{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2020:TSXCAYYUHOINVZ3ASLCLWIEGOO","short_pith_number":"pith:TSXCAYYU","schema_version":"1.0","canonical_sha256":"9cae2063143b90dae76092c4bb208673ba9f4ba02118098ed3cd4e43c5c92bd2","source":{"kind":"arxiv","id":"2007.10760","version":3},"attestation_state":"computed","paper":{"title":"Backdoor Attacks and Countermeasures on Deep Learning: A Comprehensive Review","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","cs.LG"],"primary_cat":"cs.CR","authors_text":"Anmin Fu, Bao Gia Doan, Hyoungshick Kim, Jiliang Zhang, Siqi Ma, Surya Nepal, Yansong Gao, Zhi Zhang","submitted_at":"2020-07-21T12:49:12Z","abstract_excerpt":"This work provides the community with a timely comprehensive review of backdoor attacks and countermeasures on deep learning. According to the attacker's capability and affected stage of the machine learning pipeline, the attack surfaces are recognized to be wide and then formalized into six categorizations: code poisoning, outsourcing, pretrained, data collection, collaborative learning and post-deployment. Accordingly, attacks under each categorization are combed. The countermeasures are categorized into four general classes: blind backdoor removal, offline backdoor inspection, online backdo"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2007.10760","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2020-07-21T12:49:12Z","cross_cats_sorted":["cs.CV","cs.LG"],"title_canon_sha256":"3ce0bac0b469a763141c0e793c08c460b95fd099593032eafb7370568f56875d","abstract_canon_sha256":"d35f50eb3c89136b8317cde3c1107e10d6a4bee956fd72b2efe9a86bd2e7c1b6"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T01:24:02.361771Z","signature_b64":"RVcvglmMz8r2oD3jIig+sWHU55TsmLSQ3dh3TQJYdC8ONh2n+CzwX5PMxGoL2Cov39lExUsOzCoDJMVgsZgADw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9cae2063143b90dae76092c4bb208673ba9f4ba02118098ed3cd4e43c5c92bd2","last_reissued_at":"2026-07-05T01:24:02.361203Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T01:24:02.361203Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Backdoor Attacks and Countermeasures on Deep Learning: A Comprehensive Review","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","cs.LG"],"primary_cat":"cs.CR","authors_text":"Anmin Fu, Bao Gia Doan, Hyoungshick Kim, Jiliang Zhang, Siqi Ma, Surya Nepal, Yansong Gao, Zhi Zhang","submitted_at":"2020-07-21T12:49:12Z","abstract_excerpt":"This work provides the community with a timely comprehensive review of backdoor attacks and countermeasures on deep learning. According to the attacker's capability and affected stage of the machine learning pipeline, the attack surfaces are recognized to be wide and then formalized into six categorizations: code poisoning, outsourcing, pretrained, data collection, collaborative learning and post-deployment. Accordingly, attacks under each categorization are combed. The countermeasures are categorized into four general classes: blind backdoor removal, offline backdoor inspection, online backdo"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2007.10760","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2007.10760/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2007.10760","created_at":"2026-07-05T01:24:02.361281+00:00"},{"alias_kind":"arxiv_version","alias_value":"2007.10760v3","created_at":"2026-07-05T01:24:02.361281+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2007.10760","created_at":"2026-07-05T01:24:02.361281+00:00"},{"alias_kind":"pith_short_12","alias_value":"TSXCAYYUHOIN","created_at":"2026-07-05T01:24:02.361281+00:00"},{"alias_kind":"pith_short_16","alias_value":"TSXCAYYUHOINVZ3A","created_at":"2026-07-05T01:24:02.361281+00:00"},{"alias_kind":"pith_short_8","alias_value":"TSXCAYYU","created_at":"2026-07-05T01:24:02.361281+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":4,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.25004","citing_title":"Certification of Machine Learning Models via Directional Sharpness","ref_index":28,"is_internal_anchor":false},{"citing_arxiv_id":"2606.26841","citing_title":"SpikeTimer: Exploring Active Copyright Protection in Spiking Neural Networks via Temporal Backdoor Regularization","ref_index":30,"is_internal_anchor":false},{"citing_arxiv_id":"2509.08748","citing_title":"Prototype-Guided Robust Learning against Backdoor Attacks","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2604.12232","citing_title":"TEMPLATEFUZZ: Fine-Grained Chat Template Fuzzing for Jailbreaking and Red Teaming LLMs","ref_index":13,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/TSXCAYYUHOINVZ3ASLCLWIEGOO","json":"https://pith.science/pith/TSXCAYYUHOINVZ3ASLCLWIEGOO.json","graph_json":"https://pith.science/api/pith-number/TSXCAYYUHOINVZ3ASLCLWIEGOO/graph.json","events_json":"https://pith.science/api/pith-number/TSXCAYYUHOINVZ3ASLCLWIEGOO/events.json","paper":"https://pith.science/paper/TSXCAYYU"},"agent_actions":{"view_html":"https://pith.science/pith/TSXCAYYUHOINVZ3ASLCLWIEGOO","download_json":"https://pith.science/pith/TSXCAYYUHOINVZ3ASLCLWIEGOO.json","view_paper":"https://pith.science/paper/TSXCAYYU","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2007.10760&json=true","fetch_graph":"https://pith.science/api/pith-number/TSXCAYYUHOINVZ3ASLCLWIEGOO/graph.json","fetch_events":"https://pith.science/api/pith-number/TSXCAYYUHOINVZ3ASLCLWIEGOO/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/TSXCAYYUHOINVZ3ASLCLWIEGOO/action/timestamp_anchor","attest_storage":"https://pith.science/pith/TSXCAYYUHOINVZ3ASLCLWIEGOO/action/storage_attestation","attest_author":"https://pith.science/pith/TSXCAYYUHOINVZ3ASLCLWIEGOO/action/author_attestation","sign_citation":"https://pith.science/pith/TSXCAYYUHOINVZ3ASLCLWIEGOO/action/citation_signature","submit_replication":"https://pith.science/pith/TSXCAYYUHOINVZ3ASLCLWIEGOO/action/replication_record"}},"created_at":"2026-07-05T01:24:02.361281+00:00","updated_at":"2026-07-05T01:24:02.361281+00:00"}