{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:HLRUAN2JXZKVNSHXLELJZFFTAP","short_pith_number":"pith:HLRUAN2J","schema_version":"1.0","canonical_sha256":"3ae3403749be5556c8f759169c94b303d6a4c3217ed1a60aa0b1c001f22ce038","source":{"kind":"arxiv","id":"1909.01492","version":2},"attestation_state":"computed","paper":{"title":"Achieving Verified Robustness to Symbol Substitutions via Interval Bound Propagation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.LG","stat.ML"],"primary_cat":"cs.CL","authors_text":"Chris Dyer, Dani Yogatama, Johannes Welbl, Krishnamurthy Dvijotham, Po-Sen Huang, Pushmeet Kohli, Robert Stanforth, Sven Gowal","submitted_at":"2019-09-03T23:03:10Z","abstract_excerpt":"Neural networks are part of many contemporary NLP systems, yet their empirical successes come at the price of vulnerability to adversarial attacks. Previous work has used adversarial training and data augmentation to partially mitigate such brittleness, but these are unlikely to find worst-case adversaries due to the complexity of the search space arising from discrete text perturbations. In this work, we approach the problem from the opposite direction: to formally verify a system's robustness against a predefined class of adversarial attacks. We study text classification under synonym replac"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1909.01492","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2019-09-03T23:03:10Z","cross_cats_sorted":["cs.CR","cs.LG","stat.ML"],"title_canon_sha256":"eaeecc3c8f450dd77fd9cedab91893d6adb54d1b2442c1c35d4f8c56787e17e6","abstract_canon_sha256":"1167ca3972c9651f1da88cc1073fa2b8a6c73643f218977c74bd4b9a3466fab5"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:27:32.782027Z","signature_b64":"d4TEE/LqWGc1VJVBio6OlmnefAnJJAAAWo+AD3YrbDBYFsQ6ZNEjueKke0+D+YIP3Q8qZvANZvmRzUoR/th6DQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"3ae3403749be5556c8f759169c94b303d6a4c3217ed1a60aa0b1c001f22ce038","last_reissued_at":"2026-07-05T00:27:32.781557Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:27:32.781557Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Achieving Verified Robustness to Symbol Substitutions via Interval Bound Propagation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.LG","stat.ML"],"primary_cat":"cs.CL","authors_text":"Chris Dyer, Dani Yogatama, Johannes Welbl, Krishnamurthy Dvijotham, Po-Sen Huang, Pushmeet Kohli, Robert Stanforth, Sven Gowal","submitted_at":"2019-09-03T23:03:10Z","abstract_excerpt":"Neural networks are part of many contemporary NLP systems, yet their empirical successes come at the price of vulnerability to adversarial attacks. Previous work has used adversarial training and data augmentation to partially mitigate such brittleness, but these are unlikely to find worst-case adversaries due to the complexity of the search space arising from discrete text perturbations. In this work, we approach the problem from the opposite direction: to formally verify a system's robustness against a predefined class of adversarial attacks. We study text classification under synonym replac"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1909.01492","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1909.01492/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1909.01492","created_at":"2026-07-05T00:27:32.781611+00:00"},{"alias_kind":"arxiv_version","alias_value":"1909.01492v2","created_at":"2026-07-05T00:27:32.781611+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1909.01492","created_at":"2026-07-05T00:27:32.781611+00:00"},{"alias_kind":"pith_short_12","alias_value":"HLRUAN2JXZKV","created_at":"2026-07-05T00:27:32.781611+00:00"},{"alias_kind":"pith_short_16","alias_value":"HLRUAN2JXZKVNSHX","created_at":"2026-07-05T00:27:32.781611+00:00"},{"alias_kind":"pith_short_8","alias_value":"HLRUAN2J","created_at":"2026-07-05T00:27:32.781611+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.15416","citing_title":"Margin-Adaptive Confidence Ranking for Reliable LLM Judgement","ref_index":130,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/HLRUAN2JXZKVNSHXLELJZFFTAP","json":"https://pith.science/pith/HLRUAN2JXZKVNSHXLELJZFFTAP.json","graph_json":"https://pith.science/api/pith-number/HLRUAN2JXZKVNSHXLELJZFFTAP/graph.json","events_json":"https://pith.science/api/pith-number/HLRUAN2JXZKVNSHXLELJZFFTAP/events.json","paper":"https://pith.science/paper/HLRUAN2J"},"agent_actions":{"view_html":"https://pith.science/pith/HLRUAN2JXZKVNSHXLELJZFFTAP","download_json":"https://pith.science/pith/HLRUAN2JXZKVNSHXLELJZFFTAP.json","view_paper":"https://pith.science/paper/HLRUAN2J","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1909.01492&json=true","fetch_graph":"https://pith.science/api/pith-number/HLRUAN2JXZKVNSHXLELJZFFTAP/graph.json","fetch_events":"https://pith.science/api/pith-number/HLRUAN2JXZKVNSHXLELJZFFTAP/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/HLRUAN2JXZKVNSHXLELJZFFTAP/action/timestamp_anchor","attest_storage":"https://pith.science/pith/HLRUAN2JXZKVNSHXLELJZFFTAP/action/storage_attestation","attest_author":"https://pith.science/pith/HLRUAN2JXZKVNSHXLELJZFFTAP/action/author_attestation","sign_citation":"https://pith.science/pith/HLRUAN2JXZKVNSHXLELJZFFTAP/action/citation_signature","submit_replication":"https://pith.science/pith/HLRUAN2JXZKVNSHXLELJZFFTAP/action/replication_record"}},"created_at":"2026-07-05T00:27:32.781611+00:00","updated_at":"2026-07-05T00:27:32.781611+00:00"}