{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:7WF45Z64R6TFZITSSWVFX2ZRBB","short_pith_number":"pith:7WF45Z64","canonical_record":{"source":{"id":"1803.00940","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-03-02T16:35:44Z","cross_cats_sorted":["cs.GR"],"title_canon_sha256":"083d9f695badfc5e5a0aeae6f3e9628179711c67f1525e49a85695e40b0de0c8","abstract_canon_sha256":"bb6c76fcc6f947fc6007d4aa2cae695f0a54e89f76f2f8ca8b0e5b8d6707c63b"},"schema_version":"1.0"},"canonical_sha256":"fd8bcee7dc8fa65ca27295aa5beb31087076ac0f2bc1c63196a65260591eed65","source":{"kind":"arxiv","id":"1803.00940","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1803.00940","created_at":"2026-05-18T00:22:07Z"},{"alias_kind":"arxiv_version","alias_value":"1803.00940v1","created_at":"2026-05-18T00:22:07Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1803.00940","created_at":"2026-05-18T00:22:07Z"},{"alias_kind":"pith_short_12","alias_value":"7WF45Z64R6TF","created_at":"2026-05-18T12:32:11Z"},{"alias_kind":"pith_short_16","alias_value":"7WF45Z64R6TFZITS","created_at":"2026-05-18T12:32:11Z"},{"alias_kind":"pith_short_8","alias_value":"7WF45Z64","created_at":"2026-05-18T12:32:11Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:7WF45Z64R6TFZITSSWVFX2ZRBB","target":"record","payload":{"canonical_record":{"source":{"id":"1803.00940","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-03-02T16:35:44Z","cross_cats_sorted":["cs.GR"],"title_canon_sha256":"083d9f695badfc5e5a0aeae6f3e9628179711c67f1525e49a85695e40b0de0c8","abstract_canon_sha256":"bb6c76fcc6f947fc6007d4aa2cae695f0a54e89f76f2f8ca8b0e5b8d6707c63b"},"schema_version":"1.0"},"canonical_sha256":"fd8bcee7dc8fa65ca27295aa5beb31087076ac0f2bc1c63196a65260591eed65","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:22:07.405375Z","signature_b64":"1lNF0eP/qHB3Yt/T1AVaIBQSuZlhoijjov+o8/G4I2LNo3HHyWb4D68anS6ALnWCSs+7hsPm0xVOGpYM7QT6AQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"fd8bcee7dc8fa65ca27295aa5beb31087076ac0f2bc1c63196a65260591eed65","last_reissued_at":"2026-05-18T00:22:07.404811Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:22:07.404811Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1803.00940","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:22:07Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"/EU1X98Yjcv3SKNgc0+S+XId7K9EGbphKeNwiSaf2Dn7N4uwzSwxz7qomITNZtLEINRO090WUaKfQxUe2x0oAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T14:24:25.584403Z"},"content_sha256":"4d979320a89288b748d338d20d736a15760421ce5f40944a6b90d10a1e9b3729","schema_version":"1.0","event_id":"sha256:4d979320a89288b748d338d20d736a15760421ce5f40944a6b90d10a1e9b3729"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:7WF45Z64R6TFZITSSWVFX2ZRBB","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Protecting JPEG Images Against Adversarial Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.GR"],"primary_cat":"cs.CV","authors_text":"Aaditya Prakash, Antonella DiLillo, James Storer, Nick Moran, Solomon Garber","submitted_at":"2018-03-02T16:35:44Z","abstract_excerpt":"As deep neural networks (DNNs) have been integrated into critical systems, several methods to attack these systems have been developed. These adversarial attacks make imperceptible modifications to an image that fool DNN classifiers. We present an adaptive JPEG encoder which defends against many of these attacks. Experimentally, we show that our method produces images with high visual quality while greatly reducing the potency of state-of-the-art attacks. Our algorithm requires only a modest increase in encoding time, produces a compressed image which can be decompressed by an off-the-shelf JP"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1803.00940","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:22:07Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"HjvyhHfKMnXNur6L2/ops0YKp5yMPVHngqDvELKGIa0Ix3LF73qJXJ5jHWVdIAhSTitVLxf5+DHi5NvZdVwlDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T14:24:25.585181Z"},"content_sha256":"07f73fb050b094fc60a6e6ce168dd279c6f9a8364929d6326ef150ddaeaa0c9a","schema_version":"1.0","event_id":"sha256:07f73fb050b094fc60a6e6ce168dd279c6f9a8364929d6326ef150ddaeaa0c9a"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/7WF45Z64R6TFZITSSWVFX2ZRBB/bundle.json","state_url":"https://pith.science/pith/7WF45Z64R6TFZITSSWVFX2ZRBB/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/7WF45Z64R6TFZITSSWVFX2ZRBB/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T14:24:25Z","links":{"resolver":"https://pith.science/pith/7WF45Z64R6TFZITSSWVFX2ZRBB","bundle":"https://pith.science/pith/7WF45Z64R6TFZITSSWVFX2ZRBB/bundle.json","state":"https://pith.science/pith/7WF45Z64R6TFZITSSWVFX2ZRBB/state.json","well_known_bundle":"https://pith.science/.well-known/pith/7WF45Z64R6TFZITSSWVFX2ZRBB/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:7WF45Z64R6TFZITSSWVFX2ZRBB","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"bb6c76fcc6f947fc6007d4aa2cae695f0a54e89f76f2f8ca8b0e5b8d6707c63b","cross_cats_sorted":["cs.GR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-03-02T16:35:44Z","title_canon_sha256":"083d9f695badfc5e5a0aeae6f3e9628179711c67f1525e49a85695e40b0de0c8"},"schema_version":"1.0","source":{"id":"1803.00940","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1803.00940","created_at":"2026-05-18T00:22:07Z"},{"alias_kind":"arxiv_version","alias_value":"1803.00940v1","created_at":"2026-05-18T00:22:07Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1803.00940","created_at":"2026-05-18T00:22:07Z"},{"alias_kind":"pith_short_12","alias_value":"7WF45Z64R6TF","created_at":"2026-05-18T12:32:11Z"},{"alias_kind":"pith_short_16","alias_value":"7WF45Z64R6TFZITS","created_at":"2026-05-18T12:32:11Z"},{"alias_kind":"pith_short_8","alias_value":"7WF45Z64","created_at":"2026-05-18T12:32:11Z"}],"graph_snapshots":[{"event_id":"sha256:07f73fb050b094fc60a6e6ce168dd279c6f9a8364929d6326ef150ddaeaa0c9a","target":"graph","created_at":"2026-05-18T00:22:07Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"As deep neural networks (DNNs) have been integrated into critical systems, several methods to attack these systems have been developed. These adversarial attacks make imperceptible modifications to an image that fool DNN classifiers. We present an adaptive JPEG encoder which defends against many of these attacks. Experimentally, we show that our method produces images with high visual quality while greatly reducing the potency of state-of-the-art attacks. Our algorithm requires only a modest increase in encoding time, produces a compressed image which can be decompressed by an off-the-shelf JP","authors_text":"Aaditya Prakash, Antonella DiLillo, James Storer, Nick Moran, Solomon Garber","cross_cats":["cs.GR"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-03-02T16:35:44Z","title":"Protecting JPEG Images Against Adversarial Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1803.00940","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:4d979320a89288b748d338d20d736a15760421ce5f40944a6b90d10a1e9b3729","target":"record","created_at":"2026-05-18T00:22:07Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"bb6c76fcc6f947fc6007d4aa2cae695f0a54e89f76f2f8ca8b0e5b8d6707c63b","cross_cats_sorted":["cs.GR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-03-02T16:35:44Z","title_canon_sha256":"083d9f695badfc5e5a0aeae6f3e9628179711c67f1525e49a85695e40b0de0c8"},"schema_version":"1.0","source":{"id":"1803.00940","kind":"arxiv","version":1}},"canonical_sha256":"fd8bcee7dc8fa65ca27295aa5beb31087076ac0f2bc1c63196a65260591eed65","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"fd8bcee7dc8fa65ca27295aa5beb31087076ac0f2bc1c63196a65260591eed65","first_computed_at":"2026-05-18T00:22:07.404811Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:22:07.404811Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"1lNF0eP/qHB3Yt/T1AVaIBQSuZlhoijjov+o8/G4I2LNo3HHyWb4D68anS6ALnWCSs+7hsPm0xVOGpYM7QT6AQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:22:07.405375Z","signed_message":"canonical_sha256_bytes"},"source_id":"1803.00940","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:4d979320a89288b748d338d20d736a15760421ce5f40944a6b90d10a1e9b3729","sha256:07f73fb050b094fc60a6e6ce168dd279c6f9a8364929d6326ef150ddaeaa0c9a"],"state_sha256":"e4b806ced1829661320b4881955234f1c89ee6e74d894ee1553d5661f0525b7f"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"BdipqX5WKIwjSHYEt61cD2gPbPku96ZwB4TR16QiCktBQP6+V7e5nVQzB0/zedNfn0pZ8n/mFpeSoQAl6rNNDA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T14:24:25.588089Z","bundle_sha256":"03cadce30ef3e7921304ca10dd15a0f754614d735fac8a402915dd35ed88c628"}}