{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:6JWIZBY4XQ5YRMRB2JTE5H7DFL","short_pith_number":"pith:6JWIZBY4","canonical_record":{"source":{"id":"1705.02224","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-05-05T15:28:59Z","cross_cats_sorted":["cs.CV","stat.ML"],"title_canon_sha256":"1ea9b94da6bfb4741d77649f6e2cc6393d4830ac52ba35bf8f2c102c4166cf07","abstract_canon_sha256":"6b104474153002adf7be06d7cf89655ed43b053ed0f004b8f29c646f84426234"},"schema_version":"1.0"},"canonical_sha256":"f26c8c871cbc3b88b221d2664e9fe32ad7a029dacee482299e5a7cbbd8718eab","source":{"kind":"arxiv","id":"1705.02224","version":4},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1705.02224","created_at":"2026-05-18T00:30:11Z"},{"alias_kind":"arxiv_version","alias_value":"1705.02224v4","created_at":"2026-05-18T00:30:11Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1705.02224","created_at":"2026-05-18T00:30:11Z"},{"alias_kind":"pith_short_12","alias_value":"6JWIZBY4XQ5Y","created_at":"2026-05-18T12:31:03Z"},{"alias_kind":"pith_short_16","alias_value":"6JWIZBY4XQ5YRMRB","created_at":"2026-05-18T12:31:03Z"},{"alias_kind":"pith_short_8","alias_value":"6JWIZBY4","created_at":"2026-05-18T12:31:03Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:6JWIZBY4XQ5YRMRB2JTE5H7DFL","target":"record","payload":{"canonical_record":{"source":{"id":"1705.02224","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-05-05T15:28:59Z","cross_cats_sorted":["cs.CV","stat.ML"],"title_canon_sha256":"1ea9b94da6bfb4741d77649f6e2cc6393d4830ac52ba35bf8f2c102c4166cf07","abstract_canon_sha256":"6b104474153002adf7be06d7cf89655ed43b053ed0f004b8f29c646f84426234"},"schema_version":"1.0"},"canonical_sha256":"f26c8c871cbc3b88b221d2664e9fe32ad7a029dacee482299e5a7cbbd8718eab","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:30:11.512459Z","signature_b64":"FKlOXAPpl4Sxl+AHsJn5D1O4VlX7/sEf/Lg2bO4W/Re+j7AyZ8A1Vv8F8e7Q84ztJvkcGDc3hXO7jkktVc2bCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f26c8c871cbc3b88b221d2664e9fe32ad7a029dacee482299e5a7cbbd8718eab","last_reissued_at":"2026-05-18T00:30:11.511430Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:30:11.511430Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1705.02224","source_version":4,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:30:11Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"2vZabiRG1yeqPwAS9js7nfY0SUpJ2p6xV769LmyNftRcfyL6ZKr10pA8zbsww26GUP0rO9Q0A/JxxbAo3ek5Aw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-31T17:02:14.002961Z"},"content_sha256":"da1aaf27a752e926c52d0db1f811d1a04f33bf2d820958e53cdd58617973671e","schema_version":"1.0","event_id":"sha256:da1aaf27a752e926c52d0db1f811d1a04f33bf2d820958e53cdd58617973671e"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:6JWIZBY4XQ5YRMRB2JTE5H7DFL","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Detecting Adversarial Samples Using Density Ratio Estimates","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Lovedeep Gondara","submitted_at":"2017-05-05T15:28:59Z","abstract_excerpt":"Machine learning models, especially based on deep architectures are used in everyday applications ranging from self driving cars to medical diagnostics. It has been shown that such models are dangerously susceptible to adversarial samples, indistinguishable from real samples to human eye, adversarial samples lead to incorrect classifications with high confidence. Impact of adversarial samples is far-reaching and their efficient detection remains an open problem. We propose to use direct density ratio estimation as an efficient model agnostic measure to detect adversarial samples. Our proposed "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1705.02224","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:30:11Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Nmu/RL8i4zoi3srirl+GqEFk+51/v7QIe0qD8xWt0AL6VgaG1Vy7OOIQiwu3K1lTnRlF+nBSoxFZ6dktlh7YBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-31T17:02:14.003627Z"},"content_sha256":"d7094a03adb434132b71cdc845cb4b80b6c60209255fd7ed0196f1c4f064127d","schema_version":"1.0","event_id":"sha256:d7094a03adb434132b71cdc845cb4b80b6c60209255fd7ed0196f1c4f064127d"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/6JWIZBY4XQ5YRMRB2JTE5H7DFL/bundle.json","state_url":"https://pith.science/pith/6JWIZBY4XQ5YRMRB2JTE5H7DFL/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/6JWIZBY4XQ5YRMRB2JTE5H7DFL/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-31T17:02:14Z","links":{"resolver":"https://pith.science/pith/6JWIZBY4XQ5YRMRB2JTE5H7DFL","bundle":"https://pith.science/pith/6JWIZBY4XQ5YRMRB2JTE5H7DFL/bundle.json","state":"https://pith.science/pith/6JWIZBY4XQ5YRMRB2JTE5H7DFL/state.json","well_known_bundle":"https://pith.science/.well-known/pith/6JWIZBY4XQ5YRMRB2JTE5H7DFL/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:6JWIZBY4XQ5YRMRB2JTE5H7DFL","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"6b104474153002adf7be06d7cf89655ed43b053ed0f004b8f29c646f84426234","cross_cats_sorted":["cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-05-05T15:28:59Z","title_canon_sha256":"1ea9b94da6bfb4741d77649f6e2cc6393d4830ac52ba35bf8f2c102c4166cf07"},"schema_version":"1.0","source":{"id":"1705.02224","kind":"arxiv","version":4}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1705.02224","created_at":"2026-05-18T00:30:11Z"},{"alias_kind":"arxiv_version","alias_value":"1705.02224v4","created_at":"2026-05-18T00:30:11Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1705.02224","created_at":"2026-05-18T00:30:11Z"},{"alias_kind":"pith_short_12","alias_value":"6JWIZBY4XQ5Y","created_at":"2026-05-18T12:31:03Z"},{"alias_kind":"pith_short_16","alias_value":"6JWIZBY4XQ5YRMRB","created_at":"2026-05-18T12:31:03Z"},{"alias_kind":"pith_short_8","alias_value":"6JWIZBY4","created_at":"2026-05-18T12:31:03Z"}],"graph_snapshots":[{"event_id":"sha256:d7094a03adb434132b71cdc845cb4b80b6c60209255fd7ed0196f1c4f064127d","target":"graph","created_at":"2026-05-18T00:30:11Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Machine learning models, especially based on deep architectures are used in everyday applications ranging from self driving cars to medical diagnostics. It has been shown that such models are dangerously susceptible to adversarial samples, indistinguishable from real samples to human eye, adversarial samples lead to incorrect classifications with high confidence. Impact of adversarial samples is far-reaching and their efficient detection remains an open problem. We propose to use direct density ratio estimation as an efficient model agnostic measure to detect adversarial samples. Our proposed ","authors_text":"Lovedeep Gondara","cross_cats":["cs.CV","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-05-05T15:28:59Z","title":"Detecting Adversarial Samples Using Density Ratio Estimates"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1705.02224","kind":"arxiv","version":4},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:da1aaf27a752e926c52d0db1f811d1a04f33bf2d820958e53cdd58617973671e","target":"record","created_at":"2026-05-18T00:30:11Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"6b104474153002adf7be06d7cf89655ed43b053ed0f004b8f29c646f84426234","cross_cats_sorted":["cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-05-05T15:28:59Z","title_canon_sha256":"1ea9b94da6bfb4741d77649f6e2cc6393d4830ac52ba35bf8f2c102c4166cf07"},"schema_version":"1.0","source":{"id":"1705.02224","kind":"arxiv","version":4}},"canonical_sha256":"f26c8c871cbc3b88b221d2664e9fe32ad7a029dacee482299e5a7cbbd8718eab","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"f26c8c871cbc3b88b221d2664e9fe32ad7a029dacee482299e5a7cbbd8718eab","first_computed_at":"2026-05-18T00:30:11.511430Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:30:11.511430Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"FKlOXAPpl4Sxl+AHsJn5D1O4VlX7/sEf/Lg2bO4W/Re+j7AyZ8A1Vv8F8e7Q84ztJvkcGDc3hXO7jkktVc2bCA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:30:11.512459Z","signed_message":"canonical_sha256_bytes"},"source_id":"1705.02224","source_kind":"arxiv","source_version":4}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:da1aaf27a752e926c52d0db1f811d1a04f33bf2d820958e53cdd58617973671e","sha256:d7094a03adb434132b71cdc845cb4b80b6c60209255fd7ed0196f1c4f064127d"],"state_sha256":"926f663fc49f190401494b2fdace9216976a17eee542624c8c0527ae076bdcad"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"4dEP7JX9qBjiuvDvnBlIrimRzJLxSkZZ9CxUuBJ0Gukiu1l+42o2Ci4Dy3G6uQ7cWclfQOhLgQj/LskpCu8BDA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-31T17:02:14.009051Z","bundle_sha256":"fa3c408c5e8c28b83d877c11fe71cf725c264a8fd771b938dd5c10adfdd60f16"}}