{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:2DDN3FOAYDVDKRQ6GHANH3NJKP","short_pith_number":"pith:2DDN3FOA","canonical_record":{"source":{"id":"1712.09196","kind":"arxiv","version":5},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2017-12-26T07:28:14Z","cross_cats_sorted":["cs.CR","cs.LG","stat.ML"],"title_canon_sha256":"af3636b27936eabb4855b8b33b007cfd5e777402e8ff89d54ac7491607e08a75","abstract_canon_sha256":"cb4015f2ef31822336e6863606a49c025424a01e46c44b4ce9035e4eb6fa2ed5"},"schema_version":"1.0"},"canonical_sha256":"d0c6dd95c0c0ea35461e31c0d3eda953c789da6593dc37beb3702baf999753a5","source":{"kind":"arxiv","id":"1712.09196","version":5},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1712.09196","created_at":"2026-05-17T23:41:01Z"},{"alias_kind":"arxiv_version","alias_value":"1712.09196v5","created_at":"2026-05-17T23:41:01Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1712.09196","created_at":"2026-05-17T23:41:01Z"},{"alias_kind":"pith_short_12","alias_value":"2DDN3FOAYDVD","created_at":"2026-05-18T12:30:55Z"},{"alias_kind":"pith_short_16","alias_value":"2DDN3FOAYDVDKRQ6","created_at":"2026-05-18T12:30:55Z"},{"alias_kind":"pith_short_8","alias_value":"2DDN3FOA","created_at":"2026-05-18T12:30:55Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:2DDN3FOAYDVDKRQ6GHANH3NJKP","target":"record","payload":{"canonical_record":{"source":{"id":"1712.09196","kind":"arxiv","version":5},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2017-12-26T07:28:14Z","cross_cats_sorted":["cs.CR","cs.LG","stat.ML"],"title_canon_sha256":"af3636b27936eabb4855b8b33b007cfd5e777402e8ff89d54ac7491607e08a75","abstract_canon_sha256":"cb4015f2ef31822336e6863606a49c025424a01e46c44b4ce9035e4eb6fa2ed5"},"schema_version":"1.0"},"canonical_sha256":"d0c6dd95c0c0ea35461e31c0d3eda953c789da6593dc37beb3702baf999753a5","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:41:01.398417Z","signature_b64":"MOIfmvtFSkKy/5w9yi9XGYcRbAxqv2EYvov5T8pkml46Du/5sjmwnVOmz9q6Lz5yCx8Z4Vwy50ttBj+2Zqa3CQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d0c6dd95c0c0ea35461e31c0d3eda953c789da6593dc37beb3702baf999753a5","last_reissued_at":"2026-05-17T23:41:01.397774Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:41:01.397774Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1712.09196","source_version":5,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:41:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"zjaxlpmbo6bNh2520yNeTcn//uD878Xc2frLBAGFZYoUl4ycOXHjzVIi0WhD+QBNYp5siH9PYAHze+IOuLlOCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-04T10:34:17.895957Z"},"content_sha256":"76900cc596b181fa8f814420a94d2e4b2063a90d5cff2d88e65c3ba86fd3b0c7","schema_version":"1.0","event_id":"sha256:76900cc596b181fa8f814420a94d2e4b2063a90d5cff2d88e65c3ba86fd3b0c7"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:2DDN3FOAYDVDKRQ6GHANH3NJKP","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"The Robust Manifold Defense: Adversarial Training using Generative Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.LG","stat.ML"],"primary_cat":"cs.CV","authors_text":"Ajil Jalal, Alexandros G. Dimakis, Andrew Ilyas, Constantinos Daskalakis","submitted_at":"2017-12-26T07:28:14Z","abstract_excerpt":"We propose a new type of attack for finding adversarial examples for image classifiers. Our method exploits spanners, i.e. deep neural networks whose input space is low-dimensional and whose output range approximates the set of images of interest. Spanners may be generators of GANs or decoders of VAEs. The key idea in our attack is to search over latent code pairs to find ones that generate nearby images with different classifier outputs. We argue that our attack is stronger than searching over perturbations of real images. Moreover, we show that our stronger attack can be used to reduce the a"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1712.09196","kind":"arxiv","version":5},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:41:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Af0qJfy6Aw2sgcignso61shKaQQdxWaQx+vHL2S45Kr3oZP4bdeeHQqN8PsKQIMWj2+1RNh4KrzoF6sFQYTmBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-04T10:34:17.896310Z"},"content_sha256":"d288b5072892f25a3c5c8d2e68a58e97f53274b20258d9a695521df33815af48","schema_version":"1.0","event_id":"sha256:d288b5072892f25a3c5c8d2e68a58e97f53274b20258d9a695521df33815af48"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/2DDN3FOAYDVDKRQ6GHANH3NJKP/bundle.json","state_url":"https://pith.science/pith/2DDN3FOAYDVDKRQ6GHANH3NJKP/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/2DDN3FOAYDVDKRQ6GHANH3NJKP/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-04T10:34:17Z","links":{"resolver":"https://pith.science/pith/2DDN3FOAYDVDKRQ6GHANH3NJKP","bundle":"https://pith.science/pith/2DDN3FOAYDVDKRQ6GHANH3NJKP/bundle.json","state":"https://pith.science/pith/2DDN3FOAYDVDKRQ6GHANH3NJKP/state.json","well_known_bundle":"https://pith.science/.well-known/pith/2DDN3FOAYDVDKRQ6GHANH3NJKP/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:2DDN3FOAYDVDKRQ6GHANH3NJKP","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"cb4015f2ef31822336e6863606a49c025424a01e46c44b4ce9035e4eb6fa2ed5","cross_cats_sorted":["cs.CR","cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2017-12-26T07:28:14Z","title_canon_sha256":"af3636b27936eabb4855b8b33b007cfd5e777402e8ff89d54ac7491607e08a75"},"schema_version":"1.0","source":{"id":"1712.09196","kind":"arxiv","version":5}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1712.09196","created_at":"2026-05-17T23:41:01Z"},{"alias_kind":"arxiv_version","alias_value":"1712.09196v5","created_at":"2026-05-17T23:41:01Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1712.09196","created_at":"2026-05-17T23:41:01Z"},{"alias_kind":"pith_short_12","alias_value":"2DDN3FOAYDVD","created_at":"2026-05-18T12:30:55Z"},{"alias_kind":"pith_short_16","alias_value":"2DDN3FOAYDVDKRQ6","created_at":"2026-05-18T12:30:55Z"},{"alias_kind":"pith_short_8","alias_value":"2DDN3FOA","created_at":"2026-05-18T12:30:55Z"}],"graph_snapshots":[{"event_id":"sha256:d288b5072892f25a3c5c8d2e68a58e97f53274b20258d9a695521df33815af48","target":"graph","created_at":"2026-05-17T23:41:01Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We propose a new type of attack for finding adversarial examples for image classifiers. Our method exploits spanners, i.e. deep neural networks whose input space is low-dimensional and whose output range approximates the set of images of interest. Spanners may be generators of GANs or decoders of VAEs. The key idea in our attack is to search over latent code pairs to find ones that generate nearby images with different classifier outputs. We argue that our attack is stronger than searching over perturbations of real images. Moreover, we show that our stronger attack can be used to reduce the a","authors_text":"Ajil Jalal, Alexandros G. Dimakis, Andrew Ilyas, Constantinos Daskalakis","cross_cats":["cs.CR","cs.LG","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2017-12-26T07:28:14Z","title":"The Robust Manifold Defense: Adversarial Training using Generative Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1712.09196","kind":"arxiv","version":5},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:76900cc596b181fa8f814420a94d2e4b2063a90d5cff2d88e65c3ba86fd3b0c7","target":"record","created_at":"2026-05-17T23:41:01Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"cb4015f2ef31822336e6863606a49c025424a01e46c44b4ce9035e4eb6fa2ed5","cross_cats_sorted":["cs.CR","cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2017-12-26T07:28:14Z","title_canon_sha256":"af3636b27936eabb4855b8b33b007cfd5e777402e8ff89d54ac7491607e08a75"},"schema_version":"1.0","source":{"id":"1712.09196","kind":"arxiv","version":5}},"canonical_sha256":"d0c6dd95c0c0ea35461e31c0d3eda953c789da6593dc37beb3702baf999753a5","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"d0c6dd95c0c0ea35461e31c0d3eda953c789da6593dc37beb3702baf999753a5","first_computed_at":"2026-05-17T23:41:01.397774Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:41:01.397774Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"MOIfmvtFSkKy/5w9yi9XGYcRbAxqv2EYvov5T8pkml46Du/5sjmwnVOmz9q6Lz5yCx8Z4Vwy50ttBj+2Zqa3CQ==","signature_status":"signed_v1","signed_at":"2026-05-17T23:41:01.398417Z","signed_message":"canonical_sha256_bytes"},"source_id":"1712.09196","source_kind":"arxiv","source_version":5}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:76900cc596b181fa8f814420a94d2e4b2063a90d5cff2d88e65c3ba86fd3b0c7","sha256:d288b5072892f25a3c5c8d2e68a58e97f53274b20258d9a695521df33815af48"],"state_sha256":"f36ed55306aa97bc65a61ba20cdbc35eb76e806b9c574b310a4a2ccc02d3a4bf"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Pv0QmMEdv1ZYAX2B6jqMq0udedzqVSaRz24TQpk8eKa1D0LlRWvGWKS3R7bSH/5GxPD2L83+AkhbqAbDhS4UBA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-04T10:34:17.898336Z","bundle_sha256":"dc4b5c0c95a289a969a7e0a2e57edcf52b962f0c7031a146c824d43b81877a18"}}