{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2017:Q32VHWDUNWUVJG4NGXMOSJ6K2M","short_pith_number":"pith:Q32VHWDU","schema_version":"1.0","canonical_sha256":"86f553d8746da9549b8d35d8e927cad32a1b38e24e428e9d64899184a0e3c15a","source":{"kind":"arxiv","id":"1708.06733","version":2},"attestation_state":"computed","paper":{"title":"BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"An adversary can train a neural network that performs well on normal inputs but activates malicious behavior on specific attacker-chosen triggers.","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Brendan Dolan-Gavitt, Siddharth Garg, Tianyu Gu","submitted_at":"2017-08-22T17:31:54Z","abstract_excerpt":"Deep learning-based techniques have achieved state-of-the-art performance on a wide variety of recognition and classification tasks. However, these networks are typically computationally expensive to train, requiring weeks of computation on many GPUs; as a result, many users outsource the training procedure to the cloud or rely on pre-trained models that are then fine-tuned for a specific task. In this paper we show that outsourced training introduces new security risks: an adversary can create a maliciously trained network (a backdoored neural network, or a \\emph{BadNet}) that has state-of-th"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":true,"formal_links_present":true},"canonical_record":{"source":{"id":"1708.06733","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-22T17:31:54Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"2d6d46e9e11448172b302ae907d89d20653060d9233ae659a7ec1537a22532fb","abstract_canon_sha256":"43366791bf313c93af4a47b23d2f9edc58e1862c9386c98a090808dcd58ef384"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-04T23:27:34.718906Z","signature_b64":"18NHr9xSO32SzRsylramFMFA4CvOAQlc/u5KwKHAKsmkLVGJWm2WncVsIoYAYXQ//AWyuGo5lnCiEFmdwucRDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"86f553d8746da9549b8d35d8e927cad32a1b38e24e428e9d64899184a0e3c15a","last_reissued_at":"2026-07-04T23:27:34.718401Z","signature_status":"signed_v1","first_computed_at":"2026-07-04T23:27:34.718401Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"An adversary can train a neural network that performs well on normal inputs but activates malicious behavior on specific attacker-chosen triggers.","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Brendan Dolan-Gavitt, Siddharth Garg, Tianyu Gu","submitted_at":"2017-08-22T17:31:54Z","abstract_excerpt":"Deep learning-based techniques have achieved state-of-the-art performance on a wide variety of recognition and classification tasks. However, these networks are typically computationally expensive to train, requiring weeks of computation on many GPUs; as a result, many users outsource the training procedure to the cloud or rely on pre-trained models that are then fine-tuned for a specific task. In this paper we show that outsourced training introduces new security risks: an adversary can create a maliciously trained network (a backdoored neural network, or a \\emph{BadNet}) that has state-of-th"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"an adversary can create a maliciously trained network (a backdoored neural network, or a BadNet) that has state-of-the-art performance on the user's training and validation samples, but behaves badly on specific attacker-chosen inputs.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"The attacker must have sufficient control over the training process or data to embed the backdoor without detection, as assumed in the outsourced training scenario described.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"Adversaries can create backdoored neural networks during outsourced training that maintain high accuracy on normal data but misbehave on attacker-chosen triggers.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"An adversary can train a neural network that performs well on normal inputs but activates malicious behavior on specific attacker-chosen triggers.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"e896561e719309084f64ac3ef173c9749c07cc00bc2e6a1cebd78740eb4f5c47"},"source":{"id":"1708.06733","kind":"arxiv","version":2},"verdict":{"id":"d8b14d67-a317-4c1a-91e1-0035e41b878b","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-12T23:02:56.787401Z","strongest_claim":"an adversary can create a maliciously trained network (a backdoored neural network, or a BadNet) that has state-of-the-art performance on the user's training and validation samples, but behaves badly on specific attacker-chosen inputs.","one_line_summary":"Adversaries can create backdoored neural networks during outsourced training that maintain high accuracy on normal data but misbehave on attacker-chosen triggers.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"The attacker must have sufficient control over the training process or data to embed the backdoor without detection, as assumed in the outsourced training scenario described.","pith_extraction_headline":"An adversary can train a neural network that performs well on normal inputs but activates malicious behavior on specific attacker-chosen triggers."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1708.06733/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":53,"sample":[{"doi":"","year":2012,"title":"ImageNet large scale visual recognition competition","work_id":"a84090cc-dd54-4616-a1ac-5460cf5ed05a","ref_index":1,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2013,"title":"Speech recognition with deep recurrent neural networks","work_id":"f888660f-176b-43d2-be2c-a18a573fcaa3","ref_index":2,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2014,"title":"Multilingual Distributed Representations without Word Alignment","work_id":"81a1f82b-9f78-4d94-89ce-baaeb1d57280","ref_index":3,"cited_arxiv_id":"1312.6173","is_internal_anchor":true},{"doi":"","year":2014,"title":"Neural machine translation by jointly learning to align and translate","work_id":"d804f636-e3d2-45e2-babd-d5f22b966c5a","ref_index":4,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2013,"title":"Playing atari with deep reinforce- ment learning","work_id":"01aa905f-959d-482a-ada6-cc63625b754d","ref_index":5,"cited_arxiv_id":"","is_internal_anchor":false}],"resolved_work":53,"snapshot_sha256":"5f505c2a2402a095c736de022cee50a733322fa277a0165431962bf48c801781","internal_anchors":2},"formal_canon":{"evidence_count":2,"snapshot_sha256":"d39c5a97b7db6b95818774b79c704dc28196d6416f75ba25293577e5f431ef1c"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1708.06733","created_at":"2026-07-04T23:27:34.718463+00:00"},{"alias_kind":"arxiv_version","alias_value":"1708.06733v2","created_at":"2026-07-04T23:27:34.718463+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1708.06733","created_at":"2026-07-04T23:27:34.718463+00:00"},{"alias_kind":"pith_short_12","alias_value":"Q32VHWDUNWUV","created_at":"2026-07-04T23:27:34.718463+00:00"},{"alias_kind":"pith_short_16","alias_value":"Q32VHWDUNWUVJG4N","created_at":"2026-07-04T23:27:34.718463+00:00"},{"alias_kind":"pith_short_8","alias_value":"Q32VHWDU","created_at":"2026-07-04T23:27:34.718463+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":90,"internal_anchor_count":90,"sample":[{"citing_arxiv_id":"2607.06643","citing_title":"The Power of Backdoor Absorption in Community Training","ref_index":6,"is_internal_anchor":true},{"citing_arxiv_id":"2607.07907","citing_title":"Multimodal Unlearning Across Vision, Language, Video, and Audio: Survey of Methods, Datasets, and Benchmarks","ref_index":283,"is_internal_anchor":true},{"citing_arxiv_id":"2606.23362","citing_title":"TooBad: Backdoor Diffusion Models with Ultra-Low Poison Rate and Imperceptible Trigger","ref_index":12,"is_internal_anchor":true},{"citing_arxiv_id":"2606.23361","citing_title":"Rethinking Molecular Graph Backdoors under Chemistry-aware Admission","ref_index":22,"is_internal_anchor":true},{"citing_arxiv_id":"2606.22837","citing_title":"CLIP-guided Diffusion Model for Backdoor Generation in Sensor-based Human Activity Recognition","ref_index":14,"is_internal_anchor":true},{"citing_arxiv_id":"2606.21846","citing_title":"Mind the Intention: Task-Aware Backdoor Attacks for Forecast-Driven Distribution Network Operations","ref_index":14,"is_internal_anchor":true},{"citing_arxiv_id":"2606.20553","citing_title":"From Efficiency to Leakage -- Privacy Backdoor in Federated Language Model Fine-Tuning","ref_index":23,"is_internal_anchor":true},{"citing_arxiv_id":"2606.20254","citing_title":"Quantization as a Malicious Task: Removing Quantization-Conditioned Backdoors via Task Arithmetic","ref_index":13,"is_internal_anchor":true},{"citing_arxiv_id":"2606.17815","citing_title":"Beyond Native Success: Auditing Deployment-Interface Exposure of CLIP Backdoors","ref_index":1,"is_internal_anchor":true},{"citing_arxiv_id":"2606.12655","citing_title":"Amnesia: A Stealthy Replay Attack on Continual Learning Dreams","ref_index":11,"is_internal_anchor":true},{"citing_arxiv_id":"2606.12586","citing_title":"Beyond Attack Success Rate: Examining Trigger Leakage in Vision-Language Agentic Systems","ref_index":5,"is_internal_anchor":true},{"citing_arxiv_id":"2607.01702","citing_title":"Pmeta-TLA: Backdoor Attacks for Speech Classification Models via Meta-Learning with Timbre Leakage Attack","ref_index":26,"is_internal_anchor":true},{"citing_arxiv_id":"2606.07963","citing_title":"Shared Latent Structures Enable Unified Backdoor Detection and Mitigation in LLMs","ref_index":20,"is_internal_anchor":true},{"citing_arxiv_id":"2606.06890","citing_title":"Diagnosing Visual Ignorance in Vision-Language Models","ref_index":27,"is_internal_anchor":true},{"citing_arxiv_id":"2606.02995","citing_title":"Patcher: Post-Hoc Patching of Backdoored Large Language Models","ref_index":16,"is_internal_anchor":true},{"citing_arxiv_id":"2605.31246","citing_title":"BadBone: Backdoor Attacks Against Backbone Models in Visual Prompt Learning","ref_index":20,"is_internal_anchor":true},{"citing_arxiv_id":"2605.06846","citing_title":"Narrow Secret Loyalty Dodges Black-Box Audits","ref_index":14,"is_internal_anchor":true},{"citing_arxiv_id":"2605.18646","citing_title":"Language-Switching Triggers Take a Latent Detour Through Language Models","ref_index":1,"is_internal_anchor":true},{"citing_arxiv_id":"2606.02609","citing_title":"Building Better Activation Oracles","ref_index":51,"is_internal_anchor":true},{"citing_arxiv_id":"2605.25073","citing_title":"Security in the Fine-Tuning Lifecycle of Large Language Models: Threats, Defenses,Evaluation, and Future Directions","ref_index":20,"is_internal_anchor":true},{"citing_arxiv_id":"2605.27148","citing_title":"Landseer: Exploring the Machine Learning Defense Landscape","ref_index":37,"is_internal_anchor":true},{"citing_arxiv_id":"2605.27674","citing_title":"Backdoor Attacks on Fault Detection and Localization in Cyber-Physical Systems","ref_index":26,"is_internal_anchor":true},{"citing_arxiv_id":"2605.27809","citing_title":"Density-aware Sample-specific Attack","ref_index":7,"is_internal_anchor":true},{"citing_arxiv_id":"2605.28890","citing_title":"Echoes within the Reasoning: Stealthy and Effective Watermarking via Chain of Thought","ref_index":16,"is_internal_anchor":true},{"citing_arxiv_id":"2606.00654","citing_title":"The Invitation Trap: Proactive Availability Backdoor in LLMs via Conversational Induction","ref_index":1,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":2,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/Q32VHWDUNWUVJG4NGXMOSJ6K2M","json":"https://pith.science/pith/Q32VHWDUNWUVJG4NGXMOSJ6K2M.json","graph_json":"https://pith.science/api/pith-number/Q32VHWDUNWUVJG4NGXMOSJ6K2M/graph.json","events_json":"https://pith.science/api/pith-number/Q32VHWDUNWUVJG4NGXMOSJ6K2M/events.json","paper":"https://pith.science/paper/Q32VHWDU"},"agent_actions":{"view_html":"https://pith.science/pith/Q32VHWDUNWUVJG4NGXMOSJ6K2M","download_json":"https://pith.science/pith/Q32VHWDUNWUVJG4NGXMOSJ6K2M.json","view_paper":"https://pith.science/paper/Q32VHWDU","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1708.06733&json=true","fetch_graph":"https://pith.science/api/pith-number/Q32VHWDUNWUVJG4NGXMOSJ6K2M/graph.json","fetch_events":"https://pith.science/api/pith-number/Q32VHWDUNWUVJG4NGXMOSJ6K2M/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/Q32VHWDUNWUVJG4NGXMOSJ6K2M/action/timestamp_anchor","attest_storage":"https://pith.science/pith/Q32VHWDUNWUVJG4NGXMOSJ6K2M/action/storage_attestation","attest_author":"https://pith.science/pith/Q32VHWDUNWUVJG4NGXMOSJ6K2M/action/author_attestation","sign_citation":"https://pith.science/pith/Q32VHWDUNWUVJG4NGXMOSJ6K2M/action/citation_signature","submit_replication":"https://pith.science/pith/Q32VHWDUNWUVJG4NGXMOSJ6K2M/action/replication_record"}},"created_at":"2026-07-04T23:27:34.718463+00:00","updated_at":"2026-07-04T23:27:34.718463+00:00"}