{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:UUKNPT22KNHQIW6ZBRKVOKLB7H","short_pith_number":"pith:UUKNPT22","canonical_record":{"source":{"id":"1712.05526","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-12-15T04:26:26Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"3b3a93952bb15be6868655fbe357bf682e384148cdd671f839d8e05d15e044d4","abstract_canon_sha256":"97e573e4a703a1f54ddb68b78d1d4f418db6a939dc53f98a6f11c566fbc481d4"},"schema_version":"1.0"},"canonical_sha256":"a514d7cf5a534f045bd90c55572961f9cd906a9875384f56939c032093e542b5","source":{"kind":"arxiv","id":"1712.05526","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1712.05526","created_at":"2026-05-18T03:17:11Z"},{"alias_kind":"arxiv_version","alias_value":"1712.05526v1","created_at":"2026-05-18T03:17:11Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1712.05526","created_at":"2026-05-18T03:17:11Z"},{"alias_kind":"pith_short_12","alias_value":"UUKNPT22KNHQ","created_at":"2026-05-18T12:31:49Z"},{"alias_kind":"pith_short_16","alias_value":"UUKNPT22KNHQIW6Z","created_at":"2026-05-18T12:31:49Z"},{"alias_kind":"pith_short_8","alias_value":"UUKNPT22","created_at":"2026-05-18T12:31:49Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:UUKNPT22KNHQIW6ZBRKVOKLB7H","target":"record","payload":{"canonical_record":{"source":{"id":"1712.05526","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-12-15T04:26:26Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"3b3a93952bb15be6868655fbe357bf682e384148cdd671f839d8e05d15e044d4","abstract_canon_sha256":"97e573e4a703a1f54ddb68b78d1d4f418db6a939dc53f98a6f11c566fbc481d4"},"schema_version":"1.0"},"canonical_sha256":"a514d7cf5a534f045bd90c55572961f9cd906a9875384f56939c032093e542b5","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T03:17:11.272186Z","signature_b64":"Asd9a+bH69yo4SRsenM6B8M6jeaNJeqoVREQsYAjGImx7w6gP/IOllvD/bY0ef32yZEaI6Di9PDjUirkAaJUBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a514d7cf5a534f045bd90c55572961f9cd906a9875384f56939c032093e542b5","last_reissued_at":"2026-05-18T03:17:11.271452Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T03:17:11.271452Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1712.05526","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T03:17:11Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"MeX5sMqoIsDFFtVzREFStUdOq5KSZcS2MTYXSG+Ii6OGHeWpBpcmWNz2uJSZIJMKkeCJK6ZlLivmP62yl8l8Cw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-24T12:30:47.506149Z"},"content_sha256":"8b5f3723ca931bee95d3b4af1bf523d691344d38b8d0200928cbc0d7b187a316","schema_version":"1.0","event_id":"sha256:8b5f3723ca931bee95d3b4af1bf523d691344d38b8d0200928cbc0d7b187a316"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:UUKNPT22KNHQIW6ZBRKVOKLB7H","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"A backdoor adversary can inject only around 50 poisoning samples to achieve over 90 percent attack success rate in deep learning systems.","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Bo Li, Chang Liu, Dawn Song, Kimberly Lu, Xinyun Chen","submitted_at":"2017-12-15T04:26:26Z","abstract_excerpt":"Deep learning models have achieved high performance on many tasks, and thus have been applied to many security-critical scenarios. For example, deep learning-based face recognition systems have been used to authenticate users to access many security-sensitive applications like payment apps. Such usages of deep learning systems provide the adversaries with sufficient incentives to perform attacks against these systems for their adversarial purposes. In this work, we consider a new type of attacks, called backdoor attacks, where the attacker's goal is to create a backdoor into a learning-based a"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"a backdoor adversary can inject only around 50 poisoning samples, while achieving an attack success rate of above 90%. We are also the first work to show that a data poisoning attack can create physically implementable backdoors without touching the training process.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"The victim training pipeline allows injection of a small number of poisoning samples and the model will learn the association between the imperceptible trigger and the target label from those samples alone.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"Injecting around 50 poisoned samples with a stealthy trigger creates backdoors in deep learning models achieving over 90% attack success under a weak threat model with no model or data knowledge required.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"A backdoor adversary can inject only around 50 poisoning samples to achieve over 90 percent attack success rate in deep learning systems.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"252fed86a52c6d83ee79b187b92242a2cb273dc0ff31998f73ceada7a06ad0e5"},"source":{"id":"1712.05526","kind":"arxiv","version":1},"verdict":{"id":"431a8827-2ecd-4be1-9c58-54290b8b06b2","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-14T00:33:42.984349Z","strongest_claim":"a backdoor adversary can inject only around 50 poisoning samples, while achieving an attack success rate of above 90%. We are also the first work to show that a data poisoning attack can create physically implementable backdoors without touching the training process.","one_line_summary":"Injecting around 50 poisoned samples with a stealthy trigger creates backdoors in deep learning models achieving over 90% attack success under a weak threat model with no model or data knowledge required.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"The victim training pipeline allows injection of a small number of poisoning samples and the model will learn the association between the imperceptible trigger and the target label from those samples alone.","pith_extraction_headline":"A backdoor adversary can inject only around 50 poisoning samples to achieve over 90 percent attack success rate in deep learning systems."},"references":{"count":74,"sample":[{"doi":"","year":2017,"title":"Available: https://www.tripwire.com/state-of-security/ security-data-protection/insider-threats-main-security-threat-2017/","work_id":"5282dafd-0c85-44f0-ab0f-c2f2694bf064","ref_index":1,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2015,"title":"Available: https://www.helpnetsecurity.com/2015/08/19/ the-insider-versus-the-outsider-who-poses-the-biggest-security-risk/","work_id":"30eb576c-08c2-428c-a833-e320259402ae","ref_index":2,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"Available: https://www.fastcompany.com/3065778/ baidu-says-new-face-recognition-can-replace-checking-ids-or-tickets","work_id":"e34e5d3a-8ce7-4cc8-a4e5-ee48becc62cd","ref_index":3,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2017,"title":"Available: https://www","work_id":"1301b3a5-aad9-49f2-b78e-86c73982469d","ref_index":4,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"Available: http://www.zdnet.com/article/ facial-recognition-technology-to-replace-passports-at-australian-airports","work_id":"aff6f845-7ad2-42fa-a68a-8a57b8b6625a","ref_index":5,"cited_arxiv_id":"","is_internal_anchor":false}],"resolved_work":74,"snapshot_sha256":"8696869fcdc28c181d5c45d8a5e1245f6abc0413d51e488f85eaab9282d59e50","internal_anchors":3},"formal_canon":{"evidence_count":1,"snapshot_sha256":"9b209a7962dcb52931b22c106ab9f5432d0c5757a643bc57ab58040d2cecdc02"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"431a8827-2ecd-4be1-9c58-54290b8b06b2"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T03:17:11Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ZoW9C+48F/dKum4XMF9gPZabb/2eUzuFKpcLEsRSK5jLp9PfYOybnCm27jHbegPbD6AGuKQV8Yz++DgJ2Ro+CQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-24T12:30:47.506695Z"},"content_sha256":"a1f28c92a0515bd71c62bc149e70487670197a88fc8f5f2cd57f2de76b07d233","schema_version":"1.0","event_id":"sha256:a1f28c92a0515bd71c62bc149e70487670197a88fc8f5f2cd57f2de76b07d233"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/UUKNPT22KNHQIW6ZBRKVOKLB7H/bundle.json","state_url":"https://pith.science/pith/UUKNPT22KNHQIW6ZBRKVOKLB7H/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/UUKNPT22KNHQIW6ZBRKVOKLB7H/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-24T12:30:47Z","links":{"resolver":"https://pith.science/pith/UUKNPT22KNHQIW6ZBRKVOKLB7H","bundle":"https://pith.science/pith/UUKNPT22KNHQIW6ZBRKVOKLB7H/bundle.json","state":"https://pith.science/pith/UUKNPT22KNHQIW6ZBRKVOKLB7H/state.json","well_known_bundle":"https://pith.science/.well-known/pith/UUKNPT22KNHQIW6ZBRKVOKLB7H/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:UUKNPT22KNHQIW6ZBRKVOKLB7H","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"97e573e4a703a1f54ddb68b78d1d4f418db6a939dc53f98a6f11c566fbc481d4","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-12-15T04:26:26Z","title_canon_sha256":"3b3a93952bb15be6868655fbe357bf682e384148cdd671f839d8e05d15e044d4"},"schema_version":"1.0","source":{"id":"1712.05526","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1712.05526","created_at":"2026-05-18T03:17:11Z"},{"alias_kind":"arxiv_version","alias_value":"1712.05526v1","created_at":"2026-05-18T03:17:11Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1712.05526","created_at":"2026-05-18T03:17:11Z"},{"alias_kind":"pith_short_12","alias_value":"UUKNPT22KNHQ","created_at":"2026-05-18T12:31:49Z"},{"alias_kind":"pith_short_16","alias_value":"UUKNPT22KNHQIW6Z","created_at":"2026-05-18T12:31:49Z"},{"alias_kind":"pith_short_8","alias_value":"UUKNPT22","created_at":"2026-05-18T12:31:49Z"}],"graph_snapshots":[{"event_id":"sha256:a1f28c92a0515bd71c62bc149e70487670197a88fc8f5f2cd57f2de76b07d233","target":"graph","created_at":"2026-05-18T03:17:11Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"a backdoor adversary can inject only around 50 poisoning samples, while achieving an attack success rate of above 90%. We are also the first work to show that a data poisoning attack can create physically implementable backdoors without touching the training process."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"The victim training pipeline allows injection of a small number of poisoning samples and the model will learn the association between the imperceptible trigger and the target label from those samples alone."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"Injecting around 50 poisoned samples with a stealthy trigger creates backdoors in deep learning models achieving over 90% attack success under a weak threat model with no model or data knowledge required."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"A backdoor adversary can inject only around 50 poisoning samples to achieve over 90 percent attack success rate in deep learning systems."}],"snapshot_sha256":"252fed86a52c6d83ee79b187b92242a2cb273dc0ff31998f73ceada7a06ad0e5"},"formal_canon":{"evidence_count":1,"snapshot_sha256":"9b209a7962dcb52931b22c106ab9f5432d0c5757a643bc57ab58040d2cecdc02"},"paper":{"abstract_excerpt":"Deep learning models have achieved high performance on many tasks, and thus have been applied to many security-critical scenarios. For example, deep learning-based face recognition systems have been used to authenticate users to access many security-sensitive applications like payment apps. Such usages of deep learning systems provide the adversaries with sufficient incentives to perform attacks against these systems for their adversarial purposes. In this work, we consider a new type of attacks, called backdoor attacks, where the attacker's goal is to create a backdoor into a learning-based a","authors_text":"Bo Li, Chang Liu, Dawn Song, Kimberly Lu, Xinyun Chen","cross_cats":["cs.LG"],"headline":"A backdoor adversary can inject only around 50 poisoning samples to achieve over 90 percent attack success rate in deep learning systems.","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-12-15T04:26:26Z","title":"Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning"},"references":{"count":74,"internal_anchors":3,"resolved_work":74,"sample":[{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":1,"title":"Available: https://www.tripwire.com/state-of-security/ security-data-protection/insider-threats-main-security-threat-2017/","work_id":"5282dafd-0c85-44f0-ab0f-c2f2694bf064","year":2017},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":2,"title":"Available: https://www.helpnetsecurity.com/2015/08/19/ the-insider-versus-the-outsider-who-poses-the-biggest-security-risk/","work_id":"30eb576c-08c2-428c-a833-e320259402ae","year":2015},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":3,"title":"Available: https://www.fastcompany.com/3065778/ baidu-says-new-face-recognition-can-replace-checking-ids-or-tickets","work_id":"e34e5d3a-8ce7-4cc8-a4e5-ee48becc62cd","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":4,"title":"Available: https://www","work_id":"1301b3a5-aad9-49f2-b78e-86c73982469d","year":2017},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":5,"title":"Available: http://www.zdnet.com/article/ facial-recognition-technology-to-replace-passports-at-australian-airports","work_id":"aff6f845-7ad2-42fa-a68a-8a57b8b6625a","year":null}],"snapshot_sha256":"8696869fcdc28c181d5c45d8a5e1245f6abc0413d51e488f85eaab9282d59e50"},"source":{"id":"1712.05526","kind":"arxiv","version":1},"verdict":{"created_at":"2026-05-14T00:33:42.984349Z","id":"431a8827-2ecd-4be1-9c58-54290b8b06b2","model_set":{"reader":"grok-4.3"},"one_line_summary":"Injecting around 50 poisoned samples with a stealthy trigger creates backdoors in deep learning models achieving over 90% attack success under a weak threat model with no model or data knowledge required.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"A backdoor adversary can inject only around 50 poisoning samples to achieve over 90 percent attack success rate in deep learning systems.","strongest_claim":"a backdoor adversary can inject only around 50 poisoning samples, while achieving an attack success rate of above 90%. We are also the first work to show that a data poisoning attack can create physically implementable backdoors without touching the training process.","weakest_assumption":"The victim training pipeline allows injection of a small number of poisoning samples and the model will learn the association between the imperceptible trigger and the target label from those samples alone."}},"verdict_id":"431a8827-2ecd-4be1-9c58-54290b8b06b2"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:8b5f3723ca931bee95d3b4af1bf523d691344d38b8d0200928cbc0d7b187a316","target":"record","created_at":"2026-05-18T03:17:11Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"97e573e4a703a1f54ddb68b78d1d4f418db6a939dc53f98a6f11c566fbc481d4","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-12-15T04:26:26Z","title_canon_sha256":"3b3a93952bb15be6868655fbe357bf682e384148cdd671f839d8e05d15e044d4"},"schema_version":"1.0","source":{"id":"1712.05526","kind":"arxiv","version":1}},"canonical_sha256":"a514d7cf5a534f045bd90c55572961f9cd906a9875384f56939c032093e542b5","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a514d7cf5a534f045bd90c55572961f9cd906a9875384f56939c032093e542b5","first_computed_at":"2026-05-18T03:17:11.271452Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T03:17:11.271452Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Asd9a+bH69yo4SRsenM6B8M6jeaNJeqoVREQsYAjGImx7w6gP/IOllvD/bY0ef32yZEaI6Di9PDjUirkAaJUBA==","signature_status":"signed_v1","signed_at":"2026-05-18T03:17:11.272186Z","signed_message":"canonical_sha256_bytes"},"source_id":"1712.05526","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:8b5f3723ca931bee95d3b4af1bf523d691344d38b8d0200928cbc0d7b187a316","sha256:a1f28c92a0515bd71c62bc149e70487670197a88fc8f5f2cd57f2de76b07d233"],"state_sha256":"56959ee56ee28a765e3a3f4d8e2009ce7fb30dac2091b2586edf428e46cbb1aa"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Ayp0cDgchu7GQj6dftB6wvdunRLQ5JsbJPw+0y8Y3K/EIEnd8oEjhOGbyxMtsMjyqF0f87VM3/ETLJlAlPAAAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-24T12:30:47.509046Z","bundle_sha256":"e4849cbc0a097e9499c7202fd2cdb51a9e0e1c1b1ac3ae8ca4f9f96edd33230e"}}