{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:CCHI32X3FNQG4FNFKFZ6PBSMWY","short_pith_number":"pith:CCHI32X3","canonical_record":{"source":{"id":"1812.01821","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-05T05:32:00Z","cross_cats_sorted":["cs.CV","stat.ML"],"title_canon_sha256":"17f4bee70a4c6bb0bd7ffe86e33244a69eac5491d7334b51c561c82b2b728825","abstract_canon_sha256":"7757d232b500c9845d7a596b076ba55381eec1db35050dd6ecc75a584f66e520"},"schema_version":"1.0"},"canonical_sha256":"108e8deafb2b606e15a55173e7864cb63feb12fab9370ab516de170432b9809f","source":{"kind":"arxiv","id":"1812.01821","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1812.01821","created_at":"2026-05-17T23:59:00Z"},{"alias_kind":"arxiv_version","alias_value":"1812.01821v1","created_at":"2026-05-17T23:59:00Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1812.01821","created_at":"2026-05-17T23:59:00Z"},{"alias_kind":"pith_short_12","alias_value":"CCHI32X3FNQG","created_at":"2026-05-18T12:32:16Z"},{"alias_kind":"pith_short_16","alias_value":"CCHI32X3FNQG4FNF","created_at":"2026-05-18T12:32:16Z"},{"alias_kind":"pith_short_8","alias_value":"CCHI32X3","created_at":"2026-05-18T12:32:16Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:CCHI32X3FNQG4FNFKFZ6PBSMWY","target":"record","payload":{"canonical_record":{"source":{"id":"1812.01821","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-05T05:32:00Z","cross_cats_sorted":["cs.CV","stat.ML"],"title_canon_sha256":"17f4bee70a4c6bb0bd7ffe86e33244a69eac5491d7334b51c561c82b2b728825","abstract_canon_sha256":"7757d232b500c9845d7a596b076ba55381eec1db35050dd6ecc75a584f66e520"},"schema_version":"1.0"},"canonical_sha256":"108e8deafb2b606e15a55173e7864cb63feb12fab9370ab516de170432b9809f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:59:00.535014Z","signature_b64":"m2tM59vFK74z8cf6t5p3HUXzZ8zSkAZt8Rsh9eQCd152kr4FZo+McrLPzNOtjXSJ7xnTscDts0twR43DVPNvAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"108e8deafb2b606e15a55173e7864cb63feb12fab9370ab516de170432b9809f","last_reissued_at":"2026-05-17T23:59:00.534518Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:59:00.534518Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1812.01821","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:59:00Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"u/zREdYsbEMWavh0nNJIz1rcDRXxp0g/g5zUxPIQEOLOTrJwiMHjBgLbYCww1Muc1Hw0fK50tEYUK2qHQeU6Dw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T18:19:56.873611Z"},"content_sha256":"1bc531b7e3c71cd3239ee4b9cf53a371d58423d3c7fbb099aa74b1ddeedfd918","schema_version":"1.0","event_id":"sha256:1bc531b7e3c71cd3239ee4b9cf53a371d58423d3c7fbb099aa74b1ddeedfd918"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:CCHI32X3FNQG4FNFKFZ6PBSMWY","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Regularized Ensembles and Transferability in Adversarial Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Yevgeniy Vorobeychik, Yifan Chen","submitted_at":"2018-12-05T05:32:00Z","abstract_excerpt":"Despite the considerable success of convolutional neural networks in a broad array of domains, recent research has shown these to be vulnerable to small adversarial perturbations, commonly known as adversarial examples. Moreover, such examples have shown to be remarkably portable, or transferable, from one model to another, enabling highly successful black-box attacks. We explore this issue of transferability and robustness from two dimensions: first, considering the impact of conventional $l_p$ regularization as well as replacing the top layer with a linear support vector machine (SVM), and s"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1812.01821","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:59:00Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Eoa+2iwz7PWhcRTzCSUGOI10fwHy8h/umt3a8aVf3A+63Nedt+eHbZAm9rxQ4ZA6C9f5XyhYpPH4Fi5pYFRhCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T18:19:56.873972Z"},"content_sha256":"26168b781c15b813dcf4ec9be2d523bda8debf3fc68e42ea8040b09331c222b4","schema_version":"1.0","event_id":"sha256:26168b781c15b813dcf4ec9be2d523bda8debf3fc68e42ea8040b09331c222b4"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/CCHI32X3FNQG4FNFKFZ6PBSMWY/bundle.json","state_url":"https://pith.science/pith/CCHI32X3FNQG4FNFKFZ6PBSMWY/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/CCHI32X3FNQG4FNFKFZ6PBSMWY/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T18:19:56Z","links":{"resolver":"https://pith.science/pith/CCHI32X3FNQG4FNFKFZ6PBSMWY","bundle":"https://pith.science/pith/CCHI32X3FNQG4FNFKFZ6PBSMWY/bundle.json","state":"https://pith.science/pith/CCHI32X3FNQG4FNFKFZ6PBSMWY/state.json","well_known_bundle":"https://pith.science/.well-known/pith/CCHI32X3FNQG4FNFKFZ6PBSMWY/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:CCHI32X3FNQG4FNFKFZ6PBSMWY","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"7757d232b500c9845d7a596b076ba55381eec1db35050dd6ecc75a584f66e520","cross_cats_sorted":["cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-05T05:32:00Z","title_canon_sha256":"17f4bee70a4c6bb0bd7ffe86e33244a69eac5491d7334b51c561c82b2b728825"},"schema_version":"1.0","source":{"id":"1812.01821","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1812.01821","created_at":"2026-05-17T23:59:00Z"},{"alias_kind":"arxiv_version","alias_value":"1812.01821v1","created_at":"2026-05-17T23:59:00Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1812.01821","created_at":"2026-05-17T23:59:00Z"},{"alias_kind":"pith_short_12","alias_value":"CCHI32X3FNQG","created_at":"2026-05-18T12:32:16Z"},{"alias_kind":"pith_short_16","alias_value":"CCHI32X3FNQG4FNF","created_at":"2026-05-18T12:32:16Z"},{"alias_kind":"pith_short_8","alias_value":"CCHI32X3","created_at":"2026-05-18T12:32:16Z"}],"graph_snapshots":[{"event_id":"sha256:26168b781c15b813dcf4ec9be2d523bda8debf3fc68e42ea8040b09331c222b4","target":"graph","created_at":"2026-05-17T23:59:00Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Despite the considerable success of convolutional neural networks in a broad array of domains, recent research has shown these to be vulnerable to small adversarial perturbations, commonly known as adversarial examples. Moreover, such examples have shown to be remarkably portable, or transferable, from one model to another, enabling highly successful black-box attacks. We explore this issue of transferability and robustness from two dimensions: first, considering the impact of conventional $l_p$ regularization as well as replacing the top layer with a linear support vector machine (SVM), and s","authors_text":"Yevgeniy Vorobeychik, Yifan Chen","cross_cats":["cs.CV","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-05T05:32:00Z","title":"Regularized Ensembles and Transferability in Adversarial Learning"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1812.01821","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:1bc531b7e3c71cd3239ee4b9cf53a371d58423d3c7fbb099aa74b1ddeedfd918","target":"record","created_at":"2026-05-17T23:59:00Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"7757d232b500c9845d7a596b076ba55381eec1db35050dd6ecc75a584f66e520","cross_cats_sorted":["cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-05T05:32:00Z","title_canon_sha256":"17f4bee70a4c6bb0bd7ffe86e33244a69eac5491d7334b51c561c82b2b728825"},"schema_version":"1.0","source":{"id":"1812.01821","kind":"arxiv","version":1}},"canonical_sha256":"108e8deafb2b606e15a55173e7864cb63feb12fab9370ab516de170432b9809f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"108e8deafb2b606e15a55173e7864cb63feb12fab9370ab516de170432b9809f","first_computed_at":"2026-05-17T23:59:00.534518Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:59:00.534518Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"m2tM59vFK74z8cf6t5p3HUXzZ8zSkAZt8Rsh9eQCd152kr4FZo+McrLPzNOtjXSJ7xnTscDts0twR43DVPNvAQ==","signature_status":"signed_v1","signed_at":"2026-05-17T23:59:00.535014Z","signed_message":"canonical_sha256_bytes"},"source_id":"1812.01821","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:1bc531b7e3c71cd3239ee4b9cf53a371d58423d3c7fbb099aa74b1ddeedfd918","sha256:26168b781c15b813dcf4ec9be2d523bda8debf3fc68e42ea8040b09331c222b4"],"state_sha256":"6ce38abf721ab00632188e8e1804a1834f5ff44ad474c90a21660379e3704ec2"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"sFRVF31qsVJZbIb1PW2u9mLIX7bP2Zp8H4sF6O2FF3/069v1eTd9tKvsbd2Rh2bVNF6wGoBeooIgocXLNtssBA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T18:19:56.876340Z","bundle_sha256":"024f4c7bd89191254d7f9dae9e10ae0da2e4b9072bb507e8c5e27277b79693b2"}}