{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:RKSENSL356S7BTAHLQCQHWTSVD","short_pith_number":"pith:RKSENSL3","schema_version":"1.0","canonical_sha256":"8aa446c97befa5f0cc075c0503da72a8dfe140a86c4075c8c03e9595428d26c6","source":{"kind":"arxiv","id":"2403.03593","version":3},"attestation_state":"computed","paper":{"title":"Do You Trust Your Model? Emerging Malware Threats in the Deep Learning Ecosystem","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Briland Hitaj, Dorjan Hitaj, Fabio De Gaspari, Fernando Perez-Cruz, Giulio Pagnotta, Luigi V. Mancini, Sediola Ruko","submitted_at":"2024-03-06T10:27:08Z","abstract_excerpt":"Training high-quality deep learning models is a challenging task due to computational and technical requirements. A growing number of individuals, institutions, and companies increasingly rely on pre-trained, third-party models made available in public repositories. These models are often used directly or integrated in product pipelines with no particular precautions, since they are effectively just data in tensor form and considered safe. In this paper, we raise awareness of a new machine learning supply chain threat targeting neural networks. We introduce MaleficNet 2.0, a novel technique to"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2403.03593","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2024-03-06T10:27:08Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"4683dc06f125d6634ed6ecdbc43c9aa78de67282966b41a3a164c3860d7ef76d","abstract_canon_sha256":"83d29b01649121d4014d5c7d1e675b3c3564c362b381d6f5aef08ff6ff9eb5a6"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:31:38.145977Z","signature_b64":"Xa6K5lFA0hlqf0312SEGpSf2bp7OF+B8jstMGLaO5LofI8OaVUpCN7psTwwapnYqKSj3hkK2R/LzwW5t7uiKBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"8aa446c97befa5f0cc075c0503da72a8dfe140a86c4075c8c03e9595428d26c6","last_reissued_at":"2026-07-05T11:31:38.145497Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:31:38.145497Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Do You Trust Your Model? Emerging Malware Threats in the Deep Learning Ecosystem","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Briland Hitaj, Dorjan Hitaj, Fabio De Gaspari, Fernando Perez-Cruz, Giulio Pagnotta, Luigi V. Mancini, Sediola Ruko","submitted_at":"2024-03-06T10:27:08Z","abstract_excerpt":"Training high-quality deep learning models is a challenging task due to computational and technical requirements. A growing number of individuals, institutions, and companies increasingly rely on pre-trained, third-party models made available in public repositories. These models are often used directly or integrated in product pipelines with no particular precautions, since they are effectively just data in tensor form and considered safe. In this paper, we raise awareness of a new machine learning supply chain threat targeting neural networks. We introduce MaleficNet 2.0, a novel technique to"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2403.03593","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2403.03593/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2403.03593","created_at":"2026-07-05T11:31:38.145557+00:00"},{"alias_kind":"arxiv_version","alias_value":"2403.03593v3","created_at":"2026-07-05T11:31:38.145557+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2403.03593","created_at":"2026-07-05T11:31:38.145557+00:00"},{"alias_kind":"pith_short_12","alias_value":"RKSENSL356S7","created_at":"2026-07-05T11:31:38.145557+00:00"},{"alias_kind":"pith_short_16","alias_value":"RKSENSL356S7BTAH","created_at":"2026-07-05T11:31:38.145557+00:00"},{"alias_kind":"pith_short_8","alias_value":"RKSENSL3","created_at":"2026-07-05T11:31:38.145557+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2508.19774","citing_title":"The Art of Hide and Seek: Making Pickle-Based Model Supply Chain Poisoning Stealthy Again","ref_index":47,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/RKSENSL356S7BTAHLQCQHWTSVD","json":"https://pith.science/pith/RKSENSL356S7BTAHLQCQHWTSVD.json","graph_json":"https://pith.science/api/pith-number/RKSENSL356S7BTAHLQCQHWTSVD/graph.json","events_json":"https://pith.science/api/pith-number/RKSENSL356S7BTAHLQCQHWTSVD/events.json","paper":"https://pith.science/paper/RKSENSL3"},"agent_actions":{"view_html":"https://pith.science/pith/RKSENSL356S7BTAHLQCQHWTSVD","download_json":"https://pith.science/pith/RKSENSL356S7BTAHLQCQHWTSVD.json","view_paper":"https://pith.science/paper/RKSENSL3","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2403.03593&json=true","fetch_graph":"https://pith.science/api/pith-number/RKSENSL356S7BTAHLQCQHWTSVD/graph.json","fetch_events":"https://pith.science/api/pith-number/RKSENSL356S7BTAHLQCQHWTSVD/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/RKSENSL356S7BTAHLQCQHWTSVD/action/timestamp_anchor","attest_storage":"https://pith.science/pith/RKSENSL356S7BTAHLQCQHWTSVD/action/storage_attestation","attest_author":"https://pith.science/pith/RKSENSL356S7BTAHLQCQHWTSVD/action/author_attestation","sign_citation":"https://pith.science/pith/RKSENSL356S7BTAHLQCQHWTSVD/action/citation_signature","submit_replication":"https://pith.science/pith/RKSENSL356S7BTAHLQCQHWTSVD/action/replication_record"}},"created_at":"2026-07-05T11:31:38.145557+00:00","updated_at":"2026-07-05T11:31:38.145557+00:00"}