{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:DFRLGIHBW3HHQURHCV4C4RHUKR","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"59b7c4916637fd2bfc29d3ebdfdd9af9d578072891867ce63dee18083dbbd026","cross_cats_sorted":["cs.CV","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-12-21T06:17:43Z","title_canon_sha256":"ef46d0b0a800a3fd3d394bee3376856ad4b90991fde4c4154f2e496503bd5d48"},"schema_version":"1.0","source":{"id":"1712.07805","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1712.07805","created_at":"2026-05-18T00:27:29Z"},{"alias_kind":"arxiv_version","alias_value":"1712.07805v1","created_at":"2026-05-18T00:27:29Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1712.07805","created_at":"2026-05-18T00:27:29Z"},{"alias_kind":"pith_short_12","alias_value":"DFRLGIHBW3HH","created_at":"2026-05-18T12:31:10Z"},{"alias_kind":"pith_short_16","alias_value":"DFRLGIHBW3HHQURH","created_at":"2026-05-18T12:31:10Z"},{"alias_kind":"pith_short_8","alias_value":"DFRLGIHB","created_at":"2026-05-18T12:31:10Z"}],"graph_snapshots":[{"event_id":"sha256:13d22c271b83b498f118d3ec9a25e122bd1c7ed9bdb267ca657237d1fa0a1026","target":"graph","created_at":"2026-05-18T00:27:29Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"This paper considers security risks buried in the data processing pipeline in common deep learning applications. Deep learning models usually assume a fixed scale for their training and input data. To allow deep learning applications to handle a wide range of input data, popular frameworks, such as Caffe, TensorFlow, and Torch, all provide data scaling functions to resize input to the dimensions used by deep learning models. Image scaling algorithms are intended to preserve the visual features of an image after scaling. However, common image scaling algorithms are not designed to handle human ","authors_text":"Deyue Zhang, Kang Li, Qixue Xiao, Yier Jin","cross_cats":["cs.CV","cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-12-21T06:17:43Z","title":"Wolf in Sheep's Clothing - The Downscaling Attack Against Deep Learning Applications"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1712.07805","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:fa31abe23b4862edb4e618d4d9d15a0193e41ce3569c73d84fbb60a5aaa7108b","target":"record","created_at":"2026-05-18T00:27:29Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"59b7c4916637fd2bfc29d3ebdfdd9af9d578072891867ce63dee18083dbbd026","cross_cats_sorted":["cs.CV","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-12-21T06:17:43Z","title_canon_sha256":"ef46d0b0a800a3fd3d394bee3376856ad4b90991fde4c4154f2e496503bd5d48"},"schema_version":"1.0","source":{"id":"1712.07805","kind":"arxiv","version":1}},"canonical_sha256":"1962b320e1b6ce78522715782e44f45479fcba9ae949794ccd288379a4b6b689","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"1962b320e1b6ce78522715782e44f45479fcba9ae949794ccd288379a4b6b689","first_computed_at":"2026-05-18T00:27:29.759575Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:27:29.759575Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"mjkDMay79N40vk4dvOBFEZeIaYqcwupJLC7OHTAk7zPgf7RyqDcfC6cDtyZNRZcYIQUCSVa1KQrvw7CrO+w9BQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:27:29.760347Z","signed_message":"canonical_sha256_bytes"},"source_id":"1712.07805","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:fa31abe23b4862edb4e618d4d9d15a0193e41ce3569c73d84fbb60a5aaa7108b","sha256:13d22c271b83b498f118d3ec9a25e122bd1c7ed9bdb267ca657237d1fa0a1026"],"state_sha256":"90941f64bd1cff1d209a7f3ad108c454745a758e53be320f9f4f8e4fb28bb608"}