{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:3QNLADNEU6HQCVHAP5BXH3APJR","short_pith_number":"pith:3QNLADNE","canonical_record":{"source":{"id":"1806.02924","kind":"arxiv","version":5},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-06-07T23:27:16Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"e4f33413380b729ae1c67021a6034a52d96004f4a5172f04e306e43d5304b6e4","abstract_canon_sha256":"ab124e77b7f03be93011015cbc6e2d2a3e72d1f4ca47088fa56221a00221c1bc"},"schema_version":"1.0"},"canonical_sha256":"dc1ab00da4a78f0154e07f4373ec0f4c5831ebc8dc11ae67c81fb7646c9116fb","source":{"kind":"arxiv","id":"1806.02924","version":5},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1806.02924","created_at":"2026-05-17T23:50:38Z"},{"alias_kind":"arxiv_version","alias_value":"1806.02924v5","created_at":"2026-05-17T23:50:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1806.02924","created_at":"2026-05-17T23:50:38Z"},{"alias_kind":"pith_short_12","alias_value":"3QNLADNEU6HQ","created_at":"2026-05-18T12:32:02Z"},{"alias_kind":"pith_short_16","alias_value":"3QNLADNEU6HQCVHA","created_at":"2026-05-18T12:32:02Z"},{"alias_kind":"pith_short_8","alias_value":"3QNLADNE","created_at":"2026-05-18T12:32:02Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:3QNLADNEU6HQCVHAP5BXH3APJR","target":"record","payload":{"canonical_record":{"source":{"id":"1806.02924","kind":"arxiv","version":5},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-06-07T23:27:16Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"e4f33413380b729ae1c67021a6034a52d96004f4a5172f04e306e43d5304b6e4","abstract_canon_sha256":"ab124e77b7f03be93011015cbc6e2d2a3e72d1f4ca47088fa56221a00221c1bc"},"schema_version":"1.0"},"canonical_sha256":"dc1ab00da4a78f0154e07f4373ec0f4c5831ebc8dc11ae67c81fb7646c9116fb","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:50:38.624190Z","signature_b64":"BQO1aQNatpvDmUJjx0tmeciXP3VUhO8oitl2Xrrt0+0EUsbNsgmnAg9gpdd3+mLo2GxReq78mC8DF6iQ4GnjDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"dc1ab00da4a78f0154e07f4373ec0f4c5831ebc8dc11ae67c81fb7646c9116fb","last_reissued_at":"2026-05-17T23:50:38.623752Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:50:38.623752Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1806.02924","source_version":5,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:50:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"J3xEFc9K+iAu6+F98+UZfYSp6VRuvQ++y5IZy91k7+VQU6+oKATizA+Axg/dXjqJ5yKDhZe3m/LP/luxP7OJAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T07:36:20.586953Z"},"content_sha256":"d7dee3c964e9013f4dc47ce4b2411f901bdf6a9bd88f1a67f2484249bff4c132","schema_version":"1.0","event_id":"sha256:d7dee3c964e9013f4dc47ce4b2411f901bdf6a9bd88f1a67f2484249bff4c132"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:3QNLADNEU6HQCVHAP5BXH3APJR","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Revisiting Adversarial Risk","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"stat.ML","authors_text":"Adarsh Prasad, Arun Sai Suggala, Pradeep Ravikumar, Vaishnavh Nagarajan","submitted_at":"2018-06-07T23:27:16Z","abstract_excerpt":"Recent works on adversarial perturbations show that there is an inherent trade-off between standard test accuracy and adversarial accuracy. Specifically, they show that no classifier can simultaneously be robust to adversarial perturbations and achieve high standard test accuracy. However, this is contrary to the standard notion that on tasks such as image classification, humans are robust classifiers with low error rate. In this work, we show that the main reason behind this confusion is the inexact definition of adversarial perturbation that is used in the literature. To fix this issue, we p"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1806.02924","kind":"arxiv","version":5},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:50:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"W9zmgDyPxJ16xF7qtszyFhepc/EW2WMJPhjXcpp6tsrKfxDk98vf62ui2WSn+W4+nUlNVzBt6EjxWL4HUAM8DQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T07:36:20.587303Z"},"content_sha256":"8371872fc7c7db6959830ff0ca75defb4c40663faa09c6d8179a76c64e2d3e4f","schema_version":"1.0","event_id":"sha256:8371872fc7c7db6959830ff0ca75defb4c40663faa09c6d8179a76c64e2d3e4f"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/3QNLADNEU6HQCVHAP5BXH3APJR/bundle.json","state_url":"https://pith.science/pith/3QNLADNEU6HQCVHAP5BXH3APJR/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/3QNLADNEU6HQCVHAP5BXH3APJR/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-30T07:36:20Z","links":{"resolver":"https://pith.science/pith/3QNLADNEU6HQCVHAP5BXH3APJR","bundle":"https://pith.science/pith/3QNLADNEU6HQCVHAP5BXH3APJR/bundle.json","state":"https://pith.science/pith/3QNLADNEU6HQCVHAP5BXH3APJR/state.json","well_known_bundle":"https://pith.science/.well-known/pith/3QNLADNEU6HQCVHAP5BXH3APJR/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:3QNLADNEU6HQCVHAP5BXH3APJR","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"ab124e77b7f03be93011015cbc6e2d2a3e72d1f4ca47088fa56221a00221c1bc","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-06-07T23:27:16Z","title_canon_sha256":"e4f33413380b729ae1c67021a6034a52d96004f4a5172f04e306e43d5304b6e4"},"schema_version":"1.0","source":{"id":"1806.02924","kind":"arxiv","version":5}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1806.02924","created_at":"2026-05-17T23:50:38Z"},{"alias_kind":"arxiv_version","alias_value":"1806.02924v5","created_at":"2026-05-17T23:50:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1806.02924","created_at":"2026-05-17T23:50:38Z"},{"alias_kind":"pith_short_12","alias_value":"3QNLADNEU6HQ","created_at":"2026-05-18T12:32:02Z"},{"alias_kind":"pith_short_16","alias_value":"3QNLADNEU6HQCVHA","created_at":"2026-05-18T12:32:02Z"},{"alias_kind":"pith_short_8","alias_value":"3QNLADNE","created_at":"2026-05-18T12:32:02Z"}],"graph_snapshots":[{"event_id":"sha256:8371872fc7c7db6959830ff0ca75defb4c40663faa09c6d8179a76c64e2d3e4f","target":"graph","created_at":"2026-05-17T23:50:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Recent works on adversarial perturbations show that there is an inherent trade-off between standard test accuracy and adversarial accuracy. Specifically, they show that no classifier can simultaneously be robust to adversarial perturbations and achieve high standard test accuracy. However, this is contrary to the standard notion that on tasks such as image classification, humans are robust classifiers with low error rate. In this work, we show that the main reason behind this confusion is the inexact definition of adversarial perturbation that is used in the literature. To fix this issue, we p","authors_text":"Adarsh Prasad, Arun Sai Suggala, Pradeep Ravikumar, Vaishnavh Nagarajan","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-06-07T23:27:16Z","title":"Revisiting Adversarial Risk"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1806.02924","kind":"arxiv","version":5},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:d7dee3c964e9013f4dc47ce4b2411f901bdf6a9bd88f1a67f2484249bff4c132","target":"record","created_at":"2026-05-17T23:50:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"ab124e77b7f03be93011015cbc6e2d2a3e72d1f4ca47088fa56221a00221c1bc","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-06-07T23:27:16Z","title_canon_sha256":"e4f33413380b729ae1c67021a6034a52d96004f4a5172f04e306e43d5304b6e4"},"schema_version":"1.0","source":{"id":"1806.02924","kind":"arxiv","version":5}},"canonical_sha256":"dc1ab00da4a78f0154e07f4373ec0f4c5831ebc8dc11ae67c81fb7646c9116fb","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"dc1ab00da4a78f0154e07f4373ec0f4c5831ebc8dc11ae67c81fb7646c9116fb","first_computed_at":"2026-05-17T23:50:38.623752Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:50:38.623752Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"BQO1aQNatpvDmUJjx0tmeciXP3VUhO8oitl2Xrrt0+0EUsbNsgmnAg9gpdd3+mLo2GxReq78mC8DF6iQ4GnjDg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:50:38.624190Z","signed_message":"canonical_sha256_bytes"},"source_id":"1806.02924","source_kind":"arxiv","source_version":5}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:d7dee3c964e9013f4dc47ce4b2411f901bdf6a9bd88f1a67f2484249bff4c132","sha256:8371872fc7c7db6959830ff0ca75defb4c40663faa09c6d8179a76c64e2d3e4f"],"state_sha256":"797080bcb284e6b0466d23425bb27d3f9e4db39e7106bcc58af8a73d4679644c"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Rue2OlLRogpgWKEM2j8SpuGOD4/HJkP5H3xhjMbbb5JM6Tc9RWnMXrwxeKamS2M1NnIhqFF/aoovPQ26EfGXBg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-30T07:36:20.589244Z","bundle_sha256":"544c2a19c5dcb893ffbc542d0435d33d1a04d0a5ad2e541a0d53c95a23ce8791"}}