{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:U3JWRSMXBWV3G5WYLODCHN435T","short_pith_number":"pith:U3JWRSMX","schema_version":"1.0","canonical_sha256":"a6d368c9970dabb376d85b8623b79becff7551b7772a5fb8c2757e5d626dbb5f","source":{"kind":"arxiv","id":"2606.02995","version":1},"attestation_state":"computed","paper":{"title":"Patcher: Post-Hoc Patching of Backdoored Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.IR","cs.LG"],"primary_cat":"cs.CR","authors_text":"Anjun Gao, Minghong Fang, Yueyang Quan, Yufei Xia, Zhuqing Liu","submitted_at":"2026-06-02T01:11:58Z","abstract_excerpt":"Large language models remain vulnerable to jailbreak backdoor attacks, where adversaries poison safety alignment data to embed hidden triggers that bypass safety mechanisms. Existing defenses often require comprehensive attack information or multiple triggered examples, making them impractical when defenders only observe a single reported failure case without knowing whether it stems from a backdoor attack or a natural alignment bug. This paper presents Patcher, a post-hoc defense framework that repairs backdoored language models using only a single reported failure case and the model paramete"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2606.02995","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T01:11:58Z","cross_cats_sorted":["cs.AI","cs.IR","cs.LG"],"title_canon_sha256":"9fc119bcbaf73b2f71f779cb576bbe0e9bdecf3401b7c511d70c756dd69f29dd","abstract_canon_sha256":"ec8abecc406d59848dc81732648853b8064871019588ed7ba69ddbd2290dad96"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-03T01:05:28.812796Z","signature_b64":"0b9j4+Dt8hLn5FSdk0+xyilBijthmwKYFhSdSPOfYHZU7QNOkAomhbN5LItxuWFYRMhv02i1vCSUGiKNtERwAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a6d368c9970dabb376d85b8623b79becff7551b7772a5fb8c2757e5d626dbb5f","last_reissued_at":"2026-06-03T01:05:28.812352Z","signature_status":"signed_v1","first_computed_at":"2026-06-03T01:05:28.812352Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Patcher: Post-Hoc Patching of Backdoored Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.IR","cs.LG"],"primary_cat":"cs.CR","authors_text":"Anjun Gao, Minghong Fang, Yueyang Quan, Yufei Xia, Zhuqing Liu","submitted_at":"2026-06-02T01:11:58Z","abstract_excerpt":"Large language models remain vulnerable to jailbreak backdoor attacks, where adversaries poison safety alignment data to embed hidden triggers that bypass safety mechanisms. Existing defenses often require comprehensive attack information or multiple triggered examples, making them impractical when defenders only observe a single reported failure case without knowing whether it stems from a backdoor attack or a natural alignment bug. This paper presents Patcher, a post-hoc defense framework that repairs backdoored language models using only a single reported failure case and the model paramete"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.02995","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.02995/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2606.02995","created_at":"2026-06-03T01:05:28.812420+00:00"},{"alias_kind":"arxiv_version","alias_value":"2606.02995v1","created_at":"2026-06-03T01:05:28.812420+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.02995","created_at":"2026-06-03T01:05:28.812420+00:00"},{"alias_kind":"pith_short_12","alias_value":"U3JWRSMXBWV3","created_at":"2026-06-03T01:05:28.812420+00:00"},{"alias_kind":"pith_short_16","alias_value":"U3JWRSMXBWV3G5WY","created_at":"2026-06-03T01:05:28.812420+00:00"},{"alias_kind":"pith_short_8","alias_value":"U3JWRSMX","created_at":"2026-06-03T01:05:28.812420+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/U3JWRSMXBWV3G5WYLODCHN435T","json":"https://pith.science/pith/U3JWRSMXBWV3G5WYLODCHN435T.json","graph_json":"https://pith.science/api/pith-number/U3JWRSMXBWV3G5WYLODCHN435T/graph.json","events_json":"https://pith.science/api/pith-number/U3JWRSMXBWV3G5WYLODCHN435T/events.json","paper":"https://pith.science/paper/U3JWRSMX"},"agent_actions":{"view_html":"https://pith.science/pith/U3JWRSMXBWV3G5WYLODCHN435T","download_json":"https://pith.science/pith/U3JWRSMXBWV3G5WYLODCHN435T.json","view_paper":"https://pith.science/paper/U3JWRSMX","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2606.02995&json=true","fetch_graph":"https://pith.science/api/pith-number/U3JWRSMXBWV3G5WYLODCHN435T/graph.json","fetch_events":"https://pith.science/api/pith-number/U3JWRSMXBWV3G5WYLODCHN435T/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/U3JWRSMXBWV3G5WYLODCHN435T/action/timestamp_anchor","attest_storage":"https://pith.science/pith/U3JWRSMXBWV3G5WYLODCHN435T/action/storage_attestation","attest_author":"https://pith.science/pith/U3JWRSMXBWV3G5WYLODCHN435T/action/author_attestation","sign_citation":"https://pith.science/pith/U3JWRSMXBWV3G5WYLODCHN435T/action/citation_signature","submit_replication":"https://pith.science/pith/U3JWRSMXBWV3G5WYLODCHN435T/action/replication_record"}},"created_at":"2026-06-03T01:05:28.812420+00:00","updated_at":"2026-06-03T01:05:28.812420+00:00"}