{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:DXDQTV46T4YO4SVR4NKNO2QHF6","short_pith_number":"pith:DXDQTV46","canonical_record":{"source":{"id":"1801.02780","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-01-09T03:33:33Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"ee2a1a8681488b9a99a204d6b570bb01c7873d88b121648fc1a8094481bbefdb","abstract_canon_sha256":"f165c142dffaab764882afbf7506c301ff2e4e6d4f6630d50072a9e6961978c8"},"schema_version":"1.0"},"canonical_sha256":"1dc709d79e9f30ee4ab1e354d76a072fbb897ec858f12872400d9a6241befe53","source":{"kind":"arxiv","id":"1801.02780","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1801.02780","created_at":"2026-05-18T00:20:16Z"},{"alias_kind":"arxiv_version","alias_value":"1801.02780v3","created_at":"2026-05-18T00:20:16Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1801.02780","created_at":"2026-05-18T00:20:16Z"},{"alias_kind":"pith_short_12","alias_value":"DXDQTV46T4YO","created_at":"2026-05-18T12:32:19Z"},{"alias_kind":"pith_short_16","alias_value":"DXDQTV46T4YO4SVR","created_at":"2026-05-18T12:32:19Z"},{"alias_kind":"pith_short_8","alias_value":"DXDQTV46","created_at":"2026-05-18T12:32:19Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:DXDQTV46T4YO4SVR4NKNO2QHF6","target":"record","payload":{"canonical_record":{"source":{"id":"1801.02780","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-01-09T03:33:33Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"ee2a1a8681488b9a99a204d6b570bb01c7873d88b121648fc1a8094481bbefdb","abstract_canon_sha256":"f165c142dffaab764882afbf7506c301ff2e4e6d4f6630d50072a9e6961978c8"},"schema_version":"1.0"},"canonical_sha256":"1dc709d79e9f30ee4ab1e354d76a072fbb897ec858f12872400d9a6241befe53","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:20:16.177461Z","signature_b64":"WHnjQte3ob/5aOcyIYebX4UTn8jSwOdkDSGKiWKQqxz6TU7s/hgP08DRdbdrTtcqsHEzpM/CSZTVS+diqXX5Bg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"1dc709d79e9f30ee4ab1e354d76a072fbb897ec858f12872400d9a6241befe53","last_reissued_at":"2026-05-18T00:20:16.176813Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:20:16.176813Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1801.02780","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:20:16Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"a6yHe0YqsuuRe3Tych95+AgWxHnHnp+S9GJl2ROyNX2ILqKKLbqBneYZgaBklwEl//DhUPQg+NYBPBG7FbsKBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T23:47:39.655739Z"},"content_sha256":"daa5240758daa8aae89180563bc13d615234e93f391de8a09015c13faa1b54c8","schema_version":"1.0","event_id":"sha256:daa5240758daa8aae89180563bc13d615234e93f391de8a09015c13faa1b54c8"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:DXDQTV46T4YO4SVR4NKNO2QHF6","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Rogue Signs: Deceiving Traffic Sign Recognition with Malicious Ads and Logos","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Arjun Nitin Bhagoji, Arsalan Mosenia, Chawin Sitawarin, Mung Chiang, Prateek Mittal","submitted_at":"2018-01-09T03:33:33Z","abstract_excerpt":"We propose a new real-world attack against the computer vision based systems of autonomous vehicles (AVs). Our novel Sign Embedding attack exploits the concept of adversarial examples to modify innocuous signs and advertisements in the environment such that they are classified as the adversary's desired traffic sign with high confidence. Our attack greatly expands the scope of the threat posed to AVs since adversaries are no longer restricted to just modifying existing traffic signs as in previous work. Our attack pipeline generates adversarial samples which are robust to the environmental con"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1801.02780","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:20:16Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8tRvUgTb6WgivTtPFrSPyDDOXoFo0DC2JoiXJfDLB3kJb3iA3xlPEeWziV0HDOW9Onu0yg7T4Sj2yC+7iKKEBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T23:47:39.656244Z"},"content_sha256":"314f28443dc537edfd1bd23f9b6dfd28a545a505d9b9148b820d2a0d5bc6c37a","schema_version":"1.0","event_id":"sha256:314f28443dc537edfd1bd23f9b6dfd28a545a505d9b9148b820d2a0d5bc6c37a"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/DXDQTV46T4YO4SVR4NKNO2QHF6/bundle.json","state_url":"https://pith.science/pith/DXDQTV46T4YO4SVR4NKNO2QHF6/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/DXDQTV46T4YO4SVR4NKNO2QHF6/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T23:47:39Z","links":{"resolver":"https://pith.science/pith/DXDQTV46T4YO4SVR4NKNO2QHF6","bundle":"https://pith.science/pith/DXDQTV46T4YO4SVR4NKNO2QHF6/bundle.json","state":"https://pith.science/pith/DXDQTV46T4YO4SVR4NKNO2QHF6/state.json","well_known_bundle":"https://pith.science/.well-known/pith/DXDQTV46T4YO4SVR4NKNO2QHF6/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:DXDQTV46T4YO4SVR4NKNO2QHF6","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"f165c142dffaab764882afbf7506c301ff2e4e6d4f6630d50072a9e6961978c8","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-01-09T03:33:33Z","title_canon_sha256":"ee2a1a8681488b9a99a204d6b570bb01c7873d88b121648fc1a8094481bbefdb"},"schema_version":"1.0","source":{"id":"1801.02780","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1801.02780","created_at":"2026-05-18T00:20:16Z"},{"alias_kind":"arxiv_version","alias_value":"1801.02780v3","created_at":"2026-05-18T00:20:16Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1801.02780","created_at":"2026-05-18T00:20:16Z"},{"alias_kind":"pith_short_12","alias_value":"DXDQTV46T4YO","created_at":"2026-05-18T12:32:19Z"},{"alias_kind":"pith_short_16","alias_value":"DXDQTV46T4YO4SVR","created_at":"2026-05-18T12:32:19Z"},{"alias_kind":"pith_short_8","alias_value":"DXDQTV46","created_at":"2026-05-18T12:32:19Z"}],"graph_snapshots":[{"event_id":"sha256:314f28443dc537edfd1bd23f9b6dfd28a545a505d9b9148b820d2a0d5bc6c37a","target":"graph","created_at":"2026-05-18T00:20:16Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We propose a new real-world attack against the computer vision based systems of autonomous vehicles (AVs). Our novel Sign Embedding attack exploits the concept of adversarial examples to modify innocuous signs and advertisements in the environment such that they are classified as the adversary's desired traffic sign with high confidence. Our attack greatly expands the scope of the threat posed to AVs since adversaries are no longer restricted to just modifying existing traffic signs as in previous work. Our attack pipeline generates adversarial samples which are robust to the environmental con","authors_text":"Arjun Nitin Bhagoji, Arsalan Mosenia, Chawin Sitawarin, Mung Chiang, Prateek Mittal","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-01-09T03:33:33Z","title":"Rogue Signs: Deceiving Traffic Sign Recognition with Malicious Ads and Logos"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1801.02780","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:daa5240758daa8aae89180563bc13d615234e93f391de8a09015c13faa1b54c8","target":"record","created_at":"2026-05-18T00:20:16Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"f165c142dffaab764882afbf7506c301ff2e4e6d4f6630d50072a9e6961978c8","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-01-09T03:33:33Z","title_canon_sha256":"ee2a1a8681488b9a99a204d6b570bb01c7873d88b121648fc1a8094481bbefdb"},"schema_version":"1.0","source":{"id":"1801.02780","kind":"arxiv","version":3}},"canonical_sha256":"1dc709d79e9f30ee4ab1e354d76a072fbb897ec858f12872400d9a6241befe53","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"1dc709d79e9f30ee4ab1e354d76a072fbb897ec858f12872400d9a6241befe53","first_computed_at":"2026-05-18T00:20:16.176813Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:20:16.176813Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"WHnjQte3ob/5aOcyIYebX4UTn8jSwOdkDSGKiWKQqxz6TU7s/hgP08DRdbdrTtcqsHEzpM/CSZTVS+diqXX5Bg==","signature_status":"signed_v1","signed_at":"2026-05-18T00:20:16.177461Z","signed_message":"canonical_sha256_bytes"},"source_id":"1801.02780","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:daa5240758daa8aae89180563bc13d615234e93f391de8a09015c13faa1b54c8","sha256:314f28443dc537edfd1bd23f9b6dfd28a545a505d9b9148b820d2a0d5bc6c37a"],"state_sha256":"f84c9fc953767467f1a8a5048623295c8bf13f91abfce7705f820d6753d83936"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"5Qb4UCuIbSlkWVJHJVCGQU4MzF9WkAr+douyX10WqwAC3HI6FEfRz1fkxTZdKOODpf+gEUNsfLnO5lg9rNVGDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T23:47:39.658729Z","bundle_sha256":"68b42b0ab44d7c20cc6d3269e3a3adc2a199db34001383043c747d1a134db5ff"}}