{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2015:7SDEK2CDKQ2FGNSKF4NTUGVKZT","short_pith_number":"pith:7SDEK2CD","canonical_record":{"source":{"id":"1511.05122","kind":"arxiv","version":9},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CV","submitted_at":"2015-11-16T20:48:20Z","cross_cats_sorted":["cs.LG","cs.NE"],"title_canon_sha256":"4c466abc577f6402e818e20f7012b0ada28692dbe788b282725031cccc8aa005","abstract_canon_sha256":"30d35f3dcca9851b1ebb1742f786f17fee978d8b7879f8831e4b46b61a1374cc"},"schema_version":"1.0"},"canonical_sha256":"fc86456843543453364a2f1b3a1aaaccca8cff10702a42194b036ed834ab9ed0","source":{"kind":"arxiv","id":"1511.05122","version":9},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1511.05122","created_at":"2026-05-18T01:19:38Z"},{"alias_kind":"arxiv_version","alias_value":"1511.05122v9","created_at":"2026-05-18T01:19:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1511.05122","created_at":"2026-05-18T01:19:38Z"},{"alias_kind":"pith_short_12","alias_value":"7SDEK2CDKQ2F","created_at":"2026-05-18T12:29:10Z"},{"alias_kind":"pith_short_16","alias_value":"7SDEK2CDKQ2FGNSK","created_at":"2026-05-18T12:29:10Z"},{"alias_kind":"pith_short_8","alias_value":"7SDEK2CD","created_at":"2026-05-18T12:29:10Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2015:7SDEK2CDKQ2FGNSKF4NTUGVKZT","target":"record","payload":{"canonical_record":{"source":{"id":"1511.05122","kind":"arxiv","version":9},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CV","submitted_at":"2015-11-16T20:48:20Z","cross_cats_sorted":["cs.LG","cs.NE"],"title_canon_sha256":"4c466abc577f6402e818e20f7012b0ada28692dbe788b282725031cccc8aa005","abstract_canon_sha256":"30d35f3dcca9851b1ebb1742f786f17fee978d8b7879f8831e4b46b61a1374cc"},"schema_version":"1.0"},"canonical_sha256":"fc86456843543453364a2f1b3a1aaaccca8cff10702a42194b036ed834ab9ed0","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T01:19:38.375504Z","signature_b64":"nbejrpSXgzZHGvM4Sy2LkAUll+e70QNssFKuh9IpfJVNah306H1ZzMwVgORdN3/UdQFWmPuqoAjVWo3xKEisCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"fc86456843543453364a2f1b3a1aaaccca8cff10702a42194b036ed834ab9ed0","last_reissued_at":"2026-05-18T01:19:38.374996Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T01:19:38.374996Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1511.05122","source_version":9,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T01:19:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"O0U8XXwLGJQ5YFZFMtSGw/40kbd0d3ZEdV0S4kV9OsknD/MMySOEQoyu45xNfpl6pmYDlapwKPkwZwB0UNXnDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T23:06:13.921505Z"},"content_sha256":"9a328d2db14fecd3351381aad74f0d8b9f565da5eb36bfe144f1adf1c79b4d9c","schema_version":"1.0","event_id":"sha256:9a328d2db14fecd3351381aad74f0d8b9f565da5eb36bfe144f1adf1c79b4d9c"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2015:7SDEK2CDKQ2FGNSKF4NTUGVKZT","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Adversarial Manipulation of Deep Representations","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.LG","cs.NE"],"primary_cat":"cs.CV","authors_text":"David J. Fleet, Fartash Faghri, Sara Sabour, Yanshuai Cao","submitted_at":"2015-11-16T20:48:20Z","abstract_excerpt":"We show that the representation of an image in a deep neural network (DNN) can be manipulated to mimic those of other natural images, with only minor, imperceptible perturbations to the original image. Previous methods for generating adversarial images focused on image perturbations designed to produce erroneous class labels, while we concentrate on the internal layers of DNN representations. In this way our new class of adversarial images differs qualitatively from others. While the adversary is perceptually similar to one image, its internal representation appears remarkably similar to a dif"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1511.05122","kind":"arxiv","version":9},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T01:19:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"GNe9+bLErGyoLar1Sh/wceapzJury5IMN5jR8RFOK0BK3K0yCcJ16/sDqB/UY+ZMu3CVySwFHOrwHcpqTjDzAw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T23:06:13.922181Z"},"content_sha256":"519ada4fce1456397343d0e7328db005c3a2dda18f72293ff531146ab9e63b20","schema_version":"1.0","event_id":"sha256:519ada4fce1456397343d0e7328db005c3a2dda18f72293ff531146ab9e63b20"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/7SDEK2CDKQ2FGNSKF4NTUGVKZT/bundle.json","state_url":"https://pith.science/pith/7SDEK2CDKQ2FGNSKF4NTUGVKZT/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/7SDEK2CDKQ2FGNSKF4NTUGVKZT/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T23:06:13Z","links":{"resolver":"https://pith.science/pith/7SDEK2CDKQ2FGNSKF4NTUGVKZT","bundle":"https://pith.science/pith/7SDEK2CDKQ2FGNSKF4NTUGVKZT/bundle.json","state":"https://pith.science/pith/7SDEK2CDKQ2FGNSKF4NTUGVKZT/state.json","well_known_bundle":"https://pith.science/.well-known/pith/7SDEK2CDKQ2FGNSKF4NTUGVKZT/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2015:7SDEK2CDKQ2FGNSKF4NTUGVKZT","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"30d35f3dcca9851b1ebb1742f786f17fee978d8b7879f8831e4b46b61a1374cc","cross_cats_sorted":["cs.LG","cs.NE"],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CV","submitted_at":"2015-11-16T20:48:20Z","title_canon_sha256":"4c466abc577f6402e818e20f7012b0ada28692dbe788b282725031cccc8aa005"},"schema_version":"1.0","source":{"id":"1511.05122","kind":"arxiv","version":9}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1511.05122","created_at":"2026-05-18T01:19:38Z"},{"alias_kind":"arxiv_version","alias_value":"1511.05122v9","created_at":"2026-05-18T01:19:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1511.05122","created_at":"2026-05-18T01:19:38Z"},{"alias_kind":"pith_short_12","alias_value":"7SDEK2CDKQ2F","created_at":"2026-05-18T12:29:10Z"},{"alias_kind":"pith_short_16","alias_value":"7SDEK2CDKQ2FGNSK","created_at":"2026-05-18T12:29:10Z"},{"alias_kind":"pith_short_8","alias_value":"7SDEK2CD","created_at":"2026-05-18T12:29:10Z"}],"graph_snapshots":[{"event_id":"sha256:519ada4fce1456397343d0e7328db005c3a2dda18f72293ff531146ab9e63b20","target":"graph","created_at":"2026-05-18T01:19:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We show that the representation of an image in a deep neural network (DNN) can be manipulated to mimic those of other natural images, with only minor, imperceptible perturbations to the original image. Previous methods for generating adversarial images focused on image perturbations designed to produce erroneous class labels, while we concentrate on the internal layers of DNN representations. In this way our new class of adversarial images differs qualitatively from others. While the adversary is perceptually similar to one image, its internal representation appears remarkably similar to a dif","authors_text":"David J. Fleet, Fartash Faghri, Sara Sabour, Yanshuai Cao","cross_cats":["cs.LG","cs.NE"],"headline":"","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CV","submitted_at":"2015-11-16T20:48:20Z","title":"Adversarial Manipulation of Deep Representations"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1511.05122","kind":"arxiv","version":9},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:9a328d2db14fecd3351381aad74f0d8b9f565da5eb36bfe144f1adf1c79b4d9c","target":"record","created_at":"2026-05-18T01:19:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"30d35f3dcca9851b1ebb1742f786f17fee978d8b7879f8831e4b46b61a1374cc","cross_cats_sorted":["cs.LG","cs.NE"],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CV","submitted_at":"2015-11-16T20:48:20Z","title_canon_sha256":"4c466abc577f6402e818e20f7012b0ada28692dbe788b282725031cccc8aa005"},"schema_version":"1.0","source":{"id":"1511.05122","kind":"arxiv","version":9}},"canonical_sha256":"fc86456843543453364a2f1b3a1aaaccca8cff10702a42194b036ed834ab9ed0","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"fc86456843543453364a2f1b3a1aaaccca8cff10702a42194b036ed834ab9ed0","first_computed_at":"2026-05-18T01:19:38.374996Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T01:19:38.374996Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"nbejrpSXgzZHGvM4Sy2LkAUll+e70QNssFKuh9IpfJVNah306H1ZzMwVgORdN3/UdQFWmPuqoAjVWo3xKEisCw==","signature_status":"signed_v1","signed_at":"2026-05-18T01:19:38.375504Z","signed_message":"canonical_sha256_bytes"},"source_id":"1511.05122","source_kind":"arxiv","source_version":9}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:9a328d2db14fecd3351381aad74f0d8b9f565da5eb36bfe144f1adf1c79b4d9c","sha256:519ada4fce1456397343d0e7328db005c3a2dda18f72293ff531146ab9e63b20"],"state_sha256":"37f80667b95b17dc2f9148825d382e62f45917a121fd2877cee998e3c59817c4"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Km7QhNYJMV4jATh7PMetnVrER4YyfQK7esTvqlXZF0OM2T9Tfz4EIu+AxaNhKuqfTagcobHJwvB6bzoIqCgqCA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T23:06:13.926295Z","bundle_sha256":"6c48c82a2643cb3203f0200e1a7dc24444da8362d9511732e066d436d410b229"}}