{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:7I6ODQSNVAARL2SNMW5VXDLO64","short_pith_number":"pith:7I6ODQSN","canonical_record":{"source":{"id":"1905.11971","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-28T17:47:33Z","cross_cats_sorted":["cs.CV","stat.ML"],"title_canon_sha256":"f4343e63dbefbddf56a3b2389f1d7937f6013bb1d32722c48f6366bbd40e834c","abstract_canon_sha256":"129d6b764d708194511b1bc510137b18ef58cce5b9c07db1b49635874f1f30f4"},"schema_version":"1.0"},"canonical_sha256":"fa3ce1c24da80115ea4d65bb5b8d6ef722eca9af976318380e1369717843475b","source":{"kind":"arxiv","id":"1905.11971","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.11971","created_at":"2026-05-17T23:44:49Z"},{"alias_kind":"arxiv_version","alias_value":"1905.11971v1","created_at":"2026-05-17T23:44:49Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.11971","created_at":"2026-05-17T23:44:49Z"},{"alias_kind":"pith_short_12","alias_value":"7I6ODQSNVAAR","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_16","alias_value":"7I6ODQSNVAARL2SN","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_8","alias_value":"7I6ODQSN","created_at":"2026-05-18T12:33:12Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:7I6ODQSNVAARL2SNMW5VXDLO64","target":"record","payload":{"canonical_record":{"source":{"id":"1905.11971","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-28T17:47:33Z","cross_cats_sorted":["cs.CV","stat.ML"],"title_canon_sha256":"f4343e63dbefbddf56a3b2389f1d7937f6013bb1d32722c48f6366bbd40e834c","abstract_canon_sha256":"129d6b764d708194511b1bc510137b18ef58cce5b9c07db1b49635874f1f30f4"},"schema_version":"1.0"},"canonical_sha256":"fa3ce1c24da80115ea4d65bb5b8d6ef722eca9af976318380e1369717843475b","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:44:49.804268Z","signature_b64":"jN4l2LmJMHHVj1KuuL8Y5YxBwgFEZt98prLZPPUxoBOhtNZdAtYbiz3BW94yFEsNTYTolu1X/RSRid4mBWRWCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"fa3ce1c24da80115ea4d65bb5b8d6ef722eca9af976318380e1369717843475b","last_reissued_at":"2026-05-17T23:44:49.803748Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:44:49.803748Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1905.11971","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:44:49Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"DD+9+Ej8Sn2KXuzwu8nak0zcuB7uiqklks9BEiIQYfNCMcWc8dHTSDdM54P/8t6K2XNq51V/RY83uVebe7NCCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T22:41:34.831061Z"},"content_sha256":"37103f0141cdba4cdd933cee30796711914ca478378987e3f4846bca6c7f42dd","schema_version":"1.0","event_id":"sha256:37103f0141cdba4cdd933cee30796711914ca478378987e3f4846bca6c7f42dd"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:7I6ODQSNVAARL2SNMW5VXDLO64","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"ME-Net: Towards Effective Adversarial Robustness with Matrix Estimation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Dina Katabi, Guo Zhang, Yuzhe Yang, Zhi Xu","submitted_at":"2019-05-28T17:47:33Z","abstract_excerpt":"Deep neural networks are vulnerable to adversarial attacks. The literature is rich with algorithms that can easily craft successful adversarial examples. In contrast, the performance of defense techniques still lags behind. This paper proposes ME-Net, a defense method that leverages matrix estimation (ME). In ME-Net, images are preprocessed using two steps: first pixels are randomly dropped from the image; then, the image is reconstructed using ME. We show that this process destroys the adversarial structure of the noise, while re-enforcing the global structure in the original image. Since hum"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.11971","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:44:49Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8bpp+GbmIp6832xDAZDOAcQIP4+6bWT3m4jvCmFyejDOFVYAF6sX4klTeXFl39GhMeRVBZ2F1J2xQ+c3n0GlCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T22:41:34.831418Z"},"content_sha256":"eecb7a015c3a0fcb020e9e969537061f261f7a51f2a2ed017ec9cf4a471209a5","schema_version":"1.0","event_id":"sha256:eecb7a015c3a0fcb020e9e969537061f261f7a51f2a2ed017ec9cf4a471209a5"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/7I6ODQSNVAARL2SNMW5VXDLO64/bundle.json","state_url":"https://pith.science/pith/7I6ODQSNVAARL2SNMW5VXDLO64/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/7I6ODQSNVAARL2SNMW5VXDLO64/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-02T22:41:34Z","links":{"resolver":"https://pith.science/pith/7I6ODQSNVAARL2SNMW5VXDLO64","bundle":"https://pith.science/pith/7I6ODQSNVAARL2SNMW5VXDLO64/bundle.json","state":"https://pith.science/pith/7I6ODQSNVAARL2SNMW5VXDLO64/state.json","well_known_bundle":"https://pith.science/.well-known/pith/7I6ODQSNVAARL2SNMW5VXDLO64/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:7I6ODQSNVAARL2SNMW5VXDLO64","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"129d6b764d708194511b1bc510137b18ef58cce5b9c07db1b49635874f1f30f4","cross_cats_sorted":["cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-28T17:47:33Z","title_canon_sha256":"f4343e63dbefbddf56a3b2389f1d7937f6013bb1d32722c48f6366bbd40e834c"},"schema_version":"1.0","source":{"id":"1905.11971","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.11971","created_at":"2026-05-17T23:44:49Z"},{"alias_kind":"arxiv_version","alias_value":"1905.11971v1","created_at":"2026-05-17T23:44:49Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.11971","created_at":"2026-05-17T23:44:49Z"},{"alias_kind":"pith_short_12","alias_value":"7I6ODQSNVAAR","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_16","alias_value":"7I6ODQSNVAARL2SN","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_8","alias_value":"7I6ODQSN","created_at":"2026-05-18T12:33:12Z"}],"graph_snapshots":[{"event_id":"sha256:eecb7a015c3a0fcb020e9e969537061f261f7a51f2a2ed017ec9cf4a471209a5","target":"graph","created_at":"2026-05-17T23:44:49Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep neural networks are vulnerable to adversarial attacks. The literature is rich with algorithms that can easily craft successful adversarial examples. In contrast, the performance of defense techniques still lags behind. This paper proposes ME-Net, a defense method that leverages matrix estimation (ME). In ME-Net, images are preprocessed using two steps: first pixels are randomly dropped from the image; then, the image is reconstructed using ME. We show that this process destroys the adversarial structure of the noise, while re-enforcing the global structure in the original image. Since hum","authors_text":"Dina Katabi, Guo Zhang, Yuzhe Yang, Zhi Xu","cross_cats":["cs.CV","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-28T17:47:33Z","title":"ME-Net: Towards Effective Adversarial Robustness with Matrix Estimation"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.11971","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:37103f0141cdba4cdd933cee30796711914ca478378987e3f4846bca6c7f42dd","target":"record","created_at":"2026-05-17T23:44:49Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"129d6b764d708194511b1bc510137b18ef58cce5b9c07db1b49635874f1f30f4","cross_cats_sorted":["cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-28T17:47:33Z","title_canon_sha256":"f4343e63dbefbddf56a3b2389f1d7937f6013bb1d32722c48f6366bbd40e834c"},"schema_version":"1.0","source":{"id":"1905.11971","kind":"arxiv","version":1}},"canonical_sha256":"fa3ce1c24da80115ea4d65bb5b8d6ef722eca9af976318380e1369717843475b","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"fa3ce1c24da80115ea4d65bb5b8d6ef722eca9af976318380e1369717843475b","first_computed_at":"2026-05-17T23:44:49.803748Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:44:49.803748Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"jN4l2LmJMHHVj1KuuL8Y5YxBwgFEZt98prLZPPUxoBOhtNZdAtYbiz3BW94yFEsNTYTolu1X/RSRid4mBWRWCg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:44:49.804268Z","signed_message":"canonical_sha256_bytes"},"source_id":"1905.11971","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:37103f0141cdba4cdd933cee30796711914ca478378987e3f4846bca6c7f42dd","sha256:eecb7a015c3a0fcb020e9e969537061f261f7a51f2a2ed017ec9cf4a471209a5"],"state_sha256":"df724a157ac7eed343a831dbca4c7fed7afaf0d8f2202080d2413a9aa858386d"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"1vJ9QKmeGfxx2r1jookWhIIFQ+hVOM8le9Q9K8GX9KMTa9MfXFtXpjo5oeAgEd4aZrP0ZCG3fsX7ye6Egqc4AQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-02T22:41:34.833410Z","bundle_sha256":"8bcf6d440a6c32cb364caffe40d19f8c6c75c214bb1149b8298d8821f247cdee"}}