{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:TZ3YJOKQ4HTWCADQNHQCV5LWCR","short_pith_number":"pith:TZ3YJOKQ","schema_version":"1.0","canonical_sha256":"9e7784b950e1e761007069e02af5761463d4f51ba91c5674427f7b3adfbcbfa7","source":{"kind":"arxiv","id":"2311.11225","version":2},"attestation_state":"computed","paper":{"title":"TextGuard: Provable Defense against Backdoor Attacks on Text Classification","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Bo Li, Dawn Song, Hengzhi Pei, Jinyuan Jia, Wenbo Guo","submitted_at":"2023-11-19T04:42:16Z","abstract_excerpt":"Backdoor attacks have become a major security threat for deploying machine learning models in security-critical applications. Existing research endeavors have proposed many defenses against backdoor attacks. Despite demonstrating certain empirical defense efficacy, none of these techniques could provide a formal and provable security guarantee against arbitrary attacks. As a result, they can be easily broken by strong adaptive attacks, as shown in our evaluation. In this work, we propose TextGuard, the first provable defense against backdoor attacks on text classification. In particular, TextG"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2311.11225","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.LG","submitted_at":"2023-11-19T04:42:16Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"629ec285311314775dae17c4ad731022c0937af8567f5cc04085ff139197864e","abstract_canon_sha256":"a8f0e54f401c7312c5c099b01e372f18d59ee00e4e9f84ce4c3f06e73a54c235"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:16:50.403243Z","signature_b64":"qB3I+ag0zrvBfJ22FEanAIQo6ri7vSPqQh+gpZ/vD68dN0wsgstYabSS0w79EAhkhmSWPHVpGAlGvDmvOifYDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9e7784b950e1e761007069e02af5761463d4f51ba91c5674427f7b3adfbcbfa7","last_reissued_at":"2026-07-05T07:16:50.402766Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:16:50.402766Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"TextGuard: Provable Defense against Backdoor Attacks on Text Classification","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Bo Li, Dawn Song, Hengzhi Pei, Jinyuan Jia, Wenbo Guo","submitted_at":"2023-11-19T04:42:16Z","abstract_excerpt":"Backdoor attacks have become a major security threat for deploying machine learning models in security-critical applications. Existing research endeavors have proposed many defenses against backdoor attacks. Despite demonstrating certain empirical defense efficacy, none of these techniques could provide a formal and provable security guarantee against arbitrary attacks. As a result, they can be easily broken by strong adaptive attacks, as shown in our evaluation. In this work, we propose TextGuard, the first provable defense against backdoor attacks on text classification. In particular, TextG"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2311.11225","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2311.11225/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2311.11225","created_at":"2026-07-05T07:16:50.402822+00:00"},{"alias_kind":"arxiv_version","alias_value":"2311.11225v2","created_at":"2026-07-05T07:16:50.402822+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2311.11225","created_at":"2026-07-05T07:16:50.402822+00:00"},{"alias_kind":"pith_short_12","alias_value":"TZ3YJOKQ4HTW","created_at":"2026-07-05T07:16:50.402822+00:00"},{"alias_kind":"pith_short_16","alias_value":"TZ3YJOKQ4HTWCADQ","created_at":"2026-07-05T07:16:50.402822+00:00"},{"alias_kind":"pith_short_8","alias_value":"TZ3YJOKQ","created_at":"2026-07-05T07:16:50.402822+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2512.10998","citing_title":"SCOUT: A Defense Against Data Poisoning Attacks in Fine-Tuned Language Models","ref_index":22,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/TZ3YJOKQ4HTWCADQNHQCV5LWCR","json":"https://pith.science/pith/TZ3YJOKQ4HTWCADQNHQCV5LWCR.json","graph_json":"https://pith.science/api/pith-number/TZ3YJOKQ4HTWCADQNHQCV5LWCR/graph.json","events_json":"https://pith.science/api/pith-number/TZ3YJOKQ4HTWCADQNHQCV5LWCR/events.json","paper":"https://pith.science/paper/TZ3YJOKQ"},"agent_actions":{"view_html":"https://pith.science/pith/TZ3YJOKQ4HTWCADQNHQCV5LWCR","download_json":"https://pith.science/pith/TZ3YJOKQ4HTWCADQNHQCV5LWCR.json","view_paper":"https://pith.science/paper/TZ3YJOKQ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2311.11225&json=true","fetch_graph":"https://pith.science/api/pith-number/TZ3YJOKQ4HTWCADQNHQCV5LWCR/graph.json","fetch_events":"https://pith.science/api/pith-number/TZ3YJOKQ4HTWCADQNHQCV5LWCR/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/TZ3YJOKQ4HTWCADQNHQCV5LWCR/action/timestamp_anchor","attest_storage":"https://pith.science/pith/TZ3YJOKQ4HTWCADQNHQCV5LWCR/action/storage_attestation","attest_author":"https://pith.science/pith/TZ3YJOKQ4HTWCADQNHQCV5LWCR/action/author_attestation","sign_citation":"https://pith.science/pith/TZ3YJOKQ4HTWCADQNHQCV5LWCR/action/citation_signature","submit_replication":"https://pith.science/pith/TZ3YJOKQ4HTWCADQNHQCV5LWCR/action/replication_record"}},"created_at":"2026-07-05T07:16:50.402822+00:00","updated_at":"2026-07-05T07:16:50.402822+00:00"}