{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:3R6CNBOUKREQ275SEYIKWWBHWE","short_pith_number":"pith:3R6CNBOU","schema_version":"1.0","canonical_sha256":"dc7c2685d454490d7fb22610ab5827b11c8f22d8063d1494a8942c65fe0e9463","source":{"kind":"arxiv","id":"2402.02095","version":3},"attestation_state":"computed","paper":{"title":"Contrasting Adversarial Perturbations: The Space of Harmless Perturbations","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Benhao Huang, Fan Yang, Jie Li, Lu Chen, Shaofeng Li, Yuan Luo, Zheng Li","submitted_at":"2024-02-03T09:22:07Z","abstract_excerpt":"Existing works have extensively studied adversarial examples, which are minimal perturbations that can mislead the output of deep neural networks (DNNs) while remaining imperceptible to humans. However, in this work, we reveal the existence of a harmless perturbation space, in which perturbations drawn from this space, regardless of their magnitudes, leave the network output unchanged when applied to inputs. Essentially, the harmless perturbation space emerges from the usage of non-injective functions (linear or non-linear layers) within DNNs, enabling multiple distinct inputs to be mapped to "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2402.02095","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2024-02-03T09:22:07Z","cross_cats_sorted":[],"title_canon_sha256":"e71d5ab79679d796600c3921c6b877330d0daf9fd929088c54d6c396ac7e9625","abstract_canon_sha256":"df44da45ee3a13480fbe14683d700d5e36df62f4091eca8f2de3d00c0fc50a53"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:46:44.780164Z","signature_b64":"XFyFaG/ds2v8U+DjB31aLTL1MuRT6AyibCaIeSN5wNEG4NfCfsX9dL9grM21ZcmWux0ekP0DydG+ttN2oqa5Bw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"dc7c2685d454490d7fb22610ab5827b11c8f22d8063d1494a8942c65fe0e9463","last_reissued_at":"2026-07-05T09:46:44.779716Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:46:44.779716Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Contrasting Adversarial Perturbations: The Space of Harmless Perturbations","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Benhao Huang, Fan Yang, Jie Li, Lu Chen, Shaofeng Li, Yuan Luo, Zheng Li","submitted_at":"2024-02-03T09:22:07Z","abstract_excerpt":"Existing works have extensively studied adversarial examples, which are minimal perturbations that can mislead the output of deep neural networks (DNNs) while remaining imperceptible to humans. However, in this work, we reveal the existence of a harmless perturbation space, in which perturbations drawn from this space, regardless of their magnitudes, leave the network output unchanged when applied to inputs. Essentially, the harmless perturbation space emerges from the usage of non-injective functions (linear or non-linear layers) within DNNs, enabling multiple distinct inputs to be mapped to "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2402.02095","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2402.02095/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2402.02095","created_at":"2026-07-05T09:46:44.779775+00:00"},{"alias_kind":"arxiv_version","alias_value":"2402.02095v3","created_at":"2026-07-05T09:46:44.779775+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.02095","created_at":"2026-07-05T09:46:44.779775+00:00"},{"alias_kind":"pith_short_12","alias_value":"3R6CNBOUKREQ","created_at":"2026-07-05T09:46:44.779775+00:00"},{"alias_kind":"pith_short_16","alias_value":"3R6CNBOUKREQ275S","created_at":"2026-07-05T09:46:44.779775+00:00"},{"alias_kind":"pith_short_8","alias_value":"3R6CNBOU","created_at":"2026-07-05T09:46:44.779775+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2507.16372","citing_title":"Depth Gives a False Sense of Privacy: LLM Internal States Inversion","ref_index":72,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/3R6CNBOUKREQ275SEYIKWWBHWE","json":"https://pith.science/pith/3R6CNBOUKREQ275SEYIKWWBHWE.json","graph_json":"https://pith.science/api/pith-number/3R6CNBOUKREQ275SEYIKWWBHWE/graph.json","events_json":"https://pith.science/api/pith-number/3R6CNBOUKREQ275SEYIKWWBHWE/events.json","paper":"https://pith.science/paper/3R6CNBOU"},"agent_actions":{"view_html":"https://pith.science/pith/3R6CNBOUKREQ275SEYIKWWBHWE","download_json":"https://pith.science/pith/3R6CNBOUKREQ275SEYIKWWBHWE.json","view_paper":"https://pith.science/paper/3R6CNBOU","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2402.02095&json=true","fetch_graph":"https://pith.science/api/pith-number/3R6CNBOUKREQ275SEYIKWWBHWE/graph.json","fetch_events":"https://pith.science/api/pith-number/3R6CNBOUKREQ275SEYIKWWBHWE/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/3R6CNBOUKREQ275SEYIKWWBHWE/action/timestamp_anchor","attest_storage":"https://pith.science/pith/3R6CNBOUKREQ275SEYIKWWBHWE/action/storage_attestation","attest_author":"https://pith.science/pith/3R6CNBOUKREQ275SEYIKWWBHWE/action/author_attestation","sign_citation":"https://pith.science/pith/3R6CNBOUKREQ275SEYIKWWBHWE/action/citation_signature","submit_replication":"https://pith.science/pith/3R6CNBOUKREQ275SEYIKWWBHWE/action/replication_record"}},"created_at":"2026-07-05T09:46:44.779775+00:00","updated_at":"2026-07-05T09:46:44.779775+00:00"}