{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2021:DA2W27BX7PKMHLXRHJBMDW5ZMM","short_pith_number":"pith:DA2W27BX","canonical_record":{"source":{"id":"2112.08304","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2021-12-15T17:54:08Z","cross_cats_sorted":[],"title_canon_sha256":"99dc7cb53f9a1a3945c56bb4cda94ebeac70358edd5b51043e754e2fe25e13df","abstract_canon_sha256":"9f6b9ecbb0398d8a1a1ecfc8008c55374a28afd61c9735ed9db988ae1296f189"},"schema_version":"1.0"},"canonical_sha256":"18356d7c37fbd4c3aef13a42c1dbb96312417299376be2f9d40f7c5723d6bc9d","source":{"kind":"arxiv","id":"2112.08304","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2112.08304","created_at":"2026-07-05T04:17:03Z"},{"alias_kind":"arxiv_version","alias_value":"2112.08304v2","created_at":"2026-07-05T04:17:03Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2112.08304","created_at":"2026-07-05T04:17:03Z"},{"alias_kind":"pith_short_12","alias_value":"DA2W27BX7PKM","created_at":"2026-07-05T04:17:03Z"},{"alias_kind":"pith_short_16","alias_value":"DA2W27BX7PKMHLXR","created_at":"2026-07-05T04:17:03Z"},{"alias_kind":"pith_short_8","alias_value":"DA2W27BX","created_at":"2026-07-05T04:17:03Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2021:DA2W27BX7PKMHLXRHJBMDW5ZMM","target":"record","payload":{"canonical_record":{"source":{"id":"2112.08304","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2021-12-15T17:54:08Z","cross_cats_sorted":[],"title_canon_sha256":"99dc7cb53f9a1a3945c56bb4cda94ebeac70358edd5b51043e754e2fe25e13df","abstract_canon_sha256":"9f6b9ecbb0398d8a1a1ecfc8008c55374a28afd61c9735ed9db988ae1296f189"},"schema_version":"1.0"},"canonical_sha256":"18356d7c37fbd4c3aef13a42c1dbb96312417299376be2f9d40f7c5723d6bc9d","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T04:17:03.803525Z","signature_b64":"R6CQ+t834+fOyH3ORVyoiHueEUDQO7q28I9lekeVZiTJJPKWwQv0zHMHcNh3S9VKXTiSG8IUIa11v38P8swRDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"18356d7c37fbd4c3aef13a42c1dbb96312417299376be2f9d40f7c5723d6bc9d","last_reissued_at":"2026-07-05T04:17:03.803051Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T04:17:03.803051Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2112.08304","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T04:17:03Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"JjIz+mq4dYFPinCvtGUIJ2sxBgFc7uuaxxdJe7SRmzb3bYWCJ9IEgwlieQVNHBQFxrRogzydnWowz2eHy28yDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-09T06:36:12.338343Z"},"content_sha256":"075e5974ac7ca71f4d37582b160fd44b761eacb0625a65c35570756f9c583abc","schema_version":"1.0","event_id":"sha256:075e5974ac7ca71f4d37582b160fd44b761eacb0625a65c35570756f9c583abc"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2021:DA2W27BX7PKMHLXRHJBMDW5ZMM","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"On the Convergence and Robustness of Adversarial Training","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Bowen Zhou, James Bailey, Jinfeng Yi, Quanquan Gu, Xingjun Ma, Yisen Wang","submitted_at":"2021-12-15T17:54:08Z","abstract_excerpt":"Improving the robustness of deep neural networks (DNNs) to adversarial examples is an important yet challenging problem for secure deep learning. Across existing defense techniques, adversarial training with Projected Gradient Decent (PGD) is amongst the most effective. Adversarial training solves a min-max optimization problem, with the \\textit{inner maximization} generating adversarial examples by maximizing the classification loss, and the \\textit{outer minimization} finding model parameters by minimizing the loss on adversarial examples generated from the inner maximization. A criterion th"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2112.08304","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2112.08304/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T04:17:03Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"FcVOjknHpiGkP97bnQj4Z31x9L2OccYU7L+lIN3U6SXn4P/DM6d/SZhJTCRN9lzylJM7P0uOPPSZdW30TxjSBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-09T06:36:12.338852Z"},"content_sha256":"1f256af0897ce84ea13b58b76e77a858d411ab566f0517f62dc8dfb93096e001","schema_version":"1.0","event_id":"sha256:1f256af0897ce84ea13b58b76e77a858d411ab566f0517f62dc8dfb93096e001"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/DA2W27BX7PKMHLXRHJBMDW5ZMM/bundle.json","state_url":"https://pith.science/pith/DA2W27BX7PKMHLXRHJBMDW5ZMM/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/DA2W27BX7PKMHLXRHJBMDW5ZMM/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-09T06:36:12Z","links":{"resolver":"https://pith.science/pith/DA2W27BX7PKMHLXRHJBMDW5ZMM","bundle":"https://pith.science/pith/DA2W27BX7PKMHLXRHJBMDW5ZMM/bundle.json","state":"https://pith.science/pith/DA2W27BX7PKMHLXRHJBMDW5ZMM/state.json","well_known_bundle":"https://pith.science/.well-known/pith/DA2W27BX7PKMHLXRHJBMDW5ZMM/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2021:DA2W27BX7PKMHLXRHJBMDW5ZMM","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"9f6b9ecbb0398d8a1a1ecfc8008c55374a28afd61c9735ed9db988ae1296f189","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2021-12-15T17:54:08Z","title_canon_sha256":"99dc7cb53f9a1a3945c56bb4cda94ebeac70358edd5b51043e754e2fe25e13df"},"schema_version":"1.0","source":{"id":"2112.08304","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2112.08304","created_at":"2026-07-05T04:17:03Z"},{"alias_kind":"arxiv_version","alias_value":"2112.08304v2","created_at":"2026-07-05T04:17:03Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2112.08304","created_at":"2026-07-05T04:17:03Z"},{"alias_kind":"pith_short_12","alias_value":"DA2W27BX7PKM","created_at":"2026-07-05T04:17:03Z"},{"alias_kind":"pith_short_16","alias_value":"DA2W27BX7PKMHLXR","created_at":"2026-07-05T04:17:03Z"},{"alias_kind":"pith_short_8","alias_value":"DA2W27BX","created_at":"2026-07-05T04:17:03Z"}],"graph_snapshots":[{"event_id":"sha256:1f256af0897ce84ea13b58b76e77a858d411ab566f0517f62dc8dfb93096e001","target":"graph","created_at":"2026-07-05T04:17:03Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2112.08304/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Improving the robustness of deep neural networks (DNNs) to adversarial examples is an important yet challenging problem for secure deep learning. Across existing defense techniques, adversarial training with Projected Gradient Decent (PGD) is amongst the most effective. Adversarial training solves a min-max optimization problem, with the \\textit{inner maximization} generating adversarial examples by maximizing the classification loss, and the \\textit{outer minimization} finding model parameters by minimizing the loss on adversarial examples generated from the inner maximization. A criterion th","authors_text":"Bowen Zhou, James Bailey, Jinfeng Yi, Quanquan Gu, Xingjun Ma, Yisen Wang","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2021-12-15T17:54:08Z","title":"On the Convergence and Robustness of Adversarial Training"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2112.08304","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:075e5974ac7ca71f4d37582b160fd44b761eacb0625a65c35570756f9c583abc","target":"record","created_at":"2026-07-05T04:17:03Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"9f6b9ecbb0398d8a1a1ecfc8008c55374a28afd61c9735ed9db988ae1296f189","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2021-12-15T17:54:08Z","title_canon_sha256":"99dc7cb53f9a1a3945c56bb4cda94ebeac70358edd5b51043e754e2fe25e13df"},"schema_version":"1.0","source":{"id":"2112.08304","kind":"arxiv","version":2}},"canonical_sha256":"18356d7c37fbd4c3aef13a42c1dbb96312417299376be2f9d40f7c5723d6bc9d","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"18356d7c37fbd4c3aef13a42c1dbb96312417299376be2f9d40f7c5723d6bc9d","first_computed_at":"2026-07-05T04:17:03.803051Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T04:17:03.803051Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"R6CQ+t834+fOyH3ORVyoiHueEUDQO7q28I9lekeVZiTJJPKWwQv0zHMHcNh3S9VKXTiSG8IUIa11v38P8swRDw==","signature_status":"signed_v1","signed_at":"2026-07-05T04:17:03.803525Z","signed_message":"canonical_sha256_bytes"},"source_id":"2112.08304","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:075e5974ac7ca71f4d37582b160fd44b761eacb0625a65c35570756f9c583abc","sha256:1f256af0897ce84ea13b58b76e77a858d411ab566f0517f62dc8dfb93096e001"],"state_sha256":"41450d8c421ff16e0d8200ec48db6f1f5148ac3a437194a5bc4f160638b8e9e2"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"4zs5xGcCSt17Jc+NhQYXFihH7MlO8Vok3x17wePxSeTeulFBLwWZwcMieuSFebc+Wnccy+ZDlXg+3vKkl2KJCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-09T06:36:12.344574Z","bundle_sha256":"bfe2d333a330996c539f6c7141ff10cd8d6d6deb089aac3c8dd83a3d839f2708"}}