{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:CTYTZHGOGKSIXBX6Z2FYWHTMHY","short_pith_number":"pith:CTYTZHGO","canonical_record":{"source":{"id":"1903.00585","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-03-02T00:38:38Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"1468547bfd8b7b00d2d60a3d720055f7b615488df6790ba97264cccac72b6879","abstract_canon_sha256":"615c344e46d0ba282c8a02ee483b5d1dc409aba657cc3e857cbb4271ab29cb21"},"schema_version":"1.0"},"canonical_sha256":"14f13c9cce32a48b86fece8b8b1e6c3e195619b3c36e5729c0701be9da826dda","source":{"kind":"arxiv","id":"1903.00585","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1903.00585","created_at":"2026-05-17T23:52:14Z"},{"alias_kind":"arxiv_version","alias_value":"1903.00585v1","created_at":"2026-05-17T23:52:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1903.00585","created_at":"2026-05-17T23:52:14Z"},{"alias_kind":"pith_short_12","alias_value":"CTYTZHGOGKSI","created_at":"2026-05-18T12:33:15Z"},{"alias_kind":"pith_short_16","alias_value":"CTYTZHGOGKSIXBX6","created_at":"2026-05-18T12:33:15Z"},{"alias_kind":"pith_short_8","alias_value":"CTYTZHGO","created_at":"2026-05-18T12:33:15Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:CTYTZHGOGKSIXBX6Z2FYWHTMHY","target":"record","payload":{"canonical_record":{"source":{"id":"1903.00585","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-03-02T00:38:38Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"1468547bfd8b7b00d2d60a3d720055f7b615488df6790ba97264cccac72b6879","abstract_canon_sha256":"615c344e46d0ba282c8a02ee483b5d1dc409aba657cc3e857cbb4271ab29cb21"},"schema_version":"1.0"},"canonical_sha256":"14f13c9cce32a48b86fece8b8b1e6c3e195619b3c36e5729c0701be9da826dda","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:52:14.077199Z","signature_b64":"UFrrGE3G9V8sp+Paypj0kJ6YH3EpRHAsf7Fc+HfpTGjec1LpPip1z0Im8RXwtho+PpMnmrLophd0VONxS6nhDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"14f13c9cce32a48b86fece8b8b1e6c3e195619b3c36e5729c0701be9da826dda","last_reissued_at":"2026-05-17T23:52:14.076405Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:52:14.076405Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1903.00585","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:52:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"xV/LMahtBCym7qVPCB6z7qvXcb/k1hfJhWUwQYTOZiynO66TK//coI4QZQvLxXELp1XJYBXvuCdBgbAlTAsRCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-10T05:00:22.859581Z"},"content_sha256":"7864a1e47610ddaf7553a8ebb8a178422a279616e1dc43b7328982b4de95a4a7","schema_version":"1.0","event_id":"sha256:7864a1e47610ddaf7553a8ebb8a178422a279616e1dc43b7328982b4de95a4a7"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:CTYTZHGOGKSIXBX6Z2FYWHTMHY","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"PuVAE: A Variational Autoencoder to Purify Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Hyemi Jang, Jaewoo Park, Nam Ik Cho, Sungroh Yoon, Uiwon Hwang","submitted_at":"2019-03-02T00:38:38Z","abstract_excerpt":"Deep neural networks are widely used and exhibit excellent performance in many areas. However, they are vulnerable to adversarial attacks that compromise the network at the inference time by applying elaborately designed perturbation to input data. Although several defense methods have been proposed to address specific attacks, other attack methods can circumvent these defense mechanisms. Therefore, we propose Purifying Variational Autoencoder (PuVAE), a method to purify adversarial examples. The proposed method eliminates an adversarial perturbation by projecting an adversarial example on the"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1903.00585","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:52:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"JviPkwJBiGR1Cwt06ZOPMJN9mB7JIDMaUubFtGcY9RI7fgmsz94548sFnYTM6CJoelX+b3QDU4tq+hehjgbeCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-10T05:00:22.860237Z"},"content_sha256":"a34b4f7ee678ccfb5c1ccf86fb387b5ca0db48e717a915b7205c7a7bab814ed7","schema_version":"1.0","event_id":"sha256:a34b4f7ee678ccfb5c1ccf86fb387b5ca0db48e717a915b7205c7a7bab814ed7"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/CTYTZHGOGKSIXBX6Z2FYWHTMHY/bundle.json","state_url":"https://pith.science/pith/CTYTZHGOGKSIXBX6Z2FYWHTMHY/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/CTYTZHGOGKSIXBX6Z2FYWHTMHY/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-10T05:00:22Z","links":{"resolver":"https://pith.science/pith/CTYTZHGOGKSIXBX6Z2FYWHTMHY","bundle":"https://pith.science/pith/CTYTZHGOGKSIXBX6Z2FYWHTMHY/bundle.json","state":"https://pith.science/pith/CTYTZHGOGKSIXBX6Z2FYWHTMHY/state.json","well_known_bundle":"https://pith.science/.well-known/pith/CTYTZHGOGKSIXBX6Z2FYWHTMHY/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:CTYTZHGOGKSIXBX6Z2FYWHTMHY","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"615c344e46d0ba282c8a02ee483b5d1dc409aba657cc3e857cbb4271ab29cb21","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-03-02T00:38:38Z","title_canon_sha256":"1468547bfd8b7b00d2d60a3d720055f7b615488df6790ba97264cccac72b6879"},"schema_version":"1.0","source":{"id":"1903.00585","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1903.00585","created_at":"2026-05-17T23:52:14Z"},{"alias_kind":"arxiv_version","alias_value":"1903.00585v1","created_at":"2026-05-17T23:52:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1903.00585","created_at":"2026-05-17T23:52:14Z"},{"alias_kind":"pith_short_12","alias_value":"CTYTZHGOGKSI","created_at":"2026-05-18T12:33:15Z"},{"alias_kind":"pith_short_16","alias_value":"CTYTZHGOGKSIXBX6","created_at":"2026-05-18T12:33:15Z"},{"alias_kind":"pith_short_8","alias_value":"CTYTZHGO","created_at":"2026-05-18T12:33:15Z"}],"graph_snapshots":[{"event_id":"sha256:a34b4f7ee678ccfb5c1ccf86fb387b5ca0db48e717a915b7205c7a7bab814ed7","target":"graph","created_at":"2026-05-17T23:52:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep neural networks are widely used and exhibit excellent performance in many areas. However, they are vulnerable to adversarial attacks that compromise the network at the inference time by applying elaborately designed perturbation to input data. Although several defense methods have been proposed to address specific attacks, other attack methods can circumvent these defense mechanisms. Therefore, we propose Purifying Variational Autoencoder (PuVAE), a method to purify adversarial examples. The proposed method eliminates an adversarial perturbation by projecting an adversarial example on the","authors_text":"Hyemi Jang, Jaewoo Park, Nam Ik Cho, Sungroh Yoon, Uiwon Hwang","cross_cats":["cs.CR","cs.CV","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-03-02T00:38:38Z","title":"PuVAE: A Variational Autoencoder to Purify Adversarial Examples"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1903.00585","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:7864a1e47610ddaf7553a8ebb8a178422a279616e1dc43b7328982b4de95a4a7","target":"record","created_at":"2026-05-17T23:52:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"615c344e46d0ba282c8a02ee483b5d1dc409aba657cc3e857cbb4271ab29cb21","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-03-02T00:38:38Z","title_canon_sha256":"1468547bfd8b7b00d2d60a3d720055f7b615488df6790ba97264cccac72b6879"},"schema_version":"1.0","source":{"id":"1903.00585","kind":"arxiv","version":1}},"canonical_sha256":"14f13c9cce32a48b86fece8b8b1e6c3e195619b3c36e5729c0701be9da826dda","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"14f13c9cce32a48b86fece8b8b1e6c3e195619b3c36e5729c0701be9da826dda","first_computed_at":"2026-05-17T23:52:14.076405Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:52:14.076405Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"UFrrGE3G9V8sp+Paypj0kJ6YH3EpRHAsf7Fc+HfpTGjec1LpPip1z0Im8RXwtho+PpMnmrLophd0VONxS6nhDw==","signature_status":"signed_v1","signed_at":"2026-05-17T23:52:14.077199Z","signed_message":"canonical_sha256_bytes"},"source_id":"1903.00585","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:7864a1e47610ddaf7553a8ebb8a178422a279616e1dc43b7328982b4de95a4a7","sha256:a34b4f7ee678ccfb5c1ccf86fb387b5ca0db48e717a915b7205c7a7bab814ed7"],"state_sha256":"26d8146a03e6697872d4cc50682b956e46a101534a2907efd5e21def28722ae2"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"IFQuJB9hM26ADmhLNmRzlLkbzasJ32OOAPTJ3SSFJtd/TPoe8XdvzhEMmuh9zP6G+5Xi4hkXHfRpAFZtPKMTCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-10T05:00:22.863741Z","bundle_sha256":"a591347ecbc151ccc98a04415c5d334135fc00cf3635080803381f0ccc37be46"}}