{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:TOEZEC3UFZFKIICUKPXRPWEOCL","short_pith_number":"pith:TOEZEC3U","schema_version":"1.0","canonical_sha256":"9b89920b742e4aa4205453ef17d88e12ed5b2f3ddc2a6a6d54f8d26bb621ce4e","source":{"kind":"arxiv","id":"2110.14880","version":4},"attestation_state":"computed","paper":{"title":"AEVA: Black-box Backdoor Detection Using Adversarial Extreme Value Analysis","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.LG","authors_text":"Ang Li, Cong Liu, Junfeng Guo","submitted_at":"2021-10-28T04:36:48Z","abstract_excerpt":"Deep neural networks (DNNs) are proved to be vulnerable against backdoor attacks. A backdoor is often embedded in the target DNNs through injecting a backdoor trigger into training examples, which can cause the target DNNs misclassify an input attached with the backdoor trigger. Existing backdoor detection methods often require the access to the original poisoned training data, the parameters of the target DNNs, or the predictive confidence for each given input, which are impractical in many real-world applications, e.g., on-device deployed DNNs. We address the black-box hard-label backdoor de"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2110.14880","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2021-10-28T04:36:48Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"9ca0f7554588c0d87dfea04ebd4d7fe86948d5a4f4fd0ce1bb389e73e61f6bb8","abstract_canon_sha256":"8f7796d712aee367d1ab5a45e3a6490cd9cef21a36cc5e501af08b315b6cc117"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T03:59:53.317460Z","signature_b64":"Y9bys1j5UKDSqmaE+KLfivNfmK1pcUzqQWBma1qJ2F6zv+PZRVCaW7vr+CsU0D1yuw9GO3ODcYrZ+SUknxP2DA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9b89920b742e4aa4205453ef17d88e12ed5b2f3ddc2a6a6d54f8d26bb621ce4e","last_reissued_at":"2026-07-05T03:59:53.317003Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T03:59:53.317003Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"AEVA: Black-box Backdoor Detection Using Adversarial Extreme Value Analysis","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.LG","authors_text":"Ang Li, Cong Liu, Junfeng Guo","submitted_at":"2021-10-28T04:36:48Z","abstract_excerpt":"Deep neural networks (DNNs) are proved to be vulnerable against backdoor attacks. A backdoor is often embedded in the target DNNs through injecting a backdoor trigger into training examples, which can cause the target DNNs misclassify an input attached with the backdoor trigger. Existing backdoor detection methods often require the access to the original poisoned training data, the parameters of the target DNNs, or the predictive confidence for each given input, which are impractical in many real-world applications, e.g., on-device deployed DNNs. We address the black-box hard-label backdoor de"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2110.14880","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2110.14880/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2110.14880","created_at":"2026-07-05T03:59:53.317059+00:00"},{"alias_kind":"arxiv_version","alias_value":"2110.14880v4","created_at":"2026-07-05T03:59:53.317059+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2110.14880","created_at":"2026-07-05T03:59:53.317059+00:00"},{"alias_kind":"pith_short_12","alias_value":"TOEZEC3UFZFK","created_at":"2026-07-05T03:59:53.317059+00:00"},{"alias_kind":"pith_short_16","alias_value":"TOEZEC3UFZFKIICU","created_at":"2026-07-05T03:59:53.317059+00:00"},{"alias_kind":"pith_short_8","alias_value":"TOEZEC3U","created_at":"2026-07-05T03:59:53.317059+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2604.08766","citing_title":"Follow My Eyes: Backdoor Attacks on Goal-Directed Scanpath Prediction","ref_index":22,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/TOEZEC3UFZFKIICUKPXRPWEOCL","json":"https://pith.science/pith/TOEZEC3UFZFKIICUKPXRPWEOCL.json","graph_json":"https://pith.science/api/pith-number/TOEZEC3UFZFKIICUKPXRPWEOCL/graph.json","events_json":"https://pith.science/api/pith-number/TOEZEC3UFZFKIICUKPXRPWEOCL/events.json","paper":"https://pith.science/paper/TOEZEC3U"},"agent_actions":{"view_html":"https://pith.science/pith/TOEZEC3UFZFKIICUKPXRPWEOCL","download_json":"https://pith.science/pith/TOEZEC3UFZFKIICUKPXRPWEOCL.json","view_paper":"https://pith.science/paper/TOEZEC3U","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2110.14880&json=true","fetch_graph":"https://pith.science/api/pith-number/TOEZEC3UFZFKIICUKPXRPWEOCL/graph.json","fetch_events":"https://pith.science/api/pith-number/TOEZEC3UFZFKIICUKPXRPWEOCL/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/TOEZEC3UFZFKIICUKPXRPWEOCL/action/timestamp_anchor","attest_storage":"https://pith.science/pith/TOEZEC3UFZFKIICUKPXRPWEOCL/action/storage_attestation","attest_author":"https://pith.science/pith/TOEZEC3UFZFKIICUKPXRPWEOCL/action/author_attestation","sign_citation":"https://pith.science/pith/TOEZEC3UFZFKIICUKPXRPWEOCL/action/citation_signature","submit_replication":"https://pith.science/pith/TOEZEC3UFZFKIICUKPXRPWEOCL/action/replication_record"}},"created_at":"2026-07-05T03:59:53.317059+00:00","updated_at":"2026-07-05T03:59:53.317059+00:00"}