{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:QR2H4IJOPKBLFJ4EZWN7MZZWOQ","short_pith_number":"pith:QR2H4IJO","schema_version":"1.0","canonical_sha256":"84747e212e7a82b2a784cd9bf6673674055fca76750971ad57dae08ce1e862f0","source":{"kind":"arxiv","id":"2104.02361","version":2},"attestation_state":"computed","paper":{"title":"Backdoor Attack in the Physical World","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CV"],"primary_cat":"cs.CR","authors_text":"Shu-Tao Xia, Tongqing Zhai, Yiming Li, Yong Jiang, ZhiFeng Li","submitted_at":"2021-04-06T08:37:33Z","abstract_excerpt":"Backdoor attack intends to inject hidden backdoor into the deep neural networks (DNNs), such that the prediction of infected models will be maliciously changed if the hidden backdoor is activated by the attacker-defined trigger. Currently, most existing backdoor attacks adopted the setting of static trigger, $i.e.,$ triggers across the training and testing images follow the same appearance and are located in the same area. In this paper, we revisit this attack paradigm by analyzing trigger characteristics. We demonstrate that this attack paradigm is vulnerable when the trigger in testing image"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2104.02361","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2021-04-06T08:37:33Z","cross_cats_sorted":["cs.AI","cs.CV"],"title_canon_sha256":"ccf67822789b40f469dde8f7b92dd31a3a7a7613fe59859e7361a27b72ebb144","abstract_canon_sha256":"6c6ef778f1898bb0ef9e7ebf430084b98a6263fd3632c15788ab22f8211fcb0a"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T02:34:48.443658Z","signature_b64":"/LtSfe2YLRe6fAu9UQAF2hFdNBd6SOStL4QEotgmhIu3KZMLfA14OoUZ+JX/q9xFzvbO1VFY45xhMlTKW+YjBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"84747e212e7a82b2a784cd9bf6673674055fca76750971ad57dae08ce1e862f0","last_reissued_at":"2026-07-05T02:34:48.443207Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T02:34:48.443207Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Backdoor Attack in the Physical World","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CV"],"primary_cat":"cs.CR","authors_text":"Shu-Tao Xia, Tongqing Zhai, Yiming Li, Yong Jiang, ZhiFeng Li","submitted_at":"2021-04-06T08:37:33Z","abstract_excerpt":"Backdoor attack intends to inject hidden backdoor into the deep neural networks (DNNs), such that the prediction of infected models will be maliciously changed if the hidden backdoor is activated by the attacker-defined trigger. Currently, most existing backdoor attacks adopted the setting of static trigger, $i.e.,$ triggers across the training and testing images follow the same appearance and are located in the same area. In this paper, we revisit this attack paradigm by analyzing trigger characteristics. We demonstrate that this attack paradigm is vulnerable when the trigger in testing image"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2104.02361","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2104.02361/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2104.02361","created_at":"2026-07-05T02:34:48.443262+00:00"},{"alias_kind":"arxiv_version","alias_value":"2104.02361v2","created_at":"2026-07-05T02:34:48.443262+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2104.02361","created_at":"2026-07-05T02:34:48.443262+00:00"},{"alias_kind":"pith_short_12","alias_value":"QR2H4IJOPKBL","created_at":"2026-07-05T02:34:48.443262+00:00"},{"alias_kind":"pith_short_16","alias_value":"QR2H4IJOPKBLFJ4E","created_at":"2026-07-05T02:34:48.443262+00:00"},{"alias_kind":"pith_short_8","alias_value":"QR2H4IJO","created_at":"2026-07-05T02:34:48.443262+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":4,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.12896","citing_title":"PolicyGuard: Towards Test-time and Step-level Adversary (Backdoor) Defense for Reinforcement Learning Agent","ref_index":27,"is_internal_anchor":false},{"citing_arxiv_id":"2411.12220","citing_title":"DeTrigger: A Gradient-Centric Approach to Backdoor Attack Mitigation in Federated Learning","ref_index":32,"is_internal_anchor":false},{"citing_arxiv_id":"2504.05902","citing_title":"Defending against Backdoor Attacks via Module Switching","ref_index":28,"is_internal_anchor":false},{"citing_arxiv_id":"2605.22481","citing_title":"When Stronger Triggers Backfire: A High-Dimensional Theory of Backdoor Attacks","ref_index":21,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/QR2H4IJOPKBLFJ4EZWN7MZZWOQ","json":"https://pith.science/pith/QR2H4IJOPKBLFJ4EZWN7MZZWOQ.json","graph_json":"https://pith.science/api/pith-number/QR2H4IJOPKBLFJ4EZWN7MZZWOQ/graph.json","events_json":"https://pith.science/api/pith-number/QR2H4IJOPKBLFJ4EZWN7MZZWOQ/events.json","paper":"https://pith.science/paper/QR2H4IJO"},"agent_actions":{"view_html":"https://pith.science/pith/QR2H4IJOPKBLFJ4EZWN7MZZWOQ","download_json":"https://pith.science/pith/QR2H4IJOPKBLFJ4EZWN7MZZWOQ.json","view_paper":"https://pith.science/paper/QR2H4IJO","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2104.02361&json=true","fetch_graph":"https://pith.science/api/pith-number/QR2H4IJOPKBLFJ4EZWN7MZZWOQ/graph.json","fetch_events":"https://pith.science/api/pith-number/QR2H4IJOPKBLFJ4EZWN7MZZWOQ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/QR2H4IJOPKBLFJ4EZWN7MZZWOQ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/QR2H4IJOPKBLFJ4EZWN7MZZWOQ/action/storage_attestation","attest_author":"https://pith.science/pith/QR2H4IJOPKBLFJ4EZWN7MZZWOQ/action/author_attestation","sign_citation":"https://pith.science/pith/QR2H4IJOPKBLFJ4EZWN7MZZWOQ/action/citation_signature","submit_replication":"https://pith.science/pith/QR2H4IJOPKBLFJ4EZWN7MZZWOQ/action/replication_record"}},"created_at":"2026-07-05T02:34:48.443262+00:00","updated_at":"2026-07-05T02:34:48.443262+00:00"}