{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:33NYHLTZWE5OEXMISDKYPCLNLT","short_pith_number":"pith:33NYHLTZ","canonical_record":{"source":{"id":"1807.10335","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-07-26T19:29:37Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"d8e40543d09edc784f02c7d06be9b0eba946e85b44cc63cbfd890db710540936","abstract_canon_sha256":"c0bc13c9bafcac5c86c346c9747682fc80982f7547684e677d4b074923768914"},"schema_version":"1.0"},"canonical_sha256":"dedb83ae79b13ae25d8890d587896d5ce61d75ce0c6efb9f0675a07835639f54","source":{"kind":"arxiv","id":"1807.10335","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1807.10335","created_at":"2026-05-18T00:09:40Z"},{"alias_kind":"arxiv_version","alias_value":"1807.10335v1","created_at":"2026-05-18T00:09:40Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1807.10335","created_at":"2026-05-18T00:09:40Z"},{"alias_kind":"pith_short_12","alias_value":"33NYHLTZWE5O","created_at":"2026-05-18T12:32:02Z"},{"alias_kind":"pith_short_16","alias_value":"33NYHLTZWE5OEXMI","created_at":"2026-05-18T12:32:02Z"},{"alias_kind":"pith_short_8","alias_value":"33NYHLTZ","created_at":"2026-05-18T12:32:02Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:33NYHLTZWE5OEXMISDKYPCLNLT","target":"record","payload":{"canonical_record":{"source":{"id":"1807.10335","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-07-26T19:29:37Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"d8e40543d09edc784f02c7d06be9b0eba946e85b44cc63cbfd890db710540936","abstract_canon_sha256":"c0bc13c9bafcac5c86c346c9747682fc80982f7547684e677d4b074923768914"},"schema_version":"1.0"},"canonical_sha256":"dedb83ae79b13ae25d8890d587896d5ce61d75ce0c6efb9f0675a07835639f54","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:09:40.902867Z","signature_b64":"EALxB2cD+LwBvgQYy1yxzZuVHYOeaAbQNB/DKQJl5VeDJw42Djs1uM4LYiPGTiXMVFSx8BovyuEqvLg0pAYpDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"dedb83ae79b13ae25d8890d587896d5ce61d75ce0c6efb9f0675a07835639f54","last_reissued_at":"2026-05-18T00:09:40.902108Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:09:40.902108Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1807.10335","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:09:40Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"S8gNUC06q2iwDLQC9qxklT9KLmX8Sw2mua29gbUMF0UxtJgZFZ3NrjICy2iEqbz0W6odJGmIoxgWF/4l4f9lDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-07T16:45:29.471185Z"},"content_sha256":"dd16275837aeb0b2d06edca8fd0f2d89d4b467a08edf984e011bd8c005fe8d77","schema_version":"1.0","event_id":"sha256:dd16275837aeb0b2d06edca8fd0f2d89d4b467a08edf984e011bd8c005fe8d77"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:33NYHLTZWE5OEXMISDKYPCLNLT","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"A general metric for identifying adversarial images","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CV","authors_text":"Siddharth Krishna Kumar","submitted_at":"2018-07-26T19:29:37Z","abstract_excerpt":"It is well known that a determined adversary can fool a neural network by making imperceptible adversarial perturbations to an image. Recent studies have shown that these perturbations can be detected even without information about the neural network if the strategy taken by the adversary is known beforehand. Unfortunately, these studies suffer from the generalization limitation -- the detection method has to be recalibrated every time the adversary changes his strategy. In this study, we attempt to overcome the generalization limitation by deriving a metric which reliably identifies adversari"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1807.10335","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:09:40Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Ul+zZsVaTSTcy++Bb1ipBbgaTtJHN6rotKvfEc6U+w77wA/U/r/uVXpYd0a+rWxbOwJps2bY2029Ukj32RVBBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-07T16:45:29.471843Z"},"content_sha256":"910e8d30e3ece2d8b980651ed699b1f6462e475cef6a5fee2788f6acbeee92b4","schema_version":"1.0","event_id":"sha256:910e8d30e3ece2d8b980651ed699b1f6462e475cef6a5fee2788f6acbeee92b4"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/33NYHLTZWE5OEXMISDKYPCLNLT/bundle.json","state_url":"https://pith.science/pith/33NYHLTZWE5OEXMISDKYPCLNLT/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/33NYHLTZWE5OEXMISDKYPCLNLT/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-07T16:45:29Z","links":{"resolver":"https://pith.science/pith/33NYHLTZWE5OEXMISDKYPCLNLT","bundle":"https://pith.science/pith/33NYHLTZWE5OEXMISDKYPCLNLT/bundle.json","state":"https://pith.science/pith/33NYHLTZWE5OEXMISDKYPCLNLT/state.json","well_known_bundle":"https://pith.science/.well-known/pith/33NYHLTZWE5OEXMISDKYPCLNLT/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:33NYHLTZWE5OEXMISDKYPCLNLT","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"c0bc13c9bafcac5c86c346c9747682fc80982f7547684e677d4b074923768914","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-07-26T19:29:37Z","title_canon_sha256":"d8e40543d09edc784f02c7d06be9b0eba946e85b44cc63cbfd890db710540936"},"schema_version":"1.0","source":{"id":"1807.10335","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1807.10335","created_at":"2026-05-18T00:09:40Z"},{"alias_kind":"arxiv_version","alias_value":"1807.10335v1","created_at":"2026-05-18T00:09:40Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1807.10335","created_at":"2026-05-18T00:09:40Z"},{"alias_kind":"pith_short_12","alias_value":"33NYHLTZWE5O","created_at":"2026-05-18T12:32:02Z"},{"alias_kind":"pith_short_16","alias_value":"33NYHLTZWE5OEXMI","created_at":"2026-05-18T12:32:02Z"},{"alias_kind":"pith_short_8","alias_value":"33NYHLTZ","created_at":"2026-05-18T12:32:02Z"}],"graph_snapshots":[{"event_id":"sha256:910e8d30e3ece2d8b980651ed699b1f6462e475cef6a5fee2788f6acbeee92b4","target":"graph","created_at":"2026-05-18T00:09:40Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"It is well known that a determined adversary can fool a neural network by making imperceptible adversarial perturbations to an image. Recent studies have shown that these perturbations can be detected even without information about the neural network if the strategy taken by the adversary is known beforehand. Unfortunately, these studies suffer from the generalization limitation -- the detection method has to be recalibrated every time the adversary changes his strategy. In this study, we attempt to overcome the generalization limitation by deriving a metric which reliably identifies adversari","authors_text":"Siddharth Krishna Kumar","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-07-26T19:29:37Z","title":"A general metric for identifying adversarial images"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1807.10335","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:dd16275837aeb0b2d06edca8fd0f2d89d4b467a08edf984e011bd8c005fe8d77","target":"record","created_at":"2026-05-18T00:09:40Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"c0bc13c9bafcac5c86c346c9747682fc80982f7547684e677d4b074923768914","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-07-26T19:29:37Z","title_canon_sha256":"d8e40543d09edc784f02c7d06be9b0eba946e85b44cc63cbfd890db710540936"},"schema_version":"1.0","source":{"id":"1807.10335","kind":"arxiv","version":1}},"canonical_sha256":"dedb83ae79b13ae25d8890d587896d5ce61d75ce0c6efb9f0675a07835639f54","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"dedb83ae79b13ae25d8890d587896d5ce61d75ce0c6efb9f0675a07835639f54","first_computed_at":"2026-05-18T00:09:40.902108Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:09:40.902108Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"EALxB2cD+LwBvgQYy1yxzZuVHYOeaAbQNB/DKQJl5VeDJw42Djs1uM4LYiPGTiXMVFSx8BovyuEqvLg0pAYpDQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:09:40.902867Z","signed_message":"canonical_sha256_bytes"},"source_id":"1807.10335","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:dd16275837aeb0b2d06edca8fd0f2d89d4b467a08edf984e011bd8c005fe8d77","sha256:910e8d30e3ece2d8b980651ed699b1f6462e475cef6a5fee2788f6acbeee92b4"],"state_sha256":"5013a37e983e3f6ea923b9138b517702a197aea074978bc96a66b7f14b711913"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"tZ5RVCP1QgB2xZfBm1L+T0i2Y1yaZf4dYhagJWgxXDBc28RCBXPR/KNGzTS+Nlo5zEBrk6iv6sNrmekKgUUTDA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-07T16:45:29.475233Z","bundle_sha256":"4b7c1ac9365fa2445ff422cd9dde5683b395da78f336cdaaf7c3cadee7d2f5ee"}}