{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:TN5UVWWUJBTUZOMVL53PQTJWI5","short_pith_number":"pith:TN5UVWWU","canonical_record":{"source":{"id":"1905.12457","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-29T13:44:35Z","cross_cats_sorted":[],"title_canon_sha256":"9e49c15352db6af8f7d64c137d964d3ff5a21bb7755a62c527566cadbaf6009b","abstract_canon_sha256":"a521fcd65702a439620c020dc2822009266b97bb91d01ab2d215aebe99767841"},"schema_version":"1.0"},"canonical_sha256":"9b7b4adad448674cb9955f76f84d3647501e66486a9c2ba2ca23e29dd6d932f1","source":{"kind":"arxiv","id":"1905.12457","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.12457","created_at":"2026-05-17T23:44:18Z"},{"alias_kind":"arxiv_version","alias_value":"1905.12457v2","created_at":"2026-05-17T23:44:18Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.12457","created_at":"2026-05-17T23:44:18Z"},{"alias_kind":"pith_short_12","alias_value":"TN5UVWWUJBTU","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_16","alias_value":"TN5UVWWUJBTUZOMV","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_8","alias_value":"TN5UVWWU","created_at":"2026-05-18T12:33:30Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:TN5UVWWUJBTUZOMVL53PQTJWI5","target":"record","payload":{"canonical_record":{"source":{"id":"1905.12457","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-29T13:44:35Z","cross_cats_sorted":[],"title_canon_sha256":"9e49c15352db6af8f7d64c137d964d3ff5a21bb7755a62c527566cadbaf6009b","abstract_canon_sha256":"a521fcd65702a439620c020dc2822009266b97bb91d01ab2d215aebe99767841"},"schema_version":"1.0"},"canonical_sha256":"9b7b4adad448674cb9955f76f84d3647501e66486a9c2ba2ca23e29dd6d932f1","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:44:18.407411Z","signature_b64":"riUY7vEOMx7ZiHgeubyQIMTNCqZEi9g3VLzWvs3mSqrkMwVkp7wzdZaNXH5HSp+LP7e0lO/t+K+C0SA64XEUAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9b7b4adad448674cb9955f76f84d3647501e66486a9c2ba2ca23e29dd6d932f1","last_reissued_at":"2026-05-17T23:44:18.406868Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:44:18.406868Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1905.12457","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:44:18Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"y+2HbvdFKbCr4YHDn4Qa0VLL4IUb2ygW0EBxm+FWsPKoflaGb2ZSCBYL6seI0UjdQ2hY4qUEVZyw/OVmdBalCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T14:46:26.608110Z"},"content_sha256":"b87d4fa424a4ecf6a140b3babf0de510b293bdb40f8343494c93c7f0ce6cacf7","schema_version":"1.0","event_id":"sha256:b87d4fa424a4ecf6a140b3babf0de510b293bdb40f8343494c93c7f0ce6cacf7"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:TN5UVWWUJBTUZOMVL53PQTJWI5","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"A backdoor attack against LSTM-based text classification systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Chuanshuai Chen, Jiazhu Dai","submitted_at":"2019-05-29T13:44:35Z","abstract_excerpt":"With the widespread use of deep learning system in many applications, the adversary has strong incentive to explore vulnerabilities of deep neural networks and manipulate them. Backdoor attacks against deep neural networks have been reported to be a new type of threat. In this attack, the adversary will inject backdoors into the model and then cause the misbehavior of the model through inputs including backdoor triggers. Existed research mainly focuses on backdoor attacks in image classification based on CNN, little attention has been paid to the backdoor attacks in RNN. In this paper, we impl"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.12457","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:44:18Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"SZc9NvpaFzHnnRrhe4GbbQ7cPm9na9/D5cNooyyemzLDpi1zpctYcTufKub5NvfiHJm1voewMZG1edv5FWOqCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T14:46:26.608759Z"},"content_sha256":"f50aaa285d924e291b36f32e9f6798be539f6ea9e7685c856ff4e5f481fb2647","schema_version":"1.0","event_id":"sha256:f50aaa285d924e291b36f32e9f6798be539f6ea9e7685c856ff4e5f481fb2647"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/TN5UVWWUJBTUZOMVL53PQTJWI5/bundle.json","state_url":"https://pith.science/pith/TN5UVWWUJBTUZOMVL53PQTJWI5/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/TN5UVWWUJBTUZOMVL53PQTJWI5/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-27T14:46:26Z","links":{"resolver":"https://pith.science/pith/TN5UVWWUJBTUZOMVL53PQTJWI5","bundle":"https://pith.science/pith/TN5UVWWUJBTUZOMVL53PQTJWI5/bundle.json","state":"https://pith.science/pith/TN5UVWWUJBTUZOMVL53PQTJWI5/state.json","well_known_bundle":"https://pith.science/.well-known/pith/TN5UVWWUJBTUZOMVL53PQTJWI5/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:TN5UVWWUJBTUZOMVL53PQTJWI5","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"a521fcd65702a439620c020dc2822009266b97bb91d01ab2d215aebe99767841","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-29T13:44:35Z","title_canon_sha256":"9e49c15352db6af8f7d64c137d964d3ff5a21bb7755a62c527566cadbaf6009b"},"schema_version":"1.0","source":{"id":"1905.12457","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.12457","created_at":"2026-05-17T23:44:18Z"},{"alias_kind":"arxiv_version","alias_value":"1905.12457v2","created_at":"2026-05-17T23:44:18Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.12457","created_at":"2026-05-17T23:44:18Z"},{"alias_kind":"pith_short_12","alias_value":"TN5UVWWUJBTU","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_16","alias_value":"TN5UVWWUJBTUZOMV","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_8","alias_value":"TN5UVWWU","created_at":"2026-05-18T12:33:30Z"}],"graph_snapshots":[{"event_id":"sha256:f50aaa285d924e291b36f32e9f6798be539f6ea9e7685c856ff4e5f481fb2647","target":"graph","created_at":"2026-05-17T23:44:18Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"With the widespread use of deep learning system in many applications, the adversary has strong incentive to explore vulnerabilities of deep neural networks and manipulate them. Backdoor attacks against deep neural networks have been reported to be a new type of threat. In this attack, the adversary will inject backdoors into the model and then cause the misbehavior of the model through inputs including backdoor triggers. Existed research mainly focuses on backdoor attacks in image classification based on CNN, little attention has been paid to the backdoor attacks in RNN. In this paper, we impl","authors_text":"Chuanshuai Chen, Jiazhu Dai","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-29T13:44:35Z","title":"A backdoor attack against LSTM-based text classification systems"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.12457","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:b87d4fa424a4ecf6a140b3babf0de510b293bdb40f8343494c93c7f0ce6cacf7","target":"record","created_at":"2026-05-17T23:44:18Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"a521fcd65702a439620c020dc2822009266b97bb91d01ab2d215aebe99767841","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-29T13:44:35Z","title_canon_sha256":"9e49c15352db6af8f7d64c137d964d3ff5a21bb7755a62c527566cadbaf6009b"},"schema_version":"1.0","source":{"id":"1905.12457","kind":"arxiv","version":2}},"canonical_sha256":"9b7b4adad448674cb9955f76f84d3647501e66486a9c2ba2ca23e29dd6d932f1","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"9b7b4adad448674cb9955f76f84d3647501e66486a9c2ba2ca23e29dd6d932f1","first_computed_at":"2026-05-17T23:44:18.406868Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:44:18.406868Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"riUY7vEOMx7ZiHgeubyQIMTNCqZEi9g3VLzWvs3mSqrkMwVkp7wzdZaNXH5HSp+LP7e0lO/t+K+C0SA64XEUAw==","signature_status":"signed_v1","signed_at":"2026-05-17T23:44:18.407411Z","signed_message":"canonical_sha256_bytes"},"source_id":"1905.12457","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:b87d4fa424a4ecf6a140b3babf0de510b293bdb40f8343494c93c7f0ce6cacf7","sha256:f50aaa285d924e291b36f32e9f6798be539f6ea9e7685c856ff4e5f481fb2647"],"state_sha256":"43aa12e27423bf12a34c91f90670230da7c03ff789a36f0cdfdd6b60abd1ad12"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"dkYPRGOVu6Y7nyKIgBFa2KqdIf+ACzhzlVuyd0/fyzeOxz9jYjZwjpSmK21bYqgMAFwJShYlUfxzxqZR55sdDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-27T14:46:26.611371Z","bundle_sha256":"f5fd3423161f1954c0931cf88b4dfc6faff4c4fdb72bf44aab1e7fbf1957a2f4"}}