Pith. sign in
Pith Number

pith:XGYKGKEL

pith:2026:XGYKGKELLB27GWS6QI64VWFZST
not attested not anchored not stored refs pending

Undetectable Backdoors in Model Parameters: Hiding Sparse Secrets in High Dimensions

Ashish Hooda, Atharv Singh Patlan, Kassem Fawaz, Nils Palumbo, Sarthak Choudhary, Somesh Jha

A sparse perturbation masked by Gaussian dither embeds backdoors whose detection reduces to the hard Sparse PCA problem.

arxiv:2605.04209 v2 · 2026-05-05 · cs.CR · cs.AI · cs.LG

Add to your LaTeX paper
\usepackage{pith}
\pithnumber{XGYKGKELLB27GWS6QI64VWFZST}

Prints a linked badge after your title and injects PDF metadata. Compiles on arXiv. Learn more · Embed verified badge

Record completeness

1 Bitcoin timestamp
2 Internet Archive
3 Author claim open · sign in to claim
4 Citations open
5 Replications open
Portable graph bundle live · download bundle · merged state
The bundle contains the canonical record plus signed events. A mirror can host it anywhere and recompute the same current state with the deterministic merge algorithm.

Claims

C1strongest claim

We prove that distinguishing the backdoor-injected model from this reference is at least as hard as Sparse PCA detection, which is computationally infeasible under standard hardness assumptions. The guarantee holds against any probabilistic polynomial-time distinguisher with white-box access to the parameters.

C2weakest assumption

Under a mild margin condition on the pre-trained classifier, we show that the dithered reference is functionally equivalent to the original classifier.

C3one line summary

Sparse Backdoor plants a provably undetectable backdoor in neural network weights via structured sparse perturbations and isotropic Gaussian dithering, with detection hardness reduced to Sparse PCA.

Formal links

3 machine-checked theorem links

Cited by

1 paper in Pith

Receipt and verification
First computed 2026-07-07T02:17:26.415350Z
Builder pith-number-builder-2026-05-17-v1
Signature Pith Ed25519 (pith-v1-2026-05) · public key
Schema pith-number/v1.0

Canonical hash

b9b0a3288b5875f35a5e823dcad8b994d37db6e64763d978c8deab016db7563a

Aliases

arxiv: 2605.04209 · arxiv_version: 2605.04209v2 · doi: 10.48550/arxiv.2605.04209 · pith_short_12: XGYKGKELLB27 · pith_short_16: XGYKGKELLB27GWS6 · pith_short_8: XGYKGKEL
Agent API
Verify this Pith Number yourself
curl -sH 'Accept: application/ld+json' https://pith.science/pith/XGYKGKELLB27GWS6QI64VWFZST \
  | jq -c '.canonical_record' \
  | python3 -c "import sys,json,hashlib; b=json.dumps(json.loads(sys.stdin.read()), sort_keys=True, separators=(',',':'), ensure_ascii=False).encode(); print(hashlib.sha256(b).hexdigest())"
# expect: b9b0a3288b5875f35a5e823dcad8b994d37db6e64763d978c8deab016db7563a
Canonical record JSON
{
  "metadata": {
    "abstract_canon_sha256": "be79287cd0b4835d87a4ea0069326fbe1bcf2588d839ce266ab0d2c61886c46d",
    "cross_cats_sorted": [
      "cs.AI",
      "cs.LG"
    ],
    "license": "http://creativecommons.org/licenses/by/4.0/",
    "primary_cat": "cs.CR",
    "submitted_at": "2026-05-05T18:48:09Z",
    "title_canon_sha256": "0fa9e7dc09eafd9c787eb6c712b03eb3824dfafa953e4cac6c0d93b4ed0489b0"
  },
  "schema_version": "1.0",
  "source": {
    "id": "2605.04209",
    "kind": "arxiv",
    "version": 2
  }
}