{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:HLKKBM75UCU3ZJWXGGJYA3JPPO","short_pith_number":"pith:HLKKBM75","canonical_record":{"source":{"id":"1703.01101","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-03-03T10:27:16Z","cross_cats_sorted":["cs.CR","cs.CV","cs.LG","cs.NE"],"title_canon_sha256":"25fb7545a1b2d63f21c31692bf961dc942f60a2c206bae58caf49c54efc9b57f","abstract_canon_sha256":"3a56d1bf26b97ebca65885198b4ab9c7a97554ee019c5bd423036711b694dea8"},"schema_version":"1.0"},"canonical_sha256":"3ad4a0b3fda0a9bca6d73193806d2f7b84b2d75bd3c77b292e5f658401875453","source":{"kind":"arxiv","id":"1703.01101","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1703.01101","created_at":"2026-05-18T00:49:36Z"},{"alias_kind":"arxiv_version","alias_value":"1703.01101v1","created_at":"2026-05-18T00:49:36Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1703.01101","created_at":"2026-05-18T00:49:36Z"},{"alias_kind":"pith_short_12","alias_value":"HLKKBM75UCU3","created_at":"2026-05-18T12:31:18Z"},{"alias_kind":"pith_short_16","alias_value":"HLKKBM75UCU3ZJWX","created_at":"2026-05-18T12:31:18Z"},{"alias_kind":"pith_short_8","alias_value":"HLKKBM75","created_at":"2026-05-18T12:31:18Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:HLKKBM75UCU3ZJWXGGJYA3JPPO","target":"record","payload":{"canonical_record":{"source":{"id":"1703.01101","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-03-03T10:27:16Z","cross_cats_sorted":["cs.CR","cs.CV","cs.LG","cs.NE"],"title_canon_sha256":"25fb7545a1b2d63f21c31692bf961dc942f60a2c206bae58caf49c54efc9b57f","abstract_canon_sha256":"3a56d1bf26b97ebca65885198b4ab9c7a97554ee019c5bd423036711b694dea8"},"schema_version":"1.0"},"canonical_sha256":"3ad4a0b3fda0a9bca6d73193806d2f7b84b2d75bd3c77b292e5f658401875453","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:49:36.005616Z","signature_b64":"qlxsjHhoQUkSMXP43INRZCEliqOE3NkSH0taSGJ+ppFnvVqq54PuW9YIdI5TWrymKM8MKve6JiQAHPYtt57KDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"3ad4a0b3fda0a9bca6d73193806d2f7b84b2d75bd3c77b292e5f658401875453","last_reissued_at":"2026-05-18T00:49:36.004875Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:49:36.004875Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1703.01101","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:49:36Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"DXEMe8kUkGdZp6cBkPc8IMkCXa//mM67cj85b3Y+DDj6iVIrpQIpSOMPjgjQ0zIFMO3HA9Jhkg4Vxltoq5OnAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-07T10:26:50.431338Z"},"content_sha256":"2720a0d5442bc8587d7aaa7e40c29fbfc0f7321b16e443de460e1bdf0060e387","schema_version":"1.0","event_id":"sha256:2720a0d5442bc8587d7aaa7e40c29fbfc0f7321b16e443de460e1bdf0060e387"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:HLKKBM75UCU3ZJWXGGJYA3JPPO","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Adversarial Examples for Semantic Image Segmentation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","cs.LG","cs.NE"],"primary_cat":"stat.ML","authors_text":"Jan Hendrik Metzen, Mummadi Chaithanya Kumar, Thomas Brox, Volker Fischer","submitted_at":"2017-03-03T10:27:16Z","abstract_excerpt":"Machine learning methods in general and Deep Neural Networks in particular have shown to be vulnerable to adversarial perturbations. So far this phenomenon has mainly been studied in the context of whole-image classification. In this contribution, we analyse how adversarial perturbations can affect the task of semantic segmentation. We show how existing adversarial attackers can be transferred to this task and that it is possible to create imperceptible adversarial perturbations that lead a deep network to misclassify almost all pixels of a chosen class while leaving network prediction nearly "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1703.01101","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:49:36Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"wv/999c0LfI6boWU/KbM2RWbz57t5a33HvgpCq0foj2dPtq4ctOM8HQpFIHi+KbAnZL/Y9uVSstieH9q9sv2Dw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-07T10:26:50.431906Z"},"content_sha256":"0216cc904b87eeeb6e62eff3cb866fc999dd30d1e7c80a51ac13eee343f69f8d","schema_version":"1.0","event_id":"sha256:0216cc904b87eeeb6e62eff3cb866fc999dd30d1e7c80a51ac13eee343f69f8d"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/HLKKBM75UCU3ZJWXGGJYA3JPPO/bundle.json","state_url":"https://pith.science/pith/HLKKBM75UCU3ZJWXGGJYA3JPPO/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/HLKKBM75UCU3ZJWXGGJYA3JPPO/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-07T10:26:50Z","links":{"resolver":"https://pith.science/pith/HLKKBM75UCU3ZJWXGGJYA3JPPO","bundle":"https://pith.science/pith/HLKKBM75UCU3ZJWXGGJYA3JPPO/bundle.json","state":"https://pith.science/pith/HLKKBM75UCU3ZJWXGGJYA3JPPO/state.json","well_known_bundle":"https://pith.science/.well-known/pith/HLKKBM75UCU3ZJWXGGJYA3JPPO/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:HLKKBM75UCU3ZJWXGGJYA3JPPO","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"3a56d1bf26b97ebca65885198b4ab9c7a97554ee019c5bd423036711b694dea8","cross_cats_sorted":["cs.CR","cs.CV","cs.LG","cs.NE"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-03-03T10:27:16Z","title_canon_sha256":"25fb7545a1b2d63f21c31692bf961dc942f60a2c206bae58caf49c54efc9b57f"},"schema_version":"1.0","source":{"id":"1703.01101","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1703.01101","created_at":"2026-05-18T00:49:36Z"},{"alias_kind":"arxiv_version","alias_value":"1703.01101v1","created_at":"2026-05-18T00:49:36Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1703.01101","created_at":"2026-05-18T00:49:36Z"},{"alias_kind":"pith_short_12","alias_value":"HLKKBM75UCU3","created_at":"2026-05-18T12:31:18Z"},{"alias_kind":"pith_short_16","alias_value":"HLKKBM75UCU3ZJWX","created_at":"2026-05-18T12:31:18Z"},{"alias_kind":"pith_short_8","alias_value":"HLKKBM75","created_at":"2026-05-18T12:31:18Z"}],"graph_snapshots":[{"event_id":"sha256:0216cc904b87eeeb6e62eff3cb866fc999dd30d1e7c80a51ac13eee343f69f8d","target":"graph","created_at":"2026-05-18T00:49:36Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Machine learning methods in general and Deep Neural Networks in particular have shown to be vulnerable to adversarial perturbations. So far this phenomenon has mainly been studied in the context of whole-image classification. In this contribution, we analyse how adversarial perturbations can affect the task of semantic segmentation. We show how existing adversarial attackers can be transferred to this task and that it is possible to create imperceptible adversarial perturbations that lead a deep network to misclassify almost all pixels of a chosen class while leaving network prediction nearly ","authors_text":"Jan Hendrik Metzen, Mummadi Chaithanya Kumar, Thomas Brox, Volker Fischer","cross_cats":["cs.CR","cs.CV","cs.LG","cs.NE"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-03-03T10:27:16Z","title":"Adversarial Examples for Semantic Image Segmentation"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1703.01101","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:2720a0d5442bc8587d7aaa7e40c29fbfc0f7321b16e443de460e1bdf0060e387","target":"record","created_at":"2026-05-18T00:49:36Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"3a56d1bf26b97ebca65885198b4ab9c7a97554ee019c5bd423036711b694dea8","cross_cats_sorted":["cs.CR","cs.CV","cs.LG","cs.NE"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-03-03T10:27:16Z","title_canon_sha256":"25fb7545a1b2d63f21c31692bf961dc942f60a2c206bae58caf49c54efc9b57f"},"schema_version":"1.0","source":{"id":"1703.01101","kind":"arxiv","version":1}},"canonical_sha256":"3ad4a0b3fda0a9bca6d73193806d2f7b84b2d75bd3c77b292e5f658401875453","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"3ad4a0b3fda0a9bca6d73193806d2f7b84b2d75bd3c77b292e5f658401875453","first_computed_at":"2026-05-18T00:49:36.004875Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:49:36.004875Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"qlxsjHhoQUkSMXP43INRZCEliqOE3NkSH0taSGJ+ppFnvVqq54PuW9YIdI5TWrymKM8MKve6JiQAHPYtt57KDw==","signature_status":"signed_v1","signed_at":"2026-05-18T00:49:36.005616Z","signed_message":"canonical_sha256_bytes"},"source_id":"1703.01101","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:2720a0d5442bc8587d7aaa7e40c29fbfc0f7321b16e443de460e1bdf0060e387","sha256:0216cc904b87eeeb6e62eff3cb866fc999dd30d1e7c80a51ac13eee343f69f8d"],"state_sha256":"97839aea8a8747222edd29911e102dd44b37090c8de64d1bea6065517f640945"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"J/DO5HPcFUoG6BxGR3i4NNtEt9xO0uVLZdzxZJe4NZqVkGJG+FAjYhpSbmhbOe80PAo+DDWzeXI9wMUCc4C6CQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-07T10:26:50.434896Z","bundle_sha256":"6a2eb4a231fd648b33af02a2b8a9960b6665d6096d019e10e65a1c9e6e56a1c9"}}