Pith. sign in

Paper Citation Record · LEDGER

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models

As of 17 August 2026, this Paper Citation Record lists 22 of 22 outbound references and 1 inbound Pith citation observation for arXiv:2411.09540.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2411.09540 v2

Coverage vector

measured 22 of 22 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-12T20:37:30.420221Z

measured 23 of 23 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-17T06:30:58.91139+00:00

measured 1 of 1 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-15T14:21:42.130463Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-15T18:16:14.067578Z

Reference resolution

22 of 22 outbound references displayed

  • verified exact0
  • verified fuzzy13
  • unresolved8
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 2ce0235c-986a-4280-a380-bb6f62527311 · outbound

This paper cites Exploring Visual Prompts for Adapting Large-Scale Models.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models Exploring Visual Prompts for Adapting Large-Scale Models

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-12T20:37:30.314630Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T20:37:30.314630Z digest=sha256:6edbbbb6de9664d076c213581ba102b4df5006c097f9f889fc2193063e312d08

Observation 3239486f-351a-4bcd-a086-d671c8895aa2 · outbound

This paper cites Sentinet: Detecting localized universal attacks against deep learning systems.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models Sentinet: Detecting localized universal attacks against deep learning systems

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T20:37:30.776428Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T20:37:30.325892Z digest=sha256:580ad02b97275db12218dd635149c6428351850b13fe4192b9a232c4b4f7bf09

Observation 64d2809e-eede-4e73-913d-ffd7378cdd9c · outbound

This paper cites Ahmed Salem, Rui Wen, Michael Backes, Shiqing Ma, and Yang Zhang.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models Ahmed Salem, Rui Wen, Michael Backes, Shiqing Ma, and Yang Zhang

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-12T20:37:30.356662Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T20:37:30.356662Z digest=sha256:dd2c91fad570467af4adffc638b41a03e368d270b40c6deea2940ec4111cd801

Observation 29733a22-01fd-436a-86eb-be433844e126 · outbound

This paper cites Label-Consistent Backdoor Attacks.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models Label-Consistent Backdoor Attacks

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-12T20:37:30.362103Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T20:37:30.362103Z digest=sha256:b5fd30be9fcb75194a264cc63b1c01fdd319e7d6ec76ba4f87c88152d64ce8df

Observation 420f4d28-13c0-464d-af54-b4d40012af5b · outbound

This paper cites Bppattack: Stealthy and efficient trojan attacks against deep neural networks via image quantization and contrastive adversarial learning.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models Bppattack: Stealthy and efficient trojan attacks against deep neural networks via image quantization and contrastive adversarial learning

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T20:37:30.716007Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T20:37:30.367039Z digest=sha256:4de944449806940bf446842ac7bbe9e7e72639913764da6b97c3c25921aaf955

Observation 1b775c48-542a-44ab-b238-19f3177d5984 · outbound

This paper cites Section A details the implementation and configurations of the experiments.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models Section A details the implementation and configurations of the experiments

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T20:37:30.700797Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T20:37:30.371795Z digest=sha256:8e80cb9f09f76ec86665a46d0f4573c159f8b56149609847a402e01dd9efc2d5

Observation e8c55985-593c-41bb-a148-09f1180a73f6 · outbound

This paper cites • Poison rate: The proportion of training data with the trigger pattern.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models • Poison rate: The proportion of training data with the trigger pattern

Reference 13

Resolution
malformed identifier
raw_fallback, observed 2026-08-12T20:37:30.684951Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T20:37:30.376699Z digest=sha256:59c15c80e2c3b8b841544485ca065b0bf629bf5d21aa0c1b562de893e4fbfc65

Observation fd0e8fda-b61f-4706-ba54-347ff3ccf7ce · outbound

This paper cites (2018) 0.952 0.047 0.952 0.115 0.240 0.952 0.551 SS (Tran et al.,.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models (2018) 0.952 0.047 0.952 0.115 0.240 0.952 0.551 SS (Tran et al.,

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T20:37:30.620980Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T20:37:30.396366Z digest=sha256:4f4c4dd788a372f1fd75eee226498aa3e0f387fcafd73585d991589e4f234167

Observation 017a04d4-5af8-45fd-9e3e-f275ef69be5d · outbound

This paper cites an unresolved cited work.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models Unresolved cited work

Reference 18

Resolution
unresolved
raw_fallback, observed 2026-08-12T20:37:30.603129Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T20:37:30.401170Z digest=sha256:0bace668c0138b305d32c719353eaeac6ce301ab9a9cc67af81fb1736e9e5233

Observation dbdc7220-82d1-4e20-9629-17a8a3cb3cc7 · outbound

This paper cites We analyze the impact of the reserved clean dataset size (DS) on BPROM’s performance.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models We analyze the impact of the reserved clean dataset size (DS) on BPROM’s performance

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T20:37:30.587650Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T20:37:30.405790Z digest=sha256:1ca60baeb6c96c952c3bc1d71a048745022bc8409b53c4a704d3640f01cd6ba5

Observation c7f342f8-7134-4a92-8ad9-d12a98fd607c · outbound

This paper cites 4https://github.com/vtu81/backdoor-toolbox 16 This paper has been accepted by IEEE/IFIP DSN 2025 • SCAn (Tang et al., 2021): Threshold for abnormal score = 0.5.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models 4https://github.com/vtu81/backdoor-toolbox 16 This paper has been accepted by IEEE/IFIP DSN 2025 • SCAn (Tang et al., 2021): Threshold for abnormal score = 0.5

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T20:37:30.668772Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T20:37:30.381795Z digest=sha256:3ef3b359f39ff4c7c42a1f99ece76b4bd5785144120cf716a142ade14f85c221

Observation 39f380e8-1769-4e33-90e8-ca1fc12f8453 · outbound

This paper cites (2018) cifar10 0.5002 0.3902 0.3745 0.5145 0.6154 0.3801 0.3977 0.4532 gtsrb 0.4925 0.4987 0.4925 0.4925 0.4966 0.4961 0.4929 0.4945 SCAn (Tang et al.,.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models (2018) cifar10 0.5002 0.3902 0.3745 0.5145 0.6154 0.3801 0.3977 0.4532 gtsrb 0.4925 0.4987 0.4925 0.4925 0.4966 0.4961 0.4929 0.4945 SCAn (Tang et al.,

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T20:37:30.571641Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T20:37:30.410378Z digest=sha256:d4bce8fc35d2c26147f1672dd825ed1180c135b75103c4171ba960f491714cf6

Observation 1f56c14e-1da1-42a8-b1ba-4013e47b555b · outbound

This paper cites The same meta-model is also used to classify clean (green dots) and Adap-Blend-infected models (red dots) Qi et al.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models The same meta-model is also used to classify clean (green dots) and Adap-Blend-infected models (red dots) Qi et al

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T20:37:30.555696Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T20:37:30.415497Z digest=sha256:e8d423b26bb55cb6d5d6ca5df2ac41d84702d7f142a37ecbeffb1fc98b32bd6b

Observation 9da795cc-2f24-4dc3-957b-b26e557020f7 · outbound

This paper cites (2018) cifar10 0.3877 0.3745 0.3753 0.2747 0.3749 0.3749 0.3913 0.3648 gtsrb 0.4961 0.4925 0.4946 0.4987 0.4925 0.4925 0.4925 0.4942 SCAn (Tang et al.,.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models (2018) cifar10 0.3877 0.3745 0.3753 0.2747 0.3749 0.3749 0.3913 0.3648 gtsrb 0.4961 0.4925 0.4946 0.4987 0.4925 0.4925 0.4925 0.4942 SCAn (Tang et al.,

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T20:37:30.539428Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T20:37:30.420221Z digest=sha256:c0562d7f2952ef94392d95cb856d4449a8d8e62c6b6e0c7ec6ac11fc98f9c715

Observation a3e35a1a-cfca-43b1-a615-433712bd7307 · outbound

This paper cites an unresolved cited work.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models Unresolved cited work

Reference 2011

Resolution
unresolved
raw_fallback, observed 2026-08-12T20:37:30.653468Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T20:37:30.386635Z digest=sha256:29758a9905a9e94e1683ff445d9a89ae2f8fc2be88024187191f43933dd49150

Observation 72edb3fb-1a3b-43b6-afcf-7862d5da19eb · outbound

This paper cites Neural attention distillation: Erasing backdoor triggers from deep neural networks.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models Neural attention distillation: Erasing backdoor triggers from deep neural networks

Reference 2015

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T20:37:30.746427Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T20:37:30.341530Z digest=sha256:e7cf4db04bfe12a7ef5e04930d959d3fbde66be540669b4bafafe3a40ba3c318

Observation 183ac8c2-5ae3-4841-8de3-6e99d87cdb42 · outbound

This paper cites Ranasinghe, and Hyoungshick Kim.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models Ranasinghe, and Hyoungshick Kim

Reference 2019

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T20:37:30.761130Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T20:37:30.331095Z digest=sha256:e738bdf10d4d26f6c587f4c581d94d0d8ef02c9370993989d40e30cd0de3a613

Observation 984e727b-ff2b-4839-9801-c3b3211acf0f · outbound

This paper cites To investigate the impact of inconsistency between the numbers of classes in DS and DT , we conducted experiments using CIFAR-100 as DS and STL-10 as DT.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models To investigate the impact of inconsistency between the numbers of classes in DS and DT , we conducted experiments using CIFAR-100 as DS and STL-10 as DT

Reference 2020

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T20:37:30.637455Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T20:37:30.391701Z digest=sha256:d76a5787d828cf8915f1c6dbb39259658f9daccdcbb8142dc961ceb010b3db9a

Observation 18c59da8-f783-4ed7-840a-5f546082ef44 · outbound

This paper cites Deep Residual Learning for Image Recognition.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models Deep Residual Learning for Image Recognition

Reference 2021

Resolution
unresolved
no resolver link, observed 2026-08-12T20:37:30.336234Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T20:37:30.336234Z digest=sha256:07bc24ff4bcdad9a93df79c38ed6619af5d11ba6d333a14cca7f4748940043f0

Observation 63f8b906-cb34-4d5c-94f6-9fac315d5547 · outbound

This paper cites an unresolved cited work.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models Unresolved cited work

Reference 2022

Resolution
unresolved
no resolver link, observed 2026-08-12T20:37:30.346601Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T20:37:30.346601Z digest=sha256:bf1c1278055fcb03f85182e8c17e5a2fca9011e0eb221c9f7fce58a615169a50

Observation 0aad93cd-30a4-4d1c-aaf2-f4d8553ad722 · outbound

This paper cites Revisiting the assump- tion of latent separability for backdoor defenses.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models Revisiting the assump- tion of latent separability for backdoor defenses

Reference 2023

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T20:37:30.731059Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-12T20:37:30.351630Z digest=sha256:89b825ba162d7969d1d4c493fb3066a48dc7582903315be757fba292f65eb54d

Observation 5bfc539d-9e3e-49c2-a3ce-73e486e747c2 · outbound

This paper cites Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning.

Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-12T20:37:30.320604Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T20:37:30.320604Z digest=sha256:57c5c16e5d78a3916c8a5faf456d23ef1f730c10af3b9ad425c886b0caa968bf

Pith citing papers

Observation 2ea066c2-1397-45ab-8bca-43269cf8597d · inbound

On Understanding, Identifying, and Mitigating Vulnerabilities in Agentic Large Language Models cites this paper.

On Understanding, Identifying, and Mitigating Vulnerabilities in Agentic Large Language Models Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models

Reference 59

Resolution
verified exact
local_arxiv, observed 2026-08-15T14:23:33.257433Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.

source=pdf_text observed=2026-08-15T14:21:42.130463Z digest=sha256:8f2fc7f18c4ae36cf925787b958b5261073fc625003d50a4dd22c124fc89ec89