{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:ASWLHV7MV452KTF6K22L7RGNKZ","short_pith_number":"pith:ASWLHV7M","schema_version":"1.0","canonical_sha256":"04acb3d7ecaf3ba54cbe56b4bfc4cd56420ad1cc675659708cdabf8f807e6f26","source":{"kind":"arxiv","id":"1909.00986","version":1},"attestation_state":"computed","paper":{"title":"Certified Robustness to Adversarial Word Substitutions","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CL","authors_text":"Aditi Raghunathan, Kerem G\\\"oksel, Percy Liang, Robin Jia","submitted_at":"2019-09-03T07:29:48Z","abstract_excerpt":"State-of-the-art NLP models can often be fooled by adversaries that apply seemingly innocuous label-preserving transformations (e.g., paraphrasing) to input text. The number of possible transformations scales exponentially with text length, so data augmentation cannot cover all transformations of an input. This paper considers one exponentially large family of label-preserving transformations, in which every word in the input can be replaced with a similar word. We train the first models that are provably robust to all word substitutions in this family. Our training procedure uses Interval Bou"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1909.00986","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2019-09-03T07:29:48Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"f95c4294c7ce7e619b583ad7916f695c4ff18fb545004a3585bc4bc8a156c401","abstract_canon_sha256":"e0fd97f26721f74558b717dcf9cbf4a48f9e7da0f37a4fff40aa8aaaa882ff3b"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:01:14.836456Z","signature_b64":"j0pOx/nETHfn9mUSX7vtrCbkogo04Lm5BPV3MwbBhp406dkbPVyQZAkmEob6ppEuHsfWFBvaAmqM+6eElAs7BA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"04acb3d7ecaf3ba54cbe56b4bfc4cd56420ad1cc675659708cdabf8f807e6f26","last_reissued_at":"2026-07-05T00:01:14.836071Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:01:14.836071Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Certified Robustness to Adversarial Word Substitutions","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CL","authors_text":"Aditi Raghunathan, Kerem G\\\"oksel, Percy Liang, Robin Jia","submitted_at":"2019-09-03T07:29:48Z","abstract_excerpt":"State-of-the-art NLP models can often be fooled by adversaries that apply seemingly innocuous label-preserving transformations (e.g., paraphrasing) to input text. The number of possible transformations scales exponentially with text length, so data augmentation cannot cover all transformations of an input. This paper considers one exponentially large family of label-preserving transformations, in which every word in the input can be replaced with a similar word. We train the first models that are provably robust to all word substitutions in this family. Our training procedure uses Interval Bou"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1909.00986","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1909.00986/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1909.00986","created_at":"2026-07-05T00:01:14.836125+00:00"},{"alias_kind":"arxiv_version","alias_value":"1909.00986v1","created_at":"2026-07-05T00:01:14.836125+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1909.00986","created_at":"2026-07-05T00:01:14.836125+00:00"},{"alias_kind":"pith_short_12","alias_value":"ASWLHV7MV452","created_at":"2026-07-05T00:01:14.836125+00:00"},{"alias_kind":"pith_short_16","alias_value":"ASWLHV7MV452KTF6","created_at":"2026-07-05T00:01:14.836125+00:00"},{"alias_kind":"pith_short_8","alias_value":"ASWLHV7M","created_at":"2026-07-05T00:01:14.836125+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2506.22492","citing_title":"Report on NSF Workshop on Science of Safe AI","ref_index":8,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/ASWLHV7MV452KTF6K22L7RGNKZ","json":"https://pith.science/pith/ASWLHV7MV452KTF6K22L7RGNKZ.json","graph_json":"https://pith.science/api/pith-number/ASWLHV7MV452KTF6K22L7RGNKZ/graph.json","events_json":"https://pith.science/api/pith-number/ASWLHV7MV452KTF6K22L7RGNKZ/events.json","paper":"https://pith.science/paper/ASWLHV7M"},"agent_actions":{"view_html":"https://pith.science/pith/ASWLHV7MV452KTF6K22L7RGNKZ","download_json":"https://pith.science/pith/ASWLHV7MV452KTF6K22L7RGNKZ.json","view_paper":"https://pith.science/paper/ASWLHV7M","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1909.00986&json=true","fetch_graph":"https://pith.science/api/pith-number/ASWLHV7MV452KTF6K22L7RGNKZ/graph.json","fetch_events":"https://pith.science/api/pith-number/ASWLHV7MV452KTF6K22L7RGNKZ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/ASWLHV7MV452KTF6K22L7RGNKZ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/ASWLHV7MV452KTF6K22L7RGNKZ/action/storage_attestation","attest_author":"https://pith.science/pith/ASWLHV7MV452KTF6K22L7RGNKZ/action/author_attestation","sign_citation":"https://pith.science/pith/ASWLHV7MV452KTF6K22L7RGNKZ/action/citation_signature","submit_replication":"https://pith.science/pith/ASWLHV7MV452KTF6K22L7RGNKZ/action/replication_record"}},"created_at":"2026-07-05T00:01:14.836125+00:00","updated_at":"2026-07-05T00:01:14.836125+00:00"}