{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:C5IFZC3JTZPUGX2HLGX5S5QRPX","short_pith_number":"pith:C5IFZC3J","canonical_record":{"source":{"id":"2512.12997","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2025-12-15T05:41:08Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"b381ed6f7961880860fd4b6a0af901630e10d25c9494ef320eba9c85ce6cf0db","abstract_canon_sha256":"13156a3dc582521d0ea8f80c60d28820821b311d04f57b7222c9807d1f6c432f"},"schema_version":"1.0"},"canonical_sha256":"17505c8b699e5f435f4759afd976117dfc36357cf8908a7d071a19c489b42d7f","source":{"kind":"arxiv","id":"2512.12997","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2512.12997","created_at":"2026-06-02T01:03:39Z"},{"alias_kind":"arxiv_version","alias_value":"2512.12997v2","created_at":"2026-06-02T01:03:39Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2512.12997","created_at":"2026-06-02T01:03:39Z"},{"alias_kind":"pith_short_12","alias_value":"C5IFZC3JTZPU","created_at":"2026-06-02T01:03:39Z"},{"alias_kind":"pith_short_16","alias_value":"C5IFZC3JTZPUGX2H","created_at":"2026-06-02T01:03:39Z"},{"alias_kind":"pith_short_8","alias_value":"C5IFZC3J","created_at":"2026-06-02T01:03:39Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:C5IFZC3JTZPUGX2HLGX5S5QRPX","target":"record","payload":{"canonical_record":{"source":{"id":"2512.12997","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2025-12-15T05:41:08Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"b381ed6f7961880860fd4b6a0af901630e10d25c9494ef320eba9c85ce6cf0db","abstract_canon_sha256":"13156a3dc582521d0ea8f80c60d28820821b311d04f57b7222c9807d1f6c432f"},"schema_version":"1.0"},"canonical_sha256":"17505c8b699e5f435f4759afd976117dfc36357cf8908a7d071a19c489b42d7f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-02T01:03:39.841793Z","signature_b64":"/tiw5VlnQfEct6za7QB3UTVgyG7PGPlvtDeAmz5xC74Y9H8UYcYNrwPqVtZyqvSy4l4bj4d1s9Z4VpWYgVXDDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"17505c8b699e5f435f4759afd976117dfc36357cf8908a7d071a19c489b42d7f","last_reissued_at":"2026-06-02T01:03:39.841250Z","signature_status":"signed_v1","first_computed_at":"2026-06-02T01:03:39.841250Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2512.12997","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-02T01:03:39Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"V9rPX6W0yC1RY4/CZZGQ5iNjEIlpyRZtYqiRReRO3uiTOpP0sanM+xMuXJFGS5W2CL7Qr8ipuEsu0z07kRtLDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-06T06:47:21.580181Z"},"content_sha256":"864b78fe3d1a7bc699c27cf9f9ed55f103ce38db06319b40eef9b9d9555f35e1","schema_version":"1.0","event_id":"sha256:864b78fe3d1a7bc699c27cf9f9ed55f103ce38db06319b40eef9b9d9555f35e1"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:C5IFZC3JTZPUGX2HLGX5S5QRPX","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Calibrating Uncertainty for Zero-Shot Adversarial CLIP","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CV","authors_text":"Dongping Zhang, Qibin Zhao, Wenjing Lu, Yang Yang, Yuning Qiu, Zerui Tao","submitted_at":"2025-12-15T05:41:08Z","abstract_excerpt":"CLIP delivers strong zero-shot classification but remains highly vulnerable to adversarial attacks. Prior adversarial fine-tuning work primarily matches predicted logits between clean and adversarial examples, which overlooks uncertainty calibration and may degrade the zero-shot generalization. A common expectation in reliable uncertainty estimation is that predictive uncertainty should increase as inputs become more difficult or shift away from the training distribution. However, we frequently observe the opposite in the adversarial setting: perturbations not only degrade accuracy but also su"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2512.12997","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2512.12997/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-02T01:03:39Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"s4vHySaHUMdJDXLpXBfIVJj/l3aYb+n1ilWYHFrqmQUiJcPruaEbnIkk7iSrZcB1M7uKt2wfGbxtFSKEDhmOBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-06T06:47:21.580898Z"},"content_sha256":"0e6f727031c3479f46fb3210f470712a797180a031e0fb921ce6be7efc86e7d5","schema_version":"1.0","event_id":"sha256:0e6f727031c3479f46fb3210f470712a797180a031e0fb921ce6be7efc86e7d5"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/C5IFZC3JTZPUGX2HLGX5S5QRPX/bundle.json","state_url":"https://pith.science/pith/C5IFZC3JTZPUGX2HLGX5S5QRPX/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/C5IFZC3JTZPUGX2HLGX5S5QRPX/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-06T06:47:21Z","links":{"resolver":"https://pith.science/pith/C5IFZC3JTZPUGX2HLGX5S5QRPX","bundle":"https://pith.science/pith/C5IFZC3JTZPUGX2HLGX5S5QRPX/bundle.json","state":"https://pith.science/pith/C5IFZC3JTZPUGX2HLGX5S5QRPX/state.json","well_known_bundle":"https://pith.science/.well-known/pith/C5IFZC3JTZPUGX2HLGX5S5QRPX/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:C5IFZC3JTZPUGX2HLGX5S5QRPX","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"13156a3dc582521d0ea8f80c60d28820821b311d04f57b7222c9807d1f6c432f","cross_cats_sorted":["cs.AI","cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2025-12-15T05:41:08Z","title_canon_sha256":"b381ed6f7961880860fd4b6a0af901630e10d25c9494ef320eba9c85ce6cf0db"},"schema_version":"1.0","source":{"id":"2512.12997","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2512.12997","created_at":"2026-06-02T01:03:39Z"},{"alias_kind":"arxiv_version","alias_value":"2512.12997v2","created_at":"2026-06-02T01:03:39Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2512.12997","created_at":"2026-06-02T01:03:39Z"},{"alias_kind":"pith_short_12","alias_value":"C5IFZC3JTZPU","created_at":"2026-06-02T01:03:39Z"},{"alias_kind":"pith_short_16","alias_value":"C5IFZC3JTZPUGX2H","created_at":"2026-06-02T01:03:39Z"},{"alias_kind":"pith_short_8","alias_value":"C5IFZC3J","created_at":"2026-06-02T01:03:39Z"}],"graph_snapshots":[{"event_id":"sha256:0e6f727031c3479f46fb3210f470712a797180a031e0fb921ce6be7efc86e7d5","target":"graph","created_at":"2026-06-02T01:03:39Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2512.12997/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"CLIP delivers strong zero-shot classification but remains highly vulnerable to adversarial attacks. Prior adversarial fine-tuning work primarily matches predicted logits between clean and adversarial examples, which overlooks uncertainty calibration and may degrade the zero-shot generalization. A common expectation in reliable uncertainty estimation is that predictive uncertainty should increase as inputs become more difficult or shift away from the training distribution. However, we frequently observe the opposite in the adversarial setting: perturbations not only degrade accuracy but also su","authors_text":"Dongping Zhang, Qibin Zhao, Wenjing Lu, Yang Yang, Yuning Qiu, Zerui Tao","cross_cats":["cs.AI","cs.LG"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2025-12-15T05:41:08Z","title":"Calibrating Uncertainty for Zero-Shot Adversarial CLIP"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2512.12997","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:864b78fe3d1a7bc699c27cf9f9ed55f103ce38db06319b40eef9b9d9555f35e1","target":"record","created_at":"2026-06-02T01:03:39Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"13156a3dc582521d0ea8f80c60d28820821b311d04f57b7222c9807d1f6c432f","cross_cats_sorted":["cs.AI","cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2025-12-15T05:41:08Z","title_canon_sha256":"b381ed6f7961880860fd4b6a0af901630e10d25c9494ef320eba9c85ce6cf0db"},"schema_version":"1.0","source":{"id":"2512.12997","kind":"arxiv","version":2}},"canonical_sha256":"17505c8b699e5f435f4759afd976117dfc36357cf8908a7d071a19c489b42d7f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"17505c8b699e5f435f4759afd976117dfc36357cf8908a7d071a19c489b42d7f","first_computed_at":"2026-06-02T01:03:39.841250Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-02T01:03:39.841250Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"/tiw5VlnQfEct6za7QB3UTVgyG7PGPlvtDeAmz5xC74Y9H8UYcYNrwPqVtZyqvSy4l4bj4d1s9Z4VpWYgVXDDA==","signature_status":"signed_v1","signed_at":"2026-06-02T01:03:39.841793Z","signed_message":"canonical_sha256_bytes"},"source_id":"2512.12997","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:864b78fe3d1a7bc699c27cf9f9ed55f103ce38db06319b40eef9b9d9555f35e1","sha256:0e6f727031c3479f46fb3210f470712a797180a031e0fb921ce6be7efc86e7d5"],"state_sha256":"039c6ee7c2ee8080f6c690f30dbf696de6d619027d699585945cb405fa84fedd"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"iL3LVZiSCHZkvuhA/AUZj0TdE5P8iw89aYUMhbaKGo3mCXyaUms5RtsnkPg2CpjQofGZ8Cpe7URgOAKOgQ7iDg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-06T06:47:21.585355Z","bundle_sha256":"1b98c5c62799263481c2a7db989479772c149266f80df75b681dd9ecc728f95f"}}