{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:AA2NFI4JZVQHDMS7UQRZESM26K","short_pith_number":"pith:AA2NFI4J","canonical_record":{"source":{"id":"2605.21780","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-20T22:17:29Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"9744dc4b500de7cc4c0c7e689585873110c20f6441bb27e0ccecb9042718f681","abstract_canon_sha256":"b8941a2c5a14c06f86938217f3677fa2103a18142fa9ff0eaf1bb4dab9c39847"},"schema_version":"1.0"},"canonical_sha256":"0034d2a389cd6071b25fa42392499af29cf0d8b17803bf94697e7801fd4381c4","source":{"kind":"arxiv","id":"2605.21780","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.21780","created_at":"2026-05-22T01:03:32Z"},{"alias_kind":"arxiv_version","alias_value":"2605.21780v1","created_at":"2026-05-22T01:03:32Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.21780","created_at":"2026-05-22T01:03:32Z"},{"alias_kind":"pith_short_12","alias_value":"AA2NFI4JZVQH","created_at":"2026-05-22T01:03:32Z"},{"alias_kind":"pith_short_16","alias_value":"AA2NFI4JZVQHDMS7","created_at":"2026-05-22T01:03:32Z"},{"alias_kind":"pith_short_8","alias_value":"AA2NFI4J","created_at":"2026-05-22T01:03:32Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:AA2NFI4JZVQHDMS7UQRZESM26K","target":"record","payload":{"canonical_record":{"source":{"id":"2605.21780","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-20T22:17:29Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"9744dc4b500de7cc4c0c7e689585873110c20f6441bb27e0ccecb9042718f681","abstract_canon_sha256":"b8941a2c5a14c06f86938217f3677fa2103a18142fa9ff0eaf1bb4dab9c39847"},"schema_version":"1.0"},"canonical_sha256":"0034d2a389cd6071b25fa42392499af29cf0d8b17803bf94697e7801fd4381c4","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-22T01:03:32.255880Z","signature_b64":"hwNCBjrKTVg3ycN59YiF+7ATsvceNPNJljTIRwJDn0IQ8mJnh5yma1TsFSp7j7vOq7s6EkMrlizQWl1OtrJhBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"0034d2a389cd6071b25fa42392499af29cf0d8b17803bf94697e7801fd4381c4","last_reissued_at":"2026-05-22T01:03:32.255421Z","signature_status":"signed_v1","first_computed_at":"2026-05-22T01:03:32.255421Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.21780","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-22T01:03:32Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Tqjl1YTyF1KHRTCyccAeCCrM3t4fJE8IJ3xi7nLO9lwM6C/K1DVKX8rGP5jMrfsKzyj2ePHL1qiOjX22o6w0Aw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T22:09:30.479408Z"},"content_sha256":"dd3b7dc5f7df558eca0469aba9301f6823709d7b4d2268531bc5728e5e09d1aa","schema_version":"1.0","event_id":"sha256:dd3b7dc5f7df558eca0469aba9301f6823709d7b4d2268531bc5728e5e09d1aa"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:AA2NFI4JZVQHDMS7UQRZESM26K","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Provable Robustness against Backdoor Attacks via the Primal-Dual Perspective on Differential Privacy","license":"http://creativecommons.org/licenses/by-sa/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Aman Saxena, Jan Schuchardt, Stephan G\\\"unnemann, Yan Scholten","submitted_at":"2026-05-20T22:17:29Z","abstract_excerpt":"Randomized smoothing is a powerful tool for certifying robustness to adversarial perturbations, including poisoning attacks via randomized training and evasion attacks via randomized inference. Extending these guarantees to backdoor attacks, where training and test data are jointly perturbed, remains challenging because training- and test-time randomized mechanisms must be analyzed within a single robustness certificate. We address this by connecting randomized smoothing to the dual view of differential privacy through privacy profiles, which provide a numerical procedure for composing heterog"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.21780","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.21780/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-22T01:03:32Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"79sSxIEBJiV39UhmtTZwNCQJkl1ShEl9rTYgz5W8Q2jGkRbaZKKxMs5jFLno2TW0ZvwZQnzHuCOYWqPHBAnoBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T22:09:30.480015Z"},"content_sha256":"45040dd2f231e96f7a248f49e12a1e9906caba4e8d64f7e8cf77e02260fbebc7","schema_version":"1.0","event_id":"sha256:45040dd2f231e96f7a248f49e12a1e9906caba4e8d64f7e8cf77e02260fbebc7"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/AA2NFI4JZVQHDMS7UQRZESM26K/bundle.json","state_url":"https://pith.science/pith/AA2NFI4JZVQHDMS7UQRZESM26K/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/AA2NFI4JZVQHDMS7UQRZESM26K/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T22:09:30Z","links":{"resolver":"https://pith.science/pith/AA2NFI4JZVQHDMS7UQRZESM26K","bundle":"https://pith.science/pith/AA2NFI4JZVQHDMS7UQRZESM26K/bundle.json","state":"https://pith.science/pith/AA2NFI4JZVQHDMS7UQRZESM26K/state.json","well_known_bundle":"https://pith.science/.well-known/pith/AA2NFI4JZVQHDMS7UQRZESM26K/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:AA2NFI4JZVQHDMS7UQRZESM26K","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"b8941a2c5a14c06f86938217f3677fa2103a18142fa9ff0eaf1bb4dab9c39847","cross_cats_sorted":["cs.CR"],"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-20T22:17:29Z","title_canon_sha256":"9744dc4b500de7cc4c0c7e689585873110c20f6441bb27e0ccecb9042718f681"},"schema_version":"1.0","source":{"id":"2605.21780","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.21780","created_at":"2026-05-22T01:03:32Z"},{"alias_kind":"arxiv_version","alias_value":"2605.21780v1","created_at":"2026-05-22T01:03:32Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.21780","created_at":"2026-05-22T01:03:32Z"},{"alias_kind":"pith_short_12","alias_value":"AA2NFI4JZVQH","created_at":"2026-05-22T01:03:32Z"},{"alias_kind":"pith_short_16","alias_value":"AA2NFI4JZVQHDMS7","created_at":"2026-05-22T01:03:32Z"},{"alias_kind":"pith_short_8","alias_value":"AA2NFI4J","created_at":"2026-05-22T01:03:32Z"}],"graph_snapshots":[{"event_id":"sha256:45040dd2f231e96f7a248f49e12a1e9906caba4e8d64f7e8cf77e02260fbebc7","target":"graph","created_at":"2026-05-22T01:03:32Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.21780/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Randomized smoothing is a powerful tool for certifying robustness to adversarial perturbations, including poisoning attacks via randomized training and evasion attacks via randomized inference. Extending these guarantees to backdoor attacks, where training and test data are jointly perturbed, remains challenging because training- and test-time randomized mechanisms must be analyzed within a single robustness certificate. We address this by connecting randomized smoothing to the dual view of differential privacy through privacy profiles, which provide a numerical procedure for composing heterog","authors_text":"Aman Saxena, Jan Schuchardt, Stephan G\\\"unnemann, Yan Scholten","cross_cats":["cs.CR"],"headline":"","license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-20T22:17:29Z","title":"Provable Robustness against Backdoor Attacks via the Primal-Dual Perspective on Differential Privacy"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.21780","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:dd3b7dc5f7df558eca0469aba9301f6823709d7b4d2268531bc5728e5e09d1aa","target":"record","created_at":"2026-05-22T01:03:32Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"b8941a2c5a14c06f86938217f3677fa2103a18142fa9ff0eaf1bb4dab9c39847","cross_cats_sorted":["cs.CR"],"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-20T22:17:29Z","title_canon_sha256":"9744dc4b500de7cc4c0c7e689585873110c20f6441bb27e0ccecb9042718f681"},"schema_version":"1.0","source":{"id":"2605.21780","kind":"arxiv","version":1}},"canonical_sha256":"0034d2a389cd6071b25fa42392499af29cf0d8b17803bf94697e7801fd4381c4","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"0034d2a389cd6071b25fa42392499af29cf0d8b17803bf94697e7801fd4381c4","first_computed_at":"2026-05-22T01:03:32.255421Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-22T01:03:32.255421Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"hwNCBjrKTVg3ycN59YiF+7ATsvceNPNJljTIRwJDn0IQ8mJnh5yma1TsFSp7j7vOq7s6EkMrlizQWl1OtrJhBw==","signature_status":"signed_v1","signed_at":"2026-05-22T01:03:32.255880Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.21780","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:dd3b7dc5f7df558eca0469aba9301f6823709d7b4d2268531bc5728e5e09d1aa","sha256:45040dd2f231e96f7a248f49e12a1e9906caba4e8d64f7e8cf77e02260fbebc7"],"state_sha256":"3e3b83dc33567010a2b9e38727817fc98ee26ecbef7f881f89f81c8cba4ea64e"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Fk/RXkog6dWp8By2N8C1OSpcutFeeD6gKDGCCw9XXVKENDutlYiHfyU/LLEk+nX0FBsUS262NN5ue0msBBA4BA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T22:09:30.483659Z","bundle_sha256":"f844d8e002871f62c93f78c72fddffe3190ee7745030331c503fa15ecc0c8e4c"}}