{"id":"https://openalex.org/W7162111349","doi":"https://doi.org/10.48550/arxiv.2605.22481","title":"When Stronger Triggers Backfire: A High-Dimensional Theory of Backdoor Attacks","display_name":"When Stronger Triggers Backfire: A High-Dimensional Theory of Backdoor Attacks","publication_year":2026,"publication_date":"2026-05-21","ids":{"openalex":"https://openalex.org/W7162111349","doi":"https://doi.org/10.48550/arxiv.2605.22481"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2605.22481","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.22481","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2605.22481","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5136797441","display_name":"Donald Flynn","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Flynn, Donald","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5136807381","display_name":"Hadas Yaron Goldhirsh","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Goldhirsh, Hadas Yaron","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5136749438","display_name":"Jonathan P. Keating","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Keating, Jonathan P.","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5120369194","display_name":"Inbar Seroussi","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Seroussi, Inbar","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9861999750137329,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9861999750137329,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10917","display_name":"Smart Grid Security and Resilience","score":0.0038999998942017555,"subfield":{"id":"https://openalex.org/subfields/2207","display_name":"Control and Systems Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.0015999999595806003,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.8884999752044678},{"id":"https://openalex.org/keywords/noise","display_name":"Noise (video)","score":0.5224000215530396},{"id":"https://openalex.org/keywords/regular-polygon","display_name":"Regular polygon","score":0.49619999527931213},{"id":"https://openalex.org/keywords/gaussian","display_name":"Gaussian","score":0.4884999990463257},{"id":"https://openalex.org/keywords/statistical-hypothesis-testing","display_name":"Statistical hypothesis testing","score":0.40959998965263367},{"id":"https://openalex.org/keywords/gaussian-noise","display_name":"Gaussian noise","score":0.3765999972820282},{"id":"https://openalex.org/keywords/square","display_name":"Square (algebra)","score":0.3709999918937683}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.8884999752044678},{"id":"https://openalex.org/C99498987","wikidata":"https://www.wikidata.org/wiki/Q2210247","display_name":"Noise (video)","level":3,"score":0.5224000215530396},{"id":"https://openalex.org/C112680207","wikidata":"https://www.wikidata.org/wiki/Q714886","display_name":"Regular polygon","level":2,"score":0.49619999527931213},{"id":"https://openalex.org/C163716315","wikidata":"https://www.wikidata.org/wiki/Q901177","display_name":"Gaussian","level":2,"score":0.4884999990463257},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.4851999878883362},{"id":"https://openalex.org/C87007009","wikidata":"https://www.wikidata.org/wiki/Q210832","display_name":"Statistical hypothesis testing","level":2,"score":0.40959998965263367},{"id":"https://openalex.org/C4199805","wikidata":"https://www.wikidata.org/wiki/Q2725903","display_name":"Gaussian noise","level":2,"score":0.3765999972820282},{"id":"https://openalex.org/C135692309","wikidata":"https://www.wikidata.org/wiki/Q111124","display_name":"Square (algebra)","level":2,"score":0.3709999918937683},{"id":"https://openalex.org/C2777267654","wikidata":"https://www.wikidata.org/wiki/Q3519023","display_name":"Test (biology)","level":2,"score":0.34619998931884766},{"id":"https://openalex.org/C158693339","wikidata":"https://www.wikidata.org/wiki/Q190524","display_name":"Eigenvalues and eigenvectors","level":2,"score":0.34290000796318054},{"id":"https://openalex.org/C149782125","wikidata":"https://www.wikidata.org/wiki/Q160039","display_name":"Econometrics","level":1,"score":0.3212999999523163},{"id":"https://openalex.org/C28826006","wikidata":"https://www.wikidata.org/wiki/Q33521","display_name":"Applied mathematics","level":1,"score":0.3156000077724457},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.3021000027656555},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.29440000653266907},{"id":"https://openalex.org/C16910744","wikidata":"https://www.wikidata.org/wiki/Q7705759","display_name":"Test data","level":2,"score":0.28209999203681946},{"id":"https://openalex.org/C105795698","wikidata":"https://www.wikidata.org/wiki/Q12483","display_name":"Statistics","level":1,"score":0.2782999873161316},{"id":"https://openalex.org/C111110010","wikidata":"https://www.wikidata.org/wiki/Q2627315","display_name":"Convex combination","level":4,"score":0.2741999924182892},{"id":"https://openalex.org/C47446073","wikidata":"https://www.wikidata.org/wiki/Q5165890","display_name":"Control theory (sociology)","level":3,"score":0.2685000002384186},{"id":"https://openalex.org/C163175372","wikidata":"https://www.wikidata.org/wiki/Q3339222","display_name":"Linear model","level":2,"score":0.2680000066757202},{"id":"https://openalex.org/C28901747","wikidata":"https://www.wikidata.org/wiki/Q177571","display_name":"Decision theory","level":2,"score":0.2630999982357025}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2605.22481","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.22481","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2605.22481","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.22481","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Backdoor":[0],"poisoning":[1],"attacks":[2],"behave":[3],"counter-intuitively":[4],"in":[5,24,83],"high":[6],"dimensions:":[7],"stronger":[8],"training":[9,33],"triggers":[10],"can":[11],"help":[12],"the":[13,25,32,65,71,75,87,115,133,139,143],"defender.":[14],"We":[15,78,105],"study":[16],"regularised":[17],"generalised":[18],"linear":[19],"models":[20],"on":[21,127],"Gaussian-mixture":[22],"data":[23,76],"proportional":[26,111],"regime":[27],"($p/n":[28],"\\to":[29],"\u03ba$),":[30],"varying":[31],"trigger":[34,68],"strength":[35],"$\u03b1$":[36,59],"against":[37],"a":[38,57,101,107],"fixed":[39],"test":[40,47],"trigger.":[41],"Three":[42],"phenomena":[43,141],"emerge:":[44],"(i)":[45,92],"clean":[46],"accuracy":[48],"increases":[49],"with":[50],"$\u03b1$;":[51],"(ii)":[52,94],"attack":[53],"success":[54],"peaks":[55],"at":[56],"finite":[58],"and":[60,63,90,93,129],"then":[61],"declines;":[62],"(iii)":[64],"most":[66],"damaging":[67],"direction":[69],"is":[70],"minimum":[72],"eigenvector":[73],"of":[74],"covariance.":[77],"prove":[79],"all":[80],"three":[81],"results":[82],"closed":[84],"form":[85],"for":[86],"squared":[88],"loss,":[89],"extend":[91],"to":[95,112,120],"general":[96],"convex":[97,144],"GLM":[98],"losses":[99],"via":[100],"Gaussian-proxy":[102],"fixed-point":[103],"system.":[104],"identify":[106],"finite-sample":[108],"noise":[109],"floor":[110],"$\u03ba$":[113],"as":[114],"mechanism":[116],"behind":[117],"(i),":[118],"invisible":[119],"classical":[121],"$n":[122],"\\gg":[123],"p$":[124],"analysis.":[125],"Experiments":[126],"CIFAR-10":[128],"Gaussian":[130],"surrogates":[131],"match":[132],"theory":[134],"closely;":[135],"ResNet-18":[136],"experiments":[137],"show":[138],"same":[140],"beyond":[142],"setting.":[145]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-05-23T00:00:00"}
