{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:GRHSDRPX3QUTWEBKDVQOGXFMR5","short_pith_number":"pith:GRHSDRPX","canonical_record":{"source":{"id":"1705.07535","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-05-22T01:58:59Z","cross_cats_sorted":[],"title_canon_sha256":"d5f3a4e62ffa227716ce247cd52a80f2103142beed54db65ed2e9792f66c8fbd","abstract_canon_sha256":"d233ce1ed7a816ec34f9a1f1d53225634246a16e353debdc555cdd377f132d8d"},"schema_version":"1.0"},"canonical_sha256":"344f21c5f7dc293b102a1d60e35cac8f555dfdb23f40d24bb8942d53b0c1cfd2","source":{"kind":"arxiv","id":"1705.07535","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1705.07535","created_at":"2026-05-18T00:36:49Z"},{"alias_kind":"arxiv_version","alias_value":"1705.07535v3","created_at":"2026-05-18T00:36:49Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1705.07535","created_at":"2026-05-18T00:36:49Z"},{"alias_kind":"pith_short_12","alias_value":"GRHSDRPX3QUT","created_at":"2026-05-18T12:31:18Z"},{"alias_kind":"pith_short_16","alias_value":"GRHSDRPX3QUTWEBK","created_at":"2026-05-18T12:31:18Z"},{"alias_kind":"pith_short_8","alias_value":"GRHSDRPX","created_at":"2026-05-18T12:31:18Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:GRHSDRPX3QUTWEBKDVQOGXFMR5","target":"record","payload":{"canonical_record":{"source":{"id":"1705.07535","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-05-22T01:58:59Z","cross_cats_sorted":[],"title_canon_sha256":"d5f3a4e62ffa227716ce247cd52a80f2103142beed54db65ed2e9792f66c8fbd","abstract_canon_sha256":"d233ce1ed7a816ec34f9a1f1d53225634246a16e353debdc555cdd377f132d8d"},"schema_version":"1.0"},"canonical_sha256":"344f21c5f7dc293b102a1d60e35cac8f555dfdb23f40d24bb8942d53b0c1cfd2","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:36:49.342807Z","signature_b64":"jHVqKAWBKtE2cdLkMShVeJZQIkwnKFREBpsEF6wgMUH8ozE0veV02Un2vxZZn7I3swDvNcLXuPV6gUzIS7W6Cg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"344f21c5f7dc293b102a1d60e35cac8f555dfdb23f40d24bb8942d53b0c1cfd2","last_reissued_at":"2026-05-18T00:36:49.342159Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:36:49.342159Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1705.07535","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:36:49Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Kkvx1oxWjdOH5mWZTuS7ib9055k+8+0rkAORtv8Mz51oCFloJOXYzenLdwmtxMDl0XV0Mpy32hA6bE50yKWSDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T06:10:44.318583Z"},"content_sha256":"9fbfab9c74db7177426ba1043ebf65f92ee4ade594b7928444f93a5c19f90054","schema_version":"1.0","event_id":"sha256:9fbfab9c74db7177426ba1043ebf65f92ee4ade594b7928444f93a5c19f90054"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:GRHSDRPX3QUTWEBKDVQOGXFMR5","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Evading Classifiers by Morphing in the Dark","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Ee-Chien Chang, Hung Dang, Yue Huang","submitted_at":"2017-05-22T01:58:59Z","abstract_excerpt":"Learning-based systems have been shown to be vulnerable to evasion through adversarial data manipulation. These attacks have been studied under assumptions that the adversary has certain knowledge of either the target model internals, its training dataset or at least classification scores it assigns to input samples. In this paper, we investigate a much more constrained and realistic attack scenario wherein the target classifier is minimally exposed to the adversary, revealing on its final classification decision (e.g., reject or accept an input sample). Moreover, the adversary can only manipu"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1705.07535","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:36:49Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"UyWjvnTUDPfM7HX00azyNxO0lQa3LjEh5pYPqjPxb5PSRDLvxCK0bd9CxxNJSdjNJEmAGrE9LkKB/qft7zW7Bg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T06:10:44.319223Z"},"content_sha256":"189fa8fbf7700236de92f4d2250f30510bf20041727bad96ab4f15575da75f71","schema_version":"1.0","event_id":"sha256:189fa8fbf7700236de92f4d2250f30510bf20041727bad96ab4f15575da75f71"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/GRHSDRPX3QUTWEBKDVQOGXFMR5/bundle.json","state_url":"https://pith.science/pith/GRHSDRPX3QUTWEBKDVQOGXFMR5/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/GRHSDRPX3QUTWEBKDVQOGXFMR5/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-09T06:10:44Z","links":{"resolver":"https://pith.science/pith/GRHSDRPX3QUTWEBKDVQOGXFMR5","bundle":"https://pith.science/pith/GRHSDRPX3QUTWEBKDVQOGXFMR5/bundle.json","state":"https://pith.science/pith/GRHSDRPX3QUTWEBKDVQOGXFMR5/state.json","well_known_bundle":"https://pith.science/.well-known/pith/GRHSDRPX3QUTWEBKDVQOGXFMR5/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:GRHSDRPX3QUTWEBKDVQOGXFMR5","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"d233ce1ed7a816ec34f9a1f1d53225634246a16e353debdc555cdd377f132d8d","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-05-22T01:58:59Z","title_canon_sha256":"d5f3a4e62ffa227716ce247cd52a80f2103142beed54db65ed2e9792f66c8fbd"},"schema_version":"1.0","source":{"id":"1705.07535","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1705.07535","created_at":"2026-05-18T00:36:49Z"},{"alias_kind":"arxiv_version","alias_value":"1705.07535v3","created_at":"2026-05-18T00:36:49Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1705.07535","created_at":"2026-05-18T00:36:49Z"},{"alias_kind":"pith_short_12","alias_value":"GRHSDRPX3QUT","created_at":"2026-05-18T12:31:18Z"},{"alias_kind":"pith_short_16","alias_value":"GRHSDRPX3QUTWEBK","created_at":"2026-05-18T12:31:18Z"},{"alias_kind":"pith_short_8","alias_value":"GRHSDRPX","created_at":"2026-05-18T12:31:18Z"}],"graph_snapshots":[{"event_id":"sha256:189fa8fbf7700236de92f4d2250f30510bf20041727bad96ab4f15575da75f71","target":"graph","created_at":"2026-05-18T00:36:49Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Learning-based systems have been shown to be vulnerable to evasion through adversarial data manipulation. These attacks have been studied under assumptions that the adversary has certain knowledge of either the target model internals, its training dataset or at least classification scores it assigns to input samples. In this paper, we investigate a much more constrained and realistic attack scenario wherein the target classifier is minimally exposed to the adversary, revealing on its final classification decision (e.g., reject or accept an input sample). Moreover, the adversary can only manipu","authors_text":"Ee-Chien Chang, Hung Dang, Yue Huang","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-05-22T01:58:59Z","title":"Evading Classifiers by Morphing in the Dark"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1705.07535","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:9fbfab9c74db7177426ba1043ebf65f92ee4ade594b7928444f93a5c19f90054","target":"record","created_at":"2026-05-18T00:36:49Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"d233ce1ed7a816ec34f9a1f1d53225634246a16e353debdc555cdd377f132d8d","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-05-22T01:58:59Z","title_canon_sha256":"d5f3a4e62ffa227716ce247cd52a80f2103142beed54db65ed2e9792f66c8fbd"},"schema_version":"1.0","source":{"id":"1705.07535","kind":"arxiv","version":3}},"canonical_sha256":"344f21c5f7dc293b102a1d60e35cac8f555dfdb23f40d24bb8942d53b0c1cfd2","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"344f21c5f7dc293b102a1d60e35cac8f555dfdb23f40d24bb8942d53b0c1cfd2","first_computed_at":"2026-05-18T00:36:49.342159Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:36:49.342159Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"jHVqKAWBKtE2cdLkMShVeJZQIkwnKFREBpsEF6wgMUH8ozE0veV02Un2vxZZn7I3swDvNcLXuPV6gUzIS7W6Cg==","signature_status":"signed_v1","signed_at":"2026-05-18T00:36:49.342807Z","signed_message":"canonical_sha256_bytes"},"source_id":"1705.07535","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:9fbfab9c74db7177426ba1043ebf65f92ee4ade594b7928444f93a5c19f90054","sha256:189fa8fbf7700236de92f4d2250f30510bf20041727bad96ab4f15575da75f71"],"state_sha256":"bdd4ea047e9d8f89d4d3dc9a781e320056db3597a3583b1d1e2cc3297514d811"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"7SQbVj3LZ7vu6iL7y4gAk7fyDqSZQOCczwx8nyaRFz8A8xlN9EFFhgog6nk9QRvxQEl9pYyUslo+Ll6DtE44Dg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-09T06:10:44.322627Z","bundle_sha256":"473896c5f3a31981ff4cc0b549b39e49c733dd10ceb86f989dee7dae813e1f55"}}