:08.497606+00:00"},{"alias_kind":"arxiv_version","alias_value":"1905.10447v1","created_at":"2026-05-17T23:45:08.497606+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.10447","created_at":"2026-05-17T23:45:08.497606+00:00"},{"alias_kind":"pith_short_12","alias_value":"PYIBWUBXE3OZ","created_at":"2026-05-18T12:33:24.271573+00:00"},{"alias_kind":"pith_short_16","alias_value":"PYIBWUBXE3OZMLHA","created_at":"2026-05-18T12:33:24.271573+00:00"},{"alias_kind":"pith_short_8","alias_value":"PYIBWUBX","created_at":"2026-05-18T12:33:24.271573+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/PYIBWUBXE3OZMLHANGTI5KUJ2A","json":"https://pith.science/pith/PYIBWUBXE3OZMLHANGTI5KUJ2A.json","graph_json":"https://pith.science/api/pith-number/PYIBWUBXE3OZMLHANGTI5KUJ2A/graph.json","events_json":"https://pith.science/api/pith-number/PYIBWUBXE3OZMLHANGTI5KUJ2A/events.json","paper":"https://pith.science/paper/PYIBWUBX"},"agent_actions":{"view_html":"https://pith.science/pith/PYIBWUBXE3OZMLHANGTI5KUJ2A","download_json":"https://pith.science/pith/PYIBWUBXE3OZMLHANGTI5KUJ2A.json","view_paper":"https://pith.science/paper/PYIBWUBX","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1905.10447&json=true","fetch_graph":"https://pith.science/api/pith-number/PYIBWUBXE3OZMLHANGTI5KUJ2A/graph.json","fetch_events":"https://pith.science/api/pith-number/PYIBWUBXE3OZMLHANGTI5KUJ2A/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/PYIBWUBXE3OZMLHANGTI5KUJ2A/action/timestamp_anchor","attest_storage":"https://pith.science/pith/PYIBWUBXE3OZMLHANGTI5KUJ2A/action/storage_attestation","attest_author":"https://pith.science/pith/PYIBWUBXE3OZMLHANGTI5KUJ2A/action/author_attestation","sign_citation":"https://pith.science/pith/PYIBWUBXE3OZMLHANGTI5KUJ2A/action/citation_signature","submit_replication":"https://pith.science/pith/PYIBWUBXE3OZMLHANGTI5KUJ2A/action/replication_record"}},"created_at":"2026-05-17T23:45:08.497606+00:00","updated_at":"2026-05-17T23:45:08.497606+00:00"}