{"as_of":"2026-08-14T10:02:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:e51fd58d8722df28cf03dda67882d30e026f15e6fc28c125f84ae9760c1e0021","coverage":[{"denominator":36,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":36,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-12T14:53:50.037447Z","state":"measured"},{"denominator":39,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":39,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-14T06:32:32.682623+00:00","state":"measured"},{"denominator":3,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":3,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-11T16:59:11.782620Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"pith","source_observed_at":"2026-08-06T23:13:23.111381Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2411.14834","snapshot_observed_at":"2026-08-11T16:59:11.782620Z","title":"Gradient Masking All-at-Once: Ensemble Everything Everywhere Is Not Robust","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2412.09565","last_updated":"2025-02-08T23:58:36Z","snapshot_observed_at":"2026-08-12T22:00:21.320460Z","submitted_at":"2024-12-12T18:49:53Z","title":"Obfuscated Activations Bypass LLM Latent-Space Defenses","version":2},"reference_index":108,"source":"arxiv_source","source_observed_at":"2026-08-11T16:59:11.782620Z"},"links":{"cited_paper":"/paper/2411.14834","citing_paper":"/paper/2412.09565"},"observation_digest":"sha256:21d9de0dac842c7bfade408b2f6c3a3c3eaa21b53ff12c06c46aa6c3dc430c11","observation_id":"717f7e6f-9a0e-45e0-9b1f-dbe646eb59c1","resolution":{"observed_at":"2026-08-11T16:59:11.782620Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2411.14834","snapshot_observed_at":"2026-08-10T15:07:57.603843Z","title":"Gradient masking all-at-once: Ensemble everything everywhere is not robust, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.14496","last_updated":"2025-01-24T13:52:37Z","snapshot_observed_at":"2026-08-13T03:27:17.834592Z","submitted_at":"2025-01-24T13:52:37Z","title":"A Note on Implementation Errors in Recent Adaptive Attacks Against Multi-Resolution Self-Ensembles","version":1},"reference_index":1,"source":"arxiv_source","source_observed_at":"2026-08-10T15:07:57.603843Z"},"links":{"cited_paper":"/paper/2411.14834","citing_paper":"/paper/2501.14496"},"observation_digest":"sha256:74e02770f939d6238e6bfc7255feaf0795ac6a93366e14352ccbc5b91c54d6c1","observation_id":"c2e8f636-5555-402c-93d0-d36e5ea8c869","resolution":{"observed_at":"2026-08-10T15:07:57.603843Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"cited_work":{"arxiv_id":"2411.14834","doi":null,"metadata_source":"pith","pith_arxiv_id":"2411.14834","snapshot_observed_at":"2026-08-06T23:13:23.111381Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","venue":"cs.LG","work_id":"654570cb-aadd-441a-8312-f68a7747d304","year":2024},"citing_paper":{"arxiv_id":"2506.19882","last_updated":"2025-07-07T02:00:46Z","snapshot_observed_at":"2026-08-14T09:27:38.836085Z","submitted_at":"2025-06-24T02:19:30Z","title":"Position: Machine Learning Conferences Should Establish a \"Refutations and Critiques\" Track","version":3},"reference_index":97,"source":"arxiv_source","source_observed_at":"2026-08-06T23:13:21.907911Z"},"links":{"cited_paper":"/paper/2411.14834","citing_paper":"/paper/2506.19882"},"observation_digest":"sha256:b40be47e7717aa70b7c91fd47eb5bc6eab84f9790a65cdf89fb66fad77e1b99d","observation_id":"ff203279-d3e1-42e9-b737-42f90cc9a2e6","resolution":{"observed_at":"2026-08-06T23:13:23.189698Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2411.14834/citation-record","integrity":"/paper/2411.14834/integrity","json":"/paper/2411.14834/citation-record.json","paper":"/paper/2411.14834"},"outbound":[{"citation":{"cited_paper":{"arxiv_id":"1702.06856","last_updated":"2017-03-10T04:10:18Z","snapshot_observed_at":"2026-08-12T17:40:44.784186Z","submitted_at":"2017-02-22T15:37:50Z","title":"Robustness to Adversarial Examples through an Ensemble of Specialists","version":3},"cited_work":{"arxiv_id":"1702.06856","doi":null,"metadata_source":"pith","pith_arxiv_id":"1702.06856","snapshot_observed_at":"2026-08-12T14:53:51.181401Z","title":"Robustness to Adversarial Examples through an Ensemble of Specialists","venue":"cs.NE","work_id":"8c01aa3f-1701-4b4f-8e32-513966696b18","year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.475213Z"},"links":{"cited_paper":"/paper/1702.06856","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:40192e520004a112aa038a553e0fb397ef5af018b669a183d76d1ad48aecf42f","observation_id":"e700af40-ed39-40a5-8453-da724994a0a5","resolution":{"observed_at":"2026-08-12T14:53:51.193595Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:49.494441Z","title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.494441Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:2e12e3c6f544c77e0ee53ddc912f4c2182e0511ee5a422bd28da02291d26ff75","observation_id":"6d267bd0-f9d3-4006-8124-01b0f2accdc8","resolution":{"observed_at":"2026-08-12T14:53:49.494441Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.904585Z","title":"Evasion attacks against machine learning at test time","venue":null,"work_id":"32120f81-fbc6-4c31-af60-9c0dc93ee377","year":2013},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.531196Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:3bb88daa83542e4cfe70d682c390643f4c8974b6a21e3e8329bf1b57ceb140be","observation_id":"128d5d5d-ffc5-4cf1-affd-34fbbe6607b6","resolution":{"observed_at":"2026-08-12T14:53:51.914360Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1704.01547","last_updated":"2017-04-05T17:47:25Z","snapshot_observed_at":"2026-08-13T02:07:57.702272Z","submitted_at":"2017-04-05T17:47:25Z","title":"Comment on \"Biologically inspired protection of deep networks from adversarial attacks\"","version":1},"cited_work":{"arxiv_id":"1704.01547","doi":null,"metadata_source":"pith","pith_arxiv_id":"1704.01547","snapshot_observed_at":"2026-08-12T14:53:51.121905Z","title":"Comment on \"Biologically inspired protection of deep networks from adversarial attacks\"","venue":"stat.ML","work_id":"3bfcc7b1-ae2f-46ba-9c56-5cdc4e814257","year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.549429Z"},"links":{"cited_paper":"/paper/1704.01547","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:68039c5ccc199a1c2e1b007923b8fd7c3497dbe9892654ba306ecbaf347d0a5b","observation_id":"de0ff193-5166-4b4d-8b08-7651b52ba56b","resolution":{"observed_at":"2026-08-12T14:53:51.136225Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1607.04311","last_updated":"2016-07-14T20:44:27Z","snapshot_observed_at":"2026-08-12T17:40:43.305119Z","submitted_at":"2016-07-14T20:44:27Z","title":"Defensive Distillation is Not Robust to Adversarial Examples","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1607.04311","snapshot_observed_at":"2026-08-12T14:53:49.556161Z","title":"Defensive distillation is not robust to adversarial examples","venue":null,"work_id":null,"year":2016},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.556161Z"},"links":{"cited_paper":"/paper/1607.04311","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:bd70fe894c92512455f4048eadcadd7bf38aea85085fea7e1bba3f579b91054f","observation_id":"de1b09f3-ac13-423d-9476-cc5cfdd83ec7","resolution":{"observed_at":"2026-08-12T14:53:49.556161Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:49.564786Z","title":"Towards evaluating the robustness of neural networks","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.564786Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:8ea9e7f6752cd70ab3493bc8796e03668039d3f9f440c43c8d3fca917ab20ecd","observation_id":"a3594dd7-b938-4b83-add6-301e7a66d2e3","resolution":{"observed_at":"2026-08-12T14:53:49.564786Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.822879Z","title":"Certified adversarial robustness via randomized smoothing","venue":null,"work_id":"3e130176-32fe-49e8-8539-aefe3c545c0f","year":2019},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.577258Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:c63b07143fdcc72d475f78eafd47a76915a5d5f099b553fae2d8d506beb8abca","observation_id":"7c1219a4-8011-4cb7-bf1f-f8a8fbfb0605","resolution":{"observed_at":"2026-08-12T14:53:51.832178Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.794931Z","title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","venue":null,"work_id":"7bc4fd3e-800c-4327-9378-53e70b1838d6","year":2020},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.589749Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:c8cc3b8f29fc3bd42a0d0c0ab58d50cc9ccdd164cc38e741d4c45ca30bdae732","observation_id":"7063d669-64a8-4270-afda-8d2566bdd889","resolution":{"observed_at":"2026-08-12T14:53:51.802270Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.766445Z","title":"Mind the box: l 1-apgd for sparse adversarial attacks on image classifiers","venue":null,"work_id":"6f429ecc-ef90-47ca-9080-67eb31bcfd68","year":2021},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.603087Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:5ecbc0f72c38956f9a3b80a121531438ef9004f718516ff62a47a0c8f022440b","observation_id":"90a6de1e-18ce-45ba-98a9-e02cf990be24","resolution":{"observed_at":"2026-08-12T14:53:51.772450Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.726171Z","title":"A note on implementation errors in recent adaptive attacks against multi-resolution self-ensembles, 2025","venue":null,"work_id":"eb67381b-922e-4de6-a503-cddaa801b9bb","year":2025},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.616821Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:24637e455766ee3cf02747d2815c5e1522f6b3c81960feef7a910e279ea6bfd1","observation_id":"718fd03b-459e-49b9-94dc-4274e04416b8","resolution":{"observed_at":"2026-08-12T14:53:51.732837Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.693201Z","title":"Ensemble everything everywhere: Multi-scale aggregation for adversarial robustness, 2024","venue":null,"work_id":"1cec0476-171e-499e-9a7e-8c238666077f","year":2024},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.628359Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:33773e5f34245e8f7cbde297a38d0308d9ff1d0692d4df48f285ef5652708ae0","observation_id":"21282a69-2370-4218-b347-dd4590b01900","resolution":{"observed_at":"2026-08-12T14:53:51.707237Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2207.11378","last_updated":"2023-08-09T17:06:52Z","snapshot_observed_at":"2026-08-13T14:58:34.118967Z","submitted_at":"2022-07-22T23:48:26Z","title":"Do Perceptually Aligned Gradients Imply Adversarial Robustness?","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2207.11378","snapshot_observed_at":"2026-08-12T14:53:49.636427Z","title":"Do perceptually aligned gradients imply adversarial robustness? arXiv preprint arXiv:2207.11378 , 2022","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.636427Z"},"links":{"cited_paper":"/paper/2207.11378","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:3221b372669bb27f7e00f5d5a3cffac9f0b03eb588076184db4315611f9b2461","observation_id":"287e0bf2-e22c-4e8b-97b3-0a7c889dc73a","resolution":{"observed_at":"2026-08-12T14:53:49.636427Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.643352Z","title":"Ai2: Safety and robustness certification of neural networks with abstract interpretation","venue":null,"work_id":"133d6439-23a6-4c5a-82f2-3b74dd37178c","year":2018},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.650681Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:cd2cefb6c1c9ba4b7de545b75bed40fac41b6b5ce19d17b23236a76ae41efebc","observation_id":"19664959-5658-4e6d-9b18-94517d64e1a8","resolution":{"observed_at":"2026-08-12T14:53:51.648974Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1711.00117","last_updated":"2018-01-25T19:04:48Z","snapshot_observed_at":"2026-07-06T06:07:07.703002Z","submitted_at":"2017-10-31T21:22:16Z","title":"Countering Adversarial Images using Input Transformations","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1711.00117","snapshot_observed_at":"2026-08-12T14:53:49.660015Z","title":"Countering adversarial images using input transformations","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.660015Z"},"links":{"cited_paper":"/paper/1711.00117","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:f38ca336b640f6e62fed41bf2e472a0d8e51c85cf624d294e461bc56f196e789","observation_id":"a26a68f9-dd56-41d3-87e9-34d545b08f6d","resolution":{"observed_at":"2026-08-12T14:53:49.660015Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.613295Z","title":"Certified robustness to adversarial examples with differential privacy","venue":null,"work_id":"52b88b4f-3c24-41cd-b4f2-fac69d6f4d02","year":2019},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.670366Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:ea8f11ae4a4f3dbdaab5ffb968a1784ae3699a33c48516e4fbd2e217c6effafc","observation_id":"d539ec5f-2cec-406e-bbfb-12664d330255","resolution":{"observed_at":"2026-08-12T14:53:51.620719Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2404.14309","last_updated":"2025-04-05T02:30:06Z","snapshot_observed_at":"2026-08-13T00:24:32.670986Z","submitted_at":"2024-04-22T16:10:38Z","title":"Towards Understanding the Robustness of Diffusion-Based Purification: A Stochastic Perspective","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.14309","snapshot_observed_at":"2026-08-12T14:53:49.683838Z","title":"Towards better adversarial purification via adversarial denoising diffusion training","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.683838Z"},"links":{"cited_paper":"/paper/2404.14309","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:13474061a16c4d2a90315625ca63a4337c8703c64c78e8f9df69b03026c7dc95","observation_id":"273752d5-9c32-4cd4-919a-de7a25591e17","resolution":{"observed_at":"2026-08-12T14:53:49.683838Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1511.06292","last_updated":"2016-01-19T18:15:28Z","snapshot_observed_at":"2026-07-06T04:37:06.738855Z","submitted_at":"2015-11-19T18:35:07Z","title":"Foveation-based Mechanisms Alleviate Adversarial Examples","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1511.06292","snapshot_observed_at":"2026-08-12T14:53:49.695032Z","title":"Foveation-based mechanisms alleviate adversarial examples","venue":null,"work_id":null,"year":2015},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.695032Z"},"links":{"cited_paper":"/paper/1511.06292","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:f09ee14f990dc0ab4c8d0232be2d1d7bb77a1391437c97422e2656834c962eaa","observation_id":"fd852625-9c08-46ef-abb3-833e168f1111","resolution":{"observed_at":"2026-08-12T14:53:49.695032Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:49.712438Z","title":"Towards deep learning models resistant to adversarial attacks","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.712438Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:09629850686d7b201f229a92a9b67956fc140c6f4082dab6d42480100fe0d433","observation_id":"5cddd7ea-12f3-4fcc-a0c5-7f994486b273","resolution":{"observed_at":"2026-08-12T14:53:49.712438Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1702.04267","last_updated":"2017-02-21T06:53:38Z","snapshot_observed_at":"2026-08-09T14:02:38.261220Z","submitted_at":"2017-02-14T15:44:26Z","title":"On Detecting Adversarial Perturbations","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1702.04267","snapshot_observed_at":"2026-08-12T14:53:49.745827Z","title":"On detecting adversarial perturbations","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.745827Z"},"links":{"cited_paper":"/paper/1702.04267","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:61ac29d2abf73fed01bfc1b4bf61141907add802c00caf808a5228ad63d9ecd3","observation_id":"03ba3dba-afd0-4dd6-b3d2-9695316903e1","resolution":{"observed_at":"2026-08-12T14:53:49.745827Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1703.09202","last_updated":"2017-03-27T17:45:07Z","snapshot_observed_at":"2026-07-06T05:35:22.518259Z","submitted_at":"2017-03-27T17:45:07Z","title":"Biologically inspired protection of deep networks from adversarial attacks","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1703.09202","snapshot_observed_at":"2026-08-12T14:53:49.767307Z","title":"Biologically inspired protection of deep networks from adversarial attacks","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.767307Z"},"links":{"cited_paper":"/paper/1703.09202","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:d526d7e3a7f040444e0d8ed837ceb01b8ce2986f341bbcb796c08fca1077b413","observation_id":"a0bc53ba-7838-4ec5-afa0-2298a0f46c79","resolution":{"observed_at":"2026-08-12T14:53:49.767307Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:49.792683Z","title":"Improving adversarial robustness via promoting ensemble diversity","venue":null,"work_id":null,"year":2019},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.792683Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:1c45a8d1f2de638bd80af2a40f7248f5e8c6fc51df49c273d7727ebe658bfdfa","observation_id":"d7074886-5d57-462b-86de-6bd3397eaf29","resolution":{"observed_at":"2026-08-12T14:53:49.792683Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.519417Z","title":"Practical black-box attacks against machine learning","venue":null,"work_id":"48d26c08-3bd3-4f65-86c7-ea6a9d554be8","year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.802539Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:efd7bac6e73b33b4511ca95169c768a3d8722e76c5da23ccf211ea2cca7562a6","observation_id":"bab62494-06c6-4ff3-8652-69fdb9d33746","resolution":{"observed_at":"2026-08-12T14:53:51.525501Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.484919Z","title":"Barrage of random transforms for adversarially robust defense","venue":null,"work_id":"2cda837b-ef43-48e0-8752-7ed54815901d","year":2019},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.810977Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:c027f7ef4fedb5ed7834aaf43f60ed9a3dd6384acd7bb28fada64e6e5e302ad7","observation_id":"2e03977d-314c-4f75-8240-f81472f9a95c","resolution":{"observed_at":"2026-08-12T14:53:51.491245Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.434106Z","title":"Certified defenses against adversarial examples","venue":null,"work_id":"1ca875b1-efff-4015-814e-f8d78b0d88e1","year":2018},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.816710Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:5a1fb84e17e5103d2514548f33855f3865c0ee5232ce05ef634d650c267b0821","observation_id":"9aa09eef-21df-489a-b3d5-5bd56ddd86e8","resolution":{"observed_at":"2026-08-12T14:53:51.444316Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1511.05122","last_updated":"2016-03-04T20:21:24Z","snapshot_observed_at":"2026-07-06T04:36:40.942807Z","submitted_at":"2015-11-16T20:48:20Z","title":"Adversarial Manipulation of Deep Representations","version":9},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1511.05122","snapshot_observed_at":"2026-08-12T14:53:49.829281Z","title":"Adversarial manipulation of deep representations","venue":null,"work_id":null,"year":2015},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.829281Z"},"links":{"cited_paper":"/paper/1511.05122","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:312cee793b9c49efa0bad24b81572c5c65e46ec5f83e00dad77526e8ed0e420a","observation_id":"8f9a4fe8-443b-4040-b0b0-77db521a6432","resolution":{"observed_at":"2026-08-12T14:53:49.829281Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.406879Z","title":"Public comment: Robustness eval- uation seems invalid","venue":null,"work_id":"bd59a9ce-72d9-4abf-98d6-601a69e46685","year":2024},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.837748Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:5893bdb032e95a2537a93d8a52b05c6110e5ef68ed0d22508a71a5b52cc7edfd","observation_id":"e8e66328-887f-43ca-9ed4-8f94eac8163c","resolution":{"observed_at":"2026-08-12T14:53:51.415034Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.382851Z","title":"Intriguing properties of neural networks","venue":null,"work_id":"7164df83-4857-4e82-8635-2eb634434a58","year":2014},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.850161Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:4730177083d79703d0410526e0789d0e4361649775daeac317692611b719c67b","observation_id":"d3d9b41d-766b-4200-9248-86cefbad637b","resolution":{"observed_at":"2026-08-12T14:53:51.388474Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.347405Z","title":"On adaptive attacks to adversarial example defenses","venue":null,"work_id":"151b1b3d-e63f-4c62-9845-d858807b50a5","year":2020},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.856498Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:eda7a952ed677b879372584b744d50a77a1a69c33c53912cb8083e5679d5af00","observation_id":"eaa4b932-70e0-4115-907d-e0965d3d56e5","resolution":{"observed_at":"2026-08-12T14:53:51.357585Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.311989Z","title":"Ensemble adversarial training: Attacks and defenses","venue":null,"work_id":"1bc9e89a-3436-4c41-a8db-b602060bec7c","year":2018},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.869390Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:f284165a8716ba9ea149d75c4fed827470d9b151a2499f89e7b94685cda80672","observation_id":"f6382127-2423-4069-8539-63d6dc8b49e1","resolution":{"observed_at":"2026-08-12T14:53:51.323175Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1805.12152","last_updated":"2019-09-09T08:09:25Z","snapshot_observed_at":"2026-08-12T23:53:39.680490Z","submitted_at":"2018-05-30T18:00:32Z","title":"Robustness May Be at Odds with Accuracy","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1805.12152","snapshot_observed_at":"2026-08-12T14:53:49.890355Z","title":"Robustness may be at odds with accuracy","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.890355Z"},"links":{"cited_paper":"/paper/1805.12152","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:f929921d4be2360517b8f42fbfa1b676528468110cd34863e3f61c896db81074","observation_id":"db086f34-d2c6-4674-8e8f-a9891a3594fc","resolution":{"observed_at":"2026-08-12T14:53:49.890355Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.278237Z","title":"Provable defenses against adversarial examples via the convex outer adversarial polytope","venue":null,"work_id":"8390cd2e-dc4f-4ca2-a7b7-ee2beeaaf532","year":2018},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.920072Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:4520516950452a4d36d3c3ce1ec8d30ff80c05d2cf2322edd38cb51fc6646db6","observation_id":"46a9d7fe-f7a1-4db8-9775-814805734c3c","resolution":{"observed_at":"2026-08-12T14:53:51.296416Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2001.03994","last_updated":"2020-01-12T20:30:22Z","snapshot_observed_at":"2026-08-10T02:39:16.757240Z","submitted_at":"2020-01-12T20:30:22Z","title":"Fast is better than free: Revisiting adversarial training","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2001.03994","snapshot_observed_at":"2026-08-12T14:53:49.935262Z","title":"Fast is better than free: Revisiting adversarial training","venue":null,"work_id":null,"year":2001},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.935262Z"},"links":{"cited_paper":"/paper/2001.03994","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:34df0bad2938efc000b89b6a25e647f1e5697b2f8843b15c9b3d3507dcad3a2e","observation_id":"a3659500-9e2a-4bf2-bdc1-45a26bfb4934","resolution":{"observed_at":"2026-08-12T14:53:49.935262Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1711.01991","last_updated":"2018-02-28T22:39:15Z","snapshot_observed_at":"2026-08-04T13:57:53.214741Z","submitted_at":"2017-11-06T16:22:54Z","title":"Mitigating Adversarial Effects Through Randomization","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1711.01991","snapshot_observed_at":"2026-08-12T14:53:49.943965Z","title":"Mitigating adversarial effects through randomization","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.943965Z"},"links":{"cited_paper":"/paper/1711.01991","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:8d95ef4b854b1e81d4a99e6989c277383f347c13230260960bf8777c54ced9ac","observation_id":"17055f19-c58c-4746-97d6-4cbf3ffd4973","resolution":{"observed_at":"2026-08-12T14:53:49.943965Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1704.01155","last_updated":"2017-12-05T23:45:08Z","snapshot_observed_at":"2026-07-06T05:36:32.792127Z","submitted_at":"2017-04-04T18:56:53Z","title":"Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1704.01155","snapshot_observed_at":"2026-08-12T14:53:49.956062Z","title":"Feature squeezing: Detecting adversarial examples in deep neural networks","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.956062Z"},"links":{"cited_paper":"/paper/1704.01155","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:52039005ba45f63719445b5665c75e07aa75bc9774e5cddb888be01f291173fb","observation_id":"c9f64418-68c4-4247-a308-f041475ebbc5","resolution":{"observed_at":"2026-08-12T14:53:49.956062Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1905.11971","last_updated":"2019-05-28T17:47:33Z","snapshot_observed_at":"2026-07-06T07:56:11.645313Z","submitted_at":"2019-05-28T17:47:33Z","title":"ME-Net: Towards Effective Adversarial Robustness with Matrix Estimation","version":1},"cited_work":{"arxiv_id":"1905.11971","doi":null,"metadata_source":"pith","pith_arxiv_id":"1905.11971","snapshot_observed_at":"2026-08-12T14:53:50.160419Z","title":"ME-Net: Towards Effective Adversarial Robustness with Matrix Estimation","venue":"cs.LG","work_id":"c18b8d88-92aa-4fc4-afd4-0ac23198b39e","year":2019},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.983850Z"},"links":{"cited_paper":"/paper/1905.11971","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:e51afe8477d8a8cab62cbc5b5ec9c48eb77db1a8fc2b7f5ce009869e5fcdd27c","observation_id":"5912b5f7-bb59-4425-b7c9-82380fddcf21","resolution":{"observed_at":"2026-08-12T14:53:50.185618Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.227371Z","title":"Increasing confidence in adversarial robustness evaluations","venue":null,"work_id":"6e9586d1-af6f-4980-8192-2c08ad6ba3c4","year":2022},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:50.037447Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:47ead079bd0fef0cd2921a0accae8036b27ea06ec2d6fff26f2848d8793ee9fc","observation_id":"a9337580-12b0-4298-b0fb-c33ba03fce1a","resolution":{"observed_at":"2026-08-12T14:53:51.243245Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-14T06:32:32.682623+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"state":"measured"}}],"paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","latest_version":2,"primary_category":"cs.LG","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense"},"reference_resolution":{"displayed":36,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":16,"verified_exact":3,"verified_fuzzy":17},"total_outbound_references":36},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-14T06:32:32.682623+00:00","source":"crossref"},{"observed_at":"2026-08-14T06:32:18.44784+00:00","source":"retraction_watch"}],"thesis":"As of 14 August 2026, this Paper Citation Record lists 36 of 36 outbound references and 3 inbound Pith citation observations for arXiv:2411.14834."}