{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:GN7FI2F7KE5O3TEVAWMXI6WDGB","short_pith_number":"pith:GN7FI2F7","canonical_record":{"source":{"id":"2605.29877","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"quant-ph","submitted_at":"2026-05-28T13:00:48Z","cross_cats_sorted":[],"title_canon_sha256":"d89c4270bde181ab0c87c8fa88743d6a4978f90de2bc2de8fe645a1b45c982f3","abstract_canon_sha256":"9e3cfcd84bea7a9df851ad926cdd60e8fea80b8c65a0c9f836721175e42d2e2c"},"schema_version":"1.0"},"canonical_sha256":"337e5468bf513aedcc950599747ac33072f612fb806abac8505424703eb3d12c","source":{"kind":"arxiv","id":"2605.29877","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.29877","created_at":"2026-05-29T02:05:57Z"},{"alias_kind":"arxiv_version","alias_value":"2605.29877v1","created_at":"2026-05-29T02:05:57Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.29877","created_at":"2026-05-29T02:05:57Z"},{"alias_kind":"pith_short_12","alias_value":"GN7FI2F7KE5O","created_at":"2026-05-29T02:05:57Z"},{"alias_kind":"pith_short_16","alias_value":"GN7FI2F7KE5O3TEV","created_at":"2026-05-29T02:05:57Z"},{"alias_kind":"pith_short_8","alias_value":"GN7FI2F7","created_at":"2026-05-29T02:05:57Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:GN7FI2F7KE5O3TEVAWMXI6WDGB","target":"record","payload":{"canonical_record":{"source":{"id":"2605.29877","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"quant-ph","submitted_at":"2026-05-28T13:00:48Z","cross_cats_sorted":[],"title_canon_sha256":"d89c4270bde181ab0c87c8fa88743d6a4978f90de2bc2de8fe645a1b45c982f3","abstract_canon_sha256":"9e3cfcd84bea7a9df851ad926cdd60e8fea80b8c65a0c9f836721175e42d2e2c"},"schema_version":"1.0"},"canonical_sha256":"337e5468bf513aedcc950599747ac33072f612fb806abac8505424703eb3d12c","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-29T02:05:57.334504Z","signature_b64":"VmsJTse9S4qdfzHJ3VJPcPdwEvJlSOWBbPr31sQId0vJAuP7FpbS9t27XdbpLMwLyB9opubY9/uAqhVwYPM5DA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"337e5468bf513aedcc950599747ac33072f612fb806abac8505424703eb3d12c","last_reissued_at":"2026-05-29T02:05:57.333641Z","signature_status":"signed_v1","first_computed_at":"2026-05-29T02:05:57.333641Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.29877","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-29T02:05:57Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"6u6IrIRnEmVFhtZAMnGg073PxaV2nWEDJynuM966T+tr3N9AZ2U9Co/UbUgf3CYglvNwF+znVIyhOYfkGR0sBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T14:42:53.163186Z"},"content_sha256":"a194bac5552c41ce4611f8401469867ab4971b8b176f5b8ffe797bcabb29420c","schema_version":"1.0","event_id":"sha256:a194bac5552c41ce4611f8401469867ab4971b8b176f5b8ffe797bcabb29420c"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:GN7FI2F7KE5O3TEVAWMXI6WDGB","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Verifying Adversarial Robustness in Quantum Machine Learning: from theory to physical validation via a software tool","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"quant-ph","authors_text":"Ji Guan, Mingsheng Ying","submitted_at":"2026-05-28T13:00:48Z","abstract_excerpt":"As with classical neural networks, quantum machine learning (QML) models are vulnerable to small input perturbations that can significantly alter output predictions. Certifying the robustness of QML models, particularly on NISQ hardware, is therefore a fundamental step toward trustworthy quantum AI. This chapter reviews our recently developed comprehensive formal framework for verifying adversarial robustness in QML. The core of this framework is a fidelity-based robustness lower bound computable directly from the measurement outcome distribution, which enables both formal verification and emp"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.29877","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.29877/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-29T02:05:57Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"kc23BIYJefjP/wlyUC85FOzvkQBKVSnD/xt7OFsj0DcUeibuHe+8FoyknZQbgtHpG7adupacG9IsQK52j5ZICQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T14:42:53.163587Z"},"content_sha256":"e1ce65beb54f96e59b5afbfd2844645cc705cb3b187323b2b2daa001263a4704","schema_version":"1.0","event_id":"sha256:e1ce65beb54f96e59b5afbfd2844645cc705cb3b187323b2b2daa001263a4704"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/GN7FI2F7KE5O3TEVAWMXI6WDGB/bundle.json","state_url":"https://pith.science/pith/GN7FI2F7KE5O3TEVAWMXI6WDGB/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/GN7FI2F7KE5O3TEVAWMXI6WDGB/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-09T14:42:53Z","links":{"resolver":"https://pith.science/pith/GN7FI2F7KE5O3TEVAWMXI6WDGB","bundle":"https://pith.science/pith/GN7FI2F7KE5O3TEVAWMXI6WDGB/bundle.json","state":"https://pith.science/pith/GN7FI2F7KE5O3TEVAWMXI6WDGB/state.json","well_known_bundle":"https://pith.science/.well-known/pith/GN7FI2F7KE5O3TEVAWMXI6WDGB/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:GN7FI2F7KE5O3TEVAWMXI6WDGB","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"9e3cfcd84bea7a9df851ad926cdd60e8fea80b8c65a0c9f836721175e42d2e2c","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"quant-ph","submitted_at":"2026-05-28T13:00:48Z","title_canon_sha256":"d89c4270bde181ab0c87c8fa88743d6a4978f90de2bc2de8fe645a1b45c982f3"},"schema_version":"1.0","source":{"id":"2605.29877","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.29877","created_at":"2026-05-29T02:05:57Z"},{"alias_kind":"arxiv_version","alias_value":"2605.29877v1","created_at":"2026-05-29T02:05:57Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.29877","created_at":"2026-05-29T02:05:57Z"},{"alias_kind":"pith_short_12","alias_value":"GN7FI2F7KE5O","created_at":"2026-05-29T02:05:57Z"},{"alias_kind":"pith_short_16","alias_value":"GN7FI2F7KE5O3TEV","created_at":"2026-05-29T02:05:57Z"},{"alias_kind":"pith_short_8","alias_value":"GN7FI2F7","created_at":"2026-05-29T02:05:57Z"}],"graph_snapshots":[{"event_id":"sha256:e1ce65beb54f96e59b5afbfd2844645cc705cb3b187323b2b2daa001263a4704","target":"graph","created_at":"2026-05-29T02:05:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.29877/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"As with classical neural networks, quantum machine learning (QML) models are vulnerable to small input perturbations that can significantly alter output predictions. Certifying the robustness of QML models, particularly on NISQ hardware, is therefore a fundamental step toward trustworthy quantum AI. This chapter reviews our recently developed comprehensive formal framework for verifying adversarial robustness in QML. The core of this framework is a fidelity-based robustness lower bound computable directly from the measurement outcome distribution, which enables both formal verification and emp","authors_text":"Ji Guan, Mingsheng Ying","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"quant-ph","submitted_at":"2026-05-28T13:00:48Z","title":"Verifying Adversarial Robustness in Quantum Machine Learning: from theory to physical validation via a software tool"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.29877","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:a194bac5552c41ce4611f8401469867ab4971b8b176f5b8ffe797bcabb29420c","target":"record","created_at":"2026-05-29T02:05:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"9e3cfcd84bea7a9df851ad926cdd60e8fea80b8c65a0c9f836721175e42d2e2c","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"quant-ph","submitted_at":"2026-05-28T13:00:48Z","title_canon_sha256":"d89c4270bde181ab0c87c8fa88743d6a4978f90de2bc2de8fe645a1b45c982f3"},"schema_version":"1.0","source":{"id":"2605.29877","kind":"arxiv","version":1}},"canonical_sha256":"337e5468bf513aedcc950599747ac33072f612fb806abac8505424703eb3d12c","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"337e5468bf513aedcc950599747ac33072f612fb806abac8505424703eb3d12c","first_computed_at":"2026-05-29T02:05:57.333641Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-29T02:05:57.333641Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"VmsJTse9S4qdfzHJ3VJPcPdwEvJlSOWBbPr31sQId0vJAuP7FpbS9t27XdbpLMwLyB9opubY9/uAqhVwYPM5DA==","signature_status":"signed_v1","signed_at":"2026-05-29T02:05:57.334504Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.29877","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:a194bac5552c41ce4611f8401469867ab4971b8b176f5b8ffe797bcabb29420c","sha256:e1ce65beb54f96e59b5afbfd2844645cc705cb3b187323b2b2daa001263a4704"],"state_sha256":"83d41aaead747f2144397858d5da4c1a39e6aa0c8b935fb5ae117fc87e3286ce"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"I7FefCsBZVMMepqDGK5szCcC3dwseM3V1BKoAyCr7ye6ay3Jlz4N/y1/WzWuv/oVGnXrFqpCvh8g62jY1AApBA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-09T14:42:53.165891Z","bundle_sha256":"ad53838e53361b94fa9fa2ee3b681c71e5bbe7dadf1f0a9ab6f553b96d422f13"}}