{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:HDXD7PRGHVNAWTOWIC4LFA3VZA","short_pith_number":"pith:HDXD7PRG","canonical_record":{"source":{"id":"1803.07994","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-03-21T16:25:26Z","cross_cats_sorted":["cs.CV","stat.ML"],"title_canon_sha256":"9752701a169f1518d1729490921c34abeaee0f42b798a778ab767b073c30c753","abstract_canon_sha256":"c67d7241d4f92816cabe7823b06931f4a432d67e8336f0aed6edc591e1b793b1"},"schema_version":"1.0"},"canonical_sha256":"38ee3fbe263d5a0b4dd640b8b28375c81446e846363789de2e5ac75423db499f","source":{"kind":"arxiv","id":"1803.07994","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1803.07994","created_at":"2026-05-18T00:20:28Z"},{"alias_kind":"arxiv_version","alias_value":"1803.07994v1","created_at":"2026-05-18T00:20:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1803.07994","created_at":"2026-05-18T00:20:28Z"},{"alias_kind":"pith_short_12","alias_value":"HDXD7PRGHVNA","created_at":"2026-05-18T12:32:28Z"},{"alias_kind":"pith_short_16","alias_value":"HDXD7PRGHVNAWTOW","created_at":"2026-05-18T12:32:28Z"},{"alias_kind":"pith_short_8","alias_value":"HDXD7PRG","created_at":"2026-05-18T12:32:28Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:HDXD7PRGHVNAWTOWIC4LFA3VZA","target":"record","payload":{"canonical_record":{"source":{"id":"1803.07994","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-03-21T16:25:26Z","cross_cats_sorted":["cs.CV","stat.ML"],"title_canon_sha256":"9752701a169f1518d1729490921c34abeaee0f42b798a778ab767b073c30c753","abstract_canon_sha256":"c67d7241d4f92816cabe7823b06931f4a432d67e8336f0aed6edc591e1b793b1"},"schema_version":"1.0"},"canonical_sha256":"38ee3fbe263d5a0b4dd640b8b28375c81446e846363789de2e5ac75423db499f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:20:28.311631Z","signature_b64":"Cs7JRgybchKiHAGGl9l4qV89u/L7km6jam6jU9Qjo/ChnVpGh/p6c6coqvZsLTq8lHPmqVnvatcxF7HGtWUiDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"38ee3fbe263d5a0b4dd640b8b28375c81446e846363789de2e5ac75423db499f","last_reissued_at":"2026-05-18T00:20:28.311099Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:20:28.311099Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1803.07994","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:20:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"YmukXVXO04ndkajIaiGV2kic/FVxAnKuw/ucQTnXxeBsfJ55mf0fRT0s6jlrah/Df7RjjyDUjjrpjG08PbIvBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T23:02:40.446985Z"},"content_sha256":"1ef6eac4984afc9ef76ca0f9cec236c53f9a32c953dc807d9b03b1868f090144","schema_version":"1.0","event_id":"sha256:1ef6eac4984afc9ef76ca0f9cec236c53f9a32c953dc807d9b03b1868f090144"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:HDXD7PRGHVNAWTOWIC4LFA3VZA","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Adversarial Defense based on Structure-to-Signal Autoencoders","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Andreas Dengel, Damian Borth, Joachim Folz, Joern Hees, Sebastian Palacio","submitted_at":"2018-03-21T16:25:26Z","abstract_excerpt":"Adversarial attack methods have demonstrated the fragility of deep neural networks. Their imperceptible perturbations are frequently able fool classifiers into potentially dangerous misclassifications. We propose a novel way to interpret adversarial perturbations in terms of the effective input signal that classifiers actually use. Based on this, we apply specially trained autoencoders, referred to as S2SNets, as defense mechanism. They follow a two-stage training scheme: first unsupervised, followed by a fine-tuning of the decoder, using gradients from an existing classifier. S2SNets induce a"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1803.07994","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:20:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"QZJVovbEPFqh2HyuKQ+UQ/bIhQKZIbIByjxIutenf6Gcq+HXYD2WygIhznfSKXyw40nvwsqjBJzFWSQJBJVeDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T23:02:40.447334Z"},"content_sha256":"77924d4fe6dcb72d1394ece7f4c794c25499ac5dddec925749a3236b47c39019","schema_version":"1.0","event_id":"sha256:77924d4fe6dcb72d1394ece7f4c794c25499ac5dddec925749a3236b47c39019"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/HDXD7PRGHVNAWTOWIC4LFA3VZA/bundle.json","state_url":"https://pith.science/pith/HDXD7PRGHVNAWTOWIC4LFA3VZA/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/HDXD7PRGHVNAWTOWIC4LFA3VZA/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-01T23:02:40Z","links":{"resolver":"https://pith.science/pith/HDXD7PRGHVNAWTOWIC4LFA3VZA","bundle":"https://pith.science/pith/HDXD7PRGHVNAWTOWIC4LFA3VZA/bundle.json","state":"https://pith.science/pith/HDXD7PRGHVNAWTOWIC4LFA3VZA/state.json","well_known_bundle":"https://pith.science/.well-known/pith/HDXD7PRGHVNAWTOWIC4LFA3VZA/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:HDXD7PRGHVNAWTOWIC4LFA3VZA","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"c67d7241d4f92816cabe7823b06931f4a432d67e8336f0aed6edc591e1b793b1","cross_cats_sorted":["cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-03-21T16:25:26Z","title_canon_sha256":"9752701a169f1518d1729490921c34abeaee0f42b798a778ab767b073c30c753"},"schema_version":"1.0","source":{"id":"1803.07994","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1803.07994","created_at":"2026-05-18T00:20:28Z"},{"alias_kind":"arxiv_version","alias_value":"1803.07994v1","created_at":"2026-05-18T00:20:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1803.07994","created_at":"2026-05-18T00:20:28Z"},{"alias_kind":"pith_short_12","alias_value":"HDXD7PRGHVNA","created_at":"2026-05-18T12:32:28Z"},{"alias_kind":"pith_short_16","alias_value":"HDXD7PRGHVNAWTOW","created_at":"2026-05-18T12:32:28Z"},{"alias_kind":"pith_short_8","alias_value":"HDXD7PRG","created_at":"2026-05-18T12:32:28Z"}],"graph_snapshots":[{"event_id":"sha256:77924d4fe6dcb72d1394ece7f4c794c25499ac5dddec925749a3236b47c39019","target":"graph","created_at":"2026-05-18T00:20:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Adversarial attack methods have demonstrated the fragility of deep neural networks. Their imperceptible perturbations are frequently able fool classifiers into potentially dangerous misclassifications. We propose a novel way to interpret adversarial perturbations in terms of the effective input signal that classifiers actually use. Based on this, we apply specially trained autoencoders, referred to as S2SNets, as defense mechanism. They follow a two-stage training scheme: first unsupervised, followed by a fine-tuning of the decoder, using gradients from an existing classifier. S2SNets induce a","authors_text":"Andreas Dengel, Damian Borth, Joachim Folz, Joern Hees, Sebastian Palacio","cross_cats":["cs.CV","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-03-21T16:25:26Z","title":"Adversarial Defense based on Structure-to-Signal Autoencoders"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1803.07994","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:1ef6eac4984afc9ef76ca0f9cec236c53f9a32c953dc807d9b03b1868f090144","target":"record","created_at":"2026-05-18T00:20:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"c67d7241d4f92816cabe7823b06931f4a432d67e8336f0aed6edc591e1b793b1","cross_cats_sorted":["cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-03-21T16:25:26Z","title_canon_sha256":"9752701a169f1518d1729490921c34abeaee0f42b798a778ab767b073c30c753"},"schema_version":"1.0","source":{"id":"1803.07994","kind":"arxiv","version":1}},"canonical_sha256":"38ee3fbe263d5a0b4dd640b8b28375c81446e846363789de2e5ac75423db499f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"38ee3fbe263d5a0b4dd640b8b28375c81446e846363789de2e5ac75423db499f","first_computed_at":"2026-05-18T00:20:28.311099Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:20:28.311099Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Cs7JRgybchKiHAGGl9l4qV89u/L7km6jam6jU9Qjo/ChnVpGh/p6c6coqvZsLTq8lHPmqVnvatcxF7HGtWUiDw==","signature_status":"signed_v1","signed_at":"2026-05-18T00:20:28.311631Z","signed_message":"canonical_sha256_bytes"},"source_id":"1803.07994","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:1ef6eac4984afc9ef76ca0f9cec236c53f9a32c953dc807d9b03b1868f090144","sha256:77924d4fe6dcb72d1394ece7f4c794c25499ac5dddec925749a3236b47c39019"],"state_sha256":"6f80b102b36e48a07e9f8388565cfff74fccf038614d1545ca5e900f141105f5"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"h/0ocWD/pgC/tYN+31SGZUy4Hmmx1jnrd1NAgF2coEIy/H9hzfQbcXl5AG8OG4ED02mWu4sY73No7vnMv9OeCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-01T23:02:40.449231Z","bundle_sha256":"5770b2b48ec2a62aa09d1d142bd1ce34472d60f3ee0dee3b0596bd255003ef2b"}}