{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:DPRYEKERLBN3A3IIANWLBZFX2Q","short_pith_number":"pith:DPRYEKER","canonical_record":{"source":{"id":"2510.27285","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2025-10-31T08:53:02Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"34bb5d632ba7c97bb920ecfaf53386fc10a93a2e5268b9b8c5e4fbadbbd278ed","abstract_canon_sha256":"38e44ca0f3b8e3b924dea2523295eca88dfe6cc1e5386fc44aef30b21bf85003"},"schema_version":"1.0"},"canonical_sha256":"1be3822891585bb06d08036cb0e4b7d426c89f767eaa0129b8068b4d71e378ac","source":{"kind":"arxiv","id":"2510.27285","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2510.27285","created_at":"2026-06-19T16:12:48Z"},{"alias_kind":"arxiv_version","alias_value":"2510.27285v3","created_at":"2026-06-19T16:12:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2510.27285","created_at":"2026-06-19T16:12:48Z"},{"alias_kind":"pith_short_12","alias_value":"DPRYEKERLBN3","created_at":"2026-06-19T16:12:48Z"},{"alias_kind":"pith_short_16","alias_value":"DPRYEKERLBN3A3II","created_at":"2026-06-19T16:12:48Z"},{"alias_kind":"pith_short_8","alias_value":"DPRYEKER","created_at":"2026-06-19T16:12:48Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:DPRYEKERLBN3A3IIANWLBZFX2Q","target":"record","payload":{"canonical_record":{"source":{"id":"2510.27285","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2025-10-31T08:53:02Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"34bb5d632ba7c97bb920ecfaf53386fc10a93a2e5268b9b8c5e4fbadbbd278ed","abstract_canon_sha256":"38e44ca0f3b8e3b924dea2523295eca88dfe6cc1e5386fc44aef30b21bf85003"},"schema_version":"1.0"},"canonical_sha256":"1be3822891585bb06d08036cb0e4b7d426c89f767eaa0129b8068b4d71e378ac","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-19T16:12:48.948580Z","signature_b64":"r0pa4kh9h08DAZZQnXvtKw3ap6ksWzAlxtmBRzye4ptWmVDNunnLJHEVWxF0N68cRP2QxHE9cXompgMnIkmdBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"1be3822891585bb06d08036cb0e4b7d426c89f767eaa0129b8068b4d71e378ac","last_reissued_at":"2026-06-19T16:12:48.948149Z","signature_status":"signed_v1","first_computed_at":"2026-06-19T16:12:48.948149Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2510.27285","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-19T16:12:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"1UWNFsAWL57rcMZaFapw6Vqo/QpYddhAJPmQgS9l1uw/rPLr+KLsE4WiYR5zfJo8avUBDrVIAmrrRcAE1SEfDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-25T11:40:24.776935Z"},"content_sha256":"a8ebc85ce958a8a3e48531471e3af428ad23430df3ca2705b53c01a4e3e386cb","schema_version":"1.0","event_id":"sha256:a8ebc85ce958a8a3e48531471e3af428ad23430df3ca2705b53c01a4e3e386cb"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:DPRYEKERLBN3A3IIANWLBZFX2Q","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Rethinking Robust Adversarial Concept Erasure in Diffusion Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.CV","authors_text":"Heming Yang, Qinghong Yin, Xiang Chen, Xianlin Zhang, Xueming Li, Yue Ming, Yue Zhang, Yu Tian","submitted_at":"2025-10-31T08:53:02Z","abstract_excerpt":"Concept erasure aims to selectively unlearning undesirable content in diffusion models (DMs) to reduce the risk of sensitive content generation. As a novel paradigm in concept erasure, most existing methods employ adversarial training to identify and suppress target concepts, thus reducing the likelihood of sensitive outputs. However, these methods often neglect the specificity of adversarial training in DMs, resulting in only partial mitigation. In this work, we investigate and quantify this specificity from the perspective of concept space, i.e., can adversarial samples truly fit the target "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2510.27285","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2510.27285/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-19T16:12:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"jgw4lZyH9rzpI5Yz3igmkLP49FDy8/gy+btyKZPIPotoyLEbFzibV36JTkanqP6Dk1+tcmyWwLiQeYEKeir9Bg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-25T11:40:24.777325Z"},"content_sha256":"0ceb27a5e6454bfc0e94d43a2a1a8b52aef95c69285b97dfba035b61ccec8440","schema_version":"1.0","event_id":"sha256:0ceb27a5e6454bfc0e94d43a2a1a8b52aef95c69285b97dfba035b61ccec8440"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/DPRYEKERLBN3A3IIANWLBZFX2Q/bundle.json","state_url":"https://pith.science/pith/DPRYEKERLBN3A3IIANWLBZFX2Q/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/DPRYEKERLBN3A3IIANWLBZFX2Q/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-25T11:40:24Z","links":{"resolver":"https://pith.science/pith/DPRYEKERLBN3A3IIANWLBZFX2Q","bundle":"https://pith.science/pith/DPRYEKERLBN3A3IIANWLBZFX2Q/bundle.json","state":"https://pith.science/pith/DPRYEKERLBN3A3IIANWLBZFX2Q/state.json","well_known_bundle":"https://pith.science/.well-known/pith/DPRYEKERLBN3A3IIANWLBZFX2Q/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:DPRYEKERLBN3A3IIANWLBZFX2Q","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"38e44ca0f3b8e3b924dea2523295eca88dfe6cc1e5386fc44aef30b21bf85003","cross_cats_sorted":["cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2025-10-31T08:53:02Z","title_canon_sha256":"34bb5d632ba7c97bb920ecfaf53386fc10a93a2e5268b9b8c5e4fbadbbd278ed"},"schema_version":"1.0","source":{"id":"2510.27285","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2510.27285","created_at":"2026-06-19T16:12:48Z"},{"alias_kind":"arxiv_version","alias_value":"2510.27285v3","created_at":"2026-06-19T16:12:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2510.27285","created_at":"2026-06-19T16:12:48Z"},{"alias_kind":"pith_short_12","alias_value":"DPRYEKERLBN3","created_at":"2026-06-19T16:12:48Z"},{"alias_kind":"pith_short_16","alias_value":"DPRYEKERLBN3A3II","created_at":"2026-06-19T16:12:48Z"},{"alias_kind":"pith_short_8","alias_value":"DPRYEKER","created_at":"2026-06-19T16:12:48Z"}],"graph_snapshots":[{"event_id":"sha256:0ceb27a5e6454bfc0e94d43a2a1a8b52aef95c69285b97dfba035b61ccec8440","target":"graph","created_at":"2026-06-19T16:12:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2510.27285/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Concept erasure aims to selectively unlearning undesirable content in diffusion models (DMs) to reduce the risk of sensitive content generation. As a novel paradigm in concept erasure, most existing methods employ adversarial training to identify and suppress target concepts, thus reducing the likelihood of sensitive outputs. However, these methods often neglect the specificity of adversarial training in DMs, resulting in only partial mitigation. In this work, we investigate and quantify this specificity from the perspective of concept space, i.e., can adversarial samples truly fit the target ","authors_text":"Heming Yang, Qinghong Yin, Xiang Chen, Xianlin Zhang, Xueming Li, Yue Ming, Yue Zhang, Yu Tian","cross_cats":["cs.CR"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2025-10-31T08:53:02Z","title":"Rethinking Robust Adversarial Concept Erasure in Diffusion Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2510.27285","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:a8ebc85ce958a8a3e48531471e3af428ad23430df3ca2705b53c01a4e3e386cb","target":"record","created_at":"2026-06-19T16:12:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"38e44ca0f3b8e3b924dea2523295eca88dfe6cc1e5386fc44aef30b21bf85003","cross_cats_sorted":["cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2025-10-31T08:53:02Z","title_canon_sha256":"34bb5d632ba7c97bb920ecfaf53386fc10a93a2e5268b9b8c5e4fbadbbd278ed"},"schema_version":"1.0","source":{"id":"2510.27285","kind":"arxiv","version":3}},"canonical_sha256":"1be3822891585bb06d08036cb0e4b7d426c89f767eaa0129b8068b4d71e378ac","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"1be3822891585bb06d08036cb0e4b7d426c89f767eaa0129b8068b4d71e378ac","first_computed_at":"2026-06-19T16:12:48.948149Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-19T16:12:48.948149Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"r0pa4kh9h08DAZZQnXvtKw3ap6ksWzAlxtmBRzye4ptWmVDNunnLJHEVWxF0N68cRP2QxHE9cXompgMnIkmdBA==","signature_status":"signed_v1","signed_at":"2026-06-19T16:12:48.948580Z","signed_message":"canonical_sha256_bytes"},"source_id":"2510.27285","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:a8ebc85ce958a8a3e48531471e3af428ad23430df3ca2705b53c01a4e3e386cb","sha256:0ceb27a5e6454bfc0e94d43a2a1a8b52aef95c69285b97dfba035b61ccec8440"],"state_sha256":"f7b55cf3678c0883b3e3d101d8ce3e6299ee14d8b35c3b4fd16088de34696fa3"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"HFcPw16diV+MTbwVevvPES+mZ9Qh6i/EZtfCxXVkGRJd55jGKVKZsJG3P19tcYwCjwatugME5UDkf/drN7GhAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-25T11:40:24.779348Z","bundle_sha256":"7717a802f7d097cda53f4f52036c537cd95e097247f16a3a3a84b7f6efcef998"}}