{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:BDEEWNZFRDFFZ4ZGC33S4YWKIL","short_pith_number":"pith:BDEEWNZF","schema_version":"1.0","canonical_sha256":"08c84b372588ca5cf32616f72e62ca42f7197e4a5a333165dabafc3b0cfb6d7b","source":{"kind":"arxiv","id":"1901.04684","version":1},"attestation_state":"computed","paper":{"title":"The Limitations of Adversarial Training and the Blind-Spot Attack","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","cs.LG"],"primary_cat":"stat.ML","authors_text":"Cho-Jui Hsieh, Duane Boning, Hongge Chen, Huan Zhang, Inderjit S. Dhillon, Zhao Song","submitted_at":"2019-01-15T07:21:44Z","abstract_excerpt":"The adversarial training procedure proposed by Madry et al. (2018) is one of the most effective methods to defend against adversarial examples in deep neural networks (DNNs). In our paper, we shed some lights on the practicality and the hardness of adversarial training by showing that the effectiveness (robustness on test set) of adversarial training has a strong correlation with the distance between a test point and the manifold of training data embedded by the network. Test examples that are relatively far away from this manifold are more likely to be vulnerable to adversarial attacks. Conse"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1901.04684","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2019-01-15T07:21:44Z","cross_cats_sorted":["cs.CR","cs.CV","cs.LG"],"title_canon_sha256":"ae3e2dea183e46991ca39938cdfc0788c03c7d3ce4c4f7ac3994e5212a2eeb52","abstract_canon_sha256":"ea483f5974380b8d26f2f0633d1d31ead7108e1466f854abb01a029696d159fe"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:55:33.789306Z","signature_b64":"N3E5ynTtrxihM/IOfdeyp7SdobFkF3SV3cQM3hTnVoQ5OWoDmCvjCx8d6zRE8uxtfgp+PZuFkScW660LeG7aBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"08c84b372588ca5cf32616f72e62ca42f7197e4a5a333165dabafc3b0cfb6d7b","last_reissued_at":"2026-05-17T23:55:33.788835Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:55:33.788835Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"The Limitations of Adversarial Training and the Blind-Spot Attack","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","cs.LG"],"primary_cat":"stat.ML","authors_text":"Cho-Jui Hsieh, Duane Boning, Hongge Chen, Huan Zhang, Inderjit S. Dhillon, Zhao Song","submitted_at":"2019-01-15T07:21:44Z","abstract_excerpt":"The adversarial training procedure proposed by Madry et al. (2018) is one of the most effective methods to defend against adversarial examples in deep neural networks (DNNs). In our paper, we shed some lights on the practicality and the hardness of adversarial training by showing that the effectiveness (robustness on test set) of adversarial training has a strong correlation with the distance between a test point and the manifold of training data embedded by the network. Test examples that are relatively far away from this manifold are more likely to be vulnerable to adversarial attacks. Conse"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1901.04684","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1901.04684","created_at":"2026-05-17T23:55:33.788910+00:00"},{"alias_kind":"arxiv_version","alias_value":"1901.04684v1","created_at":"2026-05-17T23:55:33.788910+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1901.04684","created_at":"2026-05-17T23:55:33.788910+00:00"},{"alias_kind":"pith_short_12","alias_value":"BDEEWNZFRDFF","created_at":"2026-05-18T12:33:12.712433+00:00"},{"alias_kind":"pith_short_16","alias_value":"BDEEWNZFRDFFZ4ZG","created_at":"2026-05-18T12:33:12.712433+00:00"},{"alias_kind":"pith_short_8","alias_value":"BDEEWNZF","created_at":"2026-05-18T12:33:12.712433+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/BDEEWNZFRDFFZ4ZGC33S4YWKIL","json":"https://pith.science/pith/BDEEWNZFRDFFZ4ZGC33S4YWKIL.json","graph_json":"https://pith.science/api/pith-number/BDEEWNZFRDFFZ4ZGC33S4YWKIL/graph.json","events_json":"https://pith.science/api/pith-number/BDEEWNZFRDFFZ4ZGC33S4YWKIL/events.json","paper":"https://pith.science/paper/BDEEWNZF"},"agent_actions":{"view_html":"https://pith.science/pith/BDEEWNZFRDFFZ4ZGC33S4YWKIL","download_json":"https://pith.science/pith/BDEEWNZFRDFFZ4ZGC33S4YWKIL.json","view_paper":"https://pith.science/paper/BDEEWNZF","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1901.04684&json=true","fetch_graph":"https://pith.science/api/pith-number/BDEEWNZFRDFFZ4ZGC33S4YWKIL/graph.json","fetch_events":"https://pith.science/api/pith-number/BDEEWNZFRDFFZ4ZGC33S4YWKIL/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/BDEEWNZFRDFFZ4ZGC33S4YWKIL/action/timestamp_anchor","attest_storage":"https://pith.science/pith/BDEEWNZFRDFFZ4ZGC33S4YWKIL/action/storage_attestation","attest_author":"https://pith.science/pith/BDEEWNZFRDFFZ4ZGC33S4YWKIL/action/author_attestation","sign_citation":"https://pith.science/pith/BDEEWNZFRDFFZ4ZGC33S4YWKIL/action/citation_signature","submit_replication":"https://pith.science/pith/BDEEWNZFRDFFZ4ZGC33S4YWKIL/action/replication_record"}},"created_at":"2026-05-17T23:55:33.788910+00:00","updated_at":"2026-05-17T23:55:33.788910+00:00"}