{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:3XISBT3W2ZIZUCWOV5MOPKN4OA","short_pith_number":"pith:3XISBT3W","canonical_record":{"source":{"id":"1905.09027","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-22T09:06:40Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"ce2e28b09b900e0042714df781445ce91009233f8418ad5efb1fd29a00f22c63","abstract_canon_sha256":"f31f8187d5f49759b7d80f94d9dc1c2d06d5ab2f869dea97f09cacbcd23ef2bf"},"schema_version":"1.0"},"canonical_sha256":"ddd120cf76d6519a0aceaf58e7a9bc703480156a8cc1e95d8260bbfebc1d0caa","source":{"kind":"arxiv","id":"1905.09027","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.09027","created_at":"2026-05-17T23:45:24Z"},{"alias_kind":"arxiv_version","alias_value":"1905.09027v1","created_at":"2026-05-17T23:45:24Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.09027","created_at":"2026-05-17T23:45:24Z"},{"alias_kind":"pith_short_12","alias_value":"3XISBT3W2ZIZ","created_at":"2026-05-18T12:33:10Z"},{"alias_kind":"pith_short_16","alias_value":"3XISBT3W2ZIZUCWO","created_at":"2026-05-18T12:33:10Z"},{"alias_kind":"pith_short_8","alias_value":"3XISBT3W","created_at":"2026-05-18T12:33:10Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:3XISBT3W2ZIZUCWOV5MOPKN4OA","target":"record","payload":{"canonical_record":{"source":{"id":"1905.09027","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-22T09:06:40Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"ce2e28b09b900e0042714df781445ce91009233f8418ad5efb1fd29a00f22c63","abstract_canon_sha256":"f31f8187d5f49759b7d80f94d9dc1c2d06d5ab2f869dea97f09cacbcd23ef2bf"},"schema_version":"1.0"},"canonical_sha256":"ddd120cf76d6519a0aceaf58e7a9bc703480156a8cc1e95d8260bbfebc1d0caa","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:45:24.574343Z","signature_b64":"RM+hnc2EhNsvnUQvPgs//ygKmsuNiXVvowOBYGM9oDVRdh0bnFuNoqzkGcDiRMCmyybPOI6RxiZKPlvVYcdyCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ddd120cf76d6519a0aceaf58e7a9bc703480156a8cc1e95d8260bbfebc1d0caa","last_reissued_at":"2026-05-17T23:45:24.573816Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:45:24.573816Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1905.09027","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:45:24Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"sjqa4IUeSyZKuYPGlb1ALCjgokU1C/9o6KibV/iIWRLQbPW8npG32eBFU1seXJq+m2HKpemmJy4IXYLfVzN6Ag==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T13:19:00.131324Z"},"content_sha256":"b8ae3ba9b95dfc02e9ffd6229ae693b08f76088b10f3e250808b65be16156f87","schema_version":"1.0","event_id":"sha256:b8ae3ba9b95dfc02e9ffd6229ae693b08f76088b10f3e250808b65be16156f87"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:3XISBT3W2ZIZUCWOV5MOPKN4OA","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Learning to Confuse: Generating Training Time Adversarial Data with Auto-Encoder","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Ji Feng, Qi-Zhi Cai, Zhi-Hua Zhou","submitted_at":"2019-05-22T09:06:40Z","abstract_excerpt":"In this work, we consider one challenging training time attack by modifying training data with bounded perturbation, hoping to manipulate the behavior (both targeted or non-targeted) of any corresponding trained classifier during test time when facing clean samples. To achieve this, we proposed to use an auto-encoder-like network to generate the pertubation on the training data paired with one differentiable system acting as the imaginary victim classifier. The perturbation generator will learn to update its weights by watching the training procedure of the imaginary classifier in order to pro"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.09027","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:45:24Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"M8v126kAWXxlvPrXclT7azPOQ+bIpZr/IzK3oSrDIPIegRyNoaiUGP5cigH3DECp9UKWUHLNagAy7lGimihiDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T13:19:00.131680Z"},"content_sha256":"c31e12379b877318589afe11f143d15e4881f77d902720c3cbdf0b570c02d1f7","schema_version":"1.0","event_id":"sha256:c31e12379b877318589afe11f143d15e4881f77d902720c3cbdf0b570c02d1f7"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/3XISBT3W2ZIZUCWOV5MOPKN4OA/bundle.json","state_url":"https://pith.science/pith/3XISBT3W2ZIZUCWOV5MOPKN4OA/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/3XISBT3W2ZIZUCWOV5MOPKN4OA/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-30T13:19:00Z","links":{"resolver":"https://pith.science/pith/3XISBT3W2ZIZUCWOV5MOPKN4OA","bundle":"https://pith.science/pith/3XISBT3W2ZIZUCWOV5MOPKN4OA/bundle.json","state":"https://pith.science/pith/3XISBT3W2ZIZUCWOV5MOPKN4OA/state.json","well_known_bundle":"https://pith.science/.well-known/pith/3XISBT3W2ZIZUCWOV5MOPKN4OA/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:3XISBT3W2ZIZUCWOV5MOPKN4OA","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"f31f8187d5f49759b7d80f94d9dc1c2d06d5ab2f869dea97f09cacbcd23ef2bf","cross_cats_sorted":["stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-22T09:06:40Z","title_canon_sha256":"ce2e28b09b900e0042714df781445ce91009233f8418ad5efb1fd29a00f22c63"},"schema_version":"1.0","source":{"id":"1905.09027","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.09027","created_at":"2026-05-17T23:45:24Z"},{"alias_kind":"arxiv_version","alias_value":"1905.09027v1","created_at":"2026-05-17T23:45:24Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.09027","created_at":"2026-05-17T23:45:24Z"},{"alias_kind":"pith_short_12","alias_value":"3XISBT3W2ZIZ","created_at":"2026-05-18T12:33:10Z"},{"alias_kind":"pith_short_16","alias_value":"3XISBT3W2ZIZUCWO","created_at":"2026-05-18T12:33:10Z"},{"alias_kind":"pith_short_8","alias_value":"3XISBT3W","created_at":"2026-05-18T12:33:10Z"}],"graph_snapshots":[{"event_id":"sha256:c31e12379b877318589afe11f143d15e4881f77d902720c3cbdf0b570c02d1f7","target":"graph","created_at":"2026-05-17T23:45:24Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"In this work, we consider one challenging training time attack by modifying training data with bounded perturbation, hoping to manipulate the behavior (both targeted or non-targeted) of any corresponding trained classifier during test time when facing clean samples. To achieve this, we proposed to use an auto-encoder-like network to generate the pertubation on the training data paired with one differentiable system acting as the imaginary victim classifier. The perturbation generator will learn to update its weights by watching the training procedure of the imaginary classifier in order to pro","authors_text":"Ji Feng, Qi-Zhi Cai, Zhi-Hua Zhou","cross_cats":["stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-22T09:06:40Z","title":"Learning to Confuse: Generating Training Time Adversarial Data with Auto-Encoder"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.09027","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:b8ae3ba9b95dfc02e9ffd6229ae693b08f76088b10f3e250808b65be16156f87","target":"record","created_at":"2026-05-17T23:45:24Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"f31f8187d5f49759b7d80f94d9dc1c2d06d5ab2f869dea97f09cacbcd23ef2bf","cross_cats_sorted":["stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-22T09:06:40Z","title_canon_sha256":"ce2e28b09b900e0042714df781445ce91009233f8418ad5efb1fd29a00f22c63"},"schema_version":"1.0","source":{"id":"1905.09027","kind":"arxiv","version":1}},"canonical_sha256":"ddd120cf76d6519a0aceaf58e7a9bc703480156a8cc1e95d8260bbfebc1d0caa","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"ddd120cf76d6519a0aceaf58e7a9bc703480156a8cc1e95d8260bbfebc1d0caa","first_computed_at":"2026-05-17T23:45:24.573816Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:45:24.573816Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"RM+hnc2EhNsvnUQvPgs//ygKmsuNiXVvowOBYGM9oDVRdh0bnFuNoqzkGcDiRMCmyybPOI6RxiZKPlvVYcdyCg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:45:24.574343Z","signed_message":"canonical_sha256_bytes"},"source_id":"1905.09027","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:b8ae3ba9b95dfc02e9ffd6229ae693b08f76088b10f3e250808b65be16156f87","sha256:c31e12379b877318589afe11f143d15e4881f77d902720c3cbdf0b570c02d1f7"],"state_sha256":"ca9d8e5fa7558a07a62284dbc8d719b23cb2d994718e46ffff1d15578c5922ec"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"dZWIhCbLM1qgse5irey4YewAsQnBswewH47ls1jb4vvfLrO9OxTwq3s91UA7eKxQbPts3QT2QFwjkUoul+IyCA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-30T13:19:00.133575Z","bundle_sha256":"22e602dcdae8daeb0778e66cf7b37cac4eed99bf974aa03ca72c20393137b88c"}}