{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:CB3PHJQCMHFHMMHPPOPA6HFWSG","short_pith_number":"pith:CB3PHJQC","canonical_record":{"source":{"id":"1906.10973","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-06-26T11:07:29Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"02e21e6ddff8275e82e77fecc285f0584e9c11c376fe1410b4ce952b49e773dc","abstract_canon_sha256":"b7c83d3c7436f4eb6b5e80eb046d4dedf5c89de578aa97f605f2d9f2ded283b1"},"schema_version":"1.0"},"canonical_sha256":"1076f3a60261ca7630ef7b9e0f1cb69198dbe9ecff6571a563fcbeeb7ac7b05c","source":{"kind":"arxiv","id":"1906.10973","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1906.10973","created_at":"2026-05-17T23:42:10Z"},{"alias_kind":"arxiv_version","alias_value":"1906.10973v1","created_at":"2026-05-17T23:42:10Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1906.10973","created_at":"2026-05-17T23:42:10Z"},{"alias_kind":"pith_short_12","alias_value":"CB3PHJQCMHFH","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_16","alias_value":"CB3PHJQCMHFHMMHP","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_8","alias_value":"CB3PHJQC","created_at":"2026-05-18T12:33:12Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:CB3PHJQCMHFHMMHPPOPA6HFWSG","target":"record","payload":{"canonical_record":{"source":{"id":"1906.10973","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-06-26T11:07:29Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"02e21e6ddff8275e82e77fecc285f0584e9c11c376fe1410b4ce952b49e773dc","abstract_canon_sha256":"b7c83d3c7436f4eb6b5e80eb046d4dedf5c89de578aa97f605f2d9f2ded283b1"},"schema_version":"1.0"},"canonical_sha256":"1076f3a60261ca7630ef7b9e0f1cb69198dbe9ecff6571a563fcbeeb7ac7b05c","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:42:10.374066Z","signature_b64":"9NgwGNmn61pITfSKa9bxs3A1Yg5ssHNuYRQMe//OXAHuoLwhZtYnDeE2ldIiUMzgeiDocI932SKna5oP0ftfCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"1076f3a60261ca7630ef7b9e0f1cb69198dbe9ecff6571a563fcbeeb7ac7b05c","last_reissued_at":"2026-05-17T23:42:10.373402Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:42:10.373402Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1906.10973","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:42:10Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"UCi45uOJWGSfU/BJaMbdCm9uNzzgXdzzKqhus9nyI6wpR3vy7fJ8+K7uwtmuf70fvlS8lbJjq5x5Biwz4MzvDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T23:08:43.076962Z"},"content_sha256":"843e9480a19a902224da9e621b356c82ddfccdfd09d40e2beead392998cbb78c","schema_version":"1.0","event_id":"sha256:843e9480a19a902224da9e621b356c82ddfccdfd09d40e2beead392998cbb78c"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:CB3PHJQCMHFHMMHPPOPA6HFWSG","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Defending Adversarial Attacks by Correcting logits","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Lingxi Xie, Qi Tian, Rui Zhang, Yanfeng Wang, Ya Zhang, Yifeng Li","submitted_at":"2019-06-26T11:07:29Z","abstract_excerpt":"Generating and eliminating adversarial examples has been an intriguing topic in the field of deep learning. While previous research verified that adversarial attacks are often fragile and can be defended via image-level processing, it remains unclear how high-level features are perturbed by such attacks. We investigate this issue from a new perspective, which purely relies on logits, the class scores before softmax, to detect and defend adversarial attacks. Our defender is a two-layer network trained on a mixed set of clean and perturbed logits, with the goal being recovering the original pred"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1906.10973","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:42:10Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"xB3TUEMbO4Hrl+5k7r+GpfXRV9zN1igrYaLwYnYZPMzt7Db6kzPQJa4eyTxYxm/vEcjcOfRn8nOIF73zyqTxAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T23:08:43.077662Z"},"content_sha256":"7c9829cf306a9cb788c010ffa120636c66156d4128c28ec6f01f54d662d69274","schema_version":"1.0","event_id":"sha256:7c9829cf306a9cb788c010ffa120636c66156d4128c28ec6f01f54d662d69274"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/CB3PHJQCMHFHMMHPPOPA6HFWSG/bundle.json","state_url":"https://pith.science/pith/CB3PHJQCMHFHMMHPPOPA6HFWSG/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/CB3PHJQCMHFHMMHPPOPA6HFWSG/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T23:08:43Z","links":{"resolver":"https://pith.science/pith/CB3PHJQCMHFHMMHPPOPA6HFWSG","bundle":"https://pith.science/pith/CB3PHJQCMHFHMMHPPOPA6HFWSG/bundle.json","state":"https://pith.science/pith/CB3PHJQCMHFHMMHPPOPA6HFWSG/state.json","well_known_bundle":"https://pith.science/.well-known/pith/CB3PHJQCMHFHMMHPPOPA6HFWSG/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:CB3PHJQCMHFHMMHPPOPA6HFWSG","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"b7c83d3c7436f4eb6b5e80eb046d4dedf5c89de578aa97f605f2d9f2ded283b1","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-06-26T11:07:29Z","title_canon_sha256":"02e21e6ddff8275e82e77fecc285f0584e9c11c376fe1410b4ce952b49e773dc"},"schema_version":"1.0","source":{"id":"1906.10973","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1906.10973","created_at":"2026-05-17T23:42:10Z"},{"alias_kind":"arxiv_version","alias_value":"1906.10973v1","created_at":"2026-05-17T23:42:10Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1906.10973","created_at":"2026-05-17T23:42:10Z"},{"alias_kind":"pith_short_12","alias_value":"CB3PHJQCMHFH","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_16","alias_value":"CB3PHJQCMHFHMMHP","created_at":"2026-05-18T12:33:12Z"},{"alias_kind":"pith_short_8","alias_value":"CB3PHJQC","created_at":"2026-05-18T12:33:12Z"}],"graph_snapshots":[{"event_id":"sha256:7c9829cf306a9cb788c010ffa120636c66156d4128c28ec6f01f54d662d69274","target":"graph","created_at":"2026-05-17T23:42:10Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Generating and eliminating adversarial examples has been an intriguing topic in the field of deep learning. While previous research verified that adversarial attacks are often fragile and can be defended via image-level processing, it remains unclear how high-level features are perturbed by such attacks. We investigate this issue from a new perspective, which purely relies on logits, the class scores before softmax, to detect and defend adversarial attacks. Our defender is a two-layer network trained on a mixed set of clean and perturbed logits, with the goal being recovering the original pred","authors_text":"Lingxi Xie, Qi Tian, Rui Zhang, Yanfeng Wang, Ya Zhang, Yifeng Li","cross_cats":["cs.CR","cs.CV","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-06-26T11:07:29Z","title":"Defending Adversarial Attacks by Correcting logits"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1906.10973","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:843e9480a19a902224da9e621b356c82ddfccdfd09d40e2beead392998cbb78c","target":"record","created_at":"2026-05-17T23:42:10Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"b7c83d3c7436f4eb6b5e80eb046d4dedf5c89de578aa97f605f2d9f2ded283b1","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-06-26T11:07:29Z","title_canon_sha256":"02e21e6ddff8275e82e77fecc285f0584e9c11c376fe1410b4ce952b49e773dc"},"schema_version":"1.0","source":{"id":"1906.10973","kind":"arxiv","version":1}},"canonical_sha256":"1076f3a60261ca7630ef7b9e0f1cb69198dbe9ecff6571a563fcbeeb7ac7b05c","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"1076f3a60261ca7630ef7b9e0f1cb69198dbe9ecff6571a563fcbeeb7ac7b05c","first_computed_at":"2026-05-17T23:42:10.373402Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:42:10.373402Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"9NgwGNmn61pITfSKa9bxs3A1Yg5ssHNuYRQMe//OXAHuoLwhZtYnDeE2ldIiUMzgeiDocI932SKna5oP0ftfCQ==","signature_status":"signed_v1","signed_at":"2026-05-17T23:42:10.374066Z","signed_message":"canonical_sha256_bytes"},"source_id":"1906.10973","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:843e9480a19a902224da9e621b356c82ddfccdfd09d40e2beead392998cbb78c","sha256:7c9829cf306a9cb788c010ffa120636c66156d4128c28ec6f01f54d662d69274"],"state_sha256":"07bf3893b8593103a4bd37258ebec439bacce835dbd250adbf2be455dfe71b1b"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"wvYSfFSuLzNWYXjS/7b14MWiNzL7gbhmdogj+iV2fgvztwUmRneONVTepBYGMfau81fa9dljsEvQMGgt1SNoAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T23:08:43.081235Z","bundle_sha256":"845be9895ea3b03f5637e56c74576553ff7f68a90ffc58b67f006389e9a5924d"}}