{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:CHTJI3AFY4GBS4NBBQZP6BGPIU","short_pith_number":"pith:CHTJI3AF","schema_version":"1.0","canonical_sha256":"11e6946c05c70c1971a10c32ff04cf453495421ccb5893b4a7e835afbc59ae7c","source":{"kind":"arxiv","id":"1905.13725","version":4},"attestation_state":"computed","paper":{"title":"Are Labels Required for Improving Adversarial Robustness?","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Alhussein Fawzi, Jean-Baptiste Alayrac, Jonathan Uesato, Po-Sen Huang, Pushmeet Kohli, Robert Stanforth","submitted_at":"2019-05-31T17:19:13Z","abstract_excerpt":"Recent work has uncovered the interesting (and somewhat surprising) finding that training models to be invariant to adversarial perturbations requires substantially larger datasets than those required for standard classification. This result is a key hurdle in the deployment of robust machine learning models in many real world applications where labeled data is expensive. Our main insight is that unlabeled data can be a competitive alternative to labeled data for training adversarially robust models. Theoretically, we show that in a simple statistical setting, the sample complexity for learnin"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1905.13725","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-31T17:19:13Z","cross_cats_sorted":["cs.CV","stat.ML"],"title_canon_sha256":"5b3994c8549d59dbb886c6a5ee943f85acbfc8a584f72af95b81c1ea009939d5","abstract_canon_sha256":"6d98142cc50e3ee1506b2a5f4b0269291607da0d64a0145e4ab74c448e4bf6b9"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:24:08.003410Z","signature_b64":"HvXfQn/YRVHNCdF9N+livK2LhLMXcfSwyKKqY4i2W/2FyRsvJlo5b78PnMjAkEjGZdqtjHtLhXNuHf0DOGTNCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"11e6946c05c70c1971a10c32ff04cf453495421ccb5893b4a7e835afbc59ae7c","last_reissued_at":"2026-07-05T00:24:08.002926Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:24:08.002926Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Are Labels Required for Improving Adversarial Robustness?","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Alhussein Fawzi, Jean-Baptiste Alayrac, Jonathan Uesato, Po-Sen Huang, Pushmeet Kohli, Robert Stanforth","submitted_at":"2019-05-31T17:19:13Z","abstract_excerpt":"Recent work has uncovered the interesting (and somewhat surprising) finding that training models to be invariant to adversarial perturbations requires substantially larger datasets than those required for standard classification. This result is a key hurdle in the deployment of robust machine learning models in many real world applications where labeled data is expensive. Our main insight is that unlabeled data can be a competitive alternative to labeled data for training adversarially robust models. Theoretically, we show that in a simple statistical setting, the sample complexity for learnin"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.13725","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1905.13725/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1905.13725","created_at":"2026-07-05T00:24:08.002985+00:00"},{"alias_kind":"arxiv_version","alias_value":"1905.13725v4","created_at":"2026-07-05T00:24:08.002985+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.13725","created_at":"2026-07-05T00:24:08.002985+00:00"},{"alias_kind":"pith_short_12","alias_value":"CHTJI3AFY4GB","created_at":"2026-07-05T00:24:08.002985+00:00"},{"alias_kind":"pith_short_16","alias_value":"CHTJI3AFY4GBS4NB","created_at":"2026-07-05T00:24:08.002985+00:00"},{"alias_kind":"pith_short_8","alias_value":"CHTJI3AF","created_at":"2026-07-05T00:24:08.002985+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"1909.00900","citing_title":"Metric Learning for Adversarial Robustness","ref_index":39,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/CHTJI3AFY4GBS4NBBQZP6BGPIU","json":"https://pith.science/pith/CHTJI3AFY4GBS4NBBQZP6BGPIU.json","graph_json":"https://pith.science/api/pith-number/CHTJI3AFY4GBS4NBBQZP6BGPIU/graph.json","events_json":"https://pith.science/api/pith-number/CHTJI3AFY4GBS4NBBQZP6BGPIU/events.json","paper":"https://pith.science/paper/CHTJI3AF"},"agent_actions":{"view_html":"https://pith.science/pith/CHTJI3AFY4GBS4NBBQZP6BGPIU","download_json":"https://pith.science/pith/CHTJI3AFY4GBS4NBBQZP6BGPIU.json","view_paper":"https://pith.science/paper/CHTJI3AF","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1905.13725&json=true","fetch_graph":"https://pith.science/api/pith-number/CHTJI3AFY4GBS4NBBQZP6BGPIU/graph.json","fetch_events":"https://pith.science/api/pith-number/CHTJI3AFY4GBS4NBBQZP6BGPIU/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/CHTJI3AFY4GBS4NBBQZP6BGPIU/action/timestamp_anchor","attest_storage":"https://pith.science/pith/CHTJI3AFY4GBS4NBBQZP6BGPIU/action/storage_attestation","attest_author":"https://pith.science/pith/CHTJI3AFY4GBS4NBBQZP6BGPIU/action/author_attestation","sign_citation":"https://pith.science/pith/CHTJI3AFY4GBS4NBBQZP6BGPIU/action/citation_signature","submit_replication":"https://pith.science/pith/CHTJI3AFY4GBS4NBBQZP6BGPIU/action/replication_record"}},"created_at":"2026-07-05T00:24:08.002985+00:00","updated_at":"2026-07-05T00:24:08.002985+00:00"}