{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:4RYKAIM3EUPBKDUZV7VROKPBVF","short_pith_number":"pith:4RYKAIM3","schema_version":"1.0","canonical_sha256":"e470a0219b251e150e99afeb1729e1a96acaeabeace12b659a1777f5502b6aa8","source":{"kind":"arxiv","id":"2106.09898","version":2},"attestation_state":"computed","paper":{"title":"Bad Characters: Imperceptible NLP Attacks","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.CR","cs.LG"],"primary_cat":"cs.CL","authors_text":"Ilia Shumailov, Nicholas Boucher, Nicolas Papernot, Ross Anderson","submitted_at":"2021-06-18T03:42:56Z","abstract_excerpt":"Several years of research have shown that machine-learning systems are vulnerable to adversarial examples, both in theory and in practice. Until now, such attacks have primarily targeted visual models, exploiting the gap between human and machine perception. Although text-based models have also been attacked with adversarial examples, such attacks struggled to preserve semantic meaning and indistinguishability. In this paper, we explore a large class of adversarial examples that can be used to attack text-based models in a black-box setting without making any human-perceptible visual modificat"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2106.09898","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CL","submitted_at":"2021-06-18T03:42:56Z","cross_cats_sorted":["cs.CR","cs.LG"],"title_canon_sha256":"d42aad650474525061002259f31ad3ccdf4cb30ad04bd4e2d00b7c04a1334e2e","abstract_canon_sha256":"2226e6643c9d2acee94a52e4d685995a5c923afd2cad46d0f8a872457bc77597"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T03:39:59.965418Z","signature_b64":"k5pVnymnbRk5kwnivKgyZ4PinKlqHybl/sML+MLQOwD2Q/NzCYAEfjHGZP1WeWRfJhNMzOnJ8uoODx2VfpjtBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e470a0219b251e150e99afeb1729e1a96acaeabeace12b659a1777f5502b6aa8","last_reissued_at":"2026-07-05T03:39:59.964989Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T03:39:59.964989Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Bad Characters: Imperceptible NLP Attacks","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.CR","cs.LG"],"primary_cat":"cs.CL","authors_text":"Ilia Shumailov, Nicholas Boucher, Nicolas Papernot, Ross Anderson","submitted_at":"2021-06-18T03:42:56Z","abstract_excerpt":"Several years of research have shown that machine-learning systems are vulnerable to adversarial examples, both in theory and in practice. Until now, such attacks have primarily targeted visual models, exploiting the gap between human and machine perception. Although text-based models have also been attacked with adversarial examples, such attacks struggled to preserve semantic meaning and indistinguishability. In this paper, we explore a large class of adversarial examples that can be used to attack text-based models in a black-box setting without making any human-perceptible visual modificat"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2106.09898","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2106.09898/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2106.09898","created_at":"2026-07-05T03:39:59.965049+00:00"},{"alias_kind":"arxiv_version","alias_value":"2106.09898v2","created_at":"2026-07-05T03:39:59.965049+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2106.09898","created_at":"2026-07-05T03:39:59.965049+00:00"},{"alias_kind":"pith_short_12","alias_value":"4RYKAIM3EUPB","created_at":"2026-07-05T03:39:59.965049+00:00"},{"alias_kind":"pith_short_16","alias_value":"4RYKAIM3EUPBKDUZ","created_at":"2026-07-05T03:39:59.965049+00:00"},{"alias_kind":"pith_short_8","alias_value":"4RYKAIM3","created_at":"2026-07-05T03:39:59.965049+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.12978","citing_title":"Trajectory-Level Redirection Attacks on Vision-Language-Action Models","ref_index":38,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/4RYKAIM3EUPBKDUZV7VROKPBVF","json":"https://pith.science/pith/4RYKAIM3EUPBKDUZV7VROKPBVF.json","graph_json":"https://pith.science/api/pith-number/4RYKAIM3EUPBKDUZV7VROKPBVF/graph.json","events_json":"https://pith.science/api/pith-number/4RYKAIM3EUPBKDUZV7VROKPBVF/events.json","paper":"https://pith.science/paper/4RYKAIM3"},"agent_actions":{"view_html":"https://pith.science/pith/4RYKAIM3EUPBKDUZV7VROKPBVF","download_json":"https://pith.science/pith/4RYKAIM3EUPBKDUZV7VROKPBVF.json","view_paper":"https://pith.science/paper/4RYKAIM3","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2106.09898&json=true","fetch_graph":"https://pith.science/api/pith-number/4RYKAIM3EUPBKDUZV7VROKPBVF/graph.json","fetch_events":"https://pith.science/api/pith-number/4RYKAIM3EUPBKDUZV7VROKPBVF/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/4RYKAIM3EUPBKDUZV7VROKPBVF/action/timestamp_anchor","attest_storage":"https://pith.science/pith/4RYKAIM3EUPBKDUZV7VROKPBVF/action/storage_attestation","attest_author":"https://pith.science/pith/4RYKAIM3EUPBKDUZV7VROKPBVF/action/author_attestation","sign_citation":"https://pith.science/pith/4RYKAIM3EUPBKDUZV7VROKPBVF/action/citation_signature","submit_replication":"https://pith.science/pith/4RYKAIM3EUPBKDUZV7VROKPBVF/action/replication_record"}},"created_at":"2026-07-05T03:39:59.965049+00:00","updated_at":"2026-07-05T03:39:59.965049+00:00"}