{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:CWXLYL4MMLLI4WVDXDTQH6QSIN","short_pith_number":"pith:CWXLYL4M","canonical_record":{"source":{"id":"1805.12017","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-05-30T15:01:38Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"985d1f2cb69ec1a64aeaf275a63e5912784f4bc9abd7c2561995487c8ea348fd","abstract_canon_sha256":"4e4e2b0a43d9709bbdd282452f78df494c311fa612a9cff54a8f559c2d7b789b"},"schema_version":"1.0"},"canonical_sha256":"15aebc2f8c62d68e5aa3b8e703fa12436bfbdd473eccc59fda985516e5afc485","source":{"kind":"arxiv","id":"1805.12017","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1805.12017","created_at":"2026-05-17T23:44:04Z"},{"alias_kind":"arxiv_version","alias_value":"1805.12017v2","created_at":"2026-05-17T23:44:04Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1805.12017","created_at":"2026-05-17T23:44:04Z"},{"alias_kind":"pith_short_12","alias_value":"CWXLYL4MMLLI","created_at":"2026-05-18T12:32:19Z"},{"alias_kind":"pith_short_16","alias_value":"CWXLYL4MMLLI4WVD","created_at":"2026-05-18T12:32:19Z"},{"alias_kind":"pith_short_8","alias_value":"CWXLYL4M","created_at":"2026-05-18T12:32:19Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:CWXLYL4MMLLI4WVDXDTQH6QSIN","target":"record","payload":{"canonical_record":{"source":{"id":"1805.12017","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-05-30T15:01:38Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"985d1f2cb69ec1a64aeaf275a63e5912784f4bc9abd7c2561995487c8ea348fd","abstract_canon_sha256":"4e4e2b0a43d9709bbdd282452f78df494c311fa612a9cff54a8f559c2d7b789b"},"schema_version":"1.0"},"canonical_sha256":"15aebc2f8c62d68e5aa3b8e703fa12436bfbdd473eccc59fda985516e5afc485","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:44:04.678854Z","signature_b64":"nSedVmhtPphiS+lBh6885ne3aRbb+sLA6s0Vv2nGLj9fZ+JgHcNf03WHK4zBOXoiPMz0yJjhiq3TSCGuwv4sBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"15aebc2f8c62d68e5aa3b8e703fa12436bfbdd473eccc59fda985516e5afc485","last_reissued_at":"2026-05-17T23:44:04.678382Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:44:04.678382Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1805.12017","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:44:04Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ED+tEvuDQfeW4A160utS3kHV71W1sYTpEg9lR67Acj7bCZN1aWF1f96OyaB8WLw93/obFdEAAibWDkZ+o6YJAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-24T05:50:09.542827Z"},"content_sha256":"0c0a493227d5bfa16773c51bca563b6e5954deb8f1fff58fb354ba66307e3857","schema_version":"1.0","event_id":"sha256:0c0a493227d5bfa16773c51bca563b6e5954deb8f1fff58fb354ba66307e3857"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:CWXLYL4MMLLI4WVDXDTQH6QSIN","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Robustifying Models Against Adversarial Attacks by Langevin Dynamics","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Arturo Marban, Klaus-Robert M\\\"uller, Shinichi Nakajima, Vignesh Srinivasan, Wojciech Samek","submitted_at":"2018-05-30T15:01:38Z","abstract_excerpt":"Adversarial attacks on deep learning models have compromised their performance considerably. As remedies, a lot of defense methods were proposed, which however, have been circumvented by newer attacking strategies. In the midst of this ensuing arms race, the problem of robustness against adversarial attacks still remains unsolved. This paper proposes a novel, simple yet effective defense strategy where adversarial samples are relaxed onto the underlying manifold of the (unknown) target class distribution. Specifically, our algorithm drives off-manifold adversarial samples towards high density "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1805.12017","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:44:04Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"BtAK33gNKQt0OPbWRdwZh9TJB7esOL5kPy6ojo9XL4BS2qRcCsizNuJhjqZGzc/OtLGPHDm9Lv02thAgsydyCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-24T05:50:09.543482Z"},"content_sha256":"06f68fef1dffdb2f3ca51ce03ee185de2a8c66cdb6d359bd72b209916be230ca","schema_version":"1.0","event_id":"sha256:06f68fef1dffdb2f3ca51ce03ee185de2a8c66cdb6d359bd72b209916be230ca"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/CWXLYL4MMLLI4WVDXDTQH6QSIN/bundle.json","state_url":"https://pith.science/pith/CWXLYL4MMLLI4WVDXDTQH6QSIN/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/CWXLYL4MMLLI4WVDXDTQH6QSIN/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-24T05:50:09Z","links":{"resolver":"https://pith.science/pith/CWXLYL4MMLLI4WVDXDTQH6QSIN","bundle":"https://pith.science/pith/CWXLYL4MMLLI4WVDXDTQH6QSIN/bundle.json","state":"https://pith.science/pith/CWXLYL4MMLLI4WVDXDTQH6QSIN/state.json","well_known_bundle":"https://pith.science/.well-known/pith/CWXLYL4MMLLI4WVDXDTQH6QSIN/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:CWXLYL4MMLLI4WVDXDTQH6QSIN","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"4e4e2b0a43d9709bbdd282452f78df494c311fa612a9cff54a8f559c2d7b789b","cross_cats_sorted":["stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-05-30T15:01:38Z","title_canon_sha256":"985d1f2cb69ec1a64aeaf275a63e5912784f4bc9abd7c2561995487c8ea348fd"},"schema_version":"1.0","source":{"id":"1805.12017","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1805.12017","created_at":"2026-05-17T23:44:04Z"},{"alias_kind":"arxiv_version","alias_value":"1805.12017v2","created_at":"2026-05-17T23:44:04Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1805.12017","created_at":"2026-05-17T23:44:04Z"},{"alias_kind":"pith_short_12","alias_value":"CWXLYL4MMLLI","created_at":"2026-05-18T12:32:19Z"},{"alias_kind":"pith_short_16","alias_value":"CWXLYL4MMLLI4WVD","created_at":"2026-05-18T12:32:19Z"},{"alias_kind":"pith_short_8","alias_value":"CWXLYL4M","created_at":"2026-05-18T12:32:19Z"}],"graph_snapshots":[{"event_id":"sha256:06f68fef1dffdb2f3ca51ce03ee185de2a8c66cdb6d359bd72b209916be230ca","target":"graph","created_at":"2026-05-17T23:44:04Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Adversarial attacks on deep learning models have compromised their performance considerably. As remedies, a lot of defense methods were proposed, which however, have been circumvented by newer attacking strategies. In the midst of this ensuing arms race, the problem of robustness against adversarial attacks still remains unsolved. This paper proposes a novel, simple yet effective defense strategy where adversarial samples are relaxed onto the underlying manifold of the (unknown) target class distribution. Specifically, our algorithm drives off-manifold adversarial samples towards high density ","authors_text":"Arturo Marban, Klaus-Robert M\\\"uller, Shinichi Nakajima, Vignesh Srinivasan, Wojciech Samek","cross_cats":["stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-05-30T15:01:38Z","title":"Robustifying Models Against Adversarial Attacks by Langevin Dynamics"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1805.12017","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:0c0a493227d5bfa16773c51bca563b6e5954deb8f1fff58fb354ba66307e3857","target":"record","created_at":"2026-05-17T23:44:04Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"4e4e2b0a43d9709bbdd282452f78df494c311fa612a9cff54a8f559c2d7b789b","cross_cats_sorted":["stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-05-30T15:01:38Z","title_canon_sha256":"985d1f2cb69ec1a64aeaf275a63e5912784f4bc9abd7c2561995487c8ea348fd"},"schema_version":"1.0","source":{"id":"1805.12017","kind":"arxiv","version":2}},"canonical_sha256":"15aebc2f8c62d68e5aa3b8e703fa12436bfbdd473eccc59fda985516e5afc485","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"15aebc2f8c62d68e5aa3b8e703fa12436bfbdd473eccc59fda985516e5afc485","first_computed_at":"2026-05-17T23:44:04.678382Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:44:04.678382Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"nSedVmhtPphiS+lBh6885ne3aRbb+sLA6s0Vv2nGLj9fZ+JgHcNf03WHK4zBOXoiPMz0yJjhiq3TSCGuwv4sBw==","signature_status":"signed_v1","signed_at":"2026-05-17T23:44:04.678854Z","signed_message":"canonical_sha256_bytes"},"source_id":"1805.12017","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:0c0a493227d5bfa16773c51bca563b6e5954deb8f1fff58fb354ba66307e3857","sha256:06f68fef1dffdb2f3ca51ce03ee185de2a8c66cdb6d359bd72b209916be230ca"],"state_sha256":"e1f2dffd78e36aa9621ffa495e1b980181aef57efa89b7a1df179dc49229b37f"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"gqNAQ+gWBI9yD3pyRDYU/l4H/2EP34AnwNf94zhSqc7EzkfdxQveO0DBWRXE0QBdeBEHTA60p3pUl8bKncQcBg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-24T05:50:09.546979Z","bundle_sha256":"b229a3ce80c5fa5a8eeb576271b7207abe1ae718f4c71af013b3ddf91dc0bf5f"}}