{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:3KGL4WZON5JEWUPE2THNVY7YT4","short_pith_number":"pith:3KGL4WZO","canonical_record":{"source":{"id":"1806.00667","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-06-02T16:43:17Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"4ba33aac9502b20fa04a8a98d56d2520e4d7d3c2a0ae99240efc167c69216f5c","abstract_canon_sha256":"4b3c4c58f3df7256ca9e746a82838f6402239ddc7650929163ff59cbebd097d2"},"schema_version":"1.0"},"canonical_sha256":"da8cbe5b2e6f524b51e4d4cedae3f89f208f26acaf2636cdf08eb2f06ab2d4bf","source":{"kind":"arxiv","id":"1806.00667","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1806.00667","created_at":"2026-05-18T00:12:03Z"},{"alias_kind":"arxiv_version","alias_value":"1806.00667v3","created_at":"2026-05-18T00:12:03Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1806.00667","created_at":"2026-05-18T00:12:03Z"},{"alias_kind":"pith_short_12","alias_value":"3KGL4WZON5JE","created_at":"2026-05-18T12:32:02Z"},{"alias_kind":"pith_short_16","alias_value":"3KGL4WZON5JEWUPE","created_at":"2026-05-18T12:32:02Z"},{"alias_kind":"pith_short_8","alias_value":"3KGL4WZO","created_at":"2026-05-18T12:32:02Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:3KGL4WZON5JEWUPE2THNVY7YT4","target":"record","payload":{"canonical_record":{"source":{"id":"1806.00667","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-06-02T16:43:17Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"4ba33aac9502b20fa04a8a98d56d2520e4d7d3c2a0ae99240efc167c69216f5c","abstract_canon_sha256":"4b3c4c58f3df7256ca9e746a82838f6402239ddc7650929163ff59cbebd097d2"},"schema_version":"1.0"},"canonical_sha256":"da8cbe5b2e6f524b51e4d4cedae3f89f208f26acaf2636cdf08eb2f06ab2d4bf","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:12:03.642364Z","signature_b64":"Iwx+7CsoJnvBHQxWZnXRNfnuVkDOOdSFCHPp1ZgpeQP5GdwWiQauWkDzb51Z055LEbj0BDpTjk8zz6PZz3vsCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"da8cbe5b2e6f524b51e4d4cedae3f89f208f26acaf2636cdf08eb2f06ab2d4bf","last_reissued_at":"2026-05-18T00:12:03.641805Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:12:03.641805Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1806.00667","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:12:03Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"WFc2KPFKCh26sirw2QkywIM0Oq/6cETU1Nn9CTq4FOv3Z57rlolhlljVugMKlwkUMFE/or0ksdHly3CpkSTUDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-11T02:07:16.559615Z"},"content_sha256":"e82bcf5f928b0f7222caeb902bc2c39c05a7651b6e1f289e724fc8df140530bd","schema_version":"1.0","event_id":"sha256:e82bcf5f928b0f7222caeb902bc2c39c05a7651b6e1f289e724fc8df140530bd"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:3KGL4WZON5JEWUPE2THNVY7YT4","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Sufficient Conditions for Idealised Models to Have No Adversarial Examples: a Theoretical and Empirical Study with Bayesian Neural Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"stat.ML","authors_text":"Lewis Smith, Yarin Gal","submitted_at":"2018-06-02T16:43:17Z","abstract_excerpt":"We prove, under two sufficient conditions, that idealised models can have no adversarial examples. We discuss which idealised models satisfy our conditions, and show that idealised Bayesian neural networks (BNNs) satisfy these. We continue by studying near-idealised BNNs using HMC inference, demonstrating the theoretical ideas in practice. We experiment with HMC on synthetic data derived from MNIST for which we know the ground-truth image density, showing that near-perfect epistemic uncertainty correlates to density under image manifold, and that adversarial images lie off the manifold in our "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1806.00667","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:12:03Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"YZrKJkCfY4SUCcBdUEIJTze7rru9qljKdYPlnzu6y2fMuYcXkI3ukyFUtQgA/Y396XMxXESDgHCiTIiuJcYsBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-11T02:07:16.560281Z"},"content_sha256":"76951ace242249479d77ba89f5d95a5a581fa1af76ef3f5d11ba5b46d853d202","schema_version":"1.0","event_id":"sha256:76951ace242249479d77ba89f5d95a5a581fa1af76ef3f5d11ba5b46d853d202"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/3KGL4WZON5JEWUPE2THNVY7YT4/bundle.json","state_url":"https://pith.science/pith/3KGL4WZON5JEWUPE2THNVY7YT4/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/3KGL4WZON5JEWUPE2THNVY7YT4/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-11T02:07:16Z","links":{"resolver":"https://pith.science/pith/3KGL4WZON5JEWUPE2THNVY7YT4","bundle":"https://pith.science/pith/3KGL4WZON5JEWUPE2THNVY7YT4/bundle.json","state":"https://pith.science/pith/3KGL4WZON5JEWUPE2THNVY7YT4/state.json","well_known_bundle":"https://pith.science/.well-known/pith/3KGL4WZON5JEWUPE2THNVY7YT4/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:3KGL4WZON5JEWUPE2THNVY7YT4","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"4b3c4c58f3df7256ca9e746a82838f6402239ddc7650929163ff59cbebd097d2","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-06-02T16:43:17Z","title_canon_sha256":"4ba33aac9502b20fa04a8a98d56d2520e4d7d3c2a0ae99240efc167c69216f5c"},"schema_version":"1.0","source":{"id":"1806.00667","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1806.00667","created_at":"2026-05-18T00:12:03Z"},{"alias_kind":"arxiv_version","alias_value":"1806.00667v3","created_at":"2026-05-18T00:12:03Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1806.00667","created_at":"2026-05-18T00:12:03Z"},{"alias_kind":"pith_short_12","alias_value":"3KGL4WZON5JE","created_at":"2026-05-18T12:32:02Z"},{"alias_kind":"pith_short_16","alias_value":"3KGL4WZON5JEWUPE","created_at":"2026-05-18T12:32:02Z"},{"alias_kind":"pith_short_8","alias_value":"3KGL4WZO","created_at":"2026-05-18T12:32:02Z"}],"graph_snapshots":[{"event_id":"sha256:76951ace242249479d77ba89f5d95a5a581fa1af76ef3f5d11ba5b46d853d202","target":"graph","created_at":"2026-05-18T00:12:03Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We prove, under two sufficient conditions, that idealised models can have no adversarial examples. We discuss which idealised models satisfy our conditions, and show that idealised Bayesian neural networks (BNNs) satisfy these. We continue by studying near-idealised BNNs using HMC inference, demonstrating the theoretical ideas in practice. We experiment with HMC on synthetic data derived from MNIST for which we know the ground-truth image density, showing that near-perfect epistemic uncertainty correlates to density under image manifold, and that adversarial images lie off the manifold in our ","authors_text":"Lewis Smith, Yarin Gal","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-06-02T16:43:17Z","title":"Sufficient Conditions for Idealised Models to Have No Adversarial Examples: a Theoretical and Empirical Study with Bayesian Neural Networks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1806.00667","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:e82bcf5f928b0f7222caeb902bc2c39c05a7651b6e1f289e724fc8df140530bd","target":"record","created_at":"2026-05-18T00:12:03Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"4b3c4c58f3df7256ca9e746a82838f6402239ddc7650929163ff59cbebd097d2","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-06-02T16:43:17Z","title_canon_sha256":"4ba33aac9502b20fa04a8a98d56d2520e4d7d3c2a0ae99240efc167c69216f5c"},"schema_version":"1.0","source":{"id":"1806.00667","kind":"arxiv","version":3}},"canonical_sha256":"da8cbe5b2e6f524b51e4d4cedae3f89f208f26acaf2636cdf08eb2f06ab2d4bf","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"da8cbe5b2e6f524b51e4d4cedae3f89f208f26acaf2636cdf08eb2f06ab2d4bf","first_computed_at":"2026-05-18T00:12:03.641805Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:12:03.641805Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Iwx+7CsoJnvBHQxWZnXRNfnuVkDOOdSFCHPp1ZgpeQP5GdwWiQauWkDzb51Z055LEbj0BDpTjk8zz6PZz3vsCA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:12:03.642364Z","signed_message":"canonical_sha256_bytes"},"source_id":"1806.00667","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:e82bcf5f928b0f7222caeb902bc2c39c05a7651b6e1f289e724fc8df140530bd","sha256:76951ace242249479d77ba89f5d95a5a581fa1af76ef3f5d11ba5b46d853d202"],"state_sha256":"ea199d771519e4187c3703d315bcfcb786d1292d1017e1a5f51d162114f5422b"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"kgz1oUMuswEmGYlimo2EPO2e8INkU4IV1MFtHPILt/Dcj/L9MXUOoSYE/bR5M/kcGeScAE7i6kkoniSjyaTkBQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-11T02:07:16.563641Z","bundle_sha256":"1f46df1987c20cd549e3b6722ca496f085c6938a5741ee0054aadcdc5af0943a"}}