{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2014:I6F6HXECCAG7OT4NJRVLVOUIFF","short_pith_number":"pith:I6F6HXEC","schema_version":"1.0","canonical_sha256":"478be3dc82100df74f8d4c6ababa88295bc68e77d0cc3da2ef932f58489d3b99","source":{"kind":"arxiv","id":"1412.6572","version":3},"attestation_state":"computed","paper":{"title":"Explaining and Harnessing Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"Neural networks are vulnerable to adversarial examples mainly because they behave linearly in their inputs.","cross_cats":["cs.LG"],"primary_cat":"stat.ML","authors_text":"Christian Szegedy, Ian J. Goodfellow, Jonathon Shlens","submitted_at":"2014-12-20T01:17:12Z","abstract_excerpt":"Several machine learning models, including neural networks, consistently misclassify adversarial examples---inputs formed by applying small but intentionally worst-case perturbations to examples from the dataset, such that the perturbed input results in the model outputting an incorrect answer with high confidence. Early attempts at explaining this phenomenon focused on nonlinearity and overfitting. We argue instead that the primary cause of neural networks' vulnerability to adversarial perturbation is their linear nature. This explanation is supported by new quantitative results while giving "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":true},"canonical_record":{"source":{"id":"1412.6572","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2014-12-20T01:17:12Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"6d7dd56a8a46845d10b69a881dab23f4ae149762ccd7d3c067c4e6a44f354796","abstract_canon_sha256":"d1cab7a040ad5c17c6bab8f4f7bd8444fa99bd96046bcd23b5f2ffefd428de73"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-04T19:26:30.840030Z","signature_b64":"tx+ppzwnpU5nmuUMShmTnNgBQ9h1CRIZc9CtPAlmsm/RmZvlHdbuo/nYapsk3hKj+dYz5a/Cd6WX73cDTUwpCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"478be3dc82100df74f8d4c6ababa88295bc68e77d0cc3da2ef932f58489d3b99","last_reissued_at":"2026-07-04T19:26:30.839514Z","signature_status":"signed_v1","first_computed_at":"2026-07-04T19:26:30.839514Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Explaining and Harnessing Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"Neural networks are vulnerable to adversarial examples mainly because they behave linearly in their inputs.","cross_cats":["cs.LG"],"primary_cat":"stat.ML","authors_text":"Christian Szegedy, Ian J. Goodfellow, Jonathon Shlens","submitted_at":"2014-12-20T01:17:12Z","abstract_excerpt":"Several machine learning models, including neural networks, consistently misclassify adversarial examples---inputs formed by applying small but intentionally worst-case perturbations to examples from the dataset, such that the perturbed input results in the model outputting an incorrect answer with high confidence. Early attempts at explaining this phenomenon focused on nonlinearity and overfitting. We argue instead that the primary cause of neural networks' vulnerability to adversarial perturbation is their linear nature. This explanation is supported by new quantitative results while giving "},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"We argue instead that the primary cause of neural networks' vulnerability to adversarial perturbation is their linear nature.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"That the network's output is sufficiently linear in the input for small perturbations so that a first-order approximation accurately predicts the effect of the perturbation.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"Neural networks' susceptibility to adversarial examples stems from their linear nature, enabling a fast sign-of-gradient method for generating perturbations that also supports adversarial training to boost robustness.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"Neural networks are vulnerable to adversarial examples mainly because they behave linearly in their inputs.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"34aa981e6ca1d17db6a71801b445cb88337fed1ca196a4cf3c369392b79fd6c6"},"source":{"id":"1412.6572","kind":"arxiv","version":3},"verdict":{"id":"f0bbef56-a890-43b2-a812-33da9c44b87a","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-11T04:54:57.437273Z","strongest_claim":"We argue instead that the primary cause of neural networks' vulnerability to adversarial perturbation is their linear nature.","one_line_summary":"Neural networks' susceptibility to adversarial examples stems from their linear nature, enabling a fast sign-of-gradient method for generating perturbations that also supports adversarial training to boost robustness.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"That the network's output is sufficiently linear in the input for small perturbations so that a first-order approximation accurately predicts the effect of the perturbation.","pith_extraction_headline":"Neural networks are vulnerable to adversarial examples mainly because they behave linearly in their inputs."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1412.6572/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":2,"snapshot_sha256":"ba7c8b09dc9104931c6a37582895c9736be60855085f0a6b8b03bccaf821d5bc"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1412.6572","created_at":"2026-07-04T19:26:30.839574+00:00"},{"alias_kind":"arxiv_version","alias_value":"1412.6572v3","created_at":"2026-07-04T19:26:30.839574+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1412.6572","created_at":"2026-07-04T19:26:30.839574+00:00"},{"alias_kind":"pith_short_12","alias_value":"I6F6HXECCAG7","created_at":"2026-07-04T19:26:30.839574+00:00"},{"alias_kind":"pith_short_16","alias_value":"I6F6HXECCAG7OT4N","created_at":"2026-07-04T19:26:30.839574+00:00"},{"alias_kind":"pith_short_8","alias_value":"I6F6HXEC","created_at":"2026-07-04T19:26:30.839574+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":271,"internal_anchor_count":271,"sample":[{"citing_arxiv_id":"2607.07745","citing_title":"LiST: Lipschitz Scaling Training for Robust and Calibrated Neural Networks","ref_index":14,"is_internal_anchor":true},{"citing_arxiv_id":"2607.07903","citing_title":"Mechanistic Interpretability of LLM Jailbreaks via Internal Attribution Graphs","ref_index":3,"is_internal_anchor":true},{"citing_arxiv_id":"2607.07918","citing_title":"Efficient Safety Alignment of Language Models via Latent Personality Traits","ref_index":14,"is_internal_anchor":true},{"citing_arxiv_id":"2607.08370","citing_title":"Tubular Neighbourhoods of Pfaffian Sets and Applications to Neural Networks","ref_index":5,"is_internal_anchor":true},{"citing_arxiv_id":"2607.07029","citing_title":"Gimitest: A Comprehensive Tool for Testing Reinforcement Learning Policies","ref_index":9,"is_internal_anchor":true},{"citing_arxiv_id":"2607.07288","citing_title":"InfraQR: Edge-Placed QR-Inspired Structured Patch Attacks on Infrared Vision-Language Models","ref_index":8,"is_internal_anchor":true},{"citing_arxiv_id":"2607.07375","citing_title":"On Adversarial Vulnerability of Vision-Language Models through the Lens of Intermediate Spectral Subspaces","ref_index":25,"is_internal_anchor":true},{"citing_arxiv_id":"2607.06421","citing_title":"Gradient-Based Inverse Design of Free-Energy Landscapes with Diffusion Models","ref_index":51,"is_internal_anchor":true},{"citing_arxiv_id":"2607.06485","citing_title":"AirflowAttack: Thermal-Airflow Adversarial Perturbations against Infrared Remote-Sensing Vision-Language Models","ref_index":15,"is_internal_anchor":true},{"citing_arxiv_id":"2606.26036","citing_title":"Detect, Unlearn, Restore: Defending Text Summarization Models Against Data Poisoning","ref_index":29,"is_internal_anchor":true},{"citing_arxiv_id":"2606.25151","citing_title":"Silent Failures in Physics-Informed Neural Networks: Parameter Poisoning and the Limits of Loss-Based Validation","ref_index":6,"is_internal_anchor":true},{"citing_arxiv_id":"2606.24995","citing_title":"Are Tabular Foundation Models Robust to Realistic Query Distribution Shifts in Microbiome Data?","ref_index":7,"is_internal_anchor":true},{"citing_arxiv_id":"2606.26199","citing_title":"MIRAGE: Protecting against Malicious Image Editing via False Moderation","ref_index":26,"is_internal_anchor":true},{"citing_arxiv_id":"2606.27103","citing_title":"The Riddle Riddle: Testing Flexible Reasoning in Large Language Models and Humans","ref_index":9,"is_internal_anchor":true},{"citing_arxiv_id":"2606.23277","citing_title":"GIF: Locally Sound Geometric Information Flow Control for LLMs","ref_index":32,"is_internal_anchor":true},{"citing_arxiv_id":"2606.22939","citing_title":"CITADEL: CSI-Based Jamming Detection and Open-Set Classification for IIoT Networks","ref_index":21,"is_internal_anchor":true},{"citing_arxiv_id":"2606.22782","citing_title":"Towards Robust Personalized Federated Learning: Vulnerability Assessment and Defense Co-Design","ref_index":13,"is_internal_anchor":true},{"citing_arxiv_id":"2606.20893","citing_title":"Exploiting Neural Audio Codec Latents for Adversarial Audio Attacks","ref_index":17,"is_internal_anchor":true},{"citing_arxiv_id":"2606.20415","citing_title":"Pseudo-Feature Padding: A Lightweight Defense Against False Data Injection in Power Grids","ref_index":1,"is_internal_anchor":true},{"citing_arxiv_id":"2606.17435","citing_title":"MorphStrata: Layer-Specific Perturbations for Generating Morphence Students in Time-Series Moving Target Defense","ref_index":5,"is_internal_anchor":true},{"citing_arxiv_id":"2606.17223","citing_title":"Safety, Security, and Cognitive Risks in Neuro-Symbolic AI","ref_index":21,"is_internal_anchor":true},{"citing_arxiv_id":"2606.20666","citing_title":"Robust Auto-associative Memory via Convolutional Restricted Hopfield Networks","ref_index":17,"is_internal_anchor":true},{"citing_arxiv_id":"2607.02074","citing_title":"Comprehensive Robustness Analysis of LiDAR-based 3D Object Detection in Autonomous Driving","ref_index":17,"is_internal_anchor":true},{"citing_arxiv_id":"2607.01679","citing_title":"Beyond Gradient-Based Attacks: Adversarial Robustness and Explainability Stability in Cybersecurity Classifiers","ref_index":13,"is_internal_anchor":true},{"citing_arxiv_id":"2606.12075","citing_title":"Categorical Robustness Assessment for Machine Learning based Network Intrusion Detection Systems","ref_index":4,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":2,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/I6F6HXECCAG7OT4NJRVLVOUIFF","json":"https://pith.science/pith/I6F6HXECCAG7OT4NJRVLVOUIFF.json","graph_json":"https://pith.science/api/pith-number/I6F6HXECCAG7OT4NJRVLVOUIFF/graph.json","events_json":"https://pith.science/api/pith-number/I6F6HXECCAG7OT4NJRVLVOUIFF/events.json","paper":"https://pith.science/paper/I6F6HXEC"},"agent_actions":{"view_html":"https://pith.science/pith/I6F6HXECCAG7OT4NJRVLVOUIFF","download_json":"https://pith.science/pith/I6F6HXECCAG7OT4NJRVLVOUIFF.json","view_paper":"https://pith.science/paper/I6F6HXEC","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1412.6572&json=true","fetch_graph":"https://pith.science/api/pith-number/I6F6HXECCAG7OT4NJRVLVOUIFF/graph.json","fetch_events":"https://pith.science/api/pith-number/I6F6HXECCAG7OT4NJRVLVOUIFF/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/I6F6HXECCAG7OT4NJRVLVOUIFF/action/timestamp_anchor","attest_storage":"https://pith.science/pith/I6F6HXECCAG7OT4NJRVLVOUIFF/action/storage_attestation","attest_author":"https://pith.science/pith/I6F6HXECCAG7OT4NJRVLVOUIFF/action/author_attestation","sign_citation":"https://pith.science/pith/I6F6HXECCAG7OT4NJRVLVOUIFF/action/citation_signature","submit_replication":"https://pith.science/pith/I6F6HXECCAG7OT4NJRVLVOUIFF/action/replication_record"}},"created_at":"2026-07-04T19:26:30.839574+00:00","updated_at":"2026-07-04T19:26:30.839574+00:00"}