{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:F6V5FVGV5FI4EVPCJOYYQ3K73V","short_pith_number":"pith:F6V5FVGV","canonical_record":{"source":{"id":"1901.09113","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-01-25T22:56:10Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"0047867a2b38be18f264042d80b9cb958f6f50d0698009091be72a6d159c0e80","abstract_canon_sha256":"0651c4eb11b48ec6eebb92fa78d3ff41451c6e7e0ae26b0a0b2437b78091ce57"},"schema_version":"1.0"},"canonical_sha256":"2fabd2d4d5e951c255e24bb1886d5fdd6ac5ec0e0ce41d7943985274caa7aae9","source":{"kind":"arxiv","id":"1901.09113","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1901.09113","created_at":"2026-05-17T23:55:30Z"},{"alias_kind":"arxiv_version","alias_value":"1901.09113v1","created_at":"2026-05-17T23:55:30Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1901.09113","created_at":"2026-05-17T23:55:30Z"},{"alias_kind":"pith_short_12","alias_value":"F6V5FVGV5FI4","created_at":"2026-05-18T12:33:15Z"},{"alias_kind":"pith_short_16","alias_value":"F6V5FVGV5FI4EVPC","created_at":"2026-05-18T12:33:15Z"},{"alias_kind":"pith_short_8","alias_value":"F6V5FVGV","created_at":"2026-05-18T12:33:15Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:F6V5FVGV5FI4EVPCJOYYQ3K73V","target":"record","payload":{"canonical_record":{"source":{"id":"1901.09113","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-01-25T22:56:10Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"0047867a2b38be18f264042d80b9cb958f6f50d0698009091be72a6d159c0e80","abstract_canon_sha256":"0651c4eb11b48ec6eebb92fa78d3ff41451c6e7e0ae26b0a0b2437b78091ce57"},"schema_version":"1.0"},"canonical_sha256":"2fabd2d4d5e951c255e24bb1886d5fdd6ac5ec0e0ce41d7943985274caa7aae9","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:55:30.508879Z","signature_b64":"viyhANjwA7BHjyYA6fRsE3L8YNdwkIhjPzXZ20OCj5uzsEXjw74he+0WlQR3bwUa5avxdowL+dgmVC53NcxMCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"2fabd2d4d5e951c255e24bb1886d5fdd6ac5ec0e0ce41d7943985274caa7aae9","last_reissued_at":"2026-05-17T23:55:30.508433Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:55:30.508433Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1901.09113","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:55:30Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"eBUEJW8AJVEsl/i/TgDQ2Z7ozF2ayZfpRrrjWMFqVoTdDsi0Kqji949eIYtWnaZ5wOeXI14mX02rU9v+EB4QDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T01:29:04.538862Z"},"content_sha256":"a5d362c10cee5ba891694996c0e6d8e6858eda04b6da6a7ce0c744e344aefa1b","schema_version":"1.0","event_id":"sha256:a5d362c10cee5ba891694996c0e6d8e6858eda04b6da6a7ce0c744e344aefa1b"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:F6V5FVGV5FI4EVPCJOYYQ3K73V","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Generative Adversarial Networks for Black-Box API Attacks with Limited Training Data","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Jason H. Li, Kemal Davaslioglu, Yalin E. Sagduyu, Yi Shi","submitted_at":"2019-01-25T22:56:10Z","abstract_excerpt":"As online systems based on machine learning are offered to public or paid subscribers via application programming interfaces (APIs), they become vulnerable to frequent exploits and attacks. This paper studies adversarial machine learning in the practical case when there are rate limitations on API calls. The adversary launches an exploratory (inference) attack by querying the API of an online machine learning system (in particular, a classifier) with input data samples, collecting returned labels to build up the training data, and training an adversarial classifier that is functionally equival"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1901.09113","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:55:30Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"KPZ1FRI48Y8ILcNsG0HyiO8fgCQUEhnyVoysbR4eHfTjszC/xMHhqJLf2/5DDg8NqDI/CW1siWS6fO036JPdDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T01:29:04.539279Z"},"content_sha256":"7269cf8381b47738ef85cf0b5f2c7ef91131ceb4a67cc44b9b0d1af7ef4e1183","schema_version":"1.0","event_id":"sha256:7269cf8381b47738ef85cf0b5f2c7ef91131ceb4a67cc44b9b0d1af7ef4e1183"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/F6V5FVGV5FI4EVPCJOYYQ3K73V/bundle.json","state_url":"https://pith.science/pith/F6V5FVGV5FI4EVPCJOYYQ3K73V/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/F6V5FVGV5FI4EVPCJOYYQ3K73V/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T01:29:04Z","links":{"resolver":"https://pith.science/pith/F6V5FVGV5FI4EVPCJOYYQ3K73V","bundle":"https://pith.science/pith/F6V5FVGV5FI4EVPCJOYYQ3K73V/bundle.json","state":"https://pith.science/pith/F6V5FVGV5FI4EVPCJOYYQ3K73V/state.json","well_known_bundle":"https://pith.science/.well-known/pith/F6V5FVGV5FI4EVPCJOYYQ3K73V/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:F6V5FVGV5FI4EVPCJOYYQ3K73V","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"0651c4eb11b48ec6eebb92fa78d3ff41451c6e7e0ae26b0a0b2437b78091ce57","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-01-25T22:56:10Z","title_canon_sha256":"0047867a2b38be18f264042d80b9cb958f6f50d0698009091be72a6d159c0e80"},"schema_version":"1.0","source":{"id":"1901.09113","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1901.09113","created_at":"2026-05-17T23:55:30Z"},{"alias_kind":"arxiv_version","alias_value":"1901.09113v1","created_at":"2026-05-17T23:55:30Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1901.09113","created_at":"2026-05-17T23:55:30Z"},{"alias_kind":"pith_short_12","alias_value":"F6V5FVGV5FI4","created_at":"2026-05-18T12:33:15Z"},{"alias_kind":"pith_short_16","alias_value":"F6V5FVGV5FI4EVPC","created_at":"2026-05-18T12:33:15Z"},{"alias_kind":"pith_short_8","alias_value":"F6V5FVGV","created_at":"2026-05-18T12:33:15Z"}],"graph_snapshots":[{"event_id":"sha256:7269cf8381b47738ef85cf0b5f2c7ef91131ceb4a67cc44b9b0d1af7ef4e1183","target":"graph","created_at":"2026-05-17T23:55:30Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"As online systems based on machine learning are offered to public or paid subscribers via application programming interfaces (APIs), they become vulnerable to frequent exploits and attacks. This paper studies adversarial machine learning in the practical case when there are rate limitations on API calls. The adversary launches an exploratory (inference) attack by querying the API of an online machine learning system (in particular, a classifier) with input data samples, collecting returned labels to build up the training data, and training an adversarial classifier that is functionally equival","authors_text":"Jason H. Li, Kemal Davaslioglu, Yalin E. Sagduyu, Yi Shi","cross_cats":["cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-01-25T22:56:10Z","title":"Generative Adversarial Networks for Black-Box API Attacks with Limited Training Data"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1901.09113","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:a5d362c10cee5ba891694996c0e6d8e6858eda04b6da6a7ce0c744e344aefa1b","target":"record","created_at":"2026-05-17T23:55:30Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"0651c4eb11b48ec6eebb92fa78d3ff41451c6e7e0ae26b0a0b2437b78091ce57","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-01-25T22:56:10Z","title_canon_sha256":"0047867a2b38be18f264042d80b9cb958f6f50d0698009091be72a6d159c0e80"},"schema_version":"1.0","source":{"id":"1901.09113","kind":"arxiv","version":1}},"canonical_sha256":"2fabd2d4d5e951c255e24bb1886d5fdd6ac5ec0e0ce41d7943985274caa7aae9","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"2fabd2d4d5e951c255e24bb1886d5fdd6ac5ec0e0ce41d7943985274caa7aae9","first_computed_at":"2026-05-17T23:55:30.508433Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:55:30.508433Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"viyhANjwA7BHjyYA6fRsE3L8YNdwkIhjPzXZ20OCj5uzsEXjw74he+0WlQR3bwUa5avxdowL+dgmVC53NcxMCg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:55:30.508879Z","signed_message":"canonical_sha256_bytes"},"source_id":"1901.09113","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:a5d362c10cee5ba891694996c0e6d8e6858eda04b6da6a7ce0c744e344aefa1b","sha256:7269cf8381b47738ef85cf0b5f2c7ef91131ceb4a67cc44b9b0d1af7ef4e1183"],"state_sha256":"1e28f722f61c279fc9e37186b1ea37794e72b570e91412cb46e8799ec0d82302"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Tq7caBnpMJ6s0hMt3OjpbPiG7Gv/h4CAAXjUIH6hZ+oi1CkOxeGn88Uucw/OEwc3jA+h5TcbotpJYhk+3tCtAA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T01:29:04.542584Z","bundle_sha256":"a74bfa6f28c59e5b4ad2542ab51fd9588fc1bd2584d5dab19f95509f8154f388"}}