{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:DFUZHVCEHPRIJM5T7RW7INAEWZ","short_pith_number":"pith:DFUZHVCE","canonical_record":{"source":{"id":"1906.07077","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-06-17T15:06:47Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"164406d9ef79a8f6597677a14415b0f7bc58ad94e84370bac7d48af4d38151c4","abstract_canon_sha256":"3d5dc77e9580876d423b8f1909327fb9a7e138c228971867071b0ea11ca6673d"},"schema_version":"1.0"},"canonical_sha256":"196993d4443be284b3b3fc6df43404b648412bd3b3b839c0eb0daefdfac37627","source":{"kind":"arxiv","id":"1906.07077","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1906.07077","created_at":"2026-05-17T23:43:11Z"},{"alias_kind":"arxiv_version","alias_value":"1906.07077v1","created_at":"2026-05-17T23:43:11Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1906.07077","created_at":"2026-05-17T23:43:11Z"},{"alias_kind":"pith_short_12","alias_value":"DFUZHVCEHPRI","created_at":"2026-05-18T12:33:15Z"},{"alias_kind":"pith_short_16","alias_value":"DFUZHVCEHPRIJM5T","created_at":"2026-05-18T12:33:15Z"},{"alias_kind":"pith_short_8","alias_value":"DFUZHVCE","created_at":"2026-05-18T12:33:15Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:DFUZHVCEHPRIJM5T7RW7INAEWZ","target":"record","payload":{"canonical_record":{"source":{"id":"1906.07077","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-06-17T15:06:47Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"164406d9ef79a8f6597677a14415b0f7bc58ad94e84370bac7d48af4d38151c4","abstract_canon_sha256":"3d5dc77e9580876d423b8f1909327fb9a7e138c228971867071b0ea11ca6673d"},"schema_version":"1.0"},"canonical_sha256":"196993d4443be284b3b3fc6df43404b648412bd3b3b839c0eb0daefdfac37627","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:43:11.968464Z","signature_b64":"czf9Au26OxjHGt91tP72B2gRhhFm1xDv507agbrtD+Q8hD+Vz/Og1pH2zaZTJKQY+RtfyikcG/xxLBQ2YhLIDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"196993d4443be284b3b3fc6df43404b648412bd3b3b839c0eb0daefdfac37627","last_reissued_at":"2026-05-17T23:43:11.967793Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:43:11.967793Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1906.07077","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:43:11Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"kQQDNbu/jk7pxQIneFZOs3akDOK6kiYof2MhpxnvufcvfWOeRbW0hAXi/t9ev8MfoZYV6EMKyoWdcClVOx8zAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-23T15:20:40.272807Z"},"content_sha256":"7fab57ec8d741dd3321a049279c9eeb8209946561cb5f32c8947a7d8c73a06bd","schema_version":"1.0","event_id":"sha256:7fab57ec8d741dd3321a049279c9eeb8209946561cb5f32c8947a7d8c73a06bd"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:DFUZHVCEHPRIJM5T7RW7INAEWZ","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"The Attack Generator: A Systematic Approach Towards Constructing Adversarial Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Fabian H\\\"uger, Felix Assion, Florens Gre{\\ss}ner, Nico Schmidt, Peter Schlicht, Umair Rasheed, Wiebke G\\\"unther","submitted_at":"2019-06-17T15:06:47Z","abstract_excerpt":"Most state-of-the-art machine learning (ML) classification systems are vulnerable to adversarial perturbations. As a consequence, adversarial robustness poses a significant challenge for the deployment of ML-based systems in safety- and security-critical environments like autonomous driving, disease detection or unmanned aerial vehicles. In the past years we have seen an impressive amount of publications presenting more and more new adversarial attacks. However, the attack research seems to be rather unstructured and new attacks often appear to be random selections from the unlimited set of po"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1906.07077","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:43:11Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"nILNzzdK7gUpZOhNTd8iNNGTN7I3lNulXO4j5FMuqarx7aO2SyYJslU2h0D+zDBxKDD3u8P6m6A0GafPq0quDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-23T15:20:40.273181Z"},"content_sha256":"9eb43b8f7c57f731e1fdeecc2e5f6922795e86457751b1a5200b8d4903619afc","schema_version":"1.0","event_id":"sha256:9eb43b8f7c57f731e1fdeecc2e5f6922795e86457751b1a5200b8d4903619afc"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/DFUZHVCEHPRIJM5T7RW7INAEWZ/bundle.json","state_url":"https://pith.science/pith/DFUZHVCEHPRIJM5T7RW7INAEWZ/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/DFUZHVCEHPRIJM5T7RW7INAEWZ/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-23T15:20:40Z","links":{"resolver":"https://pith.science/pith/DFUZHVCEHPRIJM5T7RW7INAEWZ","bundle":"https://pith.science/pith/DFUZHVCEHPRIJM5T7RW7INAEWZ/bundle.json","state":"https://pith.science/pith/DFUZHVCEHPRIJM5T7RW7INAEWZ/state.json","well_known_bundle":"https://pith.science/.well-known/pith/DFUZHVCEHPRIJM5T7RW7INAEWZ/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:DFUZHVCEHPRIJM5T7RW7INAEWZ","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"3d5dc77e9580876d423b8f1909327fb9a7e138c228971867071b0ea11ca6673d","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-06-17T15:06:47Z","title_canon_sha256":"164406d9ef79a8f6597677a14415b0f7bc58ad94e84370bac7d48af4d38151c4"},"schema_version":"1.0","source":{"id":"1906.07077","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1906.07077","created_at":"2026-05-17T23:43:11Z"},{"alias_kind":"arxiv_version","alias_value":"1906.07077v1","created_at":"2026-05-17T23:43:11Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1906.07077","created_at":"2026-05-17T23:43:11Z"},{"alias_kind":"pith_short_12","alias_value":"DFUZHVCEHPRI","created_at":"2026-05-18T12:33:15Z"},{"alias_kind":"pith_short_16","alias_value":"DFUZHVCEHPRIJM5T","created_at":"2026-05-18T12:33:15Z"},{"alias_kind":"pith_short_8","alias_value":"DFUZHVCE","created_at":"2026-05-18T12:33:15Z"}],"graph_snapshots":[{"event_id":"sha256:9eb43b8f7c57f731e1fdeecc2e5f6922795e86457751b1a5200b8d4903619afc","target":"graph","created_at":"2026-05-17T23:43:11Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Most state-of-the-art machine learning (ML) classification systems are vulnerable to adversarial perturbations. As a consequence, adversarial robustness poses a significant challenge for the deployment of ML-based systems in safety- and security-critical environments like autonomous driving, disease detection or unmanned aerial vehicles. In the past years we have seen an impressive amount of publications presenting more and more new adversarial attacks. However, the attack research seems to be rather unstructured and new attacks often appear to be random selections from the unlimited set of po","authors_text":"Fabian H\\\"uger, Felix Assion, Florens Gre{\\ss}ner, Nico Schmidt, Peter Schlicht, Umair Rasheed, Wiebke G\\\"unther","cross_cats":["cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-06-17T15:06:47Z","title":"The Attack Generator: A Systematic Approach Towards Constructing Adversarial Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1906.07077","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:7fab57ec8d741dd3321a049279c9eeb8209946561cb5f32c8947a7d8c73a06bd","target":"record","created_at":"2026-05-17T23:43:11Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"3d5dc77e9580876d423b8f1909327fb9a7e138c228971867071b0ea11ca6673d","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-06-17T15:06:47Z","title_canon_sha256":"164406d9ef79a8f6597677a14415b0f7bc58ad94e84370bac7d48af4d38151c4"},"schema_version":"1.0","source":{"id":"1906.07077","kind":"arxiv","version":1}},"canonical_sha256":"196993d4443be284b3b3fc6df43404b648412bd3b3b839c0eb0daefdfac37627","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"196993d4443be284b3b3fc6df43404b648412bd3b3b839c0eb0daefdfac37627","first_computed_at":"2026-05-17T23:43:11.967793Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:43:11.967793Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"czf9Au26OxjHGt91tP72B2gRhhFm1xDv507agbrtD+Q8hD+Vz/Og1pH2zaZTJKQY+RtfyikcG/xxLBQ2YhLIDg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:43:11.968464Z","signed_message":"canonical_sha256_bytes"},"source_id":"1906.07077","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:7fab57ec8d741dd3321a049279c9eeb8209946561cb5f32c8947a7d8c73a06bd","sha256:9eb43b8f7c57f731e1fdeecc2e5f6922795e86457751b1a5200b8d4903619afc"],"state_sha256":"75e34a9992040bc6a7d61f00c10719f014cb5e54143a23f1d666274b920fa43d"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"PTrE0PcS1bHFXPklkOAIJlFmKNr6I2dxHIMlmCCCJ+5QDRjb8GzD8jo3acK80vI7anR9y8BfGShKGiCpi63TAQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-23T15:20:40.275210Z","bundle_sha256":"a9b5c734d4f428ecf36a47e9b42386908ae27121bcfaa959123edfe1a86a9721"}}