{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:HUVJ2H7MNZNJ2VG5L5QFUDITPZ","short_pith_number":"pith:HUVJ2H7M","canonical_record":{"source":{"id":"1811.11373","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-28T03:36:25Z","cross_cats_sorted":["cs.CV","stat.ML"],"title_canon_sha256":"06fb50f99a7facfbe6b62c8c5e6ff1ee6f4b97c0396384b15dc0a4aa024306e6","abstract_canon_sha256":"e8af810e800066ed405af60c33fbbee016b9ba2b7003a70cfd737701881b39ad"},"schema_version":"1.0"},"canonical_sha256":"3d2a9d1fec6e5a9d54dd5f605a0d137e5a3ffc7f2d886a32ab612f6469cdb2c7","source":{"kind":"arxiv","id":"1811.11373","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1811.11373","created_at":"2026-05-17T23:59:43Z"},{"alias_kind":"arxiv_version","alias_value":"1811.11373v1","created_at":"2026-05-17T23:59:43Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.11373","created_at":"2026-05-17T23:59:43Z"},{"alias_kind":"pith_short_12","alias_value":"HUVJ2H7MNZNJ","created_at":"2026-05-18T12:32:28Z"},{"alias_kind":"pith_short_16","alias_value":"HUVJ2H7MNZNJ2VG5","created_at":"2026-05-18T12:32:28Z"},{"alias_kind":"pith_short_8","alias_value":"HUVJ2H7M","created_at":"2026-05-18T12:32:28Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:HUVJ2H7MNZNJ2VG5L5QFUDITPZ","target":"record","payload":{"canonical_record":{"source":{"id":"1811.11373","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-28T03:36:25Z","cross_cats_sorted":["cs.CV","stat.ML"],"title_canon_sha256":"06fb50f99a7facfbe6b62c8c5e6ff1ee6f4b97c0396384b15dc0a4aa024306e6","abstract_canon_sha256":"e8af810e800066ed405af60c33fbbee016b9ba2b7003a70cfd737701881b39ad"},"schema_version":"1.0"},"canonical_sha256":"3d2a9d1fec6e5a9d54dd5f605a0d137e5a3ffc7f2d886a32ab612f6469cdb2c7","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:59:43.143344Z","signature_b64":"YtssfacX3CIldvfv04JGa3cvNnwFHsHeb7gfeGpf9qhWRCNGsVF7aQUOBzT4kFRXCc/CvBOb1Cpggb3T4/TgBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"3d2a9d1fec6e5a9d54dd5f605a0d137e5a3ffc7f2d886a32ab612f6469cdb2c7","last_reissued_at":"2026-05-17T23:59:43.142771Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:59:43.142771Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1811.11373","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:59:43Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"eQiHI6H0mk950fLrw5nKBCnC+15+OvNjyYV285XvTTVR+MAIH4lIdb5EASKQ/h1ToOR8Rhu2avsT+RvbFnyeCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T23:41:44.895618Z"},"content_sha256":"45ea748ba81fc6185dc3c7023fc03362f89ac9d15943eddb4e4bd4c7577e0492","schema_version":"1.0","event_id":"sha256:45ea748ba81fc6185dc3c7023fc03362f89ac9d15943eddb4e4bd4c7577e0492"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:HUVJ2H7MNZNJ2VG5L5QFUDITPZ","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Formal Verification of CNN-based Perception Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Alessio Lomuscio, Panagiotis Kouvaros","submitted_at":"2018-11-28T03:36:25Z","abstract_excerpt":"We address the problem of verifying neural-based perception systems implemented by convolutional neural networks. We define a notion of local robustness based on affine and photometric transformations. We show the notion cannot be captured by previously employed notions of robustness. The method proposed is based on reachability analysis for feed-forward neural networks and relies on MILP encodings of both the CNNs and transformations under question. We present an implementation and discuss the experimental results obtained for a CNN trained from the MNIST data set."},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.11373","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:59:43Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"4/mmCLXR+h0z9A4Bb5n+WofU26kUZjzdcWfEQH2GDw2cZ981+7EHv3+pLuZeUScQ96yx4W94xnEBAgIyXmLtCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T23:41:44.895968Z"},"content_sha256":"c1eb85f2eb0e35afd4cb035a1d880459428047fa05a716e27f3e324eff8ba62d","schema_version":"1.0","event_id":"sha256:c1eb85f2eb0e35afd4cb035a1d880459428047fa05a716e27f3e324eff8ba62d"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/HUVJ2H7MNZNJ2VG5L5QFUDITPZ/bundle.json","state_url":"https://pith.science/pith/HUVJ2H7MNZNJ2VG5L5QFUDITPZ/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/HUVJ2H7MNZNJ2VG5L5QFUDITPZ/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T23:41:44Z","links":{"resolver":"https://pith.science/pith/HUVJ2H7MNZNJ2VG5L5QFUDITPZ","bundle":"https://pith.science/pith/HUVJ2H7MNZNJ2VG5L5QFUDITPZ/bundle.json","state":"https://pith.science/pith/HUVJ2H7MNZNJ2VG5L5QFUDITPZ/state.json","well_known_bundle":"https://pith.science/.well-known/pith/HUVJ2H7MNZNJ2VG5L5QFUDITPZ/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:HUVJ2H7MNZNJ2VG5L5QFUDITPZ","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e8af810e800066ed405af60c33fbbee016b9ba2b7003a70cfd737701881b39ad","cross_cats_sorted":["cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-28T03:36:25Z","title_canon_sha256":"06fb50f99a7facfbe6b62c8c5e6ff1ee6f4b97c0396384b15dc0a4aa024306e6"},"schema_version":"1.0","source":{"id":"1811.11373","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1811.11373","created_at":"2026-05-17T23:59:43Z"},{"alias_kind":"arxiv_version","alias_value":"1811.11373v1","created_at":"2026-05-17T23:59:43Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.11373","created_at":"2026-05-17T23:59:43Z"},{"alias_kind":"pith_short_12","alias_value":"HUVJ2H7MNZNJ","created_at":"2026-05-18T12:32:28Z"},{"alias_kind":"pith_short_16","alias_value":"HUVJ2H7MNZNJ2VG5","created_at":"2026-05-18T12:32:28Z"},{"alias_kind":"pith_short_8","alias_value":"HUVJ2H7M","created_at":"2026-05-18T12:32:28Z"}],"graph_snapshots":[{"event_id":"sha256:c1eb85f2eb0e35afd4cb035a1d880459428047fa05a716e27f3e324eff8ba62d","target":"graph","created_at":"2026-05-17T23:59:43Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We address the problem of verifying neural-based perception systems implemented by convolutional neural networks. We define a notion of local robustness based on affine and photometric transformations. We show the notion cannot be captured by previously employed notions of robustness. The method proposed is based on reachability analysis for feed-forward neural networks and relies on MILP encodings of both the CNNs and transformations under question. We present an implementation and discuss the experimental results obtained for a CNN trained from the MNIST data set.","authors_text":"Alessio Lomuscio, Panagiotis Kouvaros","cross_cats":["cs.CV","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-28T03:36:25Z","title":"Formal Verification of CNN-based Perception Systems"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.11373","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:45ea748ba81fc6185dc3c7023fc03362f89ac9d15943eddb4e4bd4c7577e0492","target":"record","created_at":"2026-05-17T23:59:43Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e8af810e800066ed405af60c33fbbee016b9ba2b7003a70cfd737701881b39ad","cross_cats_sorted":["cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-28T03:36:25Z","title_canon_sha256":"06fb50f99a7facfbe6b62c8c5e6ff1ee6f4b97c0396384b15dc0a4aa024306e6"},"schema_version":"1.0","source":{"id":"1811.11373","kind":"arxiv","version":1}},"canonical_sha256":"3d2a9d1fec6e5a9d54dd5f605a0d137e5a3ffc7f2d886a32ab612f6469cdb2c7","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"3d2a9d1fec6e5a9d54dd5f605a0d137e5a3ffc7f2d886a32ab612f6469cdb2c7","first_computed_at":"2026-05-17T23:59:43.142771Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:59:43.142771Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"YtssfacX3CIldvfv04JGa3cvNnwFHsHeb7gfeGpf9qhWRCNGsVF7aQUOBzT4kFRXCc/CvBOb1Cpggb3T4/TgBQ==","signature_status":"signed_v1","signed_at":"2026-05-17T23:59:43.143344Z","signed_message":"canonical_sha256_bytes"},"source_id":"1811.11373","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:45ea748ba81fc6185dc3c7023fc03362f89ac9d15943eddb4e4bd4c7577e0492","sha256:c1eb85f2eb0e35afd4cb035a1d880459428047fa05a716e27f3e324eff8ba62d"],"state_sha256":"f79db5f5314e91958bd8ca2ab1c250ba0dd16163f4d954f9930636784a20d61a"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"RRT1fhlEWdxD7cNCrxqMp3jNQOQoKHylnqsJxvX3K9EcDecc8jP9hkWBjK2+f0VXmj8bew6V1b8IvfCNr32HCg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T23:41:44.898358Z","bundle_sha256":"026858e7363cd2ae38a6b179f0bd773f8bebe5867fad50b080c89a86196c6078"}}