{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:7J7KF7G3XSBS6XVMVE4U6NTZ6V","short_pith_number":"pith:7J7KF7G3","canonical_record":{"source":{"id":"1903.00073","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-02-28T21:25:45Z","cross_cats_sorted":["cs.CR","cs.LG","stat.ML"],"title_canon_sha256":"9b65b6d74d5615923a69d90532d816ec3be0edd5f8eef1c80b56008dc5ec7e96","abstract_canon_sha256":"beaa142324840b5336fcda83b741248875bc549e7df710fcf67d37aa856f493f"},"schema_version":"1.0"},"canonical_sha256":"fa7ea2fcdbbc832f5eaca9394f3679f57a5f49389ca0c2a9dc87be2341a11e54","source":{"kind":"arxiv","id":"1903.00073","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1903.00073","created_at":"2026-05-17T23:44:29Z"},{"alias_kind":"arxiv_version","alias_value":"1903.00073v2","created_at":"2026-05-17T23:44:29Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1903.00073","created_at":"2026-05-17T23:44:29Z"},{"alias_kind":"pith_short_12","alias_value":"7J7KF7G3XSBS","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_16","alias_value":"7J7KF7G3XSBS6XVM","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_8","alias_value":"7J7KF7G3","created_at":"2026-05-18T12:33:12Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:7J7KF7G3XSBS6XVMVE4U6NTZ6V","target":"record","payload":{"canonical_record":{"source":{"id":"1903.00073","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-02-28T21:25:45Z","cross_cats_sorted":["cs.CR","cs.LG","stat.ML"],"title_canon_sha256":"9b65b6d74d5615923a69d90532d816ec3be0edd5f8eef1c80b56008dc5ec7e96","abstract_canon_sha256":"beaa142324840b5336fcda83b741248875bc549e7df710fcf67d37aa856f493f"},"schema_version":"1.0"},"canonical_sha256":"fa7ea2fcdbbc832f5eaca9394f3679f57a5f49389ca0c2a9dc87be2341a11e54","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:44:29.223253Z","signature_b64":"qPer5oKstpWzj2m/uoWBHSDIMYeim+gICGmmwSV5f1gL8zTLaIxMzQC3v8lhAc0ZGpvqjYoV1gQ5iLkQDtgCBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"fa7ea2fcdbbc832f5eaca9394f3679f57a5f49389ca0c2a9dc87be2341a11e54","last_reissued_at":"2026-05-17T23:44:29.222640Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:44:29.222640Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1903.00073","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:44:29Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"6lQ5HCSNZ5w/xgH1+JZv8RfRJ54J0aJzQso7NRP3eK9WZK6KyU3l3jJzvg0jpdW2gsNmaKJkuM9SHQpNJ/LXDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T14:02:31.978724Z"},"content_sha256":"8115824fc99f2789165bd4daafd88186a2b6cf4939cec4c10acd5fa121076137","schema_version":"1.0","event_id":"sha256:8115824fc99f2789165bd4daafd88186a2b6cf4939cec4c10acd5fa121076137"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:7J7KF7G3XSBS6XVMVE4U6NTZ6V","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"On the Effectiveness of Low Frequency Perturbations","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.LG","stat.ML"],"primary_cat":"cs.CV","authors_text":"Gavin Weiguang Ding, Marcus Brubaker, Yash Sharma","submitted_at":"2019-02-28T21:25:45Z","abstract_excerpt":"Carefully crafted, often imperceptible, adversarial perturbations have been shown to cause state-of-the-art models to yield extremely inaccurate outputs, rendering them unsuitable for safety-critical application domains. In addition, recent work has shown that constraining the attack space to a low frequency regime is particularly effective. Yet, it remains unclear whether this is due to generally constraining the attack search space or specifically removing high frequency components from consideration. By systematically controlling the frequency components of the perturbation, evaluating agai"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1903.00073","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:44:29Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"IqFL1rCX0tWzXzI1viwDrPrm/IRUAJBwbU0exolDM914r1hsBA8hbkkJIiyblaE855cbX7QotkVG0XppZ6PrCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T14:02:31.979053Z"},"content_sha256":"b4f34df1fe42946f4fd729917859786d511dffa6279c48102986905cc72d6fb0","schema_version":"1.0","event_id":"sha256:b4f34df1fe42946f4fd729917859786d511dffa6279c48102986905cc72d6fb0"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/7J7KF7G3XSBS6XVMVE4U6NTZ6V/bundle.json","state_url":"https://pith.science/pith/7J7KF7G3XSBS6XVMVE4U6NTZ6V/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/7J7KF7G3XSBS6XVMVE4U6NTZ6V/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-30T14:02:31Z","links":{"resolver":"https://pith.science/pith/7J7KF7G3XSBS6XVMVE4U6NTZ6V","bundle":"https://pith.science/pith/7J7KF7G3XSBS6XVMVE4U6NTZ6V/bundle.json","state":"https://pith.science/pith/7J7KF7G3XSBS6XVMVE4U6NTZ6V/state.json","well_known_bundle":"https://pith.science/.well-known/pith/7J7KF7G3XSBS6XVMVE4U6NTZ6V/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:7J7KF7G3XSBS6XVMVE4U6NTZ6V","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"beaa142324840b5336fcda83b741248875bc549e7df710fcf67d37aa856f493f","cross_cats_sorted":["cs.CR","cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-02-28T21:25:45Z","title_canon_sha256":"9b65b6d74d5615923a69d90532d816ec3be0edd5f8eef1c80b56008dc5ec7e96"},"schema_version":"1.0","source":{"id":"1903.00073","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1903.00073","created_at":"2026-05-17T23:44:29Z"},{"alias_kind":"arxiv_version","alias_value":"1903.00073v2","created_at":"2026-05-17T23:44:29Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1903.00073","created_at":"2026-05-17T23:44:29Z"},{"alias_kind":"pith_short_12","alias_value":"7J7KF7G3XSBS","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_16","alias_value":"7J7KF7G3XSBS6XVM","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_8","alias_value":"7J7KF7G3","created_at":"2026-05-18T12:33:12Z"}],"graph_snapshots":[{"event_id":"sha256:b4f34df1fe42946f4fd729917859786d511dffa6279c48102986905cc72d6fb0","target":"graph","created_at":"2026-05-17T23:44:29Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Carefully crafted, often imperceptible, adversarial perturbations have been shown to cause state-of-the-art models to yield extremely inaccurate outputs, rendering them unsuitable for safety-critical application domains. In addition, recent work has shown that constraining the attack space to a low frequency regime is particularly effective. Yet, it remains unclear whether this is due to generally constraining the attack search space or specifically removing high frequency components from consideration. By systematically controlling the frequency components of the perturbation, evaluating agai","authors_text":"Gavin Weiguang Ding, Marcus Brubaker, Yash Sharma","cross_cats":["cs.CR","cs.LG","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-02-28T21:25:45Z","title":"On the Effectiveness of Low Frequency Perturbations"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1903.00073","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:8115824fc99f2789165bd4daafd88186a2b6cf4939cec4c10acd5fa121076137","target":"record","created_at":"2026-05-17T23:44:29Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"beaa142324840b5336fcda83b741248875bc549e7df710fcf67d37aa856f493f","cross_cats_sorted":["cs.CR","cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-02-28T21:25:45Z","title_canon_sha256":"9b65b6d74d5615923a69d90532d816ec3be0edd5f8eef1c80b56008dc5ec7e96"},"schema_version":"1.0","source":{"id":"1903.00073","kind":"arxiv","version":2}},"canonical_sha256":"fa7ea2fcdbbc832f5eaca9394f3679f57a5f49389ca0c2a9dc87be2341a11e54","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"fa7ea2fcdbbc832f5eaca9394f3679f57a5f49389ca0c2a9dc87be2341a11e54","first_computed_at":"2026-05-17T23:44:29.222640Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:44:29.222640Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"qPer5oKstpWzj2m/uoWBHSDIMYeim+gICGmmwSV5f1gL8zTLaIxMzQC3v8lhAc0ZGpvqjYoV1gQ5iLkQDtgCBQ==","signature_status":"signed_v1","signed_at":"2026-05-17T23:44:29.223253Z","signed_message":"canonical_sha256_bytes"},"source_id":"1903.00073","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:8115824fc99f2789165bd4daafd88186a2b6cf4939cec4c10acd5fa121076137","sha256:b4f34df1fe42946f4fd729917859786d511dffa6279c48102986905cc72d6fb0"],"state_sha256":"02a5846a0974fa2983a5391d0febf44bbace3341ad568ae5e23e6a118f614161"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"3qW0qvnD5zQeFa/SmWFC8isuVpumg2hpBwof3lFQAIEuGOi13SEwtLxPRVZFpFIjJyJvCbvq6JWvmjNShAMpDg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-30T14:02:31.981229Z","bundle_sha256":"ab2af645e51a8b72785b8d3fa37c62264d8a8fdb99bbae0d629c00cc05a488e2"}}