Pith. sign in
Pith Number

pith:Q32VHWDU

pith:2017:Q32VHWDUNWUVJG4NGXMOSJ6K2M
not attested not anchored not stored refs resolved

BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain

Brendan Dolan-Gavitt, Siddharth Garg, Tianyu Gu

An adversary can train a neural network that performs well on normal inputs but activates malicious behavior on specific attacker-chosen triggers.

arxiv:1708.06733 v2 · 2017-08-22 · cs.CR · cs.LG

Add to your LaTeX paper
\usepackage{pith}
\pithnumber{Q32VHWDUNWUVJG4NGXMOSJ6K2M}

Prints a linked badge after your title and injects PDF metadata. Compiles on arXiv. Learn more · Embed verified badge

Record completeness

1 Bitcoin timestamp
2 Internet Archive
3 Author claim open · sign in to claim
4 Citations open
5 Replications open
Portable graph bundle live · download bundle · merged state
The bundle contains the canonical record plus signed events. A mirror can host it anywhere and recompute the same current state with the deterministic merge algorithm.

Claims

C1strongest claim

an adversary can create a maliciously trained network (a backdoored neural network, or a BadNet) that has state-of-the-art performance on the user's training and validation samples, but behaves badly on specific attacker-chosen inputs.

C2weakest assumption

The attacker must have sufficient control over the training process or data to embed the backdoor without detection, as assumed in the outsourced training scenario described.

C3one line summary

Adversaries can create backdoored neural networks during outsourced training that maintain high accuracy on normal data but misbehave on attacker-chosen triggers.

References

53 extracted · 53 resolved · 2 Pith anchors

[1] ImageNet large scale visual recognition competition 2012
[2] Speech recognition with deep recurrent neural networks 2013
[3] Multilingual Distributed Representations without Word Alignment 2014 · arXiv:1312.6173
[4] Neural machine translation by jointly learning to align and translate 2014
[5] Playing atari with deep reinforce- ment learning 2013

Formal links

2 machine-checked theorem links

Cited by

90 papers in Pith

Receipt and verification
First computed 2026-07-04T23:27:34.718401Z
Builder pith-number-builder-2026-05-17-v1
Signature Pith Ed25519 (pith-v1-2026-05) · public key
Schema pith-number/v1.0

Canonical hash

86f553d8746da9549b8d35d8e927cad32a1b38e24e428e9d64899184a0e3c15a

Aliases

arxiv: 1708.06733 · arxiv_version: 1708.06733v2 · doi: 10.48550/arxiv.1708.06733 · pith_short_12: Q32VHWDUNWUV · pith_short_16: Q32VHWDUNWUVJG4N · pith_short_8: Q32VHWDU
Agent API
Verify this Pith Number yourself
curl -sH 'Accept: application/ld+json' https://pith.science/pith/Q32VHWDUNWUVJG4NGXMOSJ6K2M \
  | jq -c '.canonical_record' \
  | python3 -c "import sys,json,hashlib; b=json.dumps(json.loads(sys.stdin.read()), sort_keys=True, separators=(',',':'), ensure_ascii=False).encode(); print(hashlib.sha256(b).hexdigest())"
# expect: 86f553d8746da9549b8d35d8e927cad32a1b38e24e428e9d64899184a0e3c15a
Canonical record JSON
{
  "metadata": {
    "abstract_canon_sha256": "43366791bf313c93af4a47b23d2f9edc58e1862c9386c98a090808dcd58ef384",
    "cross_cats_sorted": [
      "cs.LG"
    ],
    "license": "http://arxiv.org/licenses/nonexclusive-distrib/1.0/",
    "primary_cat": "cs.CR",
    "submitted_at": "2017-08-22T17:31:54Z",
    "title_canon_sha256": "2d6d46e9e11448172b302ae907d89d20653060d9233ae659a7ec1537a22532fb"
  },
  "schema_version": "1.0",
  "source": {
    "id": "1708.06733",
    "kind": "arxiv",
    "version": 2
  }
}