{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:CUI3QGC2XQX2WKGSRFPB6NPRFZ","short_pith_number":"pith:CUI3QGC2","canonical_record":{"source":{"id":"1708.06199","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-21T13:06:23Z","cross_cats_sorted":[],"title_canon_sha256":"d47934a129bdd1e61d82bd8e77c2fb06ac2cb9e2cec62bd1a0a6b14716bb847f","abstract_canon_sha256":"eeb192c02499f9640845c91cca924d777b1569bc94bfe924ae4e6bdd126f6aaa"},"schema_version":"1.0"},"canonical_sha256":"1511b8185abc2fab28d2895e1f35f12e5c3771c11336e656d61e276971b686d9","source":{"kind":"arxiv","id":"1708.06199","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1708.06199","created_at":"2026-05-18T00:31:35Z"},{"alias_kind":"arxiv_version","alias_value":"1708.06199v2","created_at":"2026-05-18T00:31:35Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1708.06199","created_at":"2026-05-18T00:31:35Z"},{"alias_kind":"pith_short_12","alias_value":"CUI3QGC2XQX2","created_at":"2026-05-18T12:31:10Z"},{"alias_kind":"pith_short_16","alias_value":"CUI3QGC2XQX2WKGS","created_at":"2026-05-18T12:31:10Z"},{"alias_kind":"pith_short_8","alias_value":"CUI3QGC2","created_at":"2026-05-18T12:31:10Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:CUI3QGC2XQX2WKGSRFPB6NPRFZ","target":"record","payload":{"canonical_record":{"source":{"id":"1708.06199","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-21T13:06:23Z","cross_cats_sorted":[],"title_canon_sha256":"d47934a129bdd1e61d82bd8e77c2fb06ac2cb9e2cec62bd1a0a6b14716bb847f","abstract_canon_sha256":"eeb192c02499f9640845c91cca924d777b1569bc94bfe924ae4e6bdd126f6aaa"},"schema_version":"1.0"},"canonical_sha256":"1511b8185abc2fab28d2895e1f35f12e5c3771c11336e656d61e276971b686d9","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:31:35.678154Z","signature_b64":"DgHaxuJLNlPrZ+B9B3B3557EWGkRbzg+vu1ksDmcjH/HS5Wmj1PwG6aGPhko1CEH2ZhIpanv1f4BJydyicyzCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"1511b8185abc2fab28d2895e1f35f12e5c3771c11336e656d61e276971b686d9","last_reissued_at":"2026-05-18T00:31:35.677568Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:31:35.677568Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1708.06199","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:31:35Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ch8phgjGuC2ifGaARZUIWszdoldGOGvjtk60Fxy3fmWkK/Vfh+a47qw3dOqmAoIkC8uPjyDNJjOpoympoW7lBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-11T19:36:55.284407Z"},"content_sha256":"26b25968e22b2f2d1b85568705e832c0d34ff309365b207281db63af9606b593","schema_version":"1.0","event_id":"sha256:26b25968e22b2f2d1b85568705e832c0d34ff309365b207281db63af9606b593"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:CUI3QGC2XQX2WKGSRFPB6NPRFZ","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Algorithm Substitution Attacks from a Steganographic Perspective","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Maciej Liskiewicz, Sebastian Berndt","submitted_at":"2017-08-21T13:06:23Z","abstract_excerpt":"The goal of an algorithm substitution attack (ASA), also called a subversion attack (SA), is to replace an honest implementation of a cryptographic tool by a subverted one which allows to leak private information while generating output indistinguishable from the honest output. Bellare, Paterson, and Rogaway provided at CRYPTO'14 a formal security model to capture this kind of attacks and constructed practically implementable ASAs against a large class of symmetric encryption schemes. At CCS'15, Ateniese, Magri, and Venturi extended this model to allow the attackers to work in a fully-adaptive"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1708.06199","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:31:35Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"2FGmdMKbs8dY7ziUXiWcernk24F9Tl1OJHV+bikHxXVpiYCpIfSE+4B/xcalSEaBtetXeZc7A48uRGJVUZhWBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-11T19:36:55.285140Z"},"content_sha256":"a7ef71ff6da64a814eaa73f90a7a52e6fa3c0b3e0d3cc3b0290a59b6d2aa86a4","schema_version":"1.0","event_id":"sha256:a7ef71ff6da64a814eaa73f90a7a52e6fa3c0b3e0d3cc3b0290a59b6d2aa86a4"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/CUI3QGC2XQX2WKGSRFPB6NPRFZ/bundle.json","state_url":"https://pith.science/pith/CUI3QGC2XQX2WKGSRFPB6NPRFZ/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/CUI3QGC2XQX2WKGSRFPB6NPRFZ/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-11T19:36:55Z","links":{"resolver":"https://pith.science/pith/CUI3QGC2XQX2WKGSRFPB6NPRFZ","bundle":"https://pith.science/pith/CUI3QGC2XQX2WKGSRFPB6NPRFZ/bundle.json","state":"https://pith.science/pith/CUI3QGC2XQX2WKGSRFPB6NPRFZ/state.json","well_known_bundle":"https://pith.science/.well-known/pith/CUI3QGC2XQX2WKGSRFPB6NPRFZ/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:CUI3QGC2XQX2WKGSRFPB6NPRFZ","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"eeb192c02499f9640845c91cca924d777b1569bc94bfe924ae4e6bdd126f6aaa","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-21T13:06:23Z","title_canon_sha256":"d47934a129bdd1e61d82bd8e77c2fb06ac2cb9e2cec62bd1a0a6b14716bb847f"},"schema_version":"1.0","source":{"id":"1708.06199","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1708.06199","created_at":"2026-05-18T00:31:35Z"},{"alias_kind":"arxiv_version","alias_value":"1708.06199v2","created_at":"2026-05-18T00:31:35Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1708.06199","created_at":"2026-05-18T00:31:35Z"},{"alias_kind":"pith_short_12","alias_value":"CUI3QGC2XQX2","created_at":"2026-05-18T12:31:10Z"},{"alias_kind":"pith_short_16","alias_value":"CUI3QGC2XQX2WKGS","created_at":"2026-05-18T12:31:10Z"},{"alias_kind":"pith_short_8","alias_value":"CUI3QGC2","created_at":"2026-05-18T12:31:10Z"}],"graph_snapshots":[{"event_id":"sha256:a7ef71ff6da64a814eaa73f90a7a52e6fa3c0b3e0d3cc3b0290a59b6d2aa86a4","target":"graph","created_at":"2026-05-18T00:31:35Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"The goal of an algorithm substitution attack (ASA), also called a subversion attack (SA), is to replace an honest implementation of a cryptographic tool by a subverted one which allows to leak private information while generating output indistinguishable from the honest output. Bellare, Paterson, and Rogaway provided at CRYPTO'14 a formal security model to capture this kind of attacks and constructed practically implementable ASAs against a large class of symmetric encryption schemes. At CCS'15, Ateniese, Magri, and Venturi extended this model to allow the attackers to work in a fully-adaptive","authors_text":"Maciej Liskiewicz, Sebastian Berndt","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-21T13:06:23Z","title":"Algorithm Substitution Attacks from a Steganographic Perspective"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1708.06199","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:26b25968e22b2f2d1b85568705e832c0d34ff309365b207281db63af9606b593","target":"record","created_at":"2026-05-18T00:31:35Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"eeb192c02499f9640845c91cca924d777b1569bc94bfe924ae4e6bdd126f6aaa","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-21T13:06:23Z","title_canon_sha256":"d47934a129bdd1e61d82bd8e77c2fb06ac2cb9e2cec62bd1a0a6b14716bb847f"},"schema_version":"1.0","source":{"id":"1708.06199","kind":"arxiv","version":2}},"canonical_sha256":"1511b8185abc2fab28d2895e1f35f12e5c3771c11336e656d61e276971b686d9","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"1511b8185abc2fab28d2895e1f35f12e5c3771c11336e656d61e276971b686d9","first_computed_at":"2026-05-18T00:31:35.677568Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:31:35.677568Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"DgHaxuJLNlPrZ+B9B3B3557EWGkRbzg+vu1ksDmcjH/HS5Wmj1PwG6aGPhko1CEH2ZhIpanv1f4BJydyicyzCQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:31:35.678154Z","signed_message":"canonical_sha256_bytes"},"source_id":"1708.06199","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:26b25968e22b2f2d1b85568705e832c0d34ff309365b207281db63af9606b593","sha256:a7ef71ff6da64a814eaa73f90a7a52e6fa3c0b3e0d3cc3b0290a59b6d2aa86a4"],"state_sha256":"ba9b512eb616cf84c481f5d6984795a7982eb4594f31e28a965a22ffa7f97730"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"jRWu27nRRF2skoRJO0aNG84a7YywPBDTusq7UsnCkvPNQRU9UsnH4ebHvKF1B7HqJdxNLHgh5vXR2NrKFFcxBQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-11T19:36:55.289220Z","bundle_sha256":"87c69b3fdeb52b7daf2f1e700a8d4c31d50850f2379ea1f28d6ce9c519968afc"}}