{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:HSVMBIWLPZIIK4BE4ZA77WMMLK","short_pith_number":"pith:HSVMBIWL","schema_version":"1.0","canonical_sha256":"3caac0a2cb7e50857024e641ffd98c5a9243e5e37d56b9b840c7e4180fed3027","source":{"kind":"arxiv","id":"2506.03765","version":1},"attestation_state":"computed","paper":{"title":"Prediction Inconsistency Helps Achieve Generalizable Detection of Adversarial Examples","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Chao Shen, Chenhao Lin, Cong Wang, Qian Li, Qian Wang, Sicong Han, Xinlei He, Xiyuan Wang, Zhengyu Zhao","submitted_at":"2025-06-04T09:29:11Z","abstract_excerpt":"Adversarial detection protects models from adversarial attacks by refusing suspicious test samples. However, current detection methods often suffer from weak generalization: their effectiveness tends to degrade significantly when applied to adversarially trained models rather than naturally trained ones, and they generally struggle to achieve consistent effectiveness across both white-box and black-box attack settings. In this work, we observe that an auxiliary model, differing from the primary model in training strategy or model architecture, tends to assign low confidence to the primary mode"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2506.03765","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2025-06-04T09:29:11Z","cross_cats_sorted":[],"title_canon_sha256":"636383ffcca0055f06fb8f18b76e4457e00314e15a574fd458b87519df0e9c84","abstract_canon_sha256":"f35b3796c2a55c5d8fe329cfa91ecb6f3cc1ec29fc449345be9cabee52101597"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:15:51.618720Z","signature_b64":"3BSCPAhBH4iMPiXGW/2maJUORMQAAcCIIk4Sp0TotiWEUXAEbk2MecHcE302Wi1ZrjTB80/FjL4LkNdMnLAFDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"3caac0a2cb7e50857024e641ffd98c5a9243e5e37d56b9b840c7e4180fed3027","last_reissued_at":"2026-07-05T11:15:51.618231Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:15:51.618231Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Prediction Inconsistency Helps Achieve Generalizable Detection of Adversarial Examples","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Chao Shen, Chenhao Lin, Cong Wang, Qian Li, Qian Wang, Sicong Han, Xinlei He, Xiyuan Wang, Zhengyu Zhao","submitted_at":"2025-06-04T09:29:11Z","abstract_excerpt":"Adversarial detection protects models from adversarial attacks by refusing suspicious test samples. However, current detection methods often suffer from weak generalization: their effectiveness tends to degrade significantly when applied to adversarially trained models rather than naturally trained ones, and they generally struggle to achieve consistent effectiveness across both white-box and black-box attack settings. In this work, we observe that an auxiliary model, differing from the primary model in training strategy or model architecture, tends to assign low confidence to the primary mode"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2506.03765","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2506.03765/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2506.03765","created_at":"2026-07-05T11:15:51.618286+00:00"},{"alias_kind":"arxiv_version","alias_value":"2506.03765v1","created_at":"2026-07-05T11:15:51.618286+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2506.03765","created_at":"2026-07-05T11:15:51.618286+00:00"},{"alias_kind":"pith_short_12","alias_value":"HSVMBIWLPZII","created_at":"2026-07-05T11:15:51.618286+00:00"},{"alias_kind":"pith_short_16","alias_value":"HSVMBIWLPZIIK4BE","created_at":"2026-07-05T11:15:51.618286+00:00"},{"alias_kind":"pith_short_8","alias_value":"HSVMBIWL","created_at":"2026-07-05T11:15:51.618286+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/HSVMBIWLPZIIK4BE4ZA77WMMLK","json":"https://pith.science/pith/HSVMBIWLPZIIK4BE4ZA77WMMLK.json","graph_json":"https://pith.science/api/pith-number/HSVMBIWLPZIIK4BE4ZA77WMMLK/graph.json","events_json":"https://pith.science/api/pith-number/HSVMBIWLPZIIK4BE4ZA77WMMLK/events.json","paper":"https://pith.science/paper/HSVMBIWL"},"agent_actions":{"view_html":"https://pith.science/pith/HSVMBIWLPZIIK4BE4ZA77WMMLK","download_json":"https://pith.science/pith/HSVMBIWLPZIIK4BE4ZA77WMMLK.json","view_paper":"https://pith.science/paper/HSVMBIWL","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2506.03765&json=true","fetch_graph":"https://pith.science/api/pith-number/HSVMBIWLPZIIK4BE4ZA77WMMLK/graph.json","fetch_events":"https://pith.science/api/pith-number/HSVMBIWLPZIIK4BE4ZA77WMMLK/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/HSVMBIWLPZIIK4BE4ZA77WMMLK/action/timestamp_anchor","attest_storage":"https://pith.science/pith/HSVMBIWLPZIIK4BE4ZA77WMMLK/action/storage_attestation","attest_author":"https://pith.science/pith/HSVMBIWLPZIIK4BE4ZA77WMMLK/action/author_attestation","sign_citation":"https://pith.science/pith/HSVMBIWLPZIIK4BE4ZA77WMMLK/action/citation_signature","submit_replication":"https://pith.science/pith/HSVMBIWLPZIIK4BE4ZA77WMMLK/action/replication_record"}},"created_at":"2026-07-05T11:15:51.618286+00:00","updated_at":"2026-07-05T11:15:51.618286+00:00"}