{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:B4J7JWGFQLWSLTGYPRILYTSEBA","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"4b47784054cd3c233d011a7d806f56c9bb16ec850f617a992b1317fccb207341","cross_cats_sorted":["cs.AI","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-17T04:26:52Z","title_canon_sha256":"0d7a155ecfa488d4c72bcb843413971886240d7769b9a864ebb770b0e89f89e6"},"schema_version":"1.0","source":{"id":"1905.07112","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.07112","created_at":"2026-05-17T23:45:57Z"},{"alias_kind":"arxiv_version","alias_value":"1905.07112v1","created_at":"2026-05-17T23:45:57Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.07112","created_at":"2026-05-17T23:45:57Z"},{"alias_kind":"pith_short_12","alias_value":"B4J7JWGFQLWS","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_16","alias_value":"B4J7JWGFQLWSLTGY","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_8","alias_value":"B4J7JWGF","created_at":"2026-05-18T12:33:12Z"}],"graph_snapshots":[{"event_id":"sha256:fb919433acf8a9c2f882388abc4f39e70ee69dd47f7e5dfd4dd95abb6fc6929b","target":"graph","created_at":"2026-05-17T23:45:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"At IEEE S&P 2019, the paper \"DeepSec: A Uniform Platform for Security Analysis of Deep Learning Model\" aims to to \"systematically evaluate the existing adversarial attack and defense methods.\" While the paper's goals are laudable, it fails to achieve them and presents results that are fundamentally flawed and misleading. We explain the flaws in the DeepSec work, along with how its analysis fails to meaningfully evaluate the various attacks and defenses. Specifically, DeepSec (1) evaluates each defense obliviously, using attacks crafted against undefended models; (2) evaluates attacks and defen","authors_text":"Nicholas Carlini","cross_cats":["cs.AI","cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-17T04:26:52Z","title":"A critique of the DeepSec Platform for Security Analysis of Deep Learning Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.07112","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:b5c9a4ad52428242eafba40b96fa7cbebf5c2da757ecc623963c5969245cb880","target":"record","created_at":"2026-05-17T23:45:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"4b47784054cd3c233d011a7d806f56c9bb16ec850f617a992b1317fccb207341","cross_cats_sorted":["cs.AI","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-17T04:26:52Z","title_canon_sha256":"0d7a155ecfa488d4c72bcb843413971886240d7769b9a864ebb770b0e89f89e6"},"schema_version":"1.0","source":{"id":"1905.07112","kind":"arxiv","version":1}},"canonical_sha256":"0f13f4d8c582ed25ccd87c50bc4e44083ccc3565384a50442540516258df3f12","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"0f13f4d8c582ed25ccd87c50bc4e44083ccc3565384a50442540516258df3f12","first_computed_at":"2026-05-17T23:45:57.290933Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:45:57.290933Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"rpMhyQIxEVAr50Kgxwb3MJ/rgwsAgwSFr7yV00w9gXBuTANVfS41mLxaByzL13xK42/fkalka72MH4qSiIs8AA==","signature_status":"signed_v1","signed_at":"2026-05-17T23:45:57.291487Z","signed_message":"canonical_sha256_bytes"},"source_id":"1905.07112","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:b5c9a4ad52428242eafba40b96fa7cbebf5c2da757ecc623963c5969245cb880","sha256:fb919433acf8a9c2f882388abc4f39e70ee69dd47f7e5dfd4dd95abb6fc6929b"],"state_sha256":"981fd0ba1083a4cb6d7343d6c217696dc8a83d86797bb7139bd88935f8cfee36"}