{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:ZXKCAV4G4VT3LFAVCDH6TUNJB4","short_pith_number":"pith:ZXKCAV4G","schema_version":"1.0","canonical_sha256":"cdd4205786e567b5941510cfe9d1a90f027d744847e8863ea189c1449a1d2a8b","source":{"kind":"arxiv","id":"2105.00164","version":3},"attestation_state":"computed","paper":{"title":"Hidden Backdoors in Human-Centric Language Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.CL","authors_text":"Benjamin Zi Hao Zhao, Haojin Zhu, Hui Liu, Jialiang Lu, Minhui Xue, Shaofeng Li, Tian Dong","submitted_at":"2021-05-01T04:41:00Z","abstract_excerpt":"Natural language processing (NLP) systems have been proven to be vulnerable to backdoor attacks, whereby hidden features (backdoors) are trained into a language model and may only be activated by specific inputs (called triggers), to trick the model into producing unexpected behaviors. In this paper, we create covert and natural triggers for textual backdoor attacks, \\textit{hidden backdoors}, where triggers can fool both modern language models and human inspection. We deploy our hidden backdoors through two state-of-the-art trigger embedding methods. The first approach via homograph replaceme"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2105.00164","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2021-05-01T04:41:00Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"ddb7b94a6531a6afaf170074aa5614ded6a3d188023ccff65476979f1bb67bb3","abstract_canon_sha256":"25cd97bacf488d1597f822a8dc6f283f67a7146f802a79162825e40636add160"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T03:17:50.636682Z","signature_b64":"GepRYtwicTgHFT2onSHndqx+9sXj9kunXSTy5oJPhWL6rZhQxmKaiHbedqXH2rp4NeZTTEKIV9nZ+uozSI4QBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"cdd4205786e567b5941510cfe9d1a90f027d744847e8863ea189c1449a1d2a8b","last_reissued_at":"2026-07-05T03:17:50.636142Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T03:17:50.636142Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Hidden Backdoors in Human-Centric Language Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.CL","authors_text":"Benjamin Zi Hao Zhao, Haojin Zhu, Hui Liu, Jialiang Lu, Minhui Xue, Shaofeng Li, Tian Dong","submitted_at":"2021-05-01T04:41:00Z","abstract_excerpt":"Natural language processing (NLP) systems have been proven to be vulnerable to backdoor attacks, whereby hidden features (backdoors) are trained into a language model and may only be activated by specific inputs (called triggers), to trick the model into producing unexpected behaviors. In this paper, we create covert and natural triggers for textual backdoor attacks, \\textit{hidden backdoors}, where triggers can fool both modern language models and human inspection. We deploy our hidden backdoors through two state-of-the-art trigger embedding methods. The first approach via homograph replaceme"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2105.00164","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2105.00164/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2105.00164","created_at":"2026-07-05T03:17:50.636218+00:00"},{"alias_kind":"arxiv_version","alias_value":"2105.00164v3","created_at":"2026-07-05T03:17:50.636218+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2105.00164","created_at":"2026-07-05T03:17:50.636218+00:00"},{"alias_kind":"pith_short_12","alias_value":"ZXKCAV4G4VT3","created_at":"2026-07-05T03:17:50.636218+00:00"},{"alias_kind":"pith_short_16","alias_value":"ZXKCAV4G4VT3LFAV","created_at":"2026-07-05T03:17:50.636218+00:00"},{"alias_kind":"pith_short_8","alias_value":"ZXKCAV4G","created_at":"2026-07-05T03:17:50.636218+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2502.05224","citing_title":"A Survey on Backdoor Threats in Large Language Models (LLMs): Attacks, Defenses, and Evaluations","ref_index":123,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/ZXKCAV4G4VT3LFAVCDH6TUNJB4","json":"https://pith.science/pith/ZXKCAV4G4VT3LFAVCDH6TUNJB4.json","graph_json":"https://pith.science/api/pith-number/ZXKCAV4G4VT3LFAVCDH6TUNJB4/graph.json","events_json":"https://pith.science/api/pith-number/ZXKCAV4G4VT3LFAVCDH6TUNJB4/events.json","paper":"https://pith.science/paper/ZXKCAV4G"},"agent_actions":{"view_html":"https://pith.science/pith/ZXKCAV4G4VT3LFAVCDH6TUNJB4","download_json":"https://pith.science/pith/ZXKCAV4G4VT3LFAVCDH6TUNJB4.json","view_paper":"https://pith.science/paper/ZXKCAV4G","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2105.00164&json=true","fetch_graph":"https://pith.science/api/pith-number/ZXKCAV4G4VT3LFAVCDH6TUNJB4/graph.json","fetch_events":"https://pith.science/api/pith-number/ZXKCAV4G4VT3LFAVCDH6TUNJB4/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/ZXKCAV4G4VT3LFAVCDH6TUNJB4/action/timestamp_anchor","attest_storage":"https://pith.science/pith/ZXKCAV4G4VT3LFAVCDH6TUNJB4/action/storage_attestation","attest_author":"https://pith.science/pith/ZXKCAV4G4VT3LFAVCDH6TUNJB4/action/author_attestation","sign_citation":"https://pith.science/pith/ZXKCAV4G4VT3LFAVCDH6TUNJB4/action/citation_signature","submit_replication":"https://pith.science/pith/ZXKCAV4G4VT3LFAVCDH6TUNJB4/action/replication_record"}},"created_at":"2026-07-05T03:17:50.636218+00:00","updated_at":"2026-07-05T03:17:50.636218+00:00"}