{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:ZNEI2TZGY3IYOCD5JBMHIEJATV","short_pith_number":"pith:ZNEI2TZG","canonical_record":{"source":{"id":"2508.03221","kind":"arxiv","version":5},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-08-05T08:48:37Z","cross_cats_sorted":["cs.CV"],"title_canon_sha256":"9b8ea818e249a1d9bdd0dc18c1e9e1b2f0768a91a8074db20cd5c666dc2b9ebe","abstract_canon_sha256":"b5e6bb2a23c8f9034bf8d51a0774c04aafd652e0cbd4979acdee8e5bbe026793"},"schema_version":"1.0"},"canonical_sha256":"cb488d4f26c6d187087d48587411209d6ab970e793059319e9ed9d27ef1fb5ec","source":{"kind":"arxiv","id":"2508.03221","version":5},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2508.03221","created_at":"2026-05-29T01:04:54Z"},{"alias_kind":"arxiv_version","alias_value":"2508.03221v5","created_at":"2026-05-29T01:04:54Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2508.03221","created_at":"2026-05-29T01:04:54Z"},{"alias_kind":"pith_short_12","alias_value":"ZNEI2TZGY3IY","created_at":"2026-05-29T01:04:54Z"},{"alias_kind":"pith_short_16","alias_value":"ZNEI2TZGY3IYOCD5","created_at":"2026-05-29T01:04:54Z"},{"alias_kind":"pith_short_8","alias_value":"ZNEI2TZG","created_at":"2026-05-29T01:04:54Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:ZNEI2TZGY3IYOCD5JBMHIEJATV","target":"record","payload":{"canonical_record":{"source":{"id":"2508.03221","kind":"arxiv","version":5},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-08-05T08:48:37Z","cross_cats_sorted":["cs.CV"],"title_canon_sha256":"9b8ea818e249a1d9bdd0dc18c1e9e1b2f0768a91a8074db20cd5c666dc2b9ebe","abstract_canon_sha256":"b5e6bb2a23c8f9034bf8d51a0774c04aafd652e0cbd4979acdee8e5bbe026793"},"schema_version":"1.0"},"canonical_sha256":"cb488d4f26c6d187087d48587411209d6ab970e793059319e9ed9d27ef1fb5ec","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-29T01:04:54.680991Z","signature_b64":"gkIoZR3uBju44Fw7aYzxGwYtxPLLPkZ7szR9it5vRQX/j+8TXN7N5HapbHbWPMGp2X28OvRJQRR12iYje0nbDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"cb488d4f26c6d187087d48587411209d6ab970e793059319e9ed9d27ef1fb5ec","last_reissued_at":"2026-05-29T01:04:54.680571Z","signature_status":"signed_v1","first_computed_at":"2026-05-29T01:04:54.680571Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2508.03221","source_version":5,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-29T01:04:54Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"0ZjnxkA8SE/35xIrtaG3xa1cNeZSgmCJ+viWx3ByGsv/XvqrDetlV5TRx7e0MegPChr76Tiq6Uk3UIm+qimvBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T09:17:48.181956Z"},"content_sha256":"95e7e9788cdf91b39a4f449f3f3597ca18eeb7382d471d6dc4bdd05eb4995a66","schema_version":"1.0","event_id":"sha256:95e7e9788cdf91b39a4f449f3f3597ca18eeb7382d471d6dc4bdd05eb4995a66"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:ZNEI2TZGY3IYOCD5JBMHIEJATV","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"BadBlocks: Low-Cost and Stealthy Backdoor Attacks Tailored for Text-to-Image Diffusion Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CV"],"primary_cat":"cs.CR","authors_text":"Jia Wu, Junjun Yang, Yi Du, Yu Pan","submitted_at":"2025-08-05T08:48:37Z","abstract_excerpt":"Despite the remarkable progress of diffusion models in image generation, recent studies reveal their vulnerability to backdoor attacks via covert visual or textual triggers. Although evolving defense mechanisms can detect most existing threats through visual inspection or feature analysis, we introduce BadBlocks-a novel, lightweight, and highly covert attack that challenges these safeguards. By selectively poisoning specific blocks within the UNet architecture while keeping other components intact, BadBlocks requires only 30% of the computational resources and 20% of the GPU time of convention"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2508.03221","kind":"arxiv","version":5},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2508.03221/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-29T01:04:54Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"rNlTLnFoiS60PZfc53Aa/pGG67bjwAKdfI4+3W4wWnKF2pZPi/0lLJPowz2uYjbTerCa3Yw0NMJIJgDI1KqaBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T09:17:48.182422Z"},"content_sha256":"6f2fb5ed2a07cc5b672aa1d3c2ac957012a64401b9857876d38d84f84796cef2","schema_version":"1.0","event_id":"sha256:6f2fb5ed2a07cc5b672aa1d3c2ac957012a64401b9857876d38d84f84796cef2"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/ZNEI2TZGY3IYOCD5JBMHIEJATV/bundle.json","state_url":"https://pith.science/pith/ZNEI2TZGY3IYOCD5JBMHIEJATV/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/ZNEI2TZGY3IYOCD5JBMHIEJATV/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-09T09:17:48Z","links":{"resolver":"https://pith.science/pith/ZNEI2TZGY3IYOCD5JBMHIEJATV","bundle":"https://pith.science/pith/ZNEI2TZGY3IYOCD5JBMHIEJATV/bundle.json","state":"https://pith.science/pith/ZNEI2TZGY3IYOCD5JBMHIEJATV/state.json","well_known_bundle":"https://pith.science/.well-known/pith/ZNEI2TZGY3IYOCD5JBMHIEJATV/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:ZNEI2TZGY3IYOCD5JBMHIEJATV","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"b5e6bb2a23c8f9034bf8d51a0774c04aafd652e0cbd4979acdee8e5bbe026793","cross_cats_sorted":["cs.CV"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-08-05T08:48:37Z","title_canon_sha256":"9b8ea818e249a1d9bdd0dc18c1e9e1b2f0768a91a8074db20cd5c666dc2b9ebe"},"schema_version":"1.0","source":{"id":"2508.03221","kind":"arxiv","version":5}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2508.03221","created_at":"2026-05-29T01:04:54Z"},{"alias_kind":"arxiv_version","alias_value":"2508.03221v5","created_at":"2026-05-29T01:04:54Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2508.03221","created_at":"2026-05-29T01:04:54Z"},{"alias_kind":"pith_short_12","alias_value":"ZNEI2TZGY3IY","created_at":"2026-05-29T01:04:54Z"},{"alias_kind":"pith_short_16","alias_value":"ZNEI2TZGY3IYOCD5","created_at":"2026-05-29T01:04:54Z"},{"alias_kind":"pith_short_8","alias_value":"ZNEI2TZG","created_at":"2026-05-29T01:04:54Z"}],"graph_snapshots":[{"event_id":"sha256:6f2fb5ed2a07cc5b672aa1d3c2ac957012a64401b9857876d38d84f84796cef2","target":"graph","created_at":"2026-05-29T01:04:54Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2508.03221/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Despite the remarkable progress of diffusion models in image generation, recent studies reveal their vulnerability to backdoor attacks via covert visual or textual triggers. Although evolving defense mechanisms can detect most existing threats through visual inspection or feature analysis, we introduce BadBlocks-a novel, lightweight, and highly covert attack that challenges these safeguards. By selectively poisoning specific blocks within the UNet architecture while keeping other components intact, BadBlocks requires only 30% of the computational resources and 20% of the GPU time of convention","authors_text":"Jia Wu, Junjun Yang, Yi Du, Yu Pan","cross_cats":["cs.CV"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-08-05T08:48:37Z","title":"BadBlocks: Low-Cost and Stealthy Backdoor Attacks Tailored for Text-to-Image Diffusion Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2508.03221","kind":"arxiv","version":5},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:95e7e9788cdf91b39a4f449f3f3597ca18eeb7382d471d6dc4bdd05eb4995a66","target":"record","created_at":"2026-05-29T01:04:54Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"b5e6bb2a23c8f9034bf8d51a0774c04aafd652e0cbd4979acdee8e5bbe026793","cross_cats_sorted":["cs.CV"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-08-05T08:48:37Z","title_canon_sha256":"9b8ea818e249a1d9bdd0dc18c1e9e1b2f0768a91a8074db20cd5c666dc2b9ebe"},"schema_version":"1.0","source":{"id":"2508.03221","kind":"arxiv","version":5}},"canonical_sha256":"cb488d4f26c6d187087d48587411209d6ab970e793059319e9ed9d27ef1fb5ec","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"cb488d4f26c6d187087d48587411209d6ab970e793059319e9ed9d27ef1fb5ec","first_computed_at":"2026-05-29T01:04:54.680571Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-29T01:04:54.680571Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"gkIoZR3uBju44Fw7aYzxGwYtxPLLPkZ7szR9it5vRQX/j+8TXN7N5HapbHbWPMGp2X28OvRJQRR12iYje0nbDA==","signature_status":"signed_v1","signed_at":"2026-05-29T01:04:54.680991Z","signed_message":"canonical_sha256_bytes"},"source_id":"2508.03221","source_kind":"arxiv","source_version":5}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:95e7e9788cdf91b39a4f449f3f3597ca18eeb7382d471d6dc4bdd05eb4995a66","sha256:6f2fb5ed2a07cc5b672aa1d3c2ac957012a64401b9857876d38d84f84796cef2"],"state_sha256":"2e698812c3840a7caf983c3634a66279487dc3016332d9406a005b20871c2c6f"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"gKRKA3VnYFVIyCtjm9q954akY8gn3KgyyJhugnfrxpiHWMVjXCk1nzLyUQRMJLDuskH6Sk3SOogd9SzXDQVxBw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-09T09:17:48.186019Z","bundle_sha256":"fbea9cdcd7391b8439bcfa48c4b62d832cced6484274e464a28c3a448463643f"}}