{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2014:I6F6HXECCAG7OT4NJRVLVOUIFF","short_pith_number":"pith:I6F6HXEC","canonical_record":{"source":{"id":"1412.6572","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2014-12-20T01:17:12Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"6d7dd56a8a46845d10b69a881dab23f4ae149762ccd7d3c067c4e6a44f354796","abstract_canon_sha256":"d1cab7a040ad5c17c6bab8f4f7bd8444fa99bd96046bcd23b5f2ffefd428de73"},"schema_version":"1.0"},"canonical_sha256":"478be3dc82100df74f8d4c6ababa88295bc68e77d0cc3da2ef932f58489d3b99","source":{"kind":"arxiv","id":"1412.6572","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1412.6572","created_at":"2026-07-04T19:26:30Z"},{"alias_kind":"arxiv_version","alias_value":"1412.6572v3","created_at":"2026-07-04T19:26:30Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1412.6572","created_at":"2026-07-04T19:26:30Z"},{"alias_kind":"pith_short_12","alias_value":"I6F6HXECCAG7","created_at":"2026-07-04T19:26:30Z"},{"alias_kind":"pith_short_16","alias_value":"I6F6HXECCAG7OT4N","created_at":"2026-07-04T19:26:30Z"},{"alias_kind":"pith_short_8","alias_value":"I6F6HXEC","created_at":"2026-07-04T19:26:30Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2014:I6F6HXECCAG7OT4NJRVLVOUIFF","target":"record","payload":{"canonical_record":{"source":{"id":"1412.6572","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2014-12-20T01:17:12Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"6d7dd56a8a46845d10b69a881dab23f4ae149762ccd7d3c067c4e6a44f354796","abstract_canon_sha256":"d1cab7a040ad5c17c6bab8f4f7bd8444fa99bd96046bcd23b5f2ffefd428de73"},"schema_version":"1.0"},"canonical_sha256":"478be3dc82100df74f8d4c6ababa88295bc68e77d0cc3da2ef932f58489d3b99","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-04T19:26:30.840030Z","signature_b64":"tx+ppzwnpU5nmuUMShmTnNgBQ9h1CRIZc9CtPAlmsm/RmZvlHdbuo/nYapsk3hKj+dYz5a/Cd6WX73cDTUwpCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"478be3dc82100df74f8d4c6ababa88295bc68e77d0cc3da2ef932f58489d3b99","last_reissued_at":"2026-07-04T19:26:30.839514Z","signature_status":"signed_v1","first_computed_at":"2026-07-04T19:26:30.839514Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1412.6572","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-04T19:26:30Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"lwrvEtanBzBvSU4gsuVcwLZ+av0l9/FRzur4/lBXl0K6jHgnzJR9bz1nxlnYzPMejAeHJ3txri4wb/akqqFKAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-31T18:18:56.370877Z"},"content_sha256":"2e3a99863021e203def60bd0916781964fb020b6e7671f1759e669c2ee909de2","schema_version":"1.0","event_id":"sha256:2e3a99863021e203def60bd0916781964fb020b6e7671f1759e669c2ee909de2"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2014:I6F6HXECCAG7OT4NJRVLVOUIFF","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Explaining and Harnessing Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"Neural networks are vulnerable to adversarial examples mainly because they behave linearly in their inputs.","cross_cats":["cs.LG"],"primary_cat":"stat.ML","authors_text":"Christian Szegedy, Ian J. Goodfellow, Jonathon Shlens","submitted_at":"2014-12-20T01:17:12Z","abstract_excerpt":"Several machine learning models, including neural networks, consistently misclassify adversarial examples---inputs formed by applying small but intentionally worst-case perturbations to examples from the dataset, such that the perturbed input results in the model outputting an incorrect answer with high confidence. Early attempts at explaining this phenomenon focused on nonlinearity and overfitting. We argue instead that the primary cause of neural networks' vulnerability to adversarial perturbation is their linear nature. This explanation is supported by new quantitative results while giving "},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"We argue instead that the primary cause of neural networks' vulnerability to adversarial perturbation is their linear nature.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"That the network's output is sufficiently linear in the input for small perturbations so that a first-order approximation accurately predicts the effect of the perturbation.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"Neural networks' susceptibility to adversarial examples stems from their linear nature, enabling a fast sign-of-gradient method for generating perturbations that also supports adversarial training to boost robustness.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"Neural networks are vulnerable to adversarial examples mainly because they behave linearly in their inputs.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"34aa981e6ca1d17db6a71801b445cb88337fed1ca196a4cf3c369392b79fd6c6"},"source":{"id":"1412.6572","kind":"arxiv","version":3},"verdict":{"id":"f0bbef56-a890-43b2-a812-33da9c44b87a","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-11T04:54:57.437273Z","strongest_claim":"We argue instead that the primary cause of neural networks' vulnerability to adversarial perturbation is their linear nature.","one_line_summary":"Neural networks' susceptibility to adversarial examples stems from their linear nature, enabling a fast sign-of-gradient method for generating perturbations that also supports adversarial training to boost robustness.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"That the network's output is sufficiently linear in the input for small perturbations so that a first-order approximation accurately predicts the effect of the perturbation.","pith_extraction_headline":"Neural networks are vulnerable to adversarial examples mainly because they behave linearly in their inputs."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1412.6572/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":2,"snapshot_sha256":"ba7c8b09dc9104931c6a37582895c9736be60855085f0a6b8b03bccaf821d5bc"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"f0bbef56-a890-43b2-a812-33da9c44b87a"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-04T19:26:30Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"wX3sYGeKGRl5mi0FncofWK7MDQLQSO+GheTAuxK2W5fYPuKkiTy2aF1DoBiVk7iupLMzmwxYf9DTFOhL6Kg3BQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-31T18:18:56.371996Z"},"content_sha256":"74db6abdc2b37968ee25e900088f18047dfd10cdc24c835e08e3e2c2b30be156","schema_version":"1.0","event_id":"sha256:74db6abdc2b37968ee25e900088f18047dfd10cdc24c835e08e3e2c2b30be156"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/I6F6HXECCAG7OT4NJRVLVOUIFF/bundle.json","state_url":"https://pith.science/pith/I6F6HXECCAG7OT4NJRVLVOUIFF/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/I6F6HXECCAG7OT4NJRVLVOUIFF/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-31T18:18:56Z","links":{"resolver":"https://pith.science/pith/I6F6HXECCAG7OT4NJRVLVOUIFF","bundle":"https://pith.science/pith/I6F6HXECCAG7OT4NJRVLVOUIFF/bundle.json","state":"https://pith.science/pith/I6F6HXECCAG7OT4NJRVLVOUIFF/state.json","well_known_bundle":"https://pith.science/.well-known/pith/I6F6HXECCAG7OT4NJRVLVOUIFF/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2014:I6F6HXECCAG7OT4NJRVLVOUIFF","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"d1cab7a040ad5c17c6bab8f4f7bd8444fa99bd96046bcd23b5f2ffefd428de73","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2014-12-20T01:17:12Z","title_canon_sha256":"6d7dd56a8a46845d10b69a881dab23f4ae149762ccd7d3c067c4e6a44f354796"},"schema_version":"1.0","source":{"id":"1412.6572","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1412.6572","created_at":"2026-07-04T19:26:30Z"},{"alias_kind":"arxiv_version","alias_value":"1412.6572v3","created_at":"2026-07-04T19:26:30Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1412.6572","created_at":"2026-07-04T19:26:30Z"},{"alias_kind":"pith_short_12","alias_value":"I6F6HXECCAG7","created_at":"2026-07-04T19:26:30Z"},{"alias_kind":"pith_short_16","alias_value":"I6F6HXECCAG7OT4N","created_at":"2026-07-04T19:26:30Z"},{"alias_kind":"pith_short_8","alias_value":"I6F6HXEC","created_at":"2026-07-04T19:26:30Z"}],"graph_snapshots":[{"event_id":"sha256:74db6abdc2b37968ee25e900088f18047dfd10cdc24c835e08e3e2c2b30be156","target":"graph","created_at":"2026-07-04T19:26:30Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"We argue instead that the primary cause of neural networks' vulnerability to adversarial perturbation is their linear nature."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"That the network's output is sufficiently linear in the input for small perturbations so that a first-order approximation accurately predicts the effect of the perturbation."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"Neural networks' susceptibility to adversarial examples stems from their linear nature, enabling a fast sign-of-gradient method for generating perturbations that also supports adversarial training to boost robustness."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"Neural networks are vulnerable to adversarial examples mainly because they behave linearly in their inputs."}],"snapshot_sha256":"34aa981e6ca1d17db6a71801b445cb88337fed1ca196a4cf3c369392b79fd6c6"},"formal_canon":{"evidence_count":2,"snapshot_sha256":"ba7c8b09dc9104931c6a37582895c9736be60855085f0a6b8b03bccaf821d5bc"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/1412.6572/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Several machine learning models, including neural networks, consistently misclassify adversarial examples---inputs formed by applying small but intentionally worst-case perturbations to examples from the dataset, such that the perturbed input results in the model outputting an incorrect answer with high confidence. Early attempts at explaining this phenomenon focused on nonlinearity and overfitting. We argue instead that the primary cause of neural networks' vulnerability to adversarial perturbation is their linear nature. This explanation is supported by new quantitative results while giving ","authors_text":"Christian Szegedy, Ian J. Goodfellow, Jonathon Shlens","cross_cats":["cs.LG"],"headline":"Neural networks are vulnerable to adversarial examples mainly because they behave linearly in their inputs.","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2014-12-20T01:17:12Z","title":"Explaining and Harnessing Adversarial Examples"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1412.6572","kind":"arxiv","version":3},"verdict":{"created_at":"2026-05-11T04:54:57.437273Z","id":"f0bbef56-a890-43b2-a812-33da9c44b87a","model_set":{"reader":"grok-4.3"},"one_line_summary":"Neural networks' susceptibility to adversarial examples stems from their linear nature, enabling a fast sign-of-gradient method for generating perturbations that also supports adversarial training to boost robustness.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"Neural networks are vulnerable to adversarial examples mainly because they behave linearly in their inputs.","strongest_claim":"We argue instead that the primary cause of neural networks' vulnerability to adversarial perturbation is their linear nature.","weakest_assumption":"That the network's output is sufficiently linear in the input for small perturbations so that a first-order approximation accurately predicts the effect of the perturbation."}},"verdict_id":"f0bbef56-a890-43b2-a812-33da9c44b87a"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:2e3a99863021e203def60bd0916781964fb020b6e7671f1759e669c2ee909de2","target":"record","created_at":"2026-07-04T19:26:30Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"d1cab7a040ad5c17c6bab8f4f7bd8444fa99bd96046bcd23b5f2ffefd428de73","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2014-12-20T01:17:12Z","title_canon_sha256":"6d7dd56a8a46845d10b69a881dab23f4ae149762ccd7d3c067c4e6a44f354796"},"schema_version":"1.0","source":{"id":"1412.6572","kind":"arxiv","version":3}},"canonical_sha256":"478be3dc82100df74f8d4c6ababa88295bc68e77d0cc3da2ef932f58489d3b99","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"478be3dc82100df74f8d4c6ababa88295bc68e77d0cc3da2ef932f58489d3b99","first_computed_at":"2026-07-04T19:26:30.839514Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-04T19:26:30.839514Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"tx+ppzwnpU5nmuUMShmTnNgBQ9h1CRIZc9CtPAlmsm/RmZvlHdbuo/nYapsk3hKj+dYz5a/Cd6WX73cDTUwpCg==","signature_status":"signed_v1","signed_at":"2026-07-04T19:26:30.840030Z","signed_message":"canonical_sha256_bytes"},"source_id":"1412.6572","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:2e3a99863021e203def60bd0916781964fb020b6e7671f1759e669c2ee909de2","sha256:74db6abdc2b37968ee25e900088f18047dfd10cdc24c835e08e3e2c2b30be156"],"state_sha256":"7a9911a1c8793e05b859801aea3d3b45faf5f5a7f58562f237097d591ee00d5e"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8usPdGhWE+x3My8lkqyTc0fOsk+uIiYuQG1iPBAKp7tvNuqXfUVCBa74BWfb7EeIMUf6ntehheRFNaLSnjEdBA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-31T18:18:56.377610Z","bundle_sha256":"1183d1c0f2950e7e22aa03871672fac63a5cf1ba1da178abb9ef46985ddf8d61"}}