{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:UMCRQ64YXPE22M22JTFQ75OMDD","short_pith_number":"pith:UMCRQ64Y","schema_version":"1.0","canonical_sha256":"a305187b98bbc9ad335a4ccb0ff5cc18d3de9d90a8f4516588228a4cba6762d9","source":{"kind":"arxiv","id":"2606.19535","version":1},"attestation_state":"computed","paper":{"title":"FloatDoor: Platform-Triggered Backdoors in LLMs","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Felix M\\\"achtle, Jonas Sander, Nils Loose, Thomas Eisenbarth","submitted_at":"2026-06-17T19:28:30Z","abstract_excerpt":"Large language models (LLMs) are increasingly deployed in sensitive settings such as software engineering, where their outputs directly shape downstream artifacts. Recent work has shown that an identical model can produce measurably different outputs depending on the deployment platform, a consequence of non-associative floating-point arithmetic and divergent kernel implementations. We study the security implications of this platform-dependent variability and uncover a novel attack surface on LLM deployments. We introduce FloatDoor, the first input-independent, platform-triggered backdoor atta"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2606.19535","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-17T19:28:30Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"5d8f0583ccd923832d1e6ca2092d3700f173a72e800366bfb7374379f4ee6f18","abstract_canon_sha256":"4d81cf3c4adbe605d77022dd0e0ed2c6621e0fb0dc38f0948d326b23f1e024e9"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-19T16:12:28.094664Z","signature_b64":"4Q0b18DuB0Rfw693YLMnt83eKRdgn9ITF3EWJKSRi1ZDF8ubDmvkUCe0IjVsJp3MrD1tjCptIIDgopqe9KadCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a305187b98bbc9ad335a4ccb0ff5cc18d3de9d90a8f4516588228a4cba6762d9","last_reissued_at":"2026-06-19T16:12:28.094306Z","signature_status":"signed_v1","first_computed_at":"2026-06-19T16:12:28.094306Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"FloatDoor: Platform-Triggered Backdoors in LLMs","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Felix M\\\"achtle, Jonas Sander, Nils Loose, Thomas Eisenbarth","submitted_at":"2026-06-17T19:28:30Z","abstract_excerpt":"Large language models (LLMs) are increasingly deployed in sensitive settings such as software engineering, where their outputs directly shape downstream artifacts. Recent work has shown that an identical model can produce measurably different outputs depending on the deployment platform, a consequence of non-associative floating-point arithmetic and divergent kernel implementations. We study the security implications of this platform-dependent variability and uncover a novel attack surface on LLM deployments. We introduce FloatDoor, the first input-independent, platform-triggered backdoor atta"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.19535","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.19535/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2606.19535","created_at":"2026-06-19T16:12:28.094380+00:00"},{"alias_kind":"arxiv_version","alias_value":"2606.19535v1","created_at":"2026-06-19T16:12:28.094380+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.19535","created_at":"2026-06-19T16:12:28.094380+00:00"},{"alias_kind":"pith_short_12","alias_value":"UMCRQ64YXPE2","created_at":"2026-06-19T16:12:28.094380+00:00"},{"alias_kind":"pith_short_16","alias_value":"UMCRQ64YXPE22M22","created_at":"2026-06-19T16:12:28.094380+00:00"},{"alias_kind":"pith_short_8","alias_value":"UMCRQ64Y","created_at":"2026-06-19T16:12:28.094380+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/UMCRQ64YXPE22M22JTFQ75OMDD","json":"https://pith.science/pith/UMCRQ64YXPE22M22JTFQ75OMDD.json","graph_json":"https://pith.science/api/pith-number/UMCRQ64YXPE22M22JTFQ75OMDD/graph.json","events_json":"https://pith.science/api/pith-number/UMCRQ64YXPE22M22JTFQ75OMDD/events.json","paper":"https://pith.science/paper/UMCRQ64Y"},"agent_actions":{"view_html":"https://pith.science/pith/UMCRQ64YXPE22M22JTFQ75OMDD","download_json":"https://pith.science/pith/UMCRQ64YXPE22M22JTFQ75OMDD.json","view_paper":"https://pith.science/paper/UMCRQ64Y","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2606.19535&json=true","fetch_graph":"https://pith.science/api/pith-number/UMCRQ64YXPE22M22JTFQ75OMDD/graph.json","fetch_events":"https://pith.science/api/pith-number/UMCRQ64YXPE22M22JTFQ75OMDD/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/UMCRQ64YXPE22M22JTFQ75OMDD/action/timestamp_anchor","attest_storage":"https://pith.science/pith/UMCRQ64YXPE22M22JTFQ75OMDD/action/storage_attestation","attest_author":"https://pith.science/pith/UMCRQ64YXPE22M22JTFQ75OMDD/action/author_attestation","sign_citation":"https://pith.science/pith/UMCRQ64YXPE22M22JTFQ75OMDD/action/citation_signature","submit_replication":"https://pith.science/pith/UMCRQ64YXPE22M22JTFQ75OMDD/action/replication_record"}},"created_at":"2026-06-19T16:12:28.094380+00:00","updated_at":"2026-06-19T16:12:28.094380+00:00"}