{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:7YYXKGPZ55PZN6XNJVMEPMEVWB","short_pith_number":"pith:7YYXKGPZ","canonical_record":{"source":{"id":"1712.02976","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2017-12-08T08:20:45Z","cross_cats_sorted":[],"title_canon_sha256":"a085f80514900d5c52f6c01bad5bfc6a6ed972fc950cc5cceac49ea8a952569a","abstract_canon_sha256":"1938640a62d7f0bd7c1906b2f1fea26b89cfc3fcb2a2eb8ace44f329fbfff39c"},"schema_version":"1.0"},"canonical_sha256":"fe317519f9ef5f96faed4d5847b095b075d3da98b3555995fd07c0c7583d6d61","source":{"kind":"arxiv","id":"1712.02976","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1712.02976","created_at":"2026-05-18T00:16:36Z"},{"alias_kind":"arxiv_version","alias_value":"1712.02976v2","created_at":"2026-05-18T00:16:36Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1712.02976","created_at":"2026-05-18T00:16:36Z"},{"alias_kind":"pith_short_12","alias_value":"7YYXKGPZ55PZ","created_at":"2026-05-18T12:31:05Z"},{"alias_kind":"pith_short_16","alias_value":"7YYXKGPZ55PZN6XN","created_at":"2026-05-18T12:31:05Z"},{"alias_kind":"pith_short_8","alias_value":"7YYXKGPZ","created_at":"2026-05-18T12:31:05Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:7YYXKGPZ55PZN6XNJVMEPMEVWB","target":"record","payload":{"canonical_record":{"source":{"id":"1712.02976","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2017-12-08T08:20:45Z","cross_cats_sorted":[],"title_canon_sha256":"a085f80514900d5c52f6c01bad5bfc6a6ed972fc950cc5cceac49ea8a952569a","abstract_canon_sha256":"1938640a62d7f0bd7c1906b2f1fea26b89cfc3fcb2a2eb8ace44f329fbfff39c"},"schema_version":"1.0"},"canonical_sha256":"fe317519f9ef5f96faed4d5847b095b075d3da98b3555995fd07c0c7583d6d61","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:16:36.572244Z","signature_b64":"Gtn4x6SJDsQExarmpgB5pRNzyCyVAemMQ4+xeJa6ZstFx9sEJG0aos9PD/ycMWWSAAogbw8rBqv5DdqPltYZBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"fe317519f9ef5f96faed4d5847b095b075d3da98b3555995fd07c0c7583d6d61","last_reissued_at":"2026-05-18T00:16:36.571730Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:16:36.571730Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1712.02976","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:16:36Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"SJCJanEXmhXvO+KF4U4YuVFheuFNCvzjdSXpVVHFa2dbPL3Oc6+l8dakOfC4ASdqRsrIvqkwjNY5mDAElO7bBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T16:30:56.707035Z"},"content_sha256":"054a8928e705bc9f58d5f9cf3b0f4752f6d1bca83230c87fae6e8b6bcfe508b8","schema_version":"1.0","event_id":"sha256:054a8928e705bc9f58d5f9cf3b0f4752f6d1bca83230c87fae6e8b6bcfe508b8"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:7YYXKGPZ55PZN6XNJVMEPMEVWB","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Defense against Adversarial Attacks Using High-Level Representation Guided Denoiser","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CV","authors_text":"Fangzhou Liao, Jun Zhu, Ming Liang, Tianyu Pang, Xiaolin Hu, Yinpeng Dong","submitted_at":"2017-12-08T08:20:45Z","abstract_excerpt":"Neural networks are vulnerable to adversarial examples, which poses a threat to their application in security sensitive systems. We propose high-level representation guided denoiser (HGD) as a defense for image classification. Standard denoiser suffers from the error amplification effect, in which small residual adversarial noise is progressively amplified and leads to wrong classifications. HGD overcomes this problem by using a loss function defined as the difference between the target model's outputs activated by the clean image and denoised image. Compared with ensemble adversarial training"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1712.02976","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:16:36Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"oU0zyOwwsesDnpnrdG9bz7cYCaperxhEogyEt1MjItZjAaFKmGLzVwrRBCoT26TNFZtLNCWb/SP0bRL2SGZUBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T16:30:56.707700Z"},"content_sha256":"02d8a61628aba5cefdce63fac24f9aac33e7b0a21ad7ec263710d9dacbb5f2cf","schema_version":"1.0","event_id":"sha256:02d8a61628aba5cefdce63fac24f9aac33e7b0a21ad7ec263710d9dacbb5f2cf"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/7YYXKGPZ55PZN6XNJVMEPMEVWB/bundle.json","state_url":"https://pith.science/pith/7YYXKGPZ55PZN6XNJVMEPMEVWB/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/7YYXKGPZ55PZN6XNJVMEPMEVWB/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-30T16:30:56Z","links":{"resolver":"https://pith.science/pith/7YYXKGPZ55PZN6XNJVMEPMEVWB","bundle":"https://pith.science/pith/7YYXKGPZ55PZN6XNJVMEPMEVWB/bundle.json","state":"https://pith.science/pith/7YYXKGPZ55PZN6XNJVMEPMEVWB/state.json","well_known_bundle":"https://pith.science/.well-known/pith/7YYXKGPZ55PZN6XNJVMEPMEVWB/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:7YYXKGPZ55PZN6XNJVMEPMEVWB","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"1938640a62d7f0bd7c1906b2f1fea26b89cfc3fcb2a2eb8ace44f329fbfff39c","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2017-12-08T08:20:45Z","title_canon_sha256":"a085f80514900d5c52f6c01bad5bfc6a6ed972fc950cc5cceac49ea8a952569a"},"schema_version":"1.0","source":{"id":"1712.02976","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1712.02976","created_at":"2026-05-18T00:16:36Z"},{"alias_kind":"arxiv_version","alias_value":"1712.02976v2","created_at":"2026-05-18T00:16:36Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1712.02976","created_at":"2026-05-18T00:16:36Z"},{"alias_kind":"pith_short_12","alias_value":"7YYXKGPZ55PZ","created_at":"2026-05-18T12:31:05Z"},{"alias_kind":"pith_short_16","alias_value":"7YYXKGPZ55PZN6XN","created_at":"2026-05-18T12:31:05Z"},{"alias_kind":"pith_short_8","alias_value":"7YYXKGPZ","created_at":"2026-05-18T12:31:05Z"}],"graph_snapshots":[{"event_id":"sha256:02d8a61628aba5cefdce63fac24f9aac33e7b0a21ad7ec263710d9dacbb5f2cf","target":"graph","created_at":"2026-05-18T00:16:36Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Neural networks are vulnerable to adversarial examples, which poses a threat to their application in security sensitive systems. We propose high-level representation guided denoiser (HGD) as a defense for image classification. Standard denoiser suffers from the error amplification effect, in which small residual adversarial noise is progressively amplified and leads to wrong classifications. HGD overcomes this problem by using a loss function defined as the difference between the target model's outputs activated by the clean image and denoised image. Compared with ensemble adversarial training","authors_text":"Fangzhou Liao, Jun Zhu, Ming Liang, Tianyu Pang, Xiaolin Hu, Yinpeng Dong","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2017-12-08T08:20:45Z","title":"Defense against Adversarial Attacks Using High-Level Representation Guided Denoiser"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1712.02976","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:054a8928e705bc9f58d5f9cf3b0f4752f6d1bca83230c87fae6e8b6bcfe508b8","target":"record","created_at":"2026-05-18T00:16:36Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"1938640a62d7f0bd7c1906b2f1fea26b89cfc3fcb2a2eb8ace44f329fbfff39c","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2017-12-08T08:20:45Z","title_canon_sha256":"a085f80514900d5c52f6c01bad5bfc6a6ed972fc950cc5cceac49ea8a952569a"},"schema_version":"1.0","source":{"id":"1712.02976","kind":"arxiv","version":2}},"canonical_sha256":"fe317519f9ef5f96faed4d5847b095b075d3da98b3555995fd07c0c7583d6d61","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"fe317519f9ef5f96faed4d5847b095b075d3da98b3555995fd07c0c7583d6d61","first_computed_at":"2026-05-18T00:16:36.571730Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:16:36.571730Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Gtn4x6SJDsQExarmpgB5pRNzyCyVAemMQ4+xeJa6ZstFx9sEJG0aos9PD/ycMWWSAAogbw8rBqv5DdqPltYZBA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:16:36.572244Z","signed_message":"canonical_sha256_bytes"},"source_id":"1712.02976","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:054a8928e705bc9f58d5f9cf3b0f4752f6d1bca83230c87fae6e8b6bcfe508b8","sha256:02d8a61628aba5cefdce63fac24f9aac33e7b0a21ad7ec263710d9dacbb5f2cf"],"state_sha256":"a050b5821c10c7fb6f21d5d27ce32d214d4e161ea556a5c55427e940399ccb5f"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"h7sv9xmEyWPPoeja90r+nIaTbPNJ+9E5af9wFAXjsfeUMMhMTjmQUZ3qJmsd+kyGCBMJ+FKv85d2LQRJa2KkDg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-30T16:30:56.710978Z","bundle_sha256":"584f9c84c831ef8a12366176f0dd3aea20407fdaa79fb5cbd6bdcab0127b4ba5"}}