{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:CUBNWXDYEG7VCVWWESHXKTNIBE","short_pith_number":"pith:CUBNWXDY","canonical_record":{"source":{"id":"1809.02918","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-09-09T03:49:06Z","cross_cats_sorted":["cs.CR","cs.CV","cs.LG"],"title_canon_sha256":"eb99749733aec843074b7f1a9e5bd31fd9f232f188872bb5f1d46e05d8c42206","abstract_canon_sha256":"9cf1b2b0d7b68614910df7e2ae04ff97839aa466a3e54effdca592881cd6adb5"},"schema_version":"1.0"},"canonical_sha256":"1502db5c7821bf5156d6248f754da809334bb3a9def304773955d40837d41668","source":{"kind":"arxiv","id":"1809.02918","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1809.02918","created_at":"2026-05-18T00:06:10Z"},{"alias_kind":"arxiv_version","alias_value":"1809.02918v1","created_at":"2026-05-18T00:06:10Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1809.02918","created_at":"2026-05-18T00:06:10Z"},{"alias_kind":"pith_short_12","alias_value":"CUBNWXDYEG7V","created_at":"2026-05-18T12:32:19Z"},{"alias_kind":"pith_short_16","alias_value":"CUBNWXDYEG7VCVWW","created_at":"2026-05-18T12:32:19Z"},{"alias_kind":"pith_short_8","alias_value":"CUBNWXDY","created_at":"2026-05-18T12:32:19Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:CUBNWXDYEG7VCVWWESHXKTNIBE","target":"record","payload":{"canonical_record":{"source":{"id":"1809.02918","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-09-09T03:49:06Z","cross_cats_sorted":["cs.CR","cs.CV","cs.LG"],"title_canon_sha256":"eb99749733aec843074b7f1a9e5bd31fd9f232f188872bb5f1d46e05d8c42206","abstract_canon_sha256":"9cf1b2b0d7b68614910df7e2ae04ff97839aa466a3e54effdca592881cd6adb5"},"schema_version":"1.0"},"canonical_sha256":"1502db5c7821bf5156d6248f754da809334bb3a9def304773955d40837d41668","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:06:10.645632Z","signature_b64":"urcfiyviuy1cw6uUGyX+N6VB0H3LnBTuUFH6dvUxmnYfPQ7kQRlCpzFr86tCFZm8t4rLLZOzkvfpW9hthR2qBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"1502db5c7821bf5156d6248f754da809334bb3a9def304773955d40837d41668","last_reissued_at":"2026-05-18T00:06:10.644769Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:06:10.644769Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1809.02918","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:06:10Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"p/eCduoy5b6sSikOis8MsBGYEjzQNudJNgaHHSdy7gQ+6pIGBi7yWSBKi5ulxyEatq5uDhvc1p5nealv9oMQCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T03:26:39.352299Z"},"content_sha256":"bf3f9014d96770425c3b19c2e0b91020fbac5b99bf687eff4c819c85b9267489","schema_version":"1.0","event_id":"sha256:bf3f9014d96770425c3b19c2e0b91020fbac5b99bf687eff4c819c85b9267489"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:CUBNWXDYEG7VCVWWESHXKTNIBE","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Towards Query Efficient Black-box Attacks: An Input-free Perspective","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","cs.LG"],"primary_cat":"stat.ML","authors_text":"Dacheng Tao, Jinfeng Yi, Jun Cheng, Meng Fang, Yali Du","submitted_at":"2018-09-09T03:49:06Z","abstract_excerpt":"Recent studies have highlighted that deep neural networks (DNNs) are vulnerable to adversarial attacks, even in a black-box scenario. However, most of the existing black-box attack algorithms need to make a huge amount of queries to perform attacks, which is not practical in the real world. We note one of the main reasons for the massive queries is that the adversarial example is required to be visually similar to the original image, but in many cases, how adversarial examples look like does not matter much. It inspires us to introduce a new attack called \\emph{input-free} attack, under which "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1809.02918","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:06:10Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"yvdAnTkicbykdAnFowfyvK+I5yPOKTRYYaD8fA3fuMhQHklKPB3G7i69F3yeXj8RFrcKlQCiaqr1mO0hRe9tAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T03:26:39.352680Z"},"content_sha256":"f0023d12d56b5666450234d7918f88fe5b0205013fce3bbd8133cd5e5db05a05","schema_version":"1.0","event_id":"sha256:f0023d12d56b5666450234d7918f88fe5b0205013fce3bbd8133cd5e5db05a05"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/CUBNWXDYEG7VCVWWESHXKTNIBE/bundle.json","state_url":"https://pith.science/pith/CUBNWXDYEG7VCVWWESHXKTNIBE/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/CUBNWXDYEG7VCVWWESHXKTNIBE/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-01T03:26:39Z","links":{"resolver":"https://pith.science/pith/CUBNWXDYEG7VCVWWESHXKTNIBE","bundle":"https://pith.science/pith/CUBNWXDYEG7VCVWWESHXKTNIBE/bundle.json","state":"https://pith.science/pith/CUBNWXDYEG7VCVWWESHXKTNIBE/state.json","well_known_bundle":"https://pith.science/.well-known/pith/CUBNWXDYEG7VCVWWESHXKTNIBE/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:CUBNWXDYEG7VCVWWESHXKTNIBE","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"9cf1b2b0d7b68614910df7e2ae04ff97839aa466a3e54effdca592881cd6adb5","cross_cats_sorted":["cs.CR","cs.CV","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-09-09T03:49:06Z","title_canon_sha256":"eb99749733aec843074b7f1a9e5bd31fd9f232f188872bb5f1d46e05d8c42206"},"schema_version":"1.0","source":{"id":"1809.02918","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1809.02918","created_at":"2026-05-18T00:06:10Z"},{"alias_kind":"arxiv_version","alias_value":"1809.02918v1","created_at":"2026-05-18T00:06:10Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1809.02918","created_at":"2026-05-18T00:06:10Z"},{"alias_kind":"pith_short_12","alias_value":"CUBNWXDYEG7V","created_at":"2026-05-18T12:32:19Z"},{"alias_kind":"pith_short_16","alias_value":"CUBNWXDYEG7VCVWW","created_at":"2026-05-18T12:32:19Z"},{"alias_kind":"pith_short_8","alias_value":"CUBNWXDY","created_at":"2026-05-18T12:32:19Z"}],"graph_snapshots":[{"event_id":"sha256:f0023d12d56b5666450234d7918f88fe5b0205013fce3bbd8133cd5e5db05a05","target":"graph","created_at":"2026-05-18T00:06:10Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Recent studies have highlighted that deep neural networks (DNNs) are vulnerable to adversarial attacks, even in a black-box scenario. However, most of the existing black-box attack algorithms need to make a huge amount of queries to perform attacks, which is not practical in the real world. We note one of the main reasons for the massive queries is that the adversarial example is required to be visually similar to the original image, but in many cases, how adversarial examples look like does not matter much. It inspires us to introduce a new attack called \\emph{input-free} attack, under which ","authors_text":"Dacheng Tao, Jinfeng Yi, Jun Cheng, Meng Fang, Yali Du","cross_cats":["cs.CR","cs.CV","cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-09-09T03:49:06Z","title":"Towards Query Efficient Black-box Attacks: An Input-free Perspective"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1809.02918","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:bf3f9014d96770425c3b19c2e0b91020fbac5b99bf687eff4c819c85b9267489","target":"record","created_at":"2026-05-18T00:06:10Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"9cf1b2b0d7b68614910df7e2ae04ff97839aa466a3e54effdca592881cd6adb5","cross_cats_sorted":["cs.CR","cs.CV","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-09-09T03:49:06Z","title_canon_sha256":"eb99749733aec843074b7f1a9e5bd31fd9f232f188872bb5f1d46e05d8c42206"},"schema_version":"1.0","source":{"id":"1809.02918","kind":"arxiv","version":1}},"canonical_sha256":"1502db5c7821bf5156d6248f754da809334bb3a9def304773955d40837d41668","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"1502db5c7821bf5156d6248f754da809334bb3a9def304773955d40837d41668","first_computed_at":"2026-05-18T00:06:10.644769Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:06:10.644769Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"urcfiyviuy1cw6uUGyX+N6VB0H3LnBTuUFH6dvUxmnYfPQ7kQRlCpzFr86tCFZm8t4rLLZOzkvfpW9hthR2qBw==","signature_status":"signed_v1","signed_at":"2026-05-18T00:06:10.645632Z","signed_message":"canonical_sha256_bytes"},"source_id":"1809.02918","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:bf3f9014d96770425c3b19c2e0b91020fbac5b99bf687eff4c819c85b9267489","sha256:f0023d12d56b5666450234d7918f88fe5b0205013fce3bbd8133cd5e5db05a05"],"state_sha256":"7673917f2296d557fbbb4d1c5938ef832ea1a31eab726a3b6d8bbd9417032480"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"BKqSyJPiGITDFyNCgc30mbPbtvAEMsZfLC1xjTFme2uq6jBN637JVxqLy9QlRpjXSJtqP+SANn/4Fogu8ULWCQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-01T03:26:39.355033Z","bundle_sha256":"75ae97c3875dec265a567333fcbbceac458be65a101b8a7d2edeab330e50d0c8"}}