{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:APSEPMCU4RIFFSS65LKSU3XEW6","short_pith_number":"pith:APSEPMCU","canonical_record":{"source":{"id":"1811.11493","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-28T11:03:26Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"01fb68fb5ce25387e1a1cd663caee79cb94542ab6f05114562749abfb33bce6d","abstract_canon_sha256":"0623c519e194c3e9f9ed4512b088a2576560c1c6b98ad13b05db471765dff85d"},"schema_version":"1.0"},"canonical_sha256":"03e447b054e45052ca5eead52a6ee4b7b34d0a598b6eab4c7659f10f1c0d642d","source":{"kind":"arxiv","id":"1811.11493","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1811.11493","created_at":"2026-05-17T23:59:40Z"},{"alias_kind":"arxiv_version","alias_value":"1811.11493v1","created_at":"2026-05-17T23:59:40Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.11493","created_at":"2026-05-17T23:59:40Z"},{"alias_kind":"pith_short_12","alias_value":"APSEPMCU4RIF","created_at":"2026-05-18T12:32:13Z"},{"alias_kind":"pith_short_16","alias_value":"APSEPMCU4RIFFSS6","created_at":"2026-05-18T12:32:13Z"},{"alias_kind":"pith_short_8","alias_value":"APSEPMCU","created_at":"2026-05-18T12:32:13Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:APSEPMCU4RIFFSS65LKSU3XEW6","target":"record","payload":{"canonical_record":{"source":{"id":"1811.11493","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-28T11:03:26Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"01fb68fb5ce25387e1a1cd663caee79cb94542ab6f05114562749abfb33bce6d","abstract_canon_sha256":"0623c519e194c3e9f9ed4512b088a2576560c1c6b98ad13b05db471765dff85d"},"schema_version":"1.0"},"canonical_sha256":"03e447b054e45052ca5eead52a6ee4b7b34d0a598b6eab4c7659f10f1c0d642d","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:59:40.935360Z","signature_b64":"KZujEU1o+T4mgQWhoSIf4kuqamH9x5Nh3iqGe+4OoYfi+3tQIQcBKiRo77ICuvmk7ngF7Rb0Hm38DkKXAlTwAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"03e447b054e45052ca5eead52a6ee4b7b34d0a598b6eab4c7659f10f1c0d642d","last_reissued_at":"2026-05-17T23:59:40.934844Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:59:40.934844Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1811.11493","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:59:40Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"eKLBjyyda2th6y7Mje881K/P14fknKvfBYFyyI95GVsiPKci9NXTfd8R6lgI/5TcBL6MwU6ooYojgVHjFAd3Cg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T18:58:33.546391Z"},"content_sha256":"0b6396d74e6d7804ead8c65d283d2a5d28f7a00a55e3132c3895f64f9c7e2ebd","schema_version":"1.0","event_id":"sha256:0b6396d74e6d7804ead8c65d283d2a5d28f7a00a55e3132c3895f64f9c7e2ebd"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:APSEPMCU4RIFFSS65LKSU3XEW6","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"A randomized gradient-free attack on ReLU networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Francesco Croce, Matthias Hein","submitted_at":"2018-11-28T11:03:26Z","abstract_excerpt":"It has recently been shown that neural networks but also other classifiers are vulnerable to so called adversarial attacks e.g. in object recognition an almost non-perceivable change of the image changes the decision of the classifier. Relatively fast heuristics have been proposed to produce these adversarial inputs but the problem of finding the optimal adversarial input, that is with the minimal change of the input, is NP-hard. While methods based on mixed-integer optimization which find the optimal adversarial input have been developed, they do not scale to large networks. Currently, the at"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.11493","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:59:40Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"R9jvCIN7LXfYN5P9Sh6jNeHttEh9IUnctQVPHoAXrO1h7gOG+zQxBqW/sv4i1H2WK9tijPaDyDPnQGJBDPvbAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T18:58:33.546953Z"},"content_sha256":"2ca6905505e22eaeba795a68cefbce2fd4f9b6df24d950a47dce3675704d592d","schema_version":"1.0","event_id":"sha256:2ca6905505e22eaeba795a68cefbce2fd4f9b6df24d950a47dce3675704d592d"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/APSEPMCU4RIFFSS65LKSU3XEW6/bundle.json","state_url":"https://pith.science/pith/APSEPMCU4RIFFSS65LKSU3XEW6/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/APSEPMCU4RIFFSS65LKSU3XEW6/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-01T18:58:33Z","links":{"resolver":"https://pith.science/pith/APSEPMCU4RIFFSS65LKSU3XEW6","bundle":"https://pith.science/pith/APSEPMCU4RIFFSS65LKSU3XEW6/bundle.json","state":"https://pith.science/pith/APSEPMCU4RIFFSS65LKSU3XEW6/state.json","well_known_bundle":"https://pith.science/.well-known/pith/APSEPMCU4RIFFSS65LKSU3XEW6/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:APSEPMCU4RIFFSS65LKSU3XEW6","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"0623c519e194c3e9f9ed4512b088a2576560c1c6b98ad13b05db471765dff85d","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-28T11:03:26Z","title_canon_sha256":"01fb68fb5ce25387e1a1cd663caee79cb94542ab6f05114562749abfb33bce6d"},"schema_version":"1.0","source":{"id":"1811.11493","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1811.11493","created_at":"2026-05-17T23:59:40Z"},{"alias_kind":"arxiv_version","alias_value":"1811.11493v1","created_at":"2026-05-17T23:59:40Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.11493","created_at":"2026-05-17T23:59:40Z"},{"alias_kind":"pith_short_12","alias_value":"APSEPMCU4RIF","created_at":"2026-05-18T12:32:13Z"},{"alias_kind":"pith_short_16","alias_value":"APSEPMCU4RIFFSS6","created_at":"2026-05-18T12:32:13Z"},{"alias_kind":"pith_short_8","alias_value":"APSEPMCU","created_at":"2026-05-18T12:32:13Z"}],"graph_snapshots":[{"event_id":"sha256:2ca6905505e22eaeba795a68cefbce2fd4f9b6df24d950a47dce3675704d592d","target":"graph","created_at":"2026-05-17T23:59:40Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"It has recently been shown that neural networks but also other classifiers are vulnerable to so called adversarial attacks e.g. in object recognition an almost non-perceivable change of the image changes the decision of the classifier. Relatively fast heuristics have been proposed to produce these adversarial inputs but the problem of finding the optimal adversarial input, that is with the minimal change of the input, is NP-hard. While methods based on mixed-integer optimization which find the optimal adversarial input have been developed, they do not scale to large networks. Currently, the at","authors_text":"Francesco Croce, Matthias Hein","cross_cats":["cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-28T11:03:26Z","title":"A randomized gradient-free attack on ReLU networks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.11493","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:0b6396d74e6d7804ead8c65d283d2a5d28f7a00a55e3132c3895f64f9c7e2ebd","target":"record","created_at":"2026-05-17T23:59:40Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"0623c519e194c3e9f9ed4512b088a2576560c1c6b98ad13b05db471765dff85d","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-28T11:03:26Z","title_canon_sha256":"01fb68fb5ce25387e1a1cd663caee79cb94542ab6f05114562749abfb33bce6d"},"schema_version":"1.0","source":{"id":"1811.11493","kind":"arxiv","version":1}},"canonical_sha256":"03e447b054e45052ca5eead52a6ee4b7b34d0a598b6eab4c7659f10f1c0d642d","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"03e447b054e45052ca5eead52a6ee4b7b34d0a598b6eab4c7659f10f1c0d642d","first_computed_at":"2026-05-17T23:59:40.934844Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:59:40.934844Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"KZujEU1o+T4mgQWhoSIf4kuqamH9x5Nh3iqGe+4OoYfi+3tQIQcBKiRo77ICuvmk7ngF7Rb0Hm38DkKXAlTwAg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:59:40.935360Z","signed_message":"canonical_sha256_bytes"},"source_id":"1811.11493","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:0b6396d74e6d7804ead8c65d283d2a5d28f7a00a55e3132c3895f64f9c7e2ebd","sha256:2ca6905505e22eaeba795a68cefbce2fd4f9b6df24d950a47dce3675704d592d"],"state_sha256":"88808e78864a1b61bb8581cdc801bf27bd6c6e6c99bab2996fb292bf5accf28b"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"yo6v+8OgXFZTebqZ02GVCHn7iloOgB/LecIXUbOa1CMQfL2itGrOUq+b3lxiG0LJqUSP4Q3qFoe+Ci42g18lCg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-01T18:58:33.549747Z","bundle_sha256":"4dd67d982bcec21bc4319e298e95d9dc6cae8da7dffd812aefcda3ca18af37ec"}}