{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:6QIMDSU3P6FBHQB4ZICRXQWZOV","short_pith_number":"pith:6QIMDSU3","canonical_record":{"source":{"id":"1803.09638","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-03-26T14:56:28Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"d47b19100aca5cb7fee6fdff1a32b7ea35a3c22d44401acecee2406c7cba6743","abstract_canon_sha256":"06264c8d1f98ded7fa0f55f12b471896c1f0bde73ee25593a145bacd27c4f95c"},"schema_version":"1.0"},"canonical_sha256":"f410c1ca9b7f8a13c03cca051bc2d9755e01d301d0b3cdbf2ee577f74143bc5a","source":{"kind":"arxiv","id":"1803.09638","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1803.09638","created_at":"2026-05-18T00:18:56Z"},{"alias_kind":"arxiv_version","alias_value":"1803.09638v1","created_at":"2026-05-18T00:18:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1803.09638","created_at":"2026-05-18T00:18:56Z"},{"alias_kind":"pith_short_12","alias_value":"6QIMDSU3P6FB","created_at":"2026-05-18T12:32:11Z"},{"alias_kind":"pith_short_16","alias_value":"6QIMDSU3P6FBHQB4","created_at":"2026-05-18T12:32:11Z"},{"alias_kind":"pith_short_8","alias_value":"6QIMDSU3","created_at":"2026-05-18T12:32:11Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:6QIMDSU3P6FBHQB4ZICRXQWZOV","target":"record","payload":{"canonical_record":{"source":{"id":"1803.09638","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-03-26T14:56:28Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"d47b19100aca5cb7fee6fdff1a32b7ea35a3c22d44401acecee2406c7cba6743","abstract_canon_sha256":"06264c8d1f98ded7fa0f55f12b471896c1f0bde73ee25593a145bacd27c4f95c"},"schema_version":"1.0"},"canonical_sha256":"f410c1ca9b7f8a13c03cca051bc2d9755e01d301d0b3cdbf2ee577f74143bc5a","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:18:56.890637Z","signature_b64":"k8jc/yj3tNM8Gc+ZUVsX2I0HFGdNy6yQ0J+boLu01TCSBkV46aQhfahN1D0hzfBsaaqGt+uegDcVP4RJPoFmBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f410c1ca9b7f8a13c03cca051bc2d9755e01d301d0b3cdbf2ee577f74143bc5a","last_reissued_at":"2026-05-18T00:18:56.890220Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:18:56.890220Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1803.09638","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:18:56Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"621sAbSaye6yQjfNGjohj8j0QwKkuTOxa/sT1uKhiJfnyjE3jJCpat3bphuxV1XoHtNjo5xfgKs7fF6PORXnDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T01:36:40.465972Z"},"content_sha256":"3f766b0f965672539edced1018ae522c4cf8b56ffb622ce552a812a5dcc56fe9","schema_version":"1.0","event_id":"sha256:3f766b0f965672539edced1018ae522c4cf8b56ffb622ce552a812a5dcc56fe9"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:6QIMDSU3P6FBHQB4ZICRXQWZOV","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"On the Limitation of Local Intrinsic Dimensionality for Characterizing the Subspaces of Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Chia-Mu Yu, Pei-Hsuan Lu, Pin-Yu Chen","submitted_at":"2018-03-26T14:56:28Z","abstract_excerpt":"Understanding and characterizing the subspaces of adversarial examples aid in studying the robustness of deep neural networks (DNNs) to adversarial perturbations. Very recently, Ma et al. (ICLR 2018) proposed to use local intrinsic dimensionality (LID) in layer-wise hidden representations of DNNs to study adversarial subspaces. It was demonstrated that LID can be used to characterize the adversarial subspaces associated with different attack methods, e.g., the Carlini and Wagner's (C&W) attack and the fast gradient sign attack.\n  In this paper, we use MNIST and CIFAR-10 to conduct two new sets"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1803.09638","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:18:56Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"uJVGzUHA/OCZgMUb1Vw60nqCUf6HEUPfy5PB9nnW0pO0dvdqx8raeiOpOXsL6H9l2RXNEE0pNwJqoxRSrd9dBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T01:36:40.466378Z"},"content_sha256":"00edb53fc92152717266a693b307a3029fa9fbef82167e295a719f46d655f1bf","schema_version":"1.0","event_id":"sha256:00edb53fc92152717266a693b307a3029fa9fbef82167e295a719f46d655f1bf"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/6QIMDSU3P6FBHQB4ZICRXQWZOV/bundle.json","state_url":"https://pith.science/pith/6QIMDSU3P6FBHQB4ZICRXQWZOV/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/6QIMDSU3P6FBHQB4ZICRXQWZOV/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T01:36:40Z","links":{"resolver":"https://pith.science/pith/6QIMDSU3P6FBHQB4ZICRXQWZOV","bundle":"https://pith.science/pith/6QIMDSU3P6FBHQB4ZICRXQWZOV/bundle.json","state":"https://pith.science/pith/6QIMDSU3P6FBHQB4ZICRXQWZOV/state.json","well_known_bundle":"https://pith.science/.well-known/pith/6QIMDSU3P6FBHQB4ZICRXQWZOV/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:6QIMDSU3P6FBHQB4ZICRXQWZOV","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"06264c8d1f98ded7fa0f55f12b471896c1f0bde73ee25593a145bacd27c4f95c","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-03-26T14:56:28Z","title_canon_sha256":"d47b19100aca5cb7fee6fdff1a32b7ea35a3c22d44401acecee2406c7cba6743"},"schema_version":"1.0","source":{"id":"1803.09638","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1803.09638","created_at":"2026-05-18T00:18:56Z"},{"alias_kind":"arxiv_version","alias_value":"1803.09638v1","created_at":"2026-05-18T00:18:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1803.09638","created_at":"2026-05-18T00:18:56Z"},{"alias_kind":"pith_short_12","alias_value":"6QIMDSU3P6FB","created_at":"2026-05-18T12:32:11Z"},{"alias_kind":"pith_short_16","alias_value":"6QIMDSU3P6FBHQB4","created_at":"2026-05-18T12:32:11Z"},{"alias_kind":"pith_short_8","alias_value":"6QIMDSU3","created_at":"2026-05-18T12:32:11Z"}],"graph_snapshots":[{"event_id":"sha256:00edb53fc92152717266a693b307a3029fa9fbef82167e295a719f46d655f1bf","target":"graph","created_at":"2026-05-18T00:18:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Understanding and characterizing the subspaces of adversarial examples aid in studying the robustness of deep neural networks (DNNs) to adversarial perturbations. Very recently, Ma et al. (ICLR 2018) proposed to use local intrinsic dimensionality (LID) in layer-wise hidden representations of DNNs to study adversarial subspaces. It was demonstrated that LID can be used to characterize the adversarial subspaces associated with different attack methods, e.g., the Carlini and Wagner's (C&W) attack and the fast gradient sign attack.\n  In this paper, we use MNIST and CIFAR-10 to conduct two new sets","authors_text":"Chia-Mu Yu, Pei-Hsuan Lu, Pin-Yu Chen","cross_cats":["cs.CR","cs.CV","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-03-26T14:56:28Z","title":"On the Limitation of Local Intrinsic Dimensionality for Characterizing the Subspaces of Adversarial Examples"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1803.09638","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:3f766b0f965672539edced1018ae522c4cf8b56ffb622ce552a812a5dcc56fe9","target":"record","created_at":"2026-05-18T00:18:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"06264c8d1f98ded7fa0f55f12b471896c1f0bde73ee25593a145bacd27c4f95c","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-03-26T14:56:28Z","title_canon_sha256":"d47b19100aca5cb7fee6fdff1a32b7ea35a3c22d44401acecee2406c7cba6743"},"schema_version":"1.0","source":{"id":"1803.09638","kind":"arxiv","version":1}},"canonical_sha256":"f410c1ca9b7f8a13c03cca051bc2d9755e01d301d0b3cdbf2ee577f74143bc5a","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"f410c1ca9b7f8a13c03cca051bc2d9755e01d301d0b3cdbf2ee577f74143bc5a","first_computed_at":"2026-05-18T00:18:56.890220Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:18:56.890220Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"k8jc/yj3tNM8Gc+ZUVsX2I0HFGdNy6yQ0J+boLu01TCSBkV46aQhfahN1D0hzfBsaaqGt+uegDcVP4RJPoFmBw==","signature_status":"signed_v1","signed_at":"2026-05-18T00:18:56.890637Z","signed_message":"canonical_sha256_bytes"},"source_id":"1803.09638","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:3f766b0f965672539edced1018ae522c4cf8b56ffb622ce552a812a5dcc56fe9","sha256:00edb53fc92152717266a693b307a3029fa9fbef82167e295a719f46d655f1bf"],"state_sha256":"8b724063a7590e72c6a161afcc956a578bc7279f3effe5bc9651ba67ce9696d6"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"2OggOatSIZL+qWgzmKuBomIOkstidiM9T6+vvI926Ysa2VAo3CRyJeH1qE5fi1X1eQc2XflugCBZaxRPcqZ1Aw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T01:36:40.469754Z","bundle_sha256":"404728b6af1ec2c7e52508cc7b08ff82c9343a92f8461fb3ee91db279188aff1"}}