{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:DCPJGY62NNYNLNFBYBYOLKSRZ6","short_pith_number":"pith:DCPJGY62","canonical_record":{"source":{"id":"1806.01471","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-06-05T02:55:56Z","cross_cats_sorted":["cs.CR","cs.LG"],"title_canon_sha256":"b949fd7c6879bc169806d36795f2c184a5c4e682752f515bdee9f25f1c23ed41","abstract_canon_sha256":"211ef69777e44fd8e4e3486a0bd9f1d71cc43bac80331759dfb61497c2e5e836"},"schema_version":"1.0"},"canonical_sha256":"189e9363da6b70d5b4a1c070e5aa51cf99e8ee2a456e9c02c0c72bade38f263a","source":{"kind":"arxiv","id":"1806.01471","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1806.01471","created_at":"2026-05-18T00:14:03Z"},{"alias_kind":"arxiv_version","alias_value":"1806.01471v2","created_at":"2026-05-18T00:14:03Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1806.01471","created_at":"2026-05-18T00:14:03Z"},{"alias_kind":"pith_short_12","alias_value":"DCPJGY62NNYN","created_at":"2026-05-18T12:32:19Z"},{"alias_kind":"pith_short_16","alias_value":"DCPJGY62NNYNLNFB","created_at":"2026-05-18T12:32:19Z"},{"alias_kind":"pith_short_8","alias_value":"DCPJGY62","created_at":"2026-05-18T12:32:19Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:DCPJGY62NNYNLNFBYBYOLKSRZ6","target":"record","payload":{"canonical_record":{"source":{"id":"1806.01471","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-06-05T02:55:56Z","cross_cats_sorted":["cs.CR","cs.LG"],"title_canon_sha256":"b949fd7c6879bc169806d36795f2c184a5c4e682752f515bdee9f25f1c23ed41","abstract_canon_sha256":"211ef69777e44fd8e4e3486a0bd9f1d71cc43bac80331759dfb61497c2e5e836"},"schema_version":"1.0"},"canonical_sha256":"189e9363da6b70d5b4a1c070e5aa51cf99e8ee2a456e9c02c0c72bade38f263a","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:14:03.639521Z","signature_b64":"JQao3vsxIqQyibUO5AOXJbZP/sdzzFOwIwyhumb3GpMTKUaWZw/9l2afuOYqLS+BIha6yb9lBUgFxkhV86wUDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"189e9363da6b70d5b4a1c070e5aa51cf99e8ee2a456e9c02c0c72bade38f263a","last_reissued_at":"2026-05-18T00:14:03.638801Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:14:03.638801Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1806.01471","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:14:03Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"xPTUq/slpaHWUEB+y1VfR/hqSqA7JfyfUdkRY13DmEV/mQIHG5Q9y2EaBlspV/skV7XOto8rXvBRhJGZef/8AQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T06:16:29.155082Z"},"content_sha256":"3429bc49849b582898390d2038765dec02fb63f56f355a371768ba0891540ef5","schema_version":"1.0","event_id":"sha256:3429bc49849b582898390d2038765dec02fb63f56f355a371768ba0891540ef5"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:DCPJGY62NNYNLNFBYBYOLKSRZ6","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"PAC-learning in the presence of evasion adversaries","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.LG"],"primary_cat":"stat.ML","authors_text":"Arjun Nitin Bhagoji, Daniel Cullina, Prateek Mittal","submitted_at":"2018-06-05T02:55:56Z","abstract_excerpt":"The existence of evasion attacks during the test phase of machine learning algorithms represents a significant challenge to both their deployment and understanding. These attacks can be carried out by adding imperceptible perturbations to inputs to generate adversarial examples and finding effective defenses and detectors has proven to be difficult. In this paper, we step away from the attack-defense arms race and seek to understand the limits of what can be learned in the presence of an evasion adversary. In particular, we extend the Probably Approximately Correct (PAC)-learning framework to "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1806.01471","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:14:03Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"yK6XqXUcvyM15W7HlWCSe4K56FXQlE3QvzygtTLWw1paIcSmOiClTRJLQR+NBBMGZmyRbT64LX/NZTLCeiIvBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T06:16:29.155824Z"},"content_sha256":"91cd76e7c0ea8e2f8590b1e6d7cb152cbd4a1378705c027f0d2d5fa3d01d9ed4","schema_version":"1.0","event_id":"sha256:91cd76e7c0ea8e2f8590b1e6d7cb152cbd4a1378705c027f0d2d5fa3d01d9ed4"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/DCPJGY62NNYNLNFBYBYOLKSRZ6/bundle.json","state_url":"https://pith.science/pith/DCPJGY62NNYNLNFBYBYOLKSRZ6/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/DCPJGY62NNYNLNFBYBYOLKSRZ6/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T06:16:29Z","links":{"resolver":"https://pith.science/pith/DCPJGY62NNYNLNFBYBYOLKSRZ6","bundle":"https://pith.science/pith/DCPJGY62NNYNLNFBYBYOLKSRZ6/bundle.json","state":"https://pith.science/pith/DCPJGY62NNYNLNFBYBYOLKSRZ6/state.json","well_known_bundle":"https://pith.science/.well-known/pith/DCPJGY62NNYNLNFBYBYOLKSRZ6/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:DCPJGY62NNYNLNFBYBYOLKSRZ6","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"211ef69777e44fd8e4e3486a0bd9f1d71cc43bac80331759dfb61497c2e5e836","cross_cats_sorted":["cs.CR","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-06-05T02:55:56Z","title_canon_sha256":"b949fd7c6879bc169806d36795f2c184a5c4e682752f515bdee9f25f1c23ed41"},"schema_version":"1.0","source":{"id":"1806.01471","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1806.01471","created_at":"2026-05-18T00:14:03Z"},{"alias_kind":"arxiv_version","alias_value":"1806.01471v2","created_at":"2026-05-18T00:14:03Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1806.01471","created_at":"2026-05-18T00:14:03Z"},{"alias_kind":"pith_short_12","alias_value":"DCPJGY62NNYN","created_at":"2026-05-18T12:32:19Z"},{"alias_kind":"pith_short_16","alias_value":"DCPJGY62NNYNLNFB","created_at":"2026-05-18T12:32:19Z"},{"alias_kind":"pith_short_8","alias_value":"DCPJGY62","created_at":"2026-05-18T12:32:19Z"}],"graph_snapshots":[{"event_id":"sha256:91cd76e7c0ea8e2f8590b1e6d7cb152cbd4a1378705c027f0d2d5fa3d01d9ed4","target":"graph","created_at":"2026-05-18T00:14:03Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"The existence of evasion attacks during the test phase of machine learning algorithms represents a significant challenge to both their deployment and understanding. These attacks can be carried out by adding imperceptible perturbations to inputs to generate adversarial examples and finding effective defenses and detectors has proven to be difficult. In this paper, we step away from the attack-defense arms race and seek to understand the limits of what can be learned in the presence of an evasion adversary. In particular, we extend the Probably Approximately Correct (PAC)-learning framework to ","authors_text":"Arjun Nitin Bhagoji, Daniel Cullina, Prateek Mittal","cross_cats":["cs.CR","cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-06-05T02:55:56Z","title":"PAC-learning in the presence of evasion adversaries"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1806.01471","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:3429bc49849b582898390d2038765dec02fb63f56f355a371768ba0891540ef5","target":"record","created_at":"2026-05-18T00:14:03Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"211ef69777e44fd8e4e3486a0bd9f1d71cc43bac80331759dfb61497c2e5e836","cross_cats_sorted":["cs.CR","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-06-05T02:55:56Z","title_canon_sha256":"b949fd7c6879bc169806d36795f2c184a5c4e682752f515bdee9f25f1c23ed41"},"schema_version":"1.0","source":{"id":"1806.01471","kind":"arxiv","version":2}},"canonical_sha256":"189e9363da6b70d5b4a1c070e5aa51cf99e8ee2a456e9c02c0c72bade38f263a","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"189e9363da6b70d5b4a1c070e5aa51cf99e8ee2a456e9c02c0c72bade38f263a","first_computed_at":"2026-05-18T00:14:03.638801Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:14:03.638801Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"JQao3vsxIqQyibUO5AOXJbZP/sdzzFOwIwyhumb3GpMTKUaWZw/9l2afuOYqLS+BIha6yb9lBUgFxkhV86wUDw==","signature_status":"signed_v1","signed_at":"2026-05-18T00:14:03.639521Z","signed_message":"canonical_sha256_bytes"},"source_id":"1806.01471","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:3429bc49849b582898390d2038765dec02fb63f56f355a371768ba0891540ef5","sha256:91cd76e7c0ea8e2f8590b1e6d7cb152cbd4a1378705c027f0d2d5fa3d01d9ed4"],"state_sha256":"2f777505ebd4b6f59240b3803da73ff1a37aee805070997d2b9726b983e81e3c"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Nr+3Powe0Oh+uqbEgDwjV7Zptqz1S7iuqwfrhDCW4FYONSDWQ2KSvzr+TIAfqnHmis6M8J2hDFJ7a2MTEBywCg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T06:16:29.159518Z","bundle_sha256":"a25fbb2232184633cac3b23599d94d5f3fc045c13a64d5d72f552cd63a6ceb9d"}}