{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:HMMSTWQHP4NENANJYEY3CMIWML","short_pith_number":"pith:HMMSTWQH","schema_version":"1.0","canonical_sha256":"3b1929da077f1a4681a9c131b1311662fa7b8226fb9e193c9f86b5ba2408e2da","source":{"kind":"arxiv","id":"2101.02899","version":1},"attestation_state":"computed","paper":{"title":"Adversarial Attack Attribution: Discovering Attributable Signals in Adversarial ML Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV"],"primary_cat":"cs.LG","authors_text":"Colin Busho, Josh Harguess, Keith Manville, Marissa Dotter, Mikel Rodriguez, Sherry Xie","submitted_at":"2021-01-08T08:16:41Z","abstract_excerpt":"Machine Learning (ML) models are known to be vulnerable to adversarial inputs and researchers have demonstrated that even production systems, such as self-driving cars and ML-as-a-service offerings, are susceptible. These systems represent a target for bad actors. Their disruption can cause real physical and economic harm. When attacks on production ML systems occur, the ability to attribute the attack to the responsible threat group is a critical step in formulating a response and holding the attackers accountable. We pose the following question: can adversarially perturbed inputs be attribut"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2101.02899","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2021-01-08T08:16:41Z","cross_cats_sorted":["cs.CR","cs.CV"],"title_canon_sha256":"06e6d18b1ba30b506eed9aa87110a89b3928c82b150e8432b41829da137a58bf","abstract_canon_sha256":"f7b836470e1eae195ae0a953340f21d4b954af1135bdef1db9138507cc5f955e"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T02:05:31.645776Z","signature_b64":"GJR4XZiKMhYS/jZoQpTUY4OBAIaOPnmR9bMMm7bk0itZJEUP2uRonpG0rCNMeSvSAWxajC+lp+jAV+v0J5gyDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"3b1929da077f1a4681a9c131b1311662fa7b8226fb9e193c9f86b5ba2408e2da","last_reissued_at":"2026-07-05T02:05:31.645423Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T02:05:31.645423Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Adversarial Attack Attribution: Discovering Attributable Signals in Adversarial ML Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV"],"primary_cat":"cs.LG","authors_text":"Colin Busho, Josh Harguess, Keith Manville, Marissa Dotter, Mikel Rodriguez, Sherry Xie","submitted_at":"2021-01-08T08:16:41Z","abstract_excerpt":"Machine Learning (ML) models are known to be vulnerable to adversarial inputs and researchers have demonstrated that even production systems, such as self-driving cars and ML-as-a-service offerings, are susceptible. These systems represent a target for bad actors. Their disruption can cause real physical and economic harm. When attacks on production ML systems occur, the ability to attribute the attack to the responsible threat group is a critical step in formulating a response and holding the attackers accountable. We pose the following question: can adversarially perturbed inputs be attribut"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2101.02899","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2101.02899/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2101.02899","created_at":"2026-07-05T02:05:31.645476+00:00"},{"alias_kind":"arxiv_version","alias_value":"2101.02899v1","created_at":"2026-07-05T02:05:31.645476+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2101.02899","created_at":"2026-07-05T02:05:31.645476+00:00"},{"alias_kind":"pith_short_12","alias_value":"HMMSTWQHP4NE","created_at":"2026-07-05T02:05:31.645476+00:00"},{"alias_kind":"pith_short_16","alias_value":"HMMSTWQHP4NENANJ","created_at":"2026-07-05T02:05:31.645476+00:00"},{"alias_kind":"pith_short_8","alias_value":"HMMSTWQH","created_at":"2026-07-05T02:05:31.645476+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2412.11384","citing_title":"A Comprehensive Review of Adversarial Attacks on Machine Learning","ref_index":7,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/HMMSTWQHP4NENANJYEY3CMIWML","json":"https://pith.science/pith/HMMSTWQHP4NENANJYEY3CMIWML.json","graph_json":"https://pith.science/api/pith-number/HMMSTWQHP4NENANJYEY3CMIWML/graph.json","events_json":"https://pith.science/api/pith-number/HMMSTWQHP4NENANJYEY3CMIWML/events.json","paper":"https://pith.science/paper/HMMSTWQH"},"agent_actions":{"view_html":"https://pith.science/pith/HMMSTWQHP4NENANJYEY3CMIWML","download_json":"https://pith.science/pith/HMMSTWQHP4NENANJYEY3CMIWML.json","view_paper":"https://pith.science/paper/HMMSTWQH","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2101.02899&json=true","fetch_graph":"https://pith.science/api/pith-number/HMMSTWQHP4NENANJYEY3CMIWML/graph.json","fetch_events":"https://pith.science/api/pith-number/HMMSTWQHP4NENANJYEY3CMIWML/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/HMMSTWQHP4NENANJYEY3CMIWML/action/timestamp_anchor","attest_storage":"https://pith.science/pith/HMMSTWQHP4NENANJYEY3CMIWML/action/storage_attestation","attest_author":"https://pith.science/pith/HMMSTWQHP4NENANJYEY3CMIWML/action/author_attestation","sign_citation":"https://pith.science/pith/HMMSTWQHP4NENANJYEY3CMIWML/action/citation_signature","submit_replication":"https://pith.science/pith/HMMSTWQHP4NENANJYEY3CMIWML/action/replication_record"}},"created_at":"2026-07-05T02:05:31.645476+00:00","updated_at":"2026-07-05T02:05:31.645476+00:00"}