{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:DZOIL6F45LKIRBPJYU7O54RJBD","short_pith_number":"pith:DZOIL6F4","canonical_record":{"source":{"id":"1907.10406","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-07-21T11:52:36Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"f0976a4ef508f9dfc47c2f9389387abb4bd9dc379ba40f343e3d67c859ab8a1a","abstract_canon_sha256":"f992c964a04bf3f3eb44ed9a52d53678d2d83c7bb10a0a2ce6e0ebb616303c28"},"schema_version":"1.0"},"canonical_sha256":"1e5c85f8bcead48885e9c53eeef22908d6099cc99f410b45aa9e0904f7690715","source":{"kind":"arxiv","id":"1907.10406","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1907.10406","created_at":"2026-05-17T23:39:38Z"},{"alias_kind":"arxiv_version","alias_value":"1907.10406v1","created_at":"2026-05-17T23:39:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1907.10406","created_at":"2026-05-17T23:39:38Z"},{"alias_kind":"pith_short_12","alias_value":"DZOIL6F45LKI","created_at":"2026-05-18T12:33:15Z"},{"alias_kind":"pith_short_16","alias_value":"DZOIL6F45LKIRBPJ","created_at":"2026-05-18T12:33:15Z"},{"alias_kind":"pith_short_8","alias_value":"DZOIL6F4","created_at":"2026-05-18T12:33:15Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:DZOIL6F45LKIRBPJYU7O54RJBD","target":"record","payload":{"canonical_record":{"source":{"id":"1907.10406","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-07-21T11:52:36Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"f0976a4ef508f9dfc47c2f9389387abb4bd9dc379ba40f343e3d67c859ab8a1a","abstract_canon_sha256":"f992c964a04bf3f3eb44ed9a52d53678d2d83c7bb10a0a2ce6e0ebb616303c28"},"schema_version":"1.0"},"canonical_sha256":"1e5c85f8bcead48885e9c53eeef22908d6099cc99f410b45aa9e0904f7690715","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:39:38.035813Z","signature_b64":"ypIQ0rQRoMlz0YB9nr/sx3n9bZSWd5PP7SohTeZbbXACpjCLBWY29y4XiZJk7D/eKns018D/2pguMCfjs53zDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"1e5c85f8bcead48885e9c53eeef22908d6099cc99f410b45aa9e0904f7690715","last_reissued_at":"2026-05-17T23:39:38.035153Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:39:38.035153Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1907.10406","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:39:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"U5Y8edn5ws87tqW6QQgEsnkRT8kmw96gvZxVvhLMXB/83CFuOzfxLUT/hi0xh7AB+ZQ76rQXham5V7A9WPSlCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T16:45:39.583633Z"},"content_sha256":"fb88b8044209acdd3e06a889f5a26a8d4d7525dc814e1cdb5270f7c6012d2c4d","schema_version":"1.0","event_id":"sha256:fb88b8044209acdd3e06a889f5a26a8d4d7525dc814e1cdb5270f7c6012d2c4d"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:DZOIL6F45LKIRBPJYU7O54RJBD","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Open DNN Box by Power Side-Channel Attack","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Haiyang Hao, Jinyin Chen, Qi Xuan, Xiaoniu Yang, Yi Liu, Yun Xiang, Zebin Fang, Zhefu Wu, Zhuangzhi Chen, Zuohui Chen","submitted_at":"2019-07-21T11:52:36Z","abstract_excerpt":"Deep neural networks are becoming popular and important assets of many AI companies. However, recent studies indicate that they are also vulnerable to adversarial attacks. Adversarial attacks can be either white-box or black-box. The white-box attacks assume full knowledge of the models while the black-box ones assume none. In general, revealing more internal information can enable much more powerful and efficient attacks. However, in most real-world applications, the internal information of embedded AI devices is unavailable, i.e., they are black-box. Therefore, in this work, we propose a sid"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1907.10406","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:39:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"cHJ5ZkzL7RqmATAukrX5QXuBLRTnxg2WTQ/IPrGD3Fs7Cj4QiygPC4nNPnIiYaBVDwc2v5Ioyj5QaTdjvVWYAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T16:45:39.584018Z"},"content_sha256":"5016ed3bae3059b72017bfa10cbd676493f0b3fdb90f108f16a60cda5df0ede3","schema_version":"1.0","event_id":"sha256:5016ed3bae3059b72017bfa10cbd676493f0b3fdb90f108f16a60cda5df0ede3"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/DZOIL6F45LKIRBPJYU7O54RJBD/bundle.json","state_url":"https://pith.science/pith/DZOIL6F45LKIRBPJYU7O54RJBD/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/DZOIL6F45LKIRBPJYU7O54RJBD/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T16:45:39Z","links":{"resolver":"https://pith.science/pith/DZOIL6F45LKIRBPJYU7O54RJBD","bundle":"https://pith.science/pith/DZOIL6F45LKIRBPJYU7O54RJBD/bundle.json","state":"https://pith.science/pith/DZOIL6F45LKIRBPJYU7O54RJBD/state.json","well_known_bundle":"https://pith.science/.well-known/pith/DZOIL6F45LKIRBPJYU7O54RJBD/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:DZOIL6F45LKIRBPJYU7O54RJBD","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"f992c964a04bf3f3eb44ed9a52d53678d2d83c7bb10a0a2ce6e0ebb616303c28","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-07-21T11:52:36Z","title_canon_sha256":"f0976a4ef508f9dfc47c2f9389387abb4bd9dc379ba40f343e3d67c859ab8a1a"},"schema_version":"1.0","source":{"id":"1907.10406","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1907.10406","created_at":"2026-05-17T23:39:38Z"},{"alias_kind":"arxiv_version","alias_value":"1907.10406v1","created_at":"2026-05-17T23:39:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1907.10406","created_at":"2026-05-17T23:39:38Z"},{"alias_kind":"pith_short_12","alias_value":"DZOIL6F45LKI","created_at":"2026-05-18T12:33:15Z"},{"alias_kind":"pith_short_16","alias_value":"DZOIL6F45LKIRBPJ","created_at":"2026-05-18T12:33:15Z"},{"alias_kind":"pith_short_8","alias_value":"DZOIL6F4","created_at":"2026-05-18T12:33:15Z"}],"graph_snapshots":[{"event_id":"sha256:5016ed3bae3059b72017bfa10cbd676493f0b3fdb90f108f16a60cda5df0ede3","target":"graph","created_at":"2026-05-17T23:39:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep neural networks are becoming popular and important assets of many AI companies. However, recent studies indicate that they are also vulnerable to adversarial attacks. Adversarial attacks can be either white-box or black-box. The white-box attacks assume full knowledge of the models while the black-box ones assume none. In general, revealing more internal information can enable much more powerful and efficient attacks. However, in most real-world applications, the internal information of embedded AI devices is unavailable, i.e., they are black-box. Therefore, in this work, we propose a sid","authors_text":"Haiyang Hao, Jinyin Chen, Qi Xuan, Xiaoniu Yang, Yi Liu, Yun Xiang, Zebin Fang, Zhefu Wu, Zhuangzhi Chen, Zuohui Chen","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-07-21T11:52:36Z","title":"Open DNN Box by Power Side-Channel Attack"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1907.10406","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:fb88b8044209acdd3e06a889f5a26a8d4d7525dc814e1cdb5270f7c6012d2c4d","target":"record","created_at":"2026-05-17T23:39:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"f992c964a04bf3f3eb44ed9a52d53678d2d83c7bb10a0a2ce6e0ebb616303c28","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-07-21T11:52:36Z","title_canon_sha256":"f0976a4ef508f9dfc47c2f9389387abb4bd9dc379ba40f343e3d67c859ab8a1a"},"schema_version":"1.0","source":{"id":"1907.10406","kind":"arxiv","version":1}},"canonical_sha256":"1e5c85f8bcead48885e9c53eeef22908d6099cc99f410b45aa9e0904f7690715","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"1e5c85f8bcead48885e9c53eeef22908d6099cc99f410b45aa9e0904f7690715","first_computed_at":"2026-05-17T23:39:38.035153Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:39:38.035153Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"ypIQ0rQRoMlz0YB9nr/sx3n9bZSWd5PP7SohTeZbbXACpjCLBWY29y4XiZJk7D/eKns018D/2pguMCfjs53zDA==","signature_status":"signed_v1","signed_at":"2026-05-17T23:39:38.035813Z","signed_message":"canonical_sha256_bytes"},"source_id":"1907.10406","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:fb88b8044209acdd3e06a889f5a26a8d4d7525dc814e1cdb5270f7c6012d2c4d","sha256:5016ed3bae3059b72017bfa10cbd676493f0b3fdb90f108f16a60cda5df0ede3"],"state_sha256":"71573952f2bb5ece629e618f43b2faadca64f9081603a3e665b12982d1a881e4"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"yEFHzRgYxpfccrZO2opmfz4uDNbDJQjGwIxasVQbmfxwe4BBToMPX2IsI+uGcU+szlyHVPc4JaGeeqJWMuAcBg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T16:45:39.587422Z","bundle_sha256":"4863b38672554657af79b8aacad4b70df8de45a804f88ff398f3893da3f1a429"}}