{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:Q32VHWDUNWUVJG4NGXMOSJ6K2M","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"43366791bf313c93af4a47b23d2f9edc58e1862c9386c98a090808dcd58ef384","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-22T17:31:54Z","title_canon_sha256":"2d6d46e9e11448172b302ae907d89d20653060d9233ae659a7ec1537a22532fb"},"schema_version":"1.0","source":{"id":"1708.06733","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1708.06733","created_at":"2026-07-04T23:27:34Z"},{"alias_kind":"arxiv_version","alias_value":"1708.06733v2","created_at":"2026-07-04T23:27:34Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1708.06733","created_at":"2026-07-04T23:27:34Z"},{"alias_kind":"pith_short_12","alias_value":"Q32VHWDUNWUV","created_at":"2026-07-04T23:27:34Z"},{"alias_kind":"pith_short_16","alias_value":"Q32VHWDUNWUVJG4N","created_at":"2026-07-04T23:27:34Z"},{"alias_kind":"pith_short_8","alias_value":"Q32VHWDU","created_at":"2026-07-04T23:27:34Z"}],"graph_snapshots":[{"event_id":"sha256:b9a6a2f7e6229d18384d5e3c5f5375e248b7765c47a285ceece13a866a8e7c58","target":"graph","created_at":"2026-07-04T23:27:34Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"an adversary can create a maliciously trained network (a backdoored neural network, or a BadNet) that has state-of-the-art performance on the user's training and validation samples, but behaves badly on specific attacker-chosen inputs."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"The attacker must have sufficient control over the training process or data to embed the backdoor without detection, as assumed in the outsourced training scenario described."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"Adversaries can create backdoored neural networks during outsourced training that maintain high accuracy on normal data but misbehave on attacker-chosen triggers."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"An adversary can train a neural network that performs well on normal inputs but activates malicious behavior on specific attacker-chosen triggers."}],"snapshot_sha256":"e896561e719309084f64ac3ef173c9749c07cc00bc2e6a1cebd78740eb4f5c47"},"formal_canon":{"evidence_count":2,"snapshot_sha256":"d39c5a97b7db6b95818774b79c704dc28196d6416f75ba25293577e5f431ef1c"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/1708.06733/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Deep learning-based techniques have achieved state-of-the-art performance on a wide variety of recognition and classification tasks. However, these networks are typically computationally expensive to train, requiring weeks of computation on many GPUs; as a result, many users outsource the training procedure to the cloud or rely on pre-trained models that are then fine-tuned for a specific task. In this paper we show that outsourced training introduces new security risks: an adversary can create a maliciously trained network (a backdoored neural network, or a \\emph{BadNet}) that has state-of-th","authors_text":"Brendan Dolan-Gavitt, Siddharth Garg, Tianyu Gu","cross_cats":["cs.LG"],"headline":"An adversary can train a neural network that performs well on normal inputs but activates malicious behavior on specific attacker-chosen triggers.","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-22T17:31:54Z","title":"BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain"},"references":{"count":53,"internal_anchors":2,"resolved_work":53,"sample":[{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":1,"title":"ImageNet large scale visual recognition competition","work_id":"a84090cc-dd54-4616-a1ac-5460cf5ed05a","year":2012},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":2,"title":"Speech recognition with deep recurrent neural networks","work_id":"f888660f-176b-43d2-be2c-a18a573fcaa3","year":2013},{"cited_arxiv_id":"1312.6173","doi":"","is_internal_anchor":true,"ref_index":3,"title":"Multilingual Distributed Representations without Word Alignment","work_id":"81a1f82b-9f78-4d94-89ce-baaeb1d57280","year":2014},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":4,"title":"Neural machine translation by jointly learning to align and translate","work_id":"d804f636-e3d2-45e2-babd-d5f22b966c5a","year":2014},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":5,"title":"Playing atari with deep reinforce- ment learning","work_id":"01aa905f-959d-482a-ada6-cc63625b754d","year":2013}],"snapshot_sha256":"5f505c2a2402a095c736de022cee50a733322fa277a0165431962bf48c801781"},"source":{"id":"1708.06733","kind":"arxiv","version":2},"verdict":{"created_at":"2026-05-12T23:02:56.787401Z","id":"d8b14d67-a317-4c1a-91e1-0035e41b878b","model_set":{"reader":"grok-4.3"},"one_line_summary":"Adversaries can create backdoored neural networks during outsourced training that maintain high accuracy on normal data but misbehave on attacker-chosen triggers.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"An adversary can train a neural network that performs well on normal inputs but activates malicious behavior on specific attacker-chosen triggers.","strongest_claim":"an adversary can create a maliciously trained network (a backdoored neural network, or a BadNet) that has state-of-the-art performance on the user's training and validation samples, but behaves badly on specific attacker-chosen inputs.","weakest_assumption":"The attacker must have sufficient control over the training process or data to embed the backdoor without detection, as assumed in the outsourced training scenario described."}},"verdict_id":"d8b14d67-a317-4c1a-91e1-0035e41b878b"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:0117e3affe935b8819706998556a434d251e7cbeacbb7d5c1f0ee4524a3445a6","target":"record","created_at":"2026-07-04T23:27:34Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"43366791bf313c93af4a47b23d2f9edc58e1862c9386c98a090808dcd58ef384","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-22T17:31:54Z","title_canon_sha256":"2d6d46e9e11448172b302ae907d89d20653060d9233ae659a7ec1537a22532fb"},"schema_version":"1.0","source":{"id":"1708.06733","kind":"arxiv","version":2}},"canonical_sha256":"86f553d8746da9549b8d35d8e927cad32a1b38e24e428e9d64899184a0e3c15a","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"86f553d8746da9549b8d35d8e927cad32a1b38e24e428e9d64899184a0e3c15a","first_computed_at":"2026-07-04T23:27:34.718401Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-04T23:27:34.718401Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"18NHr9xSO32SzRsylramFMFA4CvOAQlc/u5KwKHAKsmkLVGJWm2WncVsIoYAYXQ//AWyuGo5lnCiEFmdwucRDg==","signature_status":"signed_v1","signed_at":"2026-07-04T23:27:34.718906Z","signed_message":"canonical_sha256_bytes"},"source_id":"1708.06733","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:0117e3affe935b8819706998556a434d251e7cbeacbb7d5c1f0ee4524a3445a6","sha256:b9a6a2f7e6229d18384d5e3c5f5375e248b7765c47a285ceece13a866a8e7c58"],"state_sha256":"19fabebafe1391451ac50abf4b15462f2a03dcd09633b51a9c289813baf1de87"}