[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82391-en":3,"doc-seo-82391-105":29,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},82391,1099514068365,"Aurelia","https://ap-avatar.wpscdn.com/avatar/10000253d8d9f28188e?_k=1776742907772140068",8,"Research & Report","Statistically Undetectable Backdoors in Deep Neural Networks","Statistically undetectable backdoors can be planted by an adversarial trainer in a large class of deep, feedforward neural networks. In a white-box setting, the resulting models remain close to honestly trained ones in total variation distance, even when all model descriptions (e.g., weights) are fully known. The backdoor grants invariance-based adversarial examples for every input by mapping distant inputs to unusually close outputs, while provably ruling them out in polynomial time without the backdoor under standard cryptographic assumptions. The work provides theoretical and preliminary empirical evidence of a fundamental power asymmetry between trainers and users.","arXiv :2607 .09532v 1 [ cs .LG] 10 Jul 2026  \nStatistically Undetectable Backdoors in Deep Neural Networks  \nAndrej Bogdanov∗ Alon Rosen† Neekon Vafa‡  \nAbstract  \nWe show how an adversarial model trainer can plant backdoors in a large class of deep, feedforward neural networks. These backdoors are statistically undetectable in the white-box setting, meaning that the backdoored and honestly trained models are close in total variation distance, even given the full descriptions of the models (e.g., all of the weights) . The backdoor provides access to invariance-based adversarial examples for every input, mapping distant inputs to unusually close outputs. However, without the backdoor, it is provably impossible (under standard cryptographic assumptions) to generate any such adversarial examples in polynomial time. Our theoretical and preliminary empirical findings demonstrate a fundamental power asymmetry between model trainers and model users.  \n∗ University [of Ottawa. abogdano@uottawa.ca](of Ottawa. abogdano@uottawa.ca).  \n†Bocconi University. [alon.rosen@unibocconi.it](alon.rosen@unibocconi.it).  \n‡Massachusetts Institute [of Technology. nvafa@mit.edu](of Technology. nvafa@mit.edu).  \nContents  \n1 Introduction 3  \n1.1 Our Results ......................................... 3  \n1.2 Interpretations ....................................... 6  \n1.3 Cryptographic Assumptions & The Johnson-Lindenstrauss Lemma .......... 7  \n1.4 Related Work ........................................ 8  \n2 Overview of Our Construction 9  \n2.1 Backdooring Gaussian Matrices .............................. 9  \n2.2 Concentration in the Number of Solutions ........................ 11  \n2.3 Backdoors in Neural Networks .............................. 12  \n3 Preliminaries 12  \n3.1 Divergences ......................................... 13  \n3.2 Number Balancing and Symmetric Binary Perceptrons ................. 14  \n4 Backdoors for Random Gaussian Projections 15  \n4.1 Sampling the Backdoor .................................. 16  \n4.2 Concentration in the Number of Solutions ........................ 18  \n4.3 Putting It All Together .................................. 22  \n4.4 Tightness .......................................... 23  \n5 Constructing Backdoors for Neural Networks 24  \n5.1 Defining Backdoors ..................................... 24  \n5.2 Neural Network Preliminaries ............................... 26  \n5.3 Construction ........................................ 27  \n5.4 Backdoors in Deep Neural Networks ........................... 30  \n6 Basic Implementation and Experiments 32  \n6.1 Proof of Concept Implementation ............................. 32  \n6.2 Computational Hardness of Collision Finding ...................... 33  \n7 Concluding Remarks 34  \n1 Introduction  \nRecent history has demonstrated the immense utility of deep neural networks (DNNs) . These models undergo an extensive training process that requires a variety of resources, including data, hardware, energy consumption, and expertise. Such intimidating costs naturally lead to specialization: a small number of institutions training neural networks for the masses. Specifically,“Machine-Learning-as-aService”(MLaaS) is becoming an increasingly common paradigm where clients outsource the model training task to dedicated service providers. Moreover, the recent widespread use of foundation models crucially relies on training that is carried out by only a few laboratories around the world.  \nHowever, this consolidation of training power raises serious trust concerns. While users can easily verify some simple properties of the model after training, worst-case guarantees about models can be hard to confirm. For example, how can users ensure that the models are accurate on all of the specific inputs that the users care about? Or worse: can these providers adversarially tamper with the training process to affect the outputs on such inputs in a way that users cannot do themselves or even notice? If such tamp","cbCaimVWB0zjlZ2d","https://ap.wps.com/l/cbCaimVWB0zjlZ2d","pdf",560623,1,41,"English","en",105,"# Introduction\n## Our Results\n## Interpretations\n## Cryptographic Assumptions & The Johnson-Lindenstrauss Lemma\n## Related Work\n# Overview of Our Construction\n## Backdooring Gaussian Matrices\n## Concentration in the Number of Solutions\n## Backdoors in Neural Networks\n# Preliminaries\n## Divergences\n## Number Balancing and Symmetric Binary Perceptrons\n# Backdoors for Random Gaussian Projections\n## Sampling the Backdoor\n## Putting It All Together\n# Constructing Backdoors for Neural Networks\n## Defining Backdoors\n## Construction\n## Backdoors in Deep Neural Networks\n# Basic Implementation and Experiments\n## Proof of Concept Implementation\n## Computational Hardness of Collision Finding\n# Concluding Remarks","[{\"question\":\"What does “statistically undetectable” mean in the document’s setting?\",\"answer\":\"The backdoored model and the honestly trained model are close in total variation distance in a white-box setting, even when the full model description (such as all weights) is known.\"},{\"question\":\"What type of adversarial behavior does the backdoor enable?\",\"answer\":\"It provides invariance-based adversarial examples, mapping distant inputs to unusually close outputs for every input.\"},{\"question\":\"Why are these adversarial examples infeasible without the backdoor?\",\"answer\":\"Without the backdoor, generating such adversarial examples is provably impossible in polynomial time under standard cryptographic assumptions.\"}]",1784180092,103,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":27},"statistically-undetectable-backdoors-in-deep-neural-networks","",{"@graph":35,"@context":85},[36,53,68],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/statistically-undetectable-backdoors-in-deep-neural-networks/82391/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-17","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What does “statistically undetectable” mean in the document’s setting?","Question",{"text":75,"@type":76},"The backdoored model and the honestly trained model are close in total variation distance in a white-box setting, even when the full model description (such as all weights) is known.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What type of adversarial behavior does the backdoor enable?",{"text":80,"@type":76},"It provides invariance-based adversarial examples, mapping distant inputs to unusually close outputs for every input.",{"name":82,"@type":73,"acceptedAnswer":83},"Why are these adversarial examples infeasible without the backdoor?",{"text":84,"@type":76},"Without the backdoor, generating such adversarial examples is provably impossible in polynomial time under standard cryptographic assumptions.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":45,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":45,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":45,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":45,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":45,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":45,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":45,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]