{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:AIJF6DQ4SDQOWSCJPMIHSGRVZE","short_pith_number":"pith:AIJF6DQ4","canonical_record":{"source":{"id":"1705.07263","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-05-20T05:59:23Z","cross_cats_sorted":["cs.CR","cs.CV"],"title_canon_sha256":"2ee6f6d36633908310d622ba64bd88a5d8b9896f0a0337bbb4bba4155aaca9e1","abstract_canon_sha256":"4a24eb4fc99fbef110826c93a2ab3d956481815c95422e410fc6ca40610f8bee"},"schema_version":"1.0"},"canonical_sha256":"02125f0e1c90e0eb48497b10791a35c91c52e053ac2fdd9b27bbf0e895bcf3bc","source":{"kind":"arxiv","id":"1705.07263","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1705.07263","created_at":"2026-05-18T00:31:35Z"},{"alias_kind":"arxiv_version","alias_value":"1705.07263v2","created_at":"2026-05-18T00:31:35Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1705.07263","created_at":"2026-05-18T00:31:35Z"},{"alias_kind":"pith_short_12","alias_value":"AIJF6DQ4SDQO","created_at":"2026-05-18T12:31:05Z"},{"alias_kind":"pith_short_16","alias_value":"AIJF6DQ4SDQOWSCJ","created_at":"2026-05-18T12:31:05Z"},{"alias_kind":"pith_short_8","alias_value":"AIJF6DQ4","created_at":"2026-05-18T12:31:05Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:AIJF6DQ4SDQOWSCJPMIHSGRVZE","target":"record","payload":{"canonical_record":{"source":{"id":"1705.07263","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-05-20T05:59:23Z","cross_cats_sorted":["cs.CR","cs.CV"],"title_canon_sha256":"2ee6f6d36633908310d622ba64bd88a5d8b9896f0a0337bbb4bba4155aaca9e1","abstract_canon_sha256":"4a24eb4fc99fbef110826c93a2ab3d956481815c95422e410fc6ca40610f8bee"},"schema_version":"1.0"},"canonical_sha256":"02125f0e1c90e0eb48497b10791a35c91c52e053ac2fdd9b27bbf0e895bcf3bc","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:31:35.965026Z","signature_b64":"b0GSpq+OnTzC0Vw4zgwQIfGw3cpnIwUG5yCcr9dMVcJIob2P9FHLlCyBDoPtGT5yyze9/WqKoJMPOPoii/YyBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"02125f0e1c90e0eb48497b10791a35c91c52e053ac2fdd9b27bbf0e895bcf3bc","last_reissued_at":"2026-05-18T00:31:35.964573Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:31:35.964573Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1705.07263","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:31:35Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"7qDADrl5Ox97eoW65e2V3sqMckTJ3N1RqmcrbllF+c8Rw/yhtoK4tTQxzGo0826tykJXxwWRr+LBKV2TruQcDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T03:44:05.525747Z"},"content_sha256":"470237a1a8d7d77a69b86127f9c771f7c6483359ac9cdd7fc743526aa2c944c9","schema_version":"1.0","event_id":"sha256:470237a1a8d7d77a69b86127f9c771f7c6483359ac9cdd7fc743526aa2c944c9"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:AIJF6DQ4SDQOWSCJPMIHSGRVZE","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV"],"primary_cat":"cs.LG","authors_text":"David Wagner, Nicholas Carlini","submitted_at":"2017-05-20T05:59:23Z","abstract_excerpt":"Neural networks are known to be vulnerable to adversarial examples: inputs that are close to natural inputs but classified incorrectly. In order to better understand the space of adversarial examples, we survey ten recent proposals that are designed for detection and compare their efficacy. We show that all can be defeated by constructing new loss functions. We conclude that adversarial examples are significantly harder to detect than previously appreciated, and the properties believed to be intrinsic to adversarial examples are in fact not. Finally, we propose several simple guidelines for ev"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1705.07263","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:31:35Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"QfDBzOoYe0uIMNdbCw8rkOpeSFTUwczMZPk8Cb2V1uupFOUw8mKdcJOsvLMa4IpPVqzOi2uHu0J6T9e5gKjxAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T03:44:05.526451Z"},"content_sha256":"1a95dfed427a6937e5d52fb0d378172081ec47552a9f66689eaf0125f873ce05","schema_version":"1.0","event_id":"sha256:1a95dfed427a6937e5d52fb0d378172081ec47552a9f66689eaf0125f873ce05"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/AIJF6DQ4SDQOWSCJPMIHSGRVZE/bundle.json","state_url":"https://pith.science/pith/AIJF6DQ4SDQOWSCJPMIHSGRVZE/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/AIJF6DQ4SDQOWSCJPMIHSGRVZE/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T03:44:05Z","links":{"resolver":"https://pith.science/pith/AIJF6DQ4SDQOWSCJPMIHSGRVZE","bundle":"https://pith.science/pith/AIJF6DQ4SDQOWSCJPMIHSGRVZE/bundle.json","state":"https://pith.science/pith/AIJF6DQ4SDQOWSCJPMIHSGRVZE/state.json","well_known_bundle":"https://pith.science/.well-known/pith/AIJF6DQ4SDQOWSCJPMIHSGRVZE/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:AIJF6DQ4SDQOWSCJPMIHSGRVZE","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"4a24eb4fc99fbef110826c93a2ab3d956481815c95422e410fc6ca40610f8bee","cross_cats_sorted":["cs.CR","cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-05-20T05:59:23Z","title_canon_sha256":"2ee6f6d36633908310d622ba64bd88a5d8b9896f0a0337bbb4bba4155aaca9e1"},"schema_version":"1.0","source":{"id":"1705.07263","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1705.07263","created_at":"2026-05-18T00:31:35Z"},{"alias_kind":"arxiv_version","alias_value":"1705.07263v2","created_at":"2026-05-18T00:31:35Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1705.07263","created_at":"2026-05-18T00:31:35Z"},{"alias_kind":"pith_short_12","alias_value":"AIJF6DQ4SDQO","created_at":"2026-05-18T12:31:05Z"},{"alias_kind":"pith_short_16","alias_value":"AIJF6DQ4SDQOWSCJ","created_at":"2026-05-18T12:31:05Z"},{"alias_kind":"pith_short_8","alias_value":"AIJF6DQ4","created_at":"2026-05-18T12:31:05Z"}],"graph_snapshots":[{"event_id":"sha256:1a95dfed427a6937e5d52fb0d378172081ec47552a9f66689eaf0125f873ce05","target":"graph","created_at":"2026-05-18T00:31:35Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Neural networks are known to be vulnerable to adversarial examples: inputs that are close to natural inputs but classified incorrectly. In order to better understand the space of adversarial examples, we survey ten recent proposals that are designed for detection and compare their efficacy. We show that all can be defeated by constructing new loss functions. We conclude that adversarial examples are significantly harder to detect than previously appreciated, and the properties believed to be intrinsic to adversarial examples are in fact not. Finally, we propose several simple guidelines for ev","authors_text":"David Wagner, Nicholas Carlini","cross_cats":["cs.CR","cs.CV"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-05-20T05:59:23Z","title":"Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1705.07263","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:470237a1a8d7d77a69b86127f9c771f7c6483359ac9cdd7fc743526aa2c944c9","target":"record","created_at":"2026-05-18T00:31:35Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"4a24eb4fc99fbef110826c93a2ab3d956481815c95422e410fc6ca40610f8bee","cross_cats_sorted":["cs.CR","cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-05-20T05:59:23Z","title_canon_sha256":"2ee6f6d36633908310d622ba64bd88a5d8b9896f0a0337bbb4bba4155aaca9e1"},"schema_version":"1.0","source":{"id":"1705.07263","kind":"arxiv","version":2}},"canonical_sha256":"02125f0e1c90e0eb48497b10791a35c91c52e053ac2fdd9b27bbf0e895bcf3bc","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"02125f0e1c90e0eb48497b10791a35c91c52e053ac2fdd9b27bbf0e895bcf3bc","first_computed_at":"2026-05-18T00:31:35.964573Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:31:35.964573Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"b0GSpq+OnTzC0Vw4zgwQIfGw3cpnIwUG5yCcr9dMVcJIob2P9FHLlCyBDoPtGT5yyze9/WqKoJMPOPoii/YyBA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:31:35.965026Z","signed_message":"canonical_sha256_bytes"},"source_id":"1705.07263","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:470237a1a8d7d77a69b86127f9c771f7c6483359ac9cdd7fc743526aa2c944c9","sha256:1a95dfed427a6937e5d52fb0d378172081ec47552a9f66689eaf0125f873ce05"],"state_sha256":"3ba269275e76233186741a902d832ac4a0f7f65d86acf0709f267c0153fcdba0"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"BCTj4W5LAufDN77+DEaSwBxIZfGEE4euZqfLCYeGs103fqbB8/zxFxdpzxKQt3OGr2saEQ171e7+usccBlqAAQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T03:44:05.530265Z","bundle_sha256":"3a82066c2c6bfc3254b2afe8e446df8859bb1c3f6d7ee93b09d358651b845043"}}