{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:VPKERVHHLF5WZQPJWR2S52QJP5","short_pith_number":"pith:VPKERVHH","schema_version":"1.0","canonical_sha256":"abd448d4e7597b6cc1e9b4752eea097f53a1272ab9f8b6e779c8f29fa083a74c","source":{"kind":"arxiv","id":"2110.02467","version":1},"attestation_state":"computed","paper":{"title":"BadPre: Task-agnostic Backdoor Attacks to Pre-trained NLP Foundation Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CL","authors_text":"Chun Fan, Jiwei Li, Kangjie Chen, Shangwei Guo, Tianwei Zhang, Xiaofei Sun, Yuxian Meng","submitted_at":"2021-10-06T02:48:58Z","abstract_excerpt":"Pre-trained Natural Language Processing (NLP) models can be easily adapted to a variety of downstream language tasks. This significantly accelerates the development of language models. However, NLP models have been shown to be vulnerable to backdoor attacks, where a pre-defined trigger word in the input text causes model misprediction. Previous NLP backdoor attacks mainly focus on some specific tasks. This makes those attacks less general and applicable to other kinds of NLP models and tasks. In this work, we propose \\Name, the first task-agnostic backdoor attack against the pre-trained NLP mo"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2110.02467","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2021-10-06T02:48:58Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"a30d6aa895f63b0c630a4c3180c2280ff1ed91add2a5d94c3e91fc6aa6a543a0","abstract_canon_sha256":"4e7d0515b11cc6fc78ecbabce81fe482832f574d536b9f81c112de8559fb4860"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T03:20:26.466750Z","signature_b64":"hpMqEZZms6Ws/2fbUz7h7kVcLYpgU0PpUTlT/ELJivHoEmliuhvX46qfG6xP0rg8hCT1I2ekGi8bq+102tP2Ag==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"abd448d4e7597b6cc1e9b4752eea097f53a1272ab9f8b6e779c8f29fa083a74c","last_reissued_at":"2026-07-05T03:20:26.466393Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T03:20:26.466393Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"BadPre: Task-agnostic Backdoor Attacks to Pre-trained NLP Foundation Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CL","authors_text":"Chun Fan, Jiwei Li, Kangjie Chen, Shangwei Guo, Tianwei Zhang, Xiaofei Sun, Yuxian Meng","submitted_at":"2021-10-06T02:48:58Z","abstract_excerpt":"Pre-trained Natural Language Processing (NLP) models can be easily adapted to a variety of downstream language tasks. This significantly accelerates the development of language models. However, NLP models have been shown to be vulnerable to backdoor attacks, where a pre-defined trigger word in the input text causes model misprediction. Previous NLP backdoor attacks mainly focus on some specific tasks. This makes those attacks less general and applicable to other kinds of NLP models and tasks. In this work, we propose \\Name, the first task-agnostic backdoor attack against the pre-trained NLP mo"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2110.02467","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2110.02467/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2110.02467","created_at":"2026-07-05T03:20:26.466452+00:00"},{"alias_kind":"arxiv_version","alias_value":"2110.02467v1","created_at":"2026-07-05T03:20:26.466452+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2110.02467","created_at":"2026-07-05T03:20:26.466452+00:00"},{"alias_kind":"pith_short_12","alias_value":"VPKERVHHLF5W","created_at":"2026-07-05T03:20:26.466452+00:00"},{"alias_kind":"pith_short_16","alias_value":"VPKERVHHLF5WZQPJ","created_at":"2026-07-05T03:20:26.466452+00:00"},{"alias_kind":"pith_short_8","alias_value":"VPKERVHH","created_at":"2026-07-05T03:20:26.466452+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.27511","citing_title":"When the Aggregator Cheats: Data-Free Backdoors in Federated LLM-based QA Systems","ref_index":10,"is_internal_anchor":false},{"citing_arxiv_id":"2605.30189","citing_title":"Token-Level Generalization in LoRA Adapter Backdoors: Attack Characterization and Behavioral Detection","ref_index":1,"is_internal_anchor":false},{"citing_arxiv_id":"2605.09397","citing_title":"BadDLM: Backdooring Diffusion Language Models with Diverse Targets","ref_index":4,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/VPKERVHHLF5WZQPJWR2S52QJP5","json":"https://pith.science/pith/VPKERVHHLF5WZQPJWR2S52QJP5.json","graph_json":"https://pith.science/api/pith-number/VPKERVHHLF5WZQPJWR2S52QJP5/graph.json","events_json":"https://pith.science/api/pith-number/VPKERVHHLF5WZQPJWR2S52QJP5/events.json","paper":"https://pith.science/paper/VPKERVHH"},"agent_actions":{"view_html":"https://pith.science/pith/VPKERVHHLF5WZQPJWR2S52QJP5","download_json":"https://pith.science/pith/VPKERVHHLF5WZQPJWR2S52QJP5.json","view_paper":"https://pith.science/paper/VPKERVHH","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2110.02467&json=true","fetch_graph":"https://pith.science/api/pith-number/VPKERVHHLF5WZQPJWR2S52QJP5/graph.json","fetch_events":"https://pith.science/api/pith-number/VPKERVHHLF5WZQPJWR2S52QJP5/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/VPKERVHHLF5WZQPJWR2S52QJP5/action/timestamp_anchor","attest_storage":"https://pith.science/pith/VPKERVHHLF5WZQPJWR2S52QJP5/action/storage_attestation","attest_author":"https://pith.science/pith/VPKERVHHLF5WZQPJWR2S52QJP5/action/author_attestation","sign_citation":"https://pith.science/pith/VPKERVHHLF5WZQPJWR2S52QJP5/action/citation_signature","submit_replication":"https://pith.science/pith/VPKERVHHLF5WZQPJWR2S52QJP5/action/replication_record"}},"created_at":"2026-07-05T03:20:26.466452+00:00","updated_at":"2026-07-05T03:20:26.466452+00:00"}