{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:27CZXFYKH32MESFS566D3DHDKK","short_pith_number":"pith:27CZXFYK","canonical_record":{"source":{"id":"1810.10031","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-10-23T18:14:47Z","cross_cats_sorted":["cs.AI","cs.CR","stat.ML"],"title_canon_sha256":"6cd23ecf96f62d523cbd21096d442b105531c269ba4a8c4edf272a3561438a87","abstract_canon_sha256":"9ad4374087f85f2dd7ea34fa9fa81c653a7c01a249a4a07458520f2cfcabedd9"},"schema_version":"1.0"},"canonical_sha256":"d7c59b970a3ef4c248b2efbc3d8ce352bbf5b016803988aaad82e310d0e805a5","source":{"kind":"arxiv","id":"1810.10031","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1810.10031","created_at":"2026-05-18T00:02:24Z"},{"alias_kind":"arxiv_version","alias_value":"1810.10031v1","created_at":"2026-05-18T00:02:24Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1810.10031","created_at":"2026-05-18T00:02:24Z"},{"alias_kind":"pith_short_12","alias_value":"27CZXFYKH32M","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_16","alias_value":"27CZXFYKH32MESFS","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_8","alias_value":"27CZXFYK","created_at":"2026-05-18T12:31:59Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:27CZXFYKH32MESFS566D3DHDKK","target":"record","payload":{"canonical_record":{"source":{"id":"1810.10031","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-10-23T18:14:47Z","cross_cats_sorted":["cs.AI","cs.CR","stat.ML"],"title_canon_sha256":"6cd23ecf96f62d523cbd21096d442b105531c269ba4a8c4edf272a3561438a87","abstract_canon_sha256":"9ad4374087f85f2dd7ea34fa9fa81c653a7c01a249a4a07458520f2cfcabedd9"},"schema_version":"1.0"},"canonical_sha256":"d7c59b970a3ef4c248b2efbc3d8ce352bbf5b016803988aaad82e310d0e805a5","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:02:24.432289Z","signature_b64":"JdO17AGcvULRuZOoh7WXjCMONl9v8xWmt3F9C2/SjG4CFb7tcBLV5qw8+PPiEC0nv7BT5YNdn5OYGRvKa29ABA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d7c59b970a3ef4c248b2efbc3d8ce352bbf5b016803988aaad82e310d0e805a5","last_reissued_at":"2026-05-18T00:02:24.431669Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:02:24.431669Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1810.10031","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:02:24Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"+LRH0O3F1lvJOrmpdCph49g+zwEKZCBAfV3UXzpS4e5wR1xI7Nj4XbczbRGWFgRJDLJJPh8U71DE3wGXOtKkDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T02:16:49.158828Z"},"content_sha256":"7b6bf37f81e7e34cc5dee4d4cd6ae7bc40e9f6abb7b5102d5d304f9fc057ab8c","schema_version":"1.0","event_id":"sha256:7b6bf37f81e7e34cc5dee4d4cd6ae7bc40e9f6abb7b5102d5d304f9fc057ab8c"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:27CZXFYKH32MESFS566D3DHDKK","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Stochastic Substitute Training: A Gray-box Approach to Craft Adversarial Examples Against Gradient Obfuscation Defenses","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Eric Keller, Greg Cusack, Mohammad Hashemi","submitted_at":"2018-10-23T18:14:47Z","abstract_excerpt":"It has been shown that adversaries can craft example inputs to neural networks which are similar to legitimate inputs but have been created to purposely cause the neural network to misclassify the input. These adversarial examples are crafted, for example, by calculating gradients of a carefully defined loss function with respect to the input. As a countermeasure, some researchers have tried to design robust models by blocking or obfuscating gradients, even in white-box settings. Another line of research proposes introducing a separate detector to attempt to detect adversarial examples. This a"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1810.10031","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:02:24Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"zQq8vAz+U1uCEKPMOlNE2gYmi1mmoeYJeVq6C8XPqR5KT2Q0da2kI30OEhiRFc5hymzbof8bxhLWoTfpuM1DBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T02:16:49.159179Z"},"content_sha256":"9555a987417f742ce31a3a4e3da997070db230554d677554aa22522f8af0ea53","schema_version":"1.0","event_id":"sha256:9555a987417f742ce31a3a4e3da997070db230554d677554aa22522f8af0ea53"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/27CZXFYKH32MESFS566D3DHDKK/bundle.json","state_url":"https://pith.science/pith/27CZXFYKH32MESFS566D3DHDKK/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/27CZXFYKH32MESFS566D3DHDKK/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-03T02:16:49Z","links":{"resolver":"https://pith.science/pith/27CZXFYKH32MESFS566D3DHDKK","bundle":"https://pith.science/pith/27CZXFYKH32MESFS566D3DHDKK/bundle.json","state":"https://pith.science/pith/27CZXFYKH32MESFS566D3DHDKK/state.json","well_known_bundle":"https://pith.science/.well-known/pith/27CZXFYKH32MESFS566D3DHDKK/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:27CZXFYKH32MESFS566D3DHDKK","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"9ad4374087f85f2dd7ea34fa9fa81c653a7c01a249a4a07458520f2cfcabedd9","cross_cats_sorted":["cs.AI","cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-10-23T18:14:47Z","title_canon_sha256":"6cd23ecf96f62d523cbd21096d442b105531c269ba4a8c4edf272a3561438a87"},"schema_version":"1.0","source":{"id":"1810.10031","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1810.10031","created_at":"2026-05-18T00:02:24Z"},{"alias_kind":"arxiv_version","alias_value":"1810.10031v1","created_at":"2026-05-18T00:02:24Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1810.10031","created_at":"2026-05-18T00:02:24Z"},{"alias_kind":"pith_short_12","alias_value":"27CZXFYKH32M","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_16","alias_value":"27CZXFYKH32MESFS","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_8","alias_value":"27CZXFYK","created_at":"2026-05-18T12:31:59Z"}],"graph_snapshots":[{"event_id":"sha256:9555a987417f742ce31a3a4e3da997070db230554d677554aa22522f8af0ea53","target":"graph","created_at":"2026-05-18T00:02:24Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"It has been shown that adversaries can craft example inputs to neural networks which are similar to legitimate inputs but have been created to purposely cause the neural network to misclassify the input. These adversarial examples are crafted, for example, by calculating gradients of a carefully defined loss function with respect to the input. As a countermeasure, some researchers have tried to design robust models by blocking or obfuscating gradients, even in white-box settings. Another line of research proposes introducing a separate detector to attempt to detect adversarial examples. This a","authors_text":"Eric Keller, Greg Cusack, Mohammad Hashemi","cross_cats":["cs.AI","cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-10-23T18:14:47Z","title":"Stochastic Substitute Training: A Gray-box Approach to Craft Adversarial Examples Against Gradient Obfuscation Defenses"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1810.10031","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:7b6bf37f81e7e34cc5dee4d4cd6ae7bc40e9f6abb7b5102d5d304f9fc057ab8c","target":"record","created_at":"2026-05-18T00:02:24Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"9ad4374087f85f2dd7ea34fa9fa81c653a7c01a249a4a07458520f2cfcabedd9","cross_cats_sorted":["cs.AI","cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-10-23T18:14:47Z","title_canon_sha256":"6cd23ecf96f62d523cbd21096d442b105531c269ba4a8c4edf272a3561438a87"},"schema_version":"1.0","source":{"id":"1810.10031","kind":"arxiv","version":1}},"canonical_sha256":"d7c59b970a3ef4c248b2efbc3d8ce352bbf5b016803988aaad82e310d0e805a5","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"d7c59b970a3ef4c248b2efbc3d8ce352bbf5b016803988aaad82e310d0e805a5","first_computed_at":"2026-05-18T00:02:24.431669Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:02:24.431669Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"JdO17AGcvULRuZOoh7WXjCMONl9v8xWmt3F9C2/SjG4CFb7tcBLV5qw8+PPiEC0nv7BT5YNdn5OYGRvKa29ABA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:02:24.432289Z","signed_message":"canonical_sha256_bytes"},"source_id":"1810.10031","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:7b6bf37f81e7e34cc5dee4d4cd6ae7bc40e9f6abb7b5102d5d304f9fc057ab8c","sha256:9555a987417f742ce31a3a4e3da997070db230554d677554aa22522f8af0ea53"],"state_sha256":"976ef0867d84cc8e3bdefcc3febb3a24a49eb5a815276139e33b984925d4c765"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"eLUNnbTQ+aVxHblybmTAO3sO0LBNKfh3U0Xf0EpgC5WyerldlIcioDysElgBU2baHHiI8gxOkSAmNVfKDly2CA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-03T02:16:49.161109Z","bundle_sha256":"5b791461f62541cd686747e4dcbaade83536541b91954cd402f128be2c1af85a"}}