{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:WEDZ2A76HVJAZKRY2ABXNWHNR4","short_pith_number":"pith:WEDZ2A76","schema_version":"1.0","canonical_sha256":"b1079d03fe3d520caa38d00376d8ed8f05b441f5806a43455261ad912f0f15c1","source":{"kind":"arxiv","id":"2308.04466","version":3},"attestation_state":"computed","paper":{"title":"Backdoor Federated Learning by Poisoning Backdoor-Critical Layers","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","cs.LG"],"primary_cat":"cs.CR","authors_text":"Haomin Zhuang, Hao Wang, Jian Li, Mingxian Yu, Xu Yuan, Yang Hua","submitted_at":"2023-08-08T05:46:47Z","abstract_excerpt":"Federated learning (FL) has been widely deployed to enable machine learning training on sensitive data across distributed devices. However, the decentralized learning paradigm and heterogeneity of FL further extend the attack surface for backdoor attacks. Existing FL attack and defense methodologies typically focus on the whole model. None of them recognizes the existence of backdoor-critical (BC) layers-a small subset of layers that dominate the model vulnerabilities. Attacking the BC layers achieves equivalent effects as attacking the whole model but at a far smaller chance of being detected"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2308.04466","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2023-08-08T05:46:47Z","cross_cats_sorted":["cs.CV","cs.LG"],"title_canon_sha256":"c4740bc113638b06628751b5167a9d2eee9733240474554a1db02ac0ead64e69","abstract_canon_sha256":"a6ca7879ae5879c29c953cf46b3acfbec0b513ada39a417c5406abbcef5f8eea"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:07:57.499502Z","signature_b64":"pvTTaeTRwe7DiABaJQ9fBXaK6UVHq4lNvHzVFkC1LHcDF8Z4e0NZcSh9Qr7gNSoSNC9PeU0PSzlmBAzt1KCeAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b1079d03fe3d520caa38d00376d8ed8f05b441f5806a43455261ad912f0f15c1","last_reissued_at":"2026-07-05T08:07:57.499024Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:07:57.499024Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Backdoor Federated Learning by Poisoning Backdoor-Critical Layers","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","cs.LG"],"primary_cat":"cs.CR","authors_text":"Haomin Zhuang, Hao Wang, Jian Li, Mingxian Yu, Xu Yuan, Yang Hua","submitted_at":"2023-08-08T05:46:47Z","abstract_excerpt":"Federated learning (FL) has been widely deployed to enable machine learning training on sensitive data across distributed devices. However, the decentralized learning paradigm and heterogeneity of FL further extend the attack surface for backdoor attacks. Existing FL attack and defense methodologies typically focus on the whole model. None of them recognizes the existence of backdoor-critical (BC) layers-a small subset of layers that dominate the model vulnerabilities. Attacking the BC layers achieves equivalent effects as attacking the whole model but at a far smaller chance of being detected"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2308.04466","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2308.04466/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2308.04466","created_at":"2026-07-05T08:07:57.499081+00:00"},{"alias_kind":"arxiv_version","alias_value":"2308.04466v3","created_at":"2026-07-05T08:07:57.499081+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2308.04466","created_at":"2026-07-05T08:07:57.499081+00:00"},{"alias_kind":"pith_short_12","alias_value":"WEDZ2A76HVJA","created_at":"2026-07-05T08:07:57.499081+00:00"},{"alias_kind":"pith_short_16","alias_value":"WEDZ2A76HVJAZKRY","created_at":"2026-07-05T08:07:57.499081+00:00"},{"alias_kind":"pith_short_8","alias_value":"WEDZ2A76","created_at":"2026-07-05T08:07:57.499081+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2509.08089","citing_title":"Hammer and Anvil: Toward a Theory of Backdoors in Federated Learning","ref_index":35,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/WEDZ2A76HVJAZKRY2ABXNWHNR4","json":"https://pith.science/pith/WEDZ2A76HVJAZKRY2ABXNWHNR4.json","graph_json":"https://pith.science/api/pith-number/WEDZ2A76HVJAZKRY2ABXNWHNR4/graph.json","events_json":"https://pith.science/api/pith-number/WEDZ2A76HVJAZKRY2ABXNWHNR4/events.json","paper":"https://pith.science/paper/WEDZ2A76"},"agent_actions":{"view_html":"https://pith.science/pith/WEDZ2A76HVJAZKRY2ABXNWHNR4","download_json":"https://pith.science/pith/WEDZ2A76HVJAZKRY2ABXNWHNR4.json","view_paper":"https://pith.science/paper/WEDZ2A76","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2308.04466&json=true","fetch_graph":"https://pith.science/api/pith-number/WEDZ2A76HVJAZKRY2ABXNWHNR4/graph.json","fetch_events":"https://pith.science/api/pith-number/WEDZ2A76HVJAZKRY2ABXNWHNR4/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/WEDZ2A76HVJAZKRY2ABXNWHNR4/action/timestamp_anchor","attest_storage":"https://pith.science/pith/WEDZ2A76HVJAZKRY2ABXNWHNR4/action/storage_attestation","attest_author":"https://pith.science/pith/WEDZ2A76HVJAZKRY2ABXNWHNR4/action/author_attestation","sign_citation":"https://pith.science/pith/WEDZ2A76HVJAZKRY2ABXNWHNR4/action/citation_signature","submit_replication":"https://pith.science/pith/WEDZ2A76HVJAZKRY2ABXNWHNR4/action/replication_record"}},"created_at":"2026-07-05T08:07:57.499081+00:00","updated_at":"2026-07-05T08:07:57.499081+00:00"}