{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:ALNQCL2TEJD5IPB3TN6WTFJY2P","short_pith_number":"pith:ALNQCL2T","canonical_record":{"source":{"id":"1901.09413","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.IT","submitted_at":"2019-01-27T18:12:03Z","cross_cats_sorted":["cs.LG","eess.SP","math.IT"],"title_canon_sha256":"c42035a1d5dad0a13700e60a10fdc2dab544306de76e30ef15f0ab27a20660e5","abstract_canon_sha256":"cf1aebe7d0e51cba2d57e1d98f5e9c4e3210c342a1673e3cd0d4e420f3e98a0e"},"schema_version":"1.0"},"canonical_sha256":"02db012f532247d43c3b9b7d699538d3e42c171652bfb7e7d27d5432ae47a814","source":{"kind":"arxiv","id":"1901.09413","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1901.09413","created_at":"2026-05-17T23:55:24Z"},{"alias_kind":"arxiv_version","alias_value":"1901.09413v1","created_at":"2026-05-17T23:55:24Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1901.09413","created_at":"2026-05-17T23:55:24Z"},{"alias_kind":"pith_short_12","alias_value":"ALNQCL2TEJD5","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_16","alias_value":"ALNQCL2TEJD5IPB3","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_8","alias_value":"ALNQCL2T","created_at":"2026-05-18T12:33:12Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:ALNQCL2TEJD5IPB3TN6WTFJY2P","target":"record","payload":{"canonical_record":{"source":{"id":"1901.09413","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.IT","submitted_at":"2019-01-27T18:12:03Z","cross_cats_sorted":["cs.LG","eess.SP","math.IT"],"title_canon_sha256":"c42035a1d5dad0a13700e60a10fdc2dab544306de76e30ef15f0ab27a20660e5","abstract_canon_sha256":"cf1aebe7d0e51cba2d57e1d98f5e9c4e3210c342a1673e3cd0d4e420f3e98a0e"},"schema_version":"1.0"},"canonical_sha256":"02db012f532247d43c3b9b7d699538d3e42c171652bfb7e7d27d5432ae47a814","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:55:24.868571Z","signature_b64":"F7Kiv/B7LtXs953DQ3gM8rCYHeReofW/IO/zdmPZ6TZGddFIgnF312HWxz9NdRAYUDxZLNQ4tpBwhZvArpBcDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"02db012f532247d43c3b9b7d699538d3e42c171652bfb7e7d27d5432ae47a814","last_reissued_at":"2026-05-17T23:55:24.868037Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:55:24.868037Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1901.09413","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:55:24Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"6Pz3kKhUy4bbN5SuRFjDilJeJN/mQTsV11DWEi1piGLk0SkB037C84N6MRvxGeL+X701NQn2YftLgKz2VDObDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T05:04:58.778973Z"},"content_sha256":"4e7cc0d4136f2391c81f593b7bc622efc119441f64f75b5eef29b06c67619116","schema_version":"1.0","event_id":"sha256:4e7cc0d4136f2391c81f593b7bc622efc119441f64f75b5eef29b06c67619116"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:ALNQCL2TEJD5IPB3TN6WTFJY2P","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"An Information-Theoretic Explanation for the Adversarial Fragility of AI Classifiers","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG","eess.SP","math.IT"],"primary_cat":"cs.IT","authors_text":"Hui Xie, Jirong Yi, Raghu Mudumbai, Weiyu Xu","submitted_at":"2019-01-27T18:12:03Z","abstract_excerpt":"We present a simple hypothesis about a compression property of artificial intelligence (AI) classifiers and present theoretical arguments to show that this hypothesis successfully accounts for the observed fragility of AI classifiers to small adversarial perturbations. We also propose a new method for detecting when small input perturbations cause classifier errors, and show theoretical guarantees for the performance of this detection method. We present experimental results with a voice recognition system to demonstrate this method. The ideas in this paper are motivated by a simple analogy bet"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1901.09413","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:55:24Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"TW1oKXfzMz3cj4Tjc3t2mQqxFpl+M8JoBNz2F5jF6huXr9yGR1fkQH1MN4MbNpQk0mgZlQjazIoBEQyOqngsCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T05:04:58.779654Z"},"content_sha256":"82a1d7d148b4efa1ba22700115a8dc923451ba8dbb38bbde0e5cabad8a1f267c","schema_version":"1.0","event_id":"sha256:82a1d7d148b4efa1ba22700115a8dc923451ba8dbb38bbde0e5cabad8a1f267c"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/ALNQCL2TEJD5IPB3TN6WTFJY2P/bundle.json","state_url":"https://pith.science/pith/ALNQCL2TEJD5IPB3TN6WTFJY2P/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/ALNQCL2TEJD5IPB3TN6WTFJY2P/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-30T05:04:58Z","links":{"resolver":"https://pith.science/pith/ALNQCL2TEJD5IPB3TN6WTFJY2P","bundle":"https://pith.science/pith/ALNQCL2TEJD5IPB3TN6WTFJY2P/bundle.json","state":"https://pith.science/pith/ALNQCL2TEJD5IPB3TN6WTFJY2P/state.json","well_known_bundle":"https://pith.science/.well-known/pith/ALNQCL2TEJD5IPB3TN6WTFJY2P/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:ALNQCL2TEJD5IPB3TN6WTFJY2P","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"cf1aebe7d0e51cba2d57e1d98f5e9c4e3210c342a1673e3cd0d4e420f3e98a0e","cross_cats_sorted":["cs.LG","eess.SP","math.IT"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.IT","submitted_at":"2019-01-27T18:12:03Z","title_canon_sha256":"c42035a1d5dad0a13700e60a10fdc2dab544306de76e30ef15f0ab27a20660e5"},"schema_version":"1.0","source":{"id":"1901.09413","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1901.09413","created_at":"2026-05-17T23:55:24Z"},{"alias_kind":"arxiv_version","alias_value":"1901.09413v1","created_at":"2026-05-17T23:55:24Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1901.09413","created_at":"2026-05-17T23:55:24Z"},{"alias_kind":"pith_short_12","alias_value":"ALNQCL2TEJD5","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_16","alias_value":"ALNQCL2TEJD5IPB3","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_8","alias_value":"ALNQCL2T","created_at":"2026-05-18T12:33:12Z"}],"graph_snapshots":[{"event_id":"sha256:82a1d7d148b4efa1ba22700115a8dc923451ba8dbb38bbde0e5cabad8a1f267c","target":"graph","created_at":"2026-05-17T23:55:24Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We present a simple hypothesis about a compression property of artificial intelligence (AI) classifiers and present theoretical arguments to show that this hypothesis successfully accounts for the observed fragility of AI classifiers to small adversarial perturbations. We also propose a new method for detecting when small input perturbations cause classifier errors, and show theoretical guarantees for the performance of this detection method. We present experimental results with a voice recognition system to demonstrate this method. The ideas in this paper are motivated by a simple analogy bet","authors_text":"Hui Xie, Jirong Yi, Raghu Mudumbai, Weiyu Xu","cross_cats":["cs.LG","eess.SP","math.IT"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.IT","submitted_at":"2019-01-27T18:12:03Z","title":"An Information-Theoretic Explanation for the Adversarial Fragility of AI Classifiers"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1901.09413","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:4e7cc0d4136f2391c81f593b7bc622efc119441f64f75b5eef29b06c67619116","target":"record","created_at":"2026-05-17T23:55:24Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"cf1aebe7d0e51cba2d57e1d98f5e9c4e3210c342a1673e3cd0d4e420f3e98a0e","cross_cats_sorted":["cs.LG","eess.SP","math.IT"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.IT","submitted_at":"2019-01-27T18:12:03Z","title_canon_sha256":"c42035a1d5dad0a13700e60a10fdc2dab544306de76e30ef15f0ab27a20660e5"},"schema_version":"1.0","source":{"id":"1901.09413","kind":"arxiv","version":1}},"canonical_sha256":"02db012f532247d43c3b9b7d699538d3e42c171652bfb7e7d27d5432ae47a814","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"02db012f532247d43c3b9b7d699538d3e42c171652bfb7e7d27d5432ae47a814","first_computed_at":"2026-05-17T23:55:24.868037Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:55:24.868037Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"F7Kiv/B7LtXs953DQ3gM8rCYHeReofW/IO/zdmPZ6TZGddFIgnF312HWxz9NdRAYUDxZLNQ4tpBwhZvArpBcDw==","signature_status":"signed_v1","signed_at":"2026-05-17T23:55:24.868571Z","signed_message":"canonical_sha256_bytes"},"source_id":"1901.09413","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:4e7cc0d4136f2391c81f593b7bc622efc119441f64f75b5eef29b06c67619116","sha256:82a1d7d148b4efa1ba22700115a8dc923451ba8dbb38bbde0e5cabad8a1f267c"],"state_sha256":"831267e6dd773445f4f3366ead64a887bcebe911fbac66de9f76461f1d4e1e66"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"JAnHUbdvMAUcIXReRUSTkG3wR2QikW3lu/1I3fYxmvOB+tn8yAoCHsDAntWBBKiIx47uG/1Ou0Md51/ruMr7BQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-30T05:04:58.783403Z","bundle_sha256":"8a4bee4fc33b949bcea6004b782ec6b40e6e6c6908368893a7b719884af33445"}}