{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:QM6SMCNCO3LA5QT3HHDIDDDQR4","short_pith_number":"pith:QM6SMCNC","schema_version":"1.0","canonical_sha256":"833d2609a276d60ec27b39c6818c708f28fa695f5ee0bbf90e421d1b7bad40a4","source":{"kind":"arxiv","id":"2312.00050","version":2},"attestation_state":"computed","paper":{"title":"Elijah: Eliminating Backdoors Injected in Diffusion Models via Distribution Shift","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Guangyu Shen, Guanhong Tao, Kaiyuan Zhang, Pin-Yu Chen, Qiuling Xu, Shengwei An, Sheng-Yen Chou, Shiqing Ma, Siyuan Cheng, Tsung-Yi Ho, Xiangyu Zhang","submitted_at":"2023-11-27T23:58:56Z","abstract_excerpt":"Diffusion models (DM) have become state-of-the-art generative models because of their capability to generate high-quality images from noises without adversarial training. However, they are vulnerable to backdoor attacks as reported by recent studies. When a data input (e.g., some Gaussian noise) is stamped with a trigger (e.g., a white patch), the backdoored model always generates the target image (e.g., an improper photo). However, effective defense strategies to mitigate backdoors from DMs are underexplored. To bridge this gap, we propose the first backdoor detection and removal framework fo"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2312.00050","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2023-11-27T23:58:56Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"c818ea3e2d754820a3022919b9bd36db38b852d4429281b02bdd92e74b4b6737","abstract_canon_sha256":"8f1b068b8dde705755fab436a88453c772feaeb22a6a0e3fb3705340fff0a316"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:41:00.635924Z","signature_b64":"2mjOJej0Sh6Ul5jW8I4VSHwMhQT3GRDw5jwlK99+ZwjhrTkCHklKECB6h/EXbI0wU37ily4S56u415w0N9FmDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"833d2609a276d60ec27b39c6818c708f28fa695f5ee0bbf90e421d1b7bad40a4","last_reissued_at":"2026-07-05T07:41:00.635431Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:41:00.635431Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Elijah: Eliminating Backdoors Injected in Diffusion Models via Distribution Shift","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Guangyu Shen, Guanhong Tao, Kaiyuan Zhang, Pin-Yu Chen, Qiuling Xu, Shengwei An, Sheng-Yen Chou, Shiqing Ma, Siyuan Cheng, Tsung-Yi Ho, Xiangyu Zhang","submitted_at":"2023-11-27T23:58:56Z","abstract_excerpt":"Diffusion models (DM) have become state-of-the-art generative models because of their capability to generate high-quality images from noises without adversarial training. However, they are vulnerable to backdoor attacks as reported by recent studies. When a data input (e.g., some Gaussian noise) is stamped with a trigger (e.g., a white patch), the backdoored model always generates the target image (e.g., an improper photo). However, effective defense strategies to mitigate backdoors from DMs are underexplored. To bridge this gap, we propose the first backdoor detection and removal framework fo"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2312.00050","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2312.00050/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2312.00050","created_at":"2026-07-05T07:41:00.635497+00:00"},{"alias_kind":"arxiv_version","alias_value":"2312.00050v2","created_at":"2026-07-05T07:41:00.635497+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2312.00050","created_at":"2026-07-05T07:41:00.635497+00:00"},{"alias_kind":"pith_short_12","alias_value":"QM6SMCNCO3LA","created_at":"2026-07-05T07:41:00.635497+00:00"},{"alias_kind":"pith_short_16","alias_value":"QM6SMCNCO3LA5QT3","created_at":"2026-07-05T07:41:00.635497+00:00"},{"alias_kind":"pith_short_8","alias_value":"QM6SMCNC","created_at":"2026-07-05T07:41:00.635497+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2412.16512","citing_title":"TrojFlow: Flow Models are Natural Targets for Trojan Attacks","ref_index":19,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/QM6SMCNCO3LA5QT3HHDIDDDQR4","json":"https://pith.science/pith/QM6SMCNCO3LA5QT3HHDIDDDQR4.json","graph_json":"https://pith.science/api/pith-number/QM6SMCNCO3LA5QT3HHDIDDDQR4/graph.json","events_json":"https://pith.science/api/pith-number/QM6SMCNCO3LA5QT3HHDIDDDQR4/events.json","paper":"https://pith.science/paper/QM6SMCNC"},"agent_actions":{"view_html":"https://pith.science/pith/QM6SMCNCO3LA5QT3HHDIDDDQR4","download_json":"https://pith.science/pith/QM6SMCNCO3LA5QT3HHDIDDDQR4.json","view_paper":"https://pith.science/paper/QM6SMCNC","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2312.00050&json=true","fetch_graph":"https://pith.science/api/pith-number/QM6SMCNCO3LA5QT3HHDIDDDQR4/graph.json","fetch_events":"https://pith.science/api/pith-number/QM6SMCNCO3LA5QT3HHDIDDDQR4/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/QM6SMCNCO3LA5QT3HHDIDDDQR4/action/timestamp_anchor","attest_storage":"https://pith.science/pith/QM6SMCNCO3LA5QT3HHDIDDDQR4/action/storage_attestation","attest_author":"https://pith.science/pith/QM6SMCNCO3LA5QT3HHDIDDDQR4/action/author_attestation","sign_citation":"https://pith.science/pith/QM6SMCNCO3LA5QT3HHDIDDDQR4/action/citation_signature","submit_replication":"https://pith.science/pith/QM6SMCNCO3LA5QT3HHDIDDDQR4/action/replication_record"}},"created_at":"2026-07-05T07:41:00.635497+00:00","updated_at":"2026-07-05T07:41:00.635497+00:00"}