{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:FXUL2O5NBJWXHXFHV4BXCDZFCI","short_pith_number":"pith:FXUL2O5N","canonical_record":{"source":{"id":"1902.01235","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-02-01T15:36:34Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"7d2f98d9997b3cebc559d93f0182bbf78b9ffebcb448039d09d62cbac37854cb","abstract_canon_sha256":"b85db480a85f2d2cf710da47ac8c9b1fb7990013582e72aca9aec4d31c7cdc50"},"schema_version":"1.0"},"canonical_sha256":"2de8bd3bad0a6d73dca7af03710f2512188289bc335405f2da40da909ee115f2","source":{"kind":"arxiv","id":"1902.01235","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1902.01235","created_at":"2026-05-17T23:54:38Z"},{"alias_kind":"arxiv_version","alias_value":"1902.01235v2","created_at":"2026-05-17T23:54:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1902.01235","created_at":"2026-05-17T23:54:38Z"},{"alias_kind":"pith_short_12","alias_value":"FXUL2O5NBJWX","created_at":"2026-05-18T12:33:18Z"},{"alias_kind":"pith_short_16","alias_value":"FXUL2O5NBJWXHXFH","created_at":"2026-05-18T12:33:18Z"},{"alias_kind":"pith_short_8","alias_value":"FXUL2O5N","created_at":"2026-05-18T12:33:18Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:FXUL2O5NBJWXHXFHV4BXCDZFCI","target":"record","payload":{"canonical_record":{"source":{"id":"1902.01235","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-02-01T15:36:34Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"7d2f98d9997b3cebc559d93f0182bbf78b9ffebcb448039d09d62cbac37854cb","abstract_canon_sha256":"b85db480a85f2d2cf710da47ac8c9b1fb7990013582e72aca9aec4d31c7cdc50"},"schema_version":"1.0"},"canonical_sha256":"2de8bd3bad0a6d73dca7af03710f2512188289bc335405f2da40da909ee115f2","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:54:38.678964Z","signature_b64":"P7wk+DfmvvBFATPDKczHFhgiUzgVE7sN2AkZjZ6OiYwiKtRWri5G3kQbTHlT1FcsSOKMWT582gIq0V1el8SSCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"2de8bd3bad0a6d73dca7af03710f2512188289bc335405f2da40da909ee115f2","last_reissued_at":"2026-05-17T23:54:38.678409Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:54:38.678409Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1902.01235","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:54:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"7gVYTbm8JAroGQtuFCf3oR5xLyw6bcqFamikQoeXliNTESSKYI3ogGBxT9bXgiSxR6GwexAIRoNAZVXEfJBMAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-04T01:27:41.801385Z"},"content_sha256":"6588b4b4a095a2b2a25663bc308a22496ce44520178352e76856bbcdbc03ee0c","schema_version":"1.0","event_id":"sha256:6588b4b4a095a2b2a25663bc308a22496ce44520178352e76856bbcdbc03ee0c"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:FXUL2O5NBJWXHXFHV4BXCDZFCI","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Robustness Certificates Against Adversarial Examples for ReLU Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Sahil Singla, Soheil Feizi","submitted_at":"2019-02-01T15:36:34Z","abstract_excerpt":"While neural networks have achieved high performance in different learning tasks, their accuracy drops significantly in the presence of small adversarial perturbations to inputs. Defenses based on regularization and adversarial training are often followed by new attacks to defeat them. In this paper, we propose attack-agnostic robustness certificates for a multi-label classification problem using a deep ReLU network. Although computing the exact distance of a given input sample to the classification decision boundary requires solving a non-convex optimization, we characterize two lower bounds "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1902.01235","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:54:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"OBQ5yWVTHuQSC+LKM5/6CTELtICOEQuia+5egPT2342V3cUGdHpUhdsiiT9cLrmKCOMOHOffMBUr+MvFG//LCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-04T01:27:41.801739Z"},"content_sha256":"3a3932d77cc4d7d54d77039bd3b33e5154049d8f1eebee627d7299136c837e10","schema_version":"1.0","event_id":"sha256:3a3932d77cc4d7d54d77039bd3b33e5154049d8f1eebee627d7299136c837e10"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/FXUL2O5NBJWXHXFHV4BXCDZFCI/bundle.json","state_url":"https://pith.science/pith/FXUL2O5NBJWXHXFHV4BXCDZFCI/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/FXUL2O5NBJWXHXFHV4BXCDZFCI/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-04T01:27:41Z","links":{"resolver":"https://pith.science/pith/FXUL2O5NBJWXHXFHV4BXCDZFCI","bundle":"https://pith.science/pith/FXUL2O5NBJWXHXFHV4BXCDZFCI/bundle.json","state":"https://pith.science/pith/FXUL2O5NBJWXHXFHV4BXCDZFCI/state.json","well_known_bundle":"https://pith.science/.well-known/pith/FXUL2O5NBJWXHXFHV4BXCDZFCI/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:FXUL2O5NBJWXHXFHV4BXCDZFCI","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"b85db480a85f2d2cf710da47ac8c9b1fb7990013582e72aca9aec4d31c7cdc50","cross_cats_sorted":["stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-02-01T15:36:34Z","title_canon_sha256":"7d2f98d9997b3cebc559d93f0182bbf78b9ffebcb448039d09d62cbac37854cb"},"schema_version":"1.0","source":{"id":"1902.01235","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1902.01235","created_at":"2026-05-17T23:54:38Z"},{"alias_kind":"arxiv_version","alias_value":"1902.01235v2","created_at":"2026-05-17T23:54:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1902.01235","created_at":"2026-05-17T23:54:38Z"},{"alias_kind":"pith_short_12","alias_value":"FXUL2O5NBJWX","created_at":"2026-05-18T12:33:18Z"},{"alias_kind":"pith_short_16","alias_value":"FXUL2O5NBJWXHXFH","created_at":"2026-05-18T12:33:18Z"},{"alias_kind":"pith_short_8","alias_value":"FXUL2O5N","created_at":"2026-05-18T12:33:18Z"}],"graph_snapshots":[{"event_id":"sha256:3a3932d77cc4d7d54d77039bd3b33e5154049d8f1eebee627d7299136c837e10","target":"graph","created_at":"2026-05-17T23:54:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"While neural networks have achieved high performance in different learning tasks, their accuracy drops significantly in the presence of small adversarial perturbations to inputs. Defenses based on regularization and adversarial training are often followed by new attacks to defeat them. In this paper, we propose attack-agnostic robustness certificates for a multi-label classification problem using a deep ReLU network. Although computing the exact distance of a given input sample to the classification decision boundary requires solving a non-convex optimization, we characterize two lower bounds ","authors_text":"Sahil Singla, Soheil Feizi","cross_cats":["stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-02-01T15:36:34Z","title":"Robustness Certificates Against Adversarial Examples for ReLU Networks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1902.01235","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:6588b4b4a095a2b2a25663bc308a22496ce44520178352e76856bbcdbc03ee0c","target":"record","created_at":"2026-05-17T23:54:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"b85db480a85f2d2cf710da47ac8c9b1fb7990013582e72aca9aec4d31c7cdc50","cross_cats_sorted":["stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-02-01T15:36:34Z","title_canon_sha256":"7d2f98d9997b3cebc559d93f0182bbf78b9ffebcb448039d09d62cbac37854cb"},"schema_version":"1.0","source":{"id":"1902.01235","kind":"arxiv","version":2}},"canonical_sha256":"2de8bd3bad0a6d73dca7af03710f2512188289bc335405f2da40da909ee115f2","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"2de8bd3bad0a6d73dca7af03710f2512188289bc335405f2da40da909ee115f2","first_computed_at":"2026-05-17T23:54:38.678409Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:54:38.678409Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"P7wk+DfmvvBFATPDKczHFhgiUzgVE7sN2AkZjZ6OiYwiKtRWri5G3kQbTHlT1FcsSOKMWT582gIq0V1el8SSCw==","signature_status":"signed_v1","signed_at":"2026-05-17T23:54:38.678964Z","signed_message":"canonical_sha256_bytes"},"source_id":"1902.01235","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:6588b4b4a095a2b2a25663bc308a22496ce44520178352e76856bbcdbc03ee0c","sha256:3a3932d77cc4d7d54d77039bd3b33e5154049d8f1eebee627d7299136c837e10"],"state_sha256":"15440338eb36bdffef4a6ef2fd718154475ac38d756f0c43af4f976d9a68cec1"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"5CjCcfe81YzNDdX7+xM+5gu/wP+rD7sRhKU0ThJrWcIkyjfTy44rD7jeGNZ+HMukStT1A2Jcsh+4NA2taOk8CQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-04T01:27:41.803895Z","bundle_sha256":"cad06d707f2b33a49a7dc5c9f12a102f5ead5b6d53bf17e56eb3fc4b060762da"}}