{"as_of":"2026-08-17T07:17:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:2ba0b64021272d15d98964690f8d34fa9c1f6dabe8563fa907b65fddccb9db0f","coverage":[{"denominator":22,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":22,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-12T20:37:30.420221Z","state":"measured"},{"denominator":23,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":23,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-17T06:30:58.91139+00:00","state":"measured"},{"denominator":1,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":1,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-15T14:21:42.130463Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"pith","source_observed_at":"2026-08-15T18:16:14.067578Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"cited_work":{"arxiv_id":"2411.09540","doi":"10.48550/arxiv.2411.09540","metadata_source":"pith","pith_arxiv_id":"2411.09540","snapshot_observed_at":"2026-08-15T18:16:14.067578Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","venue":"cs.CV","work_id":"34e88cb7-aab0-41be-a0f0-135356eee40b","year":2024},"citing_paper":{"arxiv_id":"2608.10530","last_updated":"2026-08-11T06:11:26Z","snapshot_observed_at":"2026-08-16T10:11:08.317968Z","submitted_at":"2026-08-11T06:11:26Z","title":"On Understanding, Identifying, and Mitigating Vulnerabilities in Agentic Large Language Models","version":1},"reference_index":59,"source":"pdf_text","source_observed_at":"2026-08-15T14:21:42.130463Z"},"links":{"cited_paper":"/paper/2411.09540","citing_paper":"/paper/2608.10530"},"observation_digest":"sha256:8f2fc7f18c4ae36cf925787b958b5261073fc625003d50a4dd22c124fc89ec89","observation_id":"2ea066c2-1397-45ab-8bca-43269cf8597d","resolution":{"observed_at":"2026-08-15T14:23:33.257433Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2411.09540/citation-record","integrity":"/paper/2411.09540/integrity","json":"/paper/2411.09540/citation-record.json","paper":"/paper/2411.09540"},"outbound":[{"citation":{"cited_paper":{"arxiv_id":"2203.17274","last_updated":"2022-06-03T17:52:04Z","snapshot_observed_at":"2026-08-16T17:10:09.647539Z","submitted_at":"2022-03-31T17:59:30Z","title":"Exploring Visual Prompts for Adapting Large-Scale Models","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2203.17274","snapshot_observed_at":"2026-08-12T20:37:30.314630Z","title":"Visual prompting: Modify- ing pixel space to adapt pre-trained models","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.314630Z"},"links":{"cited_paper":"/paper/2203.17274","citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:6edbbbb6de9664d076c213581ba102b4df5006c097f9f889fc2193063e312d08","observation_id":"2ce0235c-986a-4280-a380-bb6f62527311","resolution":{"observed_at":"2026-08-12T20:37:30.314630Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.771368Z","title":"Sentinet: Detecting localized universal attacks against deep learning systems","venue":null,"work_id":"9b7c6265-143a-4a3a-b985-549f3d38057f","year":2020},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.325892Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:580ad02b97275db12218dd635149c6428351850b13fe4192b9a232c4b4f7bf09","observation_id":"3239486f-351a-4bcd-a086-d671c8895aa2","resolution":{"observed_at":"2026-08-12T20:37:30.776428Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.356662Z","title":"Ahmed Salem, Rui Wen, Michael Backes, Shiqing Ma, and Yang Zhang","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.356662Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:dd2c91fad570467af4adffc638b41a03e368d270b40c6deea2940ec4111cd801","observation_id":"64d2809e-eede-4e73-913d-ffd7378cdd9c","resolution":{"observed_at":"2026-08-12T20:37:30.356662Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1912.02771","last_updated":"2019-12-06T23:16:45Z","snapshot_observed_at":"2026-08-10T18:11:31.253134Z","submitted_at":"2019-12-05T18:05:59Z","title":"Label-Consistent Backdoor Attacks","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1912.02771","snapshot_observed_at":"2026-08-12T20:37:30.362103Z","title":"14 This paper has been accepted by IEEE/IFIP DSN 2025 Bolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li, Bimal Viswanath, Haitao Zheng, and Ben Y","venue":null,"work_id":null,"year":1912},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.362103Z"},"links":{"cited_paper":"/paper/1912.02771","citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:b5fd30be9fcb75194a264cc63b1c01fdd319e7d6ec76ba4f87c88152d64ce8df","observation_id":"29733a22-01fd-436a-86eb-be433844e126","resolution":{"observed_at":"2026-08-12T20:37:30.362103Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.710944Z","title":"Bppattack: Stealthy and efficient trojan attacks against deep neural networks via image quantization and contrastive adversarial learning","venue":null,"work_id":"dee1fdb6-e8b0-4687-9a0f-23254e5cd45c","year":2022},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.367039Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:4de944449806940bf446842ac7bbe9e7e72639913764da6b97c3c25921aaf955","observation_id":"420f4d28-13c0-464d-af54-b4d40012af5b","resolution":{"observed_at":"2026-08-12T20:37:30.716007Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.695684Z","title":"Section A details the implementation and configurations of the experiments","venue":null,"work_id":"b8579c12-64ba-47c4-a956-485ecf272791","year":2025},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.371795Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:8e80cb9f09f76ec86665a46d0f4573c159f8b56149609847a402e01dd9efc2d5","observation_id":"1b775c48-542a-44ab-b238-19f3177d5984","resolution":{"observed_at":"2026-08-12T20:37:30.700797Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.679133Z","title":"• Poison rate: The proportion of training data with the trigger pattern","venue":null,"work_id":"1b0f46ea-4a8a-4863-b44f-93d706db3e33","year":2017},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.376699Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:59c15c80e2c3b8b841544485ca065b0bf629bf5d21aa0c1b562de893e4fbfc65","observation_id":"e8c55985-593c-41bb-a148-09f1180a73f6","resolution":{"observed_at":"2026-08-12T20:37:30.684951Z","resolver_source":"raw_fallback","status":"malformed_identifier"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.615096Z","title":"(2018) 0.952 0.047 0.952 0.115 0.240 0.952 0.551 SS (Tran et al.,","venue":null,"work_id":"d13fd933-607b-41ef-9106-d25419272e31","year":2018},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.396366Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:4f4c4dd788a372f1fd75eee226498aa3e0f387fcafd73585d991589e4f234167","observation_id":"fd0e8fda-b61f-4706-ba54-347ff3ccf7ce","resolution":{"observed_at":"2026-08-12T20:37:30.620980Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.598099Z","title":null,"venue":null,"work_id":"8d394a3f-fa67-4b7b-9034-b7eef32f9a80","year":2020},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.401170Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:0bace668c0138b305d32c719353eaeac6ce301ab9a9cc67af81fb1736e9e5233","observation_id":"017a04d4-5af8-45fd-9e3e-f275ef69be5d","resolution":{"observed_at":"2026-08-12T20:37:30.603129Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.582430Z","title":"We analyze the impact of the reserved clean dataset size (DS) on BPROM’s performance","venue":null,"work_id":"de65ec46-5156-4cc4-9824-0247386b8822","year":2018},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.405790Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:1ca60baeb6c96c952c3bc1d71a048745022bc8409b53c4a704d3640f01cd6ba5","observation_id":"dbdc7220-82d1-4e20-9629-17a8a3cb3cc7","resolution":{"observed_at":"2026-08-12T20:37:30.587650Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.663888Z","title":"4https://github.com/vtu81/backdoor-toolbox 16 This paper has been accepted by IEEE/IFIP DSN 2025 • SCAn (Tang et al., 2021): Threshold for abnormal score = 0.5","venue":null,"work_id":"e5109ede-0784-4d78-a1c9-ee8de040ef76","year":2018},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.381795Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:3ef3b359f39ff4c7c42a1f99ece76b4bd5785144120cf716a142ade14f85c221","observation_id":"c7f342f8-7134-4a92-8ad9-d12a98fd607c","resolution":{"observed_at":"2026-08-12T20:37:30.668772Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.566640Z","title":"(2018) cifar10 0.5002 0.3902 0.3745 0.5145 0.6154 0.3801 0.3977 0.4532 gtsrb 0.4925 0.4987 0.4925 0.4925 0.4966 0.4961 0.4929 0.4945 SCAn (Tang et al.,","venue":null,"work_id":"712f1c17-5faa-40af-9263-3c8cf0169ecb","year":2018},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.410378Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:d4bce8fc35d2c26147f1672dd825ed1180c135b75103c4171ba960f491714cf6","observation_id":"39f380e8-1769-4e33-90e8-ca1fc12f8453","resolution":{"observed_at":"2026-08-12T20:37:30.571641Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.550325Z","title":"The same meta-model is also used to classify clean (green dots) and Adap-Blend-infected models (red dots) Qi et al","venue":null,"work_id":"c2ed3747-affa-4ad6-bc8e-2b53dc011576","year":2023},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.415497Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:e8d423b26bb55cb6d5d6ca5df2ac41d84702d7f142a37ecbeffb1fc98b32bd6b","observation_id":"1f56c14e-1da1-42a8-b1ba-4013e47b555b","resolution":{"observed_at":"2026-08-12T20:37:30.555696Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.533482Z","title":"(2018) cifar10 0.3877 0.3745 0.3753 0.2747 0.3749 0.3749 0.3913 0.3648 gtsrb 0.4961 0.4925 0.4946 0.4987 0.4925 0.4925 0.4925 0.4942 SCAn (Tang et al.,","venue":null,"work_id":"d537e8a3-56f0-4d84-9319-51163591088c","year":2018},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.420221Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:c0562d7f2952ef94392d95cb856d4449a8d8e62c6b6e0c7ec6ac11fc98f9c715","observation_id":"9da795cc-2f24-4dc3-957b-b26e557020f7","resolution":{"observed_at":"2026-08-12T20:37:30.539428Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.648718Z","title":null,"venue":null,"work_id":"322644b6-e427-446e-8d85-bfc939fd3176","year":2017},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":2011,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.386635Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:29758a9905a9e94e1683ff445d9a89ae2f8fc2be88024187191f43933dd49150","observation_id":"a3e35a1a-cfca-43b1-a615-433712bd7307","resolution":{"observed_at":"2026-08-12T20:37:30.653468Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.740512Z","title":"Neural attention distillation: Erasing backdoor triggers from deep neural networks","venue":null,"work_id":"bcd5cb84-2058-4a92-ba85-a7d5b3105595","year":2025},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":2015,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.341530Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:e7cf4db04bfe12a7ef5e04930d959d3fbde66be540669b4bafafe3a40ba3c318","observation_id":"72edb3fb-1a3b-43b6-afcf-7862d5da19eb","resolution":{"observed_at":"2026-08-12T20:37:30.746427Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.756429Z","title":"Ranasinghe, and Hyoungshick Kim","venue":null,"work_id":"f0e44148-3c26-4720-90a0-ff90c45f0bdb","year":2025},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":2019,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.331095Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:e738bdf10d4d26f6c587f4c581d94d0d8ef02c9370993989d40e30cd0de3a613","observation_id":"183ac8c2-5ae3-4841-8de3-6e99d87cdb42","resolution":{"observed_at":"2026-08-12T20:37:30.761130Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.632312Z","title":"To investigate the impact of inconsistency between the numbers of classes in DS and DT , we conducted experiments using CIFAR-100 as DS and STL-10 as DT","venue":null,"work_id":"5bc88384-0d28-4737-a4ad-b84cde0684e5","year":2025},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":2020,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.391701Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:d76a5787d828cf8915f1c6dbb39259658f9daccdcbb8142dc961ceb010b3db9a","observation_id":"984e727b-ff2b-4839-9801-c3b3211acf0f","resolution":{"observed_at":"2026-08-12T20:37:30.637455Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1512.03385","last_updated":"2015-12-10T19:51:55Z","snapshot_observed_at":"2026-07-06T04:39:28.429064Z","submitted_at":"2015-12-10T19:51:55Z","title":"Deep Residual Learning for Image Recognition","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1512.03385","snapshot_observed_at":"2026-08-12T20:37:30.336234Z","title":"Deep residual learning for image recognition","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":2021,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.336234Z"},"links":{"cited_paper":"/paper/1512.03385","citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:07bc24ff4bcdad9a93df79c38ed6619af5d11ba6d333a14cca7f4748940043f0","observation_id":"18c59da8-f783-4ed7-840a-5f546082ef44","resolution":{"observed_at":"2026-08-12T20:37:30.336234Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.346601Z","title":null,"venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":2022,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.346601Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:bf1c1278055fcb03f85182e8c17e5a2fca9011e0eb221c9f7fce58a615169a50","observation_id":"63f8b906-cb34-4d5c-94f6-9fac315d5547","resolution":{"observed_at":"2026-08-12T20:37:30.346601Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T20:37:30.726261Z","title":"Revisiting the assump- tion of latent separability for backdoor defenses","venue":null,"work_id":"91123896-6e90-4ab4-a114-1710ff88e059","year":2025},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":2023,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.351630Z"},"links":{"citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:89b825ba162d7969d1d4c493fb3066a48dc7582903315be757fba292f65eb54d","observation_id":"0aad93cd-30a4-4d1c-aaf2-f4d8553ad722","resolution":{"observed_at":"2026-08-12T20:37:30.731059Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1712.05526","last_updated":"2017-12-15T04:26:26Z","snapshot_observed_at":"2026-07-06T06:14:30.795326Z","submitted_at":"2017-12-15T04:26:26Z","title":"Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1712.05526","snapshot_observed_at":"2026-08-12T20:37:30.320604Z","title":"Targeted backdoor attacks on deep learning systems using data poisoning","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models","version":2},"reference_index":2024,"source":"pdf_text","source_observed_at":"2026-08-12T20:37:30.320604Z"},"links":{"cited_paper":"/paper/1712.05526","citing_paper":"/paper/2411.09540"},"observation_digest":"sha256:57c5c16e5d78a3916c8a5faf456d23ef1f730c10af3b9ad425c886b0caa968bf","observation_id":"5bfc539d-9e3e-49c2-a3ce-73e486e747c2","resolution":{"observed_at":"2026-08-12T20:37:30.320604Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"paper":{"arxiv_id":"2411.09540","last_updated":"2025-04-07T08:55:40Z","latest_version":2,"primary_category":"cs.CV","snapshot_observed_at":"2026-08-16T02:04:08.340199Z","submitted_at":"2024-11-14T15:56:11Z","title":"Prompting the Unseen: Detecting Hidden Backdoors in Black-Box Models"},"reference_resolution":{"displayed":22,"state_counts":{"malformed_identifier":1,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":8,"verified_exact":0,"verified_fuzzy":13},"total_outbound_references":22},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"thesis":"As of 17 August 2026, this Paper Citation Record lists 22 of 22 outbound references and 1 inbound Pith citation observation for arXiv:2411.09540."}