{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:2AIBY35W56Y75AGQ3RKF7NK2KL","short_pith_number":"pith:2AIBY35W","schema_version":"1.0","canonical_sha256":"d0101c6fb6efb1fe80d0dc545fb55a52df985293e1f73b47ddb811bd3bc234a5","source":{"kind":"arxiv","id":"2104.12609","version":1},"attestation_state":"computed","paper":{"title":"PatchGuard++: Efficient Provable Attack Detection against Adversarial Patches","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CV","authors_text":"Chong Xiang, Prateek Mittal","submitted_at":"2021-04-26T14:22:33Z","abstract_excerpt":"An adversarial patch can arbitrarily manipulate image pixels within a restricted region to induce model misclassification. The threat of this localized attack has gained significant attention because the adversary can mount a physically-realizable attack by attaching patches to the victim object. Recent provably robust defenses generally follow the PatchGuard framework by using CNNs with small receptive fields and secure feature aggregation for robust model predictions. In this paper, we extend PatchGuard to PatchGuard++ for provably detecting the adversarial patch attack to boost both provabl"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2104.12609","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2021-04-26T14:22:33Z","cross_cats_sorted":[],"title_canon_sha256":"21863d59e06694f9431208c190786e8d73d86b8b54f3a9dcfebb8120c904f1b0","abstract_canon_sha256":"16c054d156dcb9193a30862892bf696464bf02a84b16ba4dd9384279aa265406"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T02:34:58.555556Z","signature_b64":"6aHcS7Op7L0Rs5JxJeUtUkmGi+Vx+P5fsbw/I5RjZdMpH9LfzqNzmUJl5HHl5SO3XuZ7Wt9/Iqvro1ZQgQ6EBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d0101c6fb6efb1fe80d0dc545fb55a52df985293e1f73b47ddb811bd3bc234a5","last_reissued_at":"2026-07-05T02:34:58.554973Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T02:34:58.554973Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"PatchGuard++: Efficient Provable Attack Detection against Adversarial Patches","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CV","authors_text":"Chong Xiang, Prateek Mittal","submitted_at":"2021-04-26T14:22:33Z","abstract_excerpt":"An adversarial patch can arbitrarily manipulate image pixels within a restricted region to induce model misclassification. The threat of this localized attack has gained significant attention because the adversary can mount a physically-realizable attack by attaching patches to the victim object. Recent provably robust defenses generally follow the PatchGuard framework by using CNNs with small receptive fields and secure feature aggregation for robust model predictions. In this paper, we extend PatchGuard to PatchGuard++ for provably detecting the adversarial patch attack to boost both provabl"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2104.12609","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2104.12609/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2104.12609","created_at":"2026-07-05T02:34:58.555033+00:00"},{"alias_kind":"arxiv_version","alias_value":"2104.12609v1","created_at":"2026-07-05T02:34:58.555033+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2104.12609","created_at":"2026-07-05T02:34:58.555033+00:00"},{"alias_kind":"pith_short_12","alias_value":"2AIBY35W56Y7","created_at":"2026-07-05T02:34:58.555033+00:00"},{"alias_kind":"pith_short_16","alias_value":"2AIBY35W56Y75AGQ","created_at":"2026-07-05T02:34:58.555033+00:00"},{"alias_kind":"pith_short_8","alias_value":"2AIBY35W","created_at":"2026-07-05T02:34:58.555033+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2505.24703","citing_title":"PatchDEMUX: A Certifiably Robust Framework for Multi-label Classifiers Against Adversarial Patches","ref_index":31,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/2AIBY35W56Y75AGQ3RKF7NK2KL","json":"https://pith.science/pith/2AIBY35W56Y75AGQ3RKF7NK2KL.json","graph_json":"https://pith.science/api/pith-number/2AIBY35W56Y75AGQ3RKF7NK2KL/graph.json","events_json":"https://pith.science/api/pith-number/2AIBY35W56Y75AGQ3RKF7NK2KL/events.json","paper":"https://pith.science/paper/2AIBY35W"},"agent_actions":{"view_html":"https://pith.science/pith/2AIBY35W56Y75AGQ3RKF7NK2KL","download_json":"https://pith.science/pith/2AIBY35W56Y75AGQ3RKF7NK2KL.json","view_paper":"https://pith.science/paper/2AIBY35W","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2104.12609&json=true","fetch_graph":"https://pith.science/api/pith-number/2AIBY35W56Y75AGQ3RKF7NK2KL/graph.json","fetch_events":"https://pith.science/api/pith-number/2AIBY35W56Y75AGQ3RKF7NK2KL/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/2AIBY35W56Y75AGQ3RKF7NK2KL/action/timestamp_anchor","attest_storage":"https://pith.science/pith/2AIBY35W56Y75AGQ3RKF7NK2KL/action/storage_attestation","attest_author":"https://pith.science/pith/2AIBY35W56Y75AGQ3RKF7NK2KL/action/author_attestation","sign_citation":"https://pith.science/pith/2AIBY35W56Y75AGQ3RKF7NK2KL/action/citation_signature","submit_replication":"https://pith.science/pith/2AIBY35W56Y75AGQ3RKF7NK2KL/action/replication_record"}},"created_at":"2026-07-05T02:34:58.555033+00:00","updated_at":"2026-07-05T02:34:58.555033+00:00"}