{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:5AN36RVLZIIFWACK4NXVX42XWJ","short_pith_number":"pith:5AN36RVL","canonical_record":{"source":{"id":"1905.11381","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-25T21:57:51Z","cross_cats_sorted":["cs.CV","cs.LG","stat.ML"],"title_canon_sha256":"7729f49730ebd834525eb2ccc3b5e9cf8562188ac6620574634aa09ff67953b2","abstract_canon_sha256":"0659ca25c2c98594f6cdc6c2ed4550dc79fc76b14909afcd05b699cb322aeb86"},"schema_version":"1.0"},"canonical_sha256":"e81bbf46abca105b004ae36f5bf357b27d686d7434ac3700943b6cf097ab44d3","source":{"kind":"arxiv","id":"1905.11381","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.11381","created_at":"2026-05-17T23:44:53Z"},{"alias_kind":"arxiv_version","alias_value":"1905.11381v1","created_at":"2026-05-17T23:44:53Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.11381","created_at":"2026-05-17T23:44:53Z"},{"alias_kind":"pith_short_12","alias_value":"5AN36RVLZIIF","created_at":"2026-05-18T12:33:10Z"},{"alias_kind":"pith_short_16","alias_value":"5AN36RVLZIIFWACK","created_at":"2026-05-18T12:33:10Z"},{"alias_kind":"pith_short_8","alias_value":"5AN36RVL","created_at":"2026-05-18T12:33:10Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:5AN36RVLZIIFWACK4NXVX42XWJ","target":"record","payload":{"canonical_record":{"source":{"id":"1905.11381","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-25T21:57:51Z","cross_cats_sorted":["cs.CV","cs.LG","stat.ML"],"title_canon_sha256":"7729f49730ebd834525eb2ccc3b5e9cf8562188ac6620574634aa09ff67953b2","abstract_canon_sha256":"0659ca25c2c98594f6cdc6c2ed4550dc79fc76b14909afcd05b699cb322aeb86"},"schema_version":"1.0"},"canonical_sha256":"e81bbf46abca105b004ae36f5bf357b27d686d7434ac3700943b6cf097ab44d3","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:44:53.517241Z","signature_b64":"crpRjZ72xx6QsTGOqlfQa1v0IB+Xvz2qCKvWyDE1aO6Ic+cFk9mjeGcRzEliczX/WmVE2KnXAZhdeg1qjRTRCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e81bbf46abca105b004ae36f5bf357b27d686d7434ac3700943b6cf097ab44d3","last_reissued_at":"2026-05-17T23:44:53.516711Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:44:53.516711Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1905.11381","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:44:53Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Gu72XB1gXDWddu08alb6OhJRehWTUh1xSgFgFeGHEEwn9VkuUnxKhSA8zlfNQxLvUrXhO4/veNQQmhGTAhsrBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T01:16:55.300836Z"},"content_sha256":"5833ad60a4b9333b3ff5686f56c25a6d2b4ee753beee334b272868a0d858992b","schema_version":"1.0","event_id":"sha256:5833ad60a4b9333b3ff5686f56c25a6d2b4ee753beee334b272868a0d858992b"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:5AN36RVLZIIFWACK4NXVX42XWJ","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Trust but Verify: An Information-Theoretic Explanation for the Adversarial Fragility of Machine Learning Systems, and a General Defense against Adversarial Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","cs.LG","stat.ML"],"primary_cat":"cs.CR","authors_text":"Hui Xie, Jirong Yi, Leixin Zhou, Raghuraman Mudumbai, Weiyu Xu, Xiaodong Wu","submitted_at":"2019-05-25T21:57:51Z","abstract_excerpt":"Deep-learning based classification algorithms have been shown to be susceptible to adversarial attacks: minor changes to the input of classifiers can dramatically change their outputs, while being imperceptible to humans. In this paper, we present a simple hypothesis about a feature compression property of artificial intelligence (AI) classifiers and present theoretical arguments to show that this hypothesis successfully accounts for the observed fragility of AI classifiers to small adversarial perturbations. Drawing on ideas from information and coding theory, we propose a general class of de"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.11381","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:44:53Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"tVMn50IrruguCYK0NPmPgbm59LGt50sEDZs9SsvpOVvPEBgWxDoMmKkj/IuZEUVy74Q/+59TJaSyPBoBLnBTBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T01:16:55.301523Z"},"content_sha256":"d8166b99d9b4aefa1ea7ec59b9ad1780d5c9f956bd838840519da474d7ed22b6","schema_version":"1.0","event_id":"sha256:d8166b99d9b4aefa1ea7ec59b9ad1780d5c9f956bd838840519da474d7ed22b6"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/5AN36RVLZIIFWACK4NXVX42XWJ/bundle.json","state_url":"https://pith.science/pith/5AN36RVLZIIFWACK4NXVX42XWJ/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/5AN36RVLZIIFWACK4NXVX42XWJ/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-30T01:16:55Z","links":{"resolver":"https://pith.science/pith/5AN36RVLZIIFWACK4NXVX42XWJ","bundle":"https://pith.science/pith/5AN36RVLZIIFWACK4NXVX42XWJ/bundle.json","state":"https://pith.science/pith/5AN36RVLZIIFWACK4NXVX42XWJ/state.json","well_known_bundle":"https://pith.science/.well-known/pith/5AN36RVLZIIFWACK4NXVX42XWJ/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:5AN36RVLZIIFWACK4NXVX42XWJ","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"0659ca25c2c98594f6cdc6c2ed4550dc79fc76b14909afcd05b699cb322aeb86","cross_cats_sorted":["cs.CV","cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-25T21:57:51Z","title_canon_sha256":"7729f49730ebd834525eb2ccc3b5e9cf8562188ac6620574634aa09ff67953b2"},"schema_version":"1.0","source":{"id":"1905.11381","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.11381","created_at":"2026-05-17T23:44:53Z"},{"alias_kind":"arxiv_version","alias_value":"1905.11381v1","created_at":"2026-05-17T23:44:53Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.11381","created_at":"2026-05-17T23:44:53Z"},{"alias_kind":"pith_short_12","alias_value":"5AN36RVLZIIF","created_at":"2026-05-18T12:33:10Z"},{"alias_kind":"pith_short_16","alias_value":"5AN36RVLZIIFWACK","created_at":"2026-05-18T12:33:10Z"},{"alias_kind":"pith_short_8","alias_value":"5AN36RVL","created_at":"2026-05-18T12:33:10Z"}],"graph_snapshots":[{"event_id":"sha256:d8166b99d9b4aefa1ea7ec59b9ad1780d5c9f956bd838840519da474d7ed22b6","target":"graph","created_at":"2026-05-17T23:44:53Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep-learning based classification algorithms have been shown to be susceptible to adversarial attacks: minor changes to the input of classifiers can dramatically change their outputs, while being imperceptible to humans. In this paper, we present a simple hypothesis about a feature compression property of artificial intelligence (AI) classifiers and present theoretical arguments to show that this hypothesis successfully accounts for the observed fragility of AI classifiers to small adversarial perturbations. Drawing on ideas from information and coding theory, we propose a general class of de","authors_text":"Hui Xie, Jirong Yi, Leixin Zhou, Raghuraman Mudumbai, Weiyu Xu, Xiaodong Wu","cross_cats":["cs.CV","cs.LG","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-25T21:57:51Z","title":"Trust but Verify: An Information-Theoretic Explanation for the Adversarial Fragility of Machine Learning Systems, and a General Defense against Adversarial Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.11381","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:5833ad60a4b9333b3ff5686f56c25a6d2b4ee753beee334b272868a0d858992b","target":"record","created_at":"2026-05-17T23:44:53Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"0659ca25c2c98594f6cdc6c2ed4550dc79fc76b14909afcd05b699cb322aeb86","cross_cats_sorted":["cs.CV","cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-25T21:57:51Z","title_canon_sha256":"7729f49730ebd834525eb2ccc3b5e9cf8562188ac6620574634aa09ff67953b2"},"schema_version":"1.0","source":{"id":"1905.11381","kind":"arxiv","version":1}},"canonical_sha256":"e81bbf46abca105b004ae36f5bf357b27d686d7434ac3700943b6cf097ab44d3","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"e81bbf46abca105b004ae36f5bf357b27d686d7434ac3700943b6cf097ab44d3","first_computed_at":"2026-05-17T23:44:53.516711Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:44:53.516711Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"crpRjZ72xx6QsTGOqlfQa1v0IB+Xvz2qCKvWyDE1aO6Ic+cFk9mjeGcRzEliczX/WmVE2KnXAZhdeg1qjRTRCg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:44:53.517241Z","signed_message":"canonical_sha256_bytes"},"source_id":"1905.11381","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:5833ad60a4b9333b3ff5686f56c25a6d2b4ee753beee334b272868a0d858992b","sha256:d8166b99d9b4aefa1ea7ec59b9ad1780d5c9f956bd838840519da474d7ed22b6"],"state_sha256":"da9cc55656fb45df43081abf3673e82c8e7cf86a6cda726267ba849a822b0488"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"GmGHyfYvQUXDLGT006h/zzZ3B7y1Clz/SY8JQKV5ljD5CFcfj7183hosVfbD5rahiolgWc22Hy7h74fNNnFTAw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-30T01:16:55.305361Z","bundle_sha256":"2775cb93c7d132e588eee06a51148dd322b4bfa031910e7e1f191b61910434d6"}}