{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:6WFP4QISKATSJDDGAMUWRKJVIO","short_pith_number":"pith:6WFP4QIS","canonical_record":{"source":{"id":"1906.04392","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-06-11T04:55:18Z","cross_cats_sorted":["cs.CR","cs.LG","cs.NE"],"title_canon_sha256":"bd4d6f4de22604db5f8ffd2568942ca6e155d51701b3ea92cd73b2e6add4bf34","abstract_canon_sha256":"b06c35e548a7777874d048eb697d5c41d6ebb62d9b67bcf1db888ef003d04656"},"schema_version":"1.0"},"canonical_sha256":"f58afe41125027248c66032968a93543a35080859e04e68c2a2c53133975c104","source":{"kind":"arxiv","id":"1906.04392","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1906.04392","created_at":"2026-05-17T23:43:39Z"},{"alias_kind":"arxiv_version","alias_value":"1906.04392v1","created_at":"2026-05-17T23:43:39Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1906.04392","created_at":"2026-05-17T23:43:39Z"},{"alias_kind":"pith_short_12","alias_value":"6WFP4QISKATS","created_at":"2026-05-18T12:33:10Z"},{"alias_kind":"pith_short_16","alias_value":"6WFP4QISKATSJDDG","created_at":"2026-05-18T12:33:10Z"},{"alias_kind":"pith_short_8","alias_value":"6WFP4QIS","created_at":"2026-05-18T12:33:10Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:6WFP4QISKATSJDDGAMUWRKJVIO","target":"record","payload":{"canonical_record":{"source":{"id":"1906.04392","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-06-11T04:55:18Z","cross_cats_sorted":["cs.CR","cs.LG","cs.NE"],"title_canon_sha256":"bd4d6f4de22604db5f8ffd2568942ca6e155d51701b3ea92cd73b2e6add4bf34","abstract_canon_sha256":"b06c35e548a7777874d048eb697d5c41d6ebb62d9b67bcf1db888ef003d04656"},"schema_version":"1.0"},"canonical_sha256":"f58afe41125027248c66032968a93543a35080859e04e68c2a2c53133975c104","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:43:39.413146Z","signature_b64":"hAzRXfLq67XxU++5kGTZYh6hwdLNm3PmCNiZHAhAW0SExKdDrxBo2WHBnDLR4IXLw9yMylaCK1LWjRJ7H66FAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f58afe41125027248c66032968a93543a35080859e04e68c2a2c53133975c104","last_reissued_at":"2026-05-17T23:43:39.412540Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:43:39.412540Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1906.04392","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:43:39Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"RZSwBRplI4Yzz8Sowzqbb/sDNxt4JLsudlNwwecRTktZaZS8VvLMifbjTRwI58I4OQqvTjmaOLsmKeWJ/ttmAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T21:51:37.486266Z"},"content_sha256":"42ab8800b2ce6226d419bbd886e49cf54b0b15030bab940287660d30457f527c","schema_version":"1.0","event_id":"sha256:42ab8800b2ce6226d419bbd886e49cf54b0b15030bab940287660d30457f527c"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:6WFP4QISKATSJDDGAMUWRKJVIO","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Subspace Attack: Exploiting Promising Subspaces for Query-Efficient Black-box Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.LG","cs.NE"],"primary_cat":"cs.CV","authors_text":"Changshui Zhang, Yiwen Guo, Ziang Yan","submitted_at":"2019-06-11T04:55:18Z","abstract_excerpt":"Unlike the white-box counterparts that are widely studied and readily accessible, adversarial examples in black-box settings are generally more Herculean on account of the difficulty of estimating gradients. Many methods achieve the task by issuing numerous queries to target classification systems, which makes the whole procedure costly and suspicious to the systems. In this paper, we aim at reducing the query complexity of black-box attacks in this category. We propose to exploit gradients of a few reference models which arguably span some promising search subspaces. Experimental results show"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1906.04392","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:43:39Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"C3bWyqYihznmcdYGu+oZrgYEddoqCMTttAAW6EvRP31viY0A5EL7Ge5DaV2HG+fj5pOhw4Fy72nDjUrw/TieBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T21:51:37.486935Z"},"content_sha256":"82e717811f3db27bde2b1f971d0bd365ed009527740d4369220084803c203bbd","schema_version":"1.0","event_id":"sha256:82e717811f3db27bde2b1f971d0bd365ed009527740d4369220084803c203bbd"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/6WFP4QISKATSJDDGAMUWRKJVIO/bundle.json","state_url":"https://pith.science/pith/6WFP4QISKATSJDDGAMUWRKJVIO/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/6WFP4QISKATSJDDGAMUWRKJVIO/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-27T21:51:37Z","links":{"resolver":"https://pith.science/pith/6WFP4QISKATSJDDGAMUWRKJVIO","bundle":"https://pith.science/pith/6WFP4QISKATSJDDGAMUWRKJVIO/bundle.json","state":"https://pith.science/pith/6WFP4QISKATSJDDGAMUWRKJVIO/state.json","well_known_bundle":"https://pith.science/.well-known/pith/6WFP4QISKATSJDDGAMUWRKJVIO/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:6WFP4QISKATSJDDGAMUWRKJVIO","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"b06c35e548a7777874d048eb697d5c41d6ebb62d9b67bcf1db888ef003d04656","cross_cats_sorted":["cs.CR","cs.LG","cs.NE"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-06-11T04:55:18Z","title_canon_sha256":"bd4d6f4de22604db5f8ffd2568942ca6e155d51701b3ea92cd73b2e6add4bf34"},"schema_version":"1.0","source":{"id":"1906.04392","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1906.04392","created_at":"2026-05-17T23:43:39Z"},{"alias_kind":"arxiv_version","alias_value":"1906.04392v1","created_at":"2026-05-17T23:43:39Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1906.04392","created_at":"2026-05-17T23:43:39Z"},{"alias_kind":"pith_short_12","alias_value":"6WFP4QISKATS","created_at":"2026-05-18T12:33:10Z"},{"alias_kind":"pith_short_16","alias_value":"6WFP4QISKATSJDDG","created_at":"2026-05-18T12:33:10Z"},{"alias_kind":"pith_short_8","alias_value":"6WFP4QIS","created_at":"2026-05-18T12:33:10Z"}],"graph_snapshots":[{"event_id":"sha256:82e717811f3db27bde2b1f971d0bd365ed009527740d4369220084803c203bbd","target":"graph","created_at":"2026-05-17T23:43:39Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Unlike the white-box counterparts that are widely studied and readily accessible, adversarial examples in black-box settings are generally more Herculean on account of the difficulty of estimating gradients. Many methods achieve the task by issuing numerous queries to target classification systems, which makes the whole procedure costly and suspicious to the systems. In this paper, we aim at reducing the query complexity of black-box attacks in this category. We propose to exploit gradients of a few reference models which arguably span some promising search subspaces. Experimental results show","authors_text":"Changshui Zhang, Yiwen Guo, Ziang Yan","cross_cats":["cs.CR","cs.LG","cs.NE"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-06-11T04:55:18Z","title":"Subspace Attack: Exploiting Promising Subspaces for Query-Efficient Black-box Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1906.04392","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:42ab8800b2ce6226d419bbd886e49cf54b0b15030bab940287660d30457f527c","target":"record","created_at":"2026-05-17T23:43:39Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"b06c35e548a7777874d048eb697d5c41d6ebb62d9b67bcf1db888ef003d04656","cross_cats_sorted":["cs.CR","cs.LG","cs.NE"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-06-11T04:55:18Z","title_canon_sha256":"bd4d6f4de22604db5f8ffd2568942ca6e155d51701b3ea92cd73b2e6add4bf34"},"schema_version":"1.0","source":{"id":"1906.04392","kind":"arxiv","version":1}},"canonical_sha256":"f58afe41125027248c66032968a93543a35080859e04e68c2a2c53133975c104","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"f58afe41125027248c66032968a93543a35080859e04e68c2a2c53133975c104","first_computed_at":"2026-05-17T23:43:39.412540Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:43:39.412540Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"hAzRXfLq67XxU++5kGTZYh6hwdLNm3PmCNiZHAhAW0SExKdDrxBo2WHBnDLR4IXLw9yMylaCK1LWjRJ7H66FAg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:43:39.413146Z","signed_message":"canonical_sha256_bytes"},"source_id":"1906.04392","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:42ab8800b2ce6226d419bbd886e49cf54b0b15030bab940287660d30457f527c","sha256:82e717811f3db27bde2b1f971d0bd365ed009527740d4369220084803c203bbd"],"state_sha256":"b8e579da7ccbefdc5f0fae8735c3f9e8cf5b1d6e408ce976ad9ddc7148d99ef5"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"v1x0pLNZEo1KGXl+FsY0A214ehaG4RtlON3gD0Uki1easDovP1HvRWVGULGGvs1QLXqp0k0qh9dIHDDkeJhmDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-27T21:51:37.490019Z","bundle_sha256":"8b1af085a78c873e833f2153452c32b7685fc58653126072c7507a52fa02411c"}}