{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:56GRLXRNQOCY5A6IKPBI24XOTE","short_pith_number":"pith:56GRLXRN","schema_version":"1.0","canonical_sha256":"ef8d15de2d83858e83c853c28d72ee993c62f890e227b20bd2d8e8118dc99e7d","source":{"kind":"arxiv","id":"2102.10055","version":1},"attestation_state":"computed","paper":{"title":"Effective and Efficient Vote Attack on Capsule Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CV","authors_text":"Baoyuan Wu, Jindong Gu, Volker Tresp","submitted_at":"2021-02-19T17:35:07Z","abstract_excerpt":"Standard Convolutional Neural Networks (CNNs) can be easily fooled by images with small quasi-imperceptible artificial perturbations. As alternatives to CNNs, the recently proposed Capsule Networks (CapsNets) are shown to be more robust to white-box attacks than CNNs under popular attack protocols. Besides, the class-conditional reconstruction part of CapsNets is also used to detect adversarial examples. In this work, we investigate the adversarial robustness of CapsNets, especially how the inner workings of CapsNets change when the output capsules are attacked. The first observation is that a"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2102.10055","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2021-02-19T17:35:07Z","cross_cats_sorted":[],"title_canon_sha256":"cadbdf9a6b2359bb3a9fbecc4a41e57994c46cacb60d183ccdf0a8be8147527d","abstract_canon_sha256":"162b17263c0edabcdf101e1fb509d6ee7d075d53980fd81fee5dfb7b2cf196b0"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T02:16:39.294227Z","signature_b64":"0QAMVegrlL3AmNd2Jln3UmNu6A7i9OvTsODCIE+Wd16yixgPzaAhHNswHOwTPZWqZNEr0l9vrBrbpvCLOJ8fCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ef8d15de2d83858e83c853c28d72ee993c62f890e227b20bd2d8e8118dc99e7d","last_reissued_at":"2026-07-05T02:16:39.293885Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T02:16:39.293885Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Effective and Efficient Vote Attack on Capsule Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CV","authors_text":"Baoyuan Wu, Jindong Gu, Volker Tresp","submitted_at":"2021-02-19T17:35:07Z","abstract_excerpt":"Standard Convolutional Neural Networks (CNNs) can be easily fooled by images with small quasi-imperceptible artificial perturbations. As alternatives to CNNs, the recently proposed Capsule Networks (CapsNets) are shown to be more robust to white-box attacks than CNNs under popular attack protocols. Besides, the class-conditional reconstruction part of CapsNets is also used to detect adversarial examples. In this work, we investigate the adversarial robustness of CapsNets, especially how the inner workings of CapsNets change when the output capsules are attacked. The first observation is that a"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2102.10055","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2102.10055/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2102.10055","created_at":"2026-07-05T02:16:39.293946+00:00"},{"alias_kind":"arxiv_version","alias_value":"2102.10055v1","created_at":"2026-07-05T02:16:39.293946+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2102.10055","created_at":"2026-07-05T02:16:39.293946+00:00"},{"alias_kind":"pith_short_12","alias_value":"56GRLXRNQOCY","created_at":"2026-07-05T02:16:39.293946+00:00"},{"alias_kind":"pith_short_16","alias_value":"56GRLXRNQOCY5A6I","created_at":"2026-07-05T02:16:39.293946+00:00"},{"alias_kind":"pith_short_8","alias_value":"56GRLXRN","created_at":"2026-07-05T02:16:39.293946+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2502.01262","citing_title":"FSPGD: Rethinking Black-box Attacks on Semantic Segmentation","ref_index":16,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/56GRLXRNQOCY5A6IKPBI24XOTE","json":"https://pith.science/pith/56GRLXRNQOCY5A6IKPBI24XOTE.json","graph_json":"https://pith.science/api/pith-number/56GRLXRNQOCY5A6IKPBI24XOTE/graph.json","events_json":"https://pith.science/api/pith-number/56GRLXRNQOCY5A6IKPBI24XOTE/events.json","paper":"https://pith.science/paper/56GRLXRN"},"agent_actions":{"view_html":"https://pith.science/pith/56GRLXRNQOCY5A6IKPBI24XOTE","download_json":"https://pith.science/pith/56GRLXRNQOCY5A6IKPBI24XOTE.json","view_paper":"https://pith.science/paper/56GRLXRN","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2102.10055&json=true","fetch_graph":"https://pith.science/api/pith-number/56GRLXRNQOCY5A6IKPBI24XOTE/graph.json","fetch_events":"https://pith.science/api/pith-number/56GRLXRNQOCY5A6IKPBI24XOTE/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/56GRLXRNQOCY5A6IKPBI24XOTE/action/timestamp_anchor","attest_storage":"https://pith.science/pith/56GRLXRNQOCY5A6IKPBI24XOTE/action/storage_attestation","attest_author":"https://pith.science/pith/56GRLXRNQOCY5A6IKPBI24XOTE/action/author_attestation","sign_citation":"https://pith.science/pith/56GRLXRNQOCY5A6IKPBI24XOTE/action/citation_signature","submit_replication":"https://pith.science/pith/56GRLXRNQOCY5A6IKPBI24XOTE/action/replication_record"}},"created_at":"2026-07-05T02:16:39.293946+00:00","updated_at":"2026-07-05T02:16:39.293946+00:00"}