{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:2VYPY5UGV5FJSUPKFVNMV6YAJ6","short_pith_number":"pith:2VYPY5UG","canonical_record":{"source":{"id":"1812.03405","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-08T23:50:11Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"84258a29a40fe81838f5ea05210a978f461c5a24b49d2893b8e473865f2f83fc","abstract_canon_sha256":"23734324f5d3649f3f9f048e06bff3e205ab0489ff46369c4843497d2560d492"},"schema_version":"1.0"},"canonical_sha256":"d570fc7686af4a9951ea2d5acafb004fa9c9beb05516d8405ca08b898ebbf509","source":{"kind":"arxiv","id":"1812.03405","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1812.03405","created_at":"2026-05-17T23:58:46Z"},{"alias_kind":"arxiv_version","alias_value":"1812.03405v1","created_at":"2026-05-17T23:58:46Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1812.03405","created_at":"2026-05-17T23:58:46Z"},{"alias_kind":"pith_short_12","alias_value":"2VYPY5UGV5FJ","created_at":"2026-05-18T12:32:02Z"},{"alias_kind":"pith_short_16","alias_value":"2VYPY5UGV5FJSUPK","created_at":"2026-05-18T12:32:02Z"},{"alias_kind":"pith_short_8","alias_value":"2VYPY5UG","created_at":"2026-05-18T12:32:02Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:2VYPY5UGV5FJSUPKFVNMV6YAJ6","target":"record","payload":{"canonical_record":{"source":{"id":"1812.03405","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-08T23:50:11Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"84258a29a40fe81838f5ea05210a978f461c5a24b49d2893b8e473865f2f83fc","abstract_canon_sha256":"23734324f5d3649f3f9f048e06bff3e205ab0489ff46369c4843497d2560d492"},"schema_version":"1.0"},"canonical_sha256":"d570fc7686af4a9951ea2d5acafb004fa9c9beb05516d8405ca08b898ebbf509","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:58:46.336334Z","signature_b64":"/gbNLrgbEllbaIWzBlcNUk6qMSej67D4BLNaWReTeNLYJDxSvmfiZou5/x+kxxJ59MKOcBUnkaNgBIW1WCVUCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d570fc7686af4a9951ea2d5acafb004fa9c9beb05516d8405ca08b898ebbf509","last_reissued_at":"2026-05-17T23:58:46.335932Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:58:46.335932Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1812.03405","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:58:46Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"/k+mam7Ut2juQrRanjlC0JtHSZH9tf3yXQClaEYOsteF9O7IgTelpz7Q0jKA0w6py2Ov4Vtn7Nxz7cqwm/FUDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T01:13:44.554473Z"},"content_sha256":"75d6e5767ac1c789ec60040c61e878934321c941fa0471a69516f9ca90e6cbd2","schema_version":"1.0","event_id":"sha256:75d6e5767ac1c789ec60040c61e878934321c941fa0471a69516f9ca90e6cbd2"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:2VYPY5UGV5FJSUPKFVNMV6YAJ6","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"AutoGAN: Robust Classifier Against Adversarial Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Blerta Lindqvist, Rauf Izmailov, Shridatt Sugrim","submitted_at":"2018-12-08T23:50:11Z","abstract_excerpt":"Classifiers fail to classify correctly input images that have been purposefully and imperceptibly perturbed to cause misclassification. This susceptability has been shown to be consistent across classifiers, regardless of their type, architecture or parameters. Common defenses against adversarial attacks modify the classifer boundary by training on additional adversarial examples created in various ways. In this paper, we introduce AutoGAN, which counters adversarial attacks by enhancing the lower-dimensional manifold defined by the training data and by projecting perturbed data points onto it"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1812.03405","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:58:46Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"4uMVlkYsgk1YjO6WkcscgYL3kqa/OrK0mp6gqh0CldfIYu9v2uVBGSbFVSEk1MSxedZj5KGw02izLPeULRIBBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T01:13:44.554817Z"},"content_sha256":"fbed3226178d67a3a3a8b7edbba24c2d68c17b07bada73a54996b02722e5726d","schema_version":"1.0","event_id":"sha256:fbed3226178d67a3a3a8b7edbba24c2d68c17b07bada73a54996b02722e5726d"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/2VYPY5UGV5FJSUPKFVNMV6YAJ6/bundle.json","state_url":"https://pith.science/pith/2VYPY5UGV5FJSUPKFVNMV6YAJ6/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/2VYPY5UGV5FJSUPKFVNMV6YAJ6/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-02T01:13:44Z","links":{"resolver":"https://pith.science/pith/2VYPY5UGV5FJSUPKFVNMV6YAJ6","bundle":"https://pith.science/pith/2VYPY5UGV5FJSUPKFVNMV6YAJ6/bundle.json","state":"https://pith.science/pith/2VYPY5UGV5FJSUPKFVNMV6YAJ6/state.json","well_known_bundle":"https://pith.science/.well-known/pith/2VYPY5UGV5FJSUPKFVNMV6YAJ6/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:2VYPY5UGV5FJSUPKFVNMV6YAJ6","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"23734324f5d3649f3f9f048e06bff3e205ab0489ff46369c4843497d2560d492","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-08T23:50:11Z","title_canon_sha256":"84258a29a40fe81838f5ea05210a978f461c5a24b49d2893b8e473865f2f83fc"},"schema_version":"1.0","source":{"id":"1812.03405","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1812.03405","created_at":"2026-05-17T23:58:46Z"},{"alias_kind":"arxiv_version","alias_value":"1812.03405v1","created_at":"2026-05-17T23:58:46Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1812.03405","created_at":"2026-05-17T23:58:46Z"},{"alias_kind":"pith_short_12","alias_value":"2VYPY5UGV5FJ","created_at":"2026-05-18T12:32:02Z"},{"alias_kind":"pith_short_16","alias_value":"2VYPY5UGV5FJSUPK","created_at":"2026-05-18T12:32:02Z"},{"alias_kind":"pith_short_8","alias_value":"2VYPY5UG","created_at":"2026-05-18T12:32:02Z"}],"graph_snapshots":[{"event_id":"sha256:fbed3226178d67a3a3a8b7edbba24c2d68c17b07bada73a54996b02722e5726d","target":"graph","created_at":"2026-05-17T23:58:46Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Classifiers fail to classify correctly input images that have been purposefully and imperceptibly perturbed to cause misclassification. This susceptability has been shown to be consistent across classifiers, regardless of their type, architecture or parameters. Common defenses against adversarial attacks modify the classifer boundary by training on additional adversarial examples created in various ways. In this paper, we introduce AutoGAN, which counters adversarial attacks by enhancing the lower-dimensional manifold defined by the training data and by projecting perturbed data points onto it","authors_text":"Blerta Lindqvist, Rauf Izmailov, Shridatt Sugrim","cross_cats":["cs.CR","cs.CV","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-08T23:50:11Z","title":"AutoGAN: Robust Classifier Against Adversarial Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1812.03405","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:75d6e5767ac1c789ec60040c61e878934321c941fa0471a69516f9ca90e6cbd2","target":"record","created_at":"2026-05-17T23:58:46Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"23734324f5d3649f3f9f048e06bff3e205ab0489ff46369c4843497d2560d492","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-08T23:50:11Z","title_canon_sha256":"84258a29a40fe81838f5ea05210a978f461c5a24b49d2893b8e473865f2f83fc"},"schema_version":"1.0","source":{"id":"1812.03405","kind":"arxiv","version":1}},"canonical_sha256":"d570fc7686af4a9951ea2d5acafb004fa9c9beb05516d8405ca08b898ebbf509","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"d570fc7686af4a9951ea2d5acafb004fa9c9beb05516d8405ca08b898ebbf509","first_computed_at":"2026-05-17T23:58:46.335932Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:58:46.335932Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"/gbNLrgbEllbaIWzBlcNUk6qMSej67D4BLNaWReTeNLYJDxSvmfiZou5/x+kxxJ59MKOcBUnkaNgBIW1WCVUCQ==","signature_status":"signed_v1","signed_at":"2026-05-17T23:58:46.336334Z","signed_message":"canonical_sha256_bytes"},"source_id":"1812.03405","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:75d6e5767ac1c789ec60040c61e878934321c941fa0471a69516f9ca90e6cbd2","sha256:fbed3226178d67a3a3a8b7edbba24c2d68c17b07bada73a54996b02722e5726d"],"state_sha256":"7e5c7cc104a8e60f2e0bba2cc10a508c05bd5d73f8c1a9f50f46039d2cfad26b"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"hZ/ZwZXe07X/gjsbRyyiv30v8oKLVU1vefKD2odIYCRLxriEECT9ceLmbtCBBjhPlKYYvWgR5PISi08lDrT6Bg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-02T01:13:44.556740Z","bundle_sha256":"555f1ae490d492bd49ee7359d0830b5c4e38d0b297b8478db68f56aef9a17971"}}