{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:GTPJQ6IQQL323TVLPXC2L5NVMP","short_pith_number":"pith:GTPJQ6IQ","schema_version":"1.0","canonical_sha256":"34de98791082f7adceab7dc5a5f5b563eca2cf322aa5d24842bbfc4e9e31fa7f","source":{"kind":"arxiv","id":"2506.23581","version":2},"attestation_state":"computed","paper":{"title":"PBCAT: Patch-based composite adversarial training against physically realizable attacks on object detection","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CV","authors_text":"Jie Shi, Wei Zhang, Xiao Li, Xiaolin Hu, Yifan Huang, Yiming Zhu, Yingzhe He","submitted_at":"2025-06-30T07:36:21Z","abstract_excerpt":"Object detection plays a crucial role in many security-sensitive applications. However, several recent studies have shown that object detectors can be easily fooled by physically realizable attacks, \\eg, adversarial patches and recent adversarial textures, which pose realistic and urgent threats. Adversarial Training (AT) has been recognized as the most effective defense against adversarial attacks. While AT has been extensively studied in the $l_\\infty$ attack settings on classification models, AT against physically realizable attacks on object detectors has received limited exploration. Earl"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2506.23581","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2025-06-30T07:36:21Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"eb1c6c6d0a385d77c0fad6fca0af9ff571274229bd2f6402fba1aa49d6aa4f37","abstract_canon_sha256":"7d80daba195d5e28be52bbce8a47087e5f9f25efada412adc023217c88e1d1e0"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:34:10.237613Z","signature_b64":"q1Anoo2XoYAL+xAKtkAAhz4MIRJiTGvr6Wt/rktt1eWw7tLvmusGfQrLzjzeNPuvbdsolKurJqV84Zn+YzF4CA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"34de98791082f7adceab7dc5a5f5b563eca2cf322aa5d24842bbfc4e9e31fa7f","last_reissued_at":"2026-07-05T11:34:10.237178Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:34:10.237178Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"PBCAT: Patch-based composite adversarial training against physically realizable attacks on object detection","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CV","authors_text":"Jie Shi, Wei Zhang, Xiao Li, Xiaolin Hu, Yifan Huang, Yiming Zhu, Yingzhe He","submitted_at":"2025-06-30T07:36:21Z","abstract_excerpt":"Object detection plays a crucial role in many security-sensitive applications. However, several recent studies have shown that object detectors can be easily fooled by physically realizable attacks, \\eg, adversarial patches and recent adversarial textures, which pose realistic and urgent threats. Adversarial Training (AT) has been recognized as the most effective defense against adversarial attacks. While AT has been extensively studied in the $l_\\infty$ attack settings on classification models, AT against physically realizable attacks on object detectors has received limited exploration. Earl"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2506.23581","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2506.23581/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2506.23581","created_at":"2026-07-05T11:34:10.237233+00:00"},{"alias_kind":"arxiv_version","alias_value":"2506.23581v2","created_at":"2026-07-05T11:34:10.237233+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2506.23581","created_at":"2026-07-05T11:34:10.237233+00:00"},{"alias_kind":"pith_short_12","alias_value":"GTPJQ6IQQL32","created_at":"2026-07-05T11:34:10.237233+00:00"},{"alias_kind":"pith_short_16","alias_value":"GTPJQ6IQQL323TVL","created_at":"2026-07-05T11:34:10.237233+00:00"},{"alias_kind":"pith_short_8","alias_value":"GTPJQ6IQ","created_at":"2026-07-05T11:34:10.237233+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/GTPJQ6IQQL323TVLPXC2L5NVMP","json":"https://pith.science/pith/GTPJQ6IQQL323TVLPXC2L5NVMP.json","graph_json":"https://pith.science/api/pith-number/GTPJQ6IQQL323TVLPXC2L5NVMP/graph.json","events_json":"https://pith.science/api/pith-number/GTPJQ6IQQL323TVLPXC2L5NVMP/events.json","paper":"https://pith.science/paper/GTPJQ6IQ"},"agent_actions":{"view_html":"https://pith.science/pith/GTPJQ6IQQL323TVLPXC2L5NVMP","download_json":"https://pith.science/pith/GTPJQ6IQQL323TVLPXC2L5NVMP.json","view_paper":"https://pith.science/paper/GTPJQ6IQ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2506.23581&json=true","fetch_graph":"https://pith.science/api/pith-number/GTPJQ6IQQL323TVLPXC2L5NVMP/graph.json","fetch_events":"https://pith.science/api/pith-number/GTPJQ6IQQL323TVLPXC2L5NVMP/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/GTPJQ6IQQL323TVLPXC2L5NVMP/action/timestamp_anchor","attest_storage":"https://pith.science/pith/GTPJQ6IQQL323TVLPXC2L5NVMP/action/storage_attestation","attest_author":"https://pith.science/pith/GTPJQ6IQQL323TVLPXC2L5NVMP/action/author_attestation","sign_citation":"https://pith.science/pith/GTPJQ6IQQL323TVLPXC2L5NVMP/action/citation_signature","submit_replication":"https://pith.science/pith/GTPJQ6IQQL323TVLPXC2L5NVMP/action/replication_record"}},"created_at":"2026-07-05T11:34:10.237233+00:00","updated_at":"2026-07-05T11:34:10.237233+00:00"}