{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:ICWUUKLVEPXDF67YN6IA3EVOYF","short_pith_number":"pith:ICWUUKLV","canonical_record":{"source":{"id":"1811.01057","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-02T19:08:04Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"dbc36c32c7996bedd33b5a5697b9b58af83334b5821f05bdbac52721a84e0dc1","abstract_canon_sha256":"464986fdfe78bebfb09344017d47bc8a96f7a545d2cfd549e79ae6eb51249ec3"},"schema_version":"1.0"},"canonical_sha256":"40ad4a297523ee32fbf86f900d92aec1605b881d8890820e005ae0f13a92af11","source":{"kind":"arxiv","id":"1811.01057","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1811.01057","created_at":"2026-05-18T00:01:37Z"},{"alias_kind":"arxiv_version","alias_value":"1811.01057v1","created_at":"2026-05-18T00:01:37Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.01057","created_at":"2026-05-18T00:01:37Z"},{"alias_kind":"pith_short_12","alias_value":"ICWUUKLVEPXD","created_at":"2026-05-18T12:32:28Z"},{"alias_kind":"pith_short_16","alias_value":"ICWUUKLVEPXDF67Y","created_at":"2026-05-18T12:32:28Z"},{"alias_kind":"pith_short_8","alias_value":"ICWUUKLV","created_at":"2026-05-18T12:32:28Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:ICWUUKLVEPXDF67YN6IA3EVOYF","target":"record","payload":{"canonical_record":{"source":{"id":"1811.01057","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-02T19:08:04Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"dbc36c32c7996bedd33b5a5697b9b58af83334b5821f05bdbac52721a84e0dc1","abstract_canon_sha256":"464986fdfe78bebfb09344017d47bc8a96f7a545d2cfd549e79ae6eb51249ec3"},"schema_version":"1.0"},"canonical_sha256":"40ad4a297523ee32fbf86f900d92aec1605b881d8890820e005ae0f13a92af11","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:01:37.169297Z","signature_b64":"5r/2BbFuvVKwuFxpusrLXL58hSrKNkQ5jMMq+qQbdHk1ycOX+kmjxPW5lJyg7wb2LR1IJSHZiuTehoX6Wph2CQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"40ad4a297523ee32fbf86f900d92aec1605b881d8890820e005ae0f13a92af11","last_reissued_at":"2026-05-18T00:01:37.168819Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:01:37.168819Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1811.01057","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:01:37Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"+03d/UQlg3iWYVbqPyZYtLRyktRTzts6SRYt8prL7p3baEGMlpmfkZxDjSxuBtUkF5irevM5YVGKTkbywRWLAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T02:18:28.114795Z"},"content_sha256":"f3e3fc5656134452c806311996ce2f475f9e3d03c5e2745a6faee838411802cb","schema_version":"1.0","event_id":"sha256:f3e3fc5656134452c806311996ce2f475f9e3d03c5e2745a6faee838411802cb"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:ICWUUKLVEPXDF67YN6IA3EVOYF","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Semidefinite relaxations for certifying robustness to adversarial examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Aditi Raghunathan, Jacob Steinhardt, Percy Liang","submitted_at":"2018-11-02T19:08:04Z","abstract_excerpt":"Despite their impressive performance on diverse tasks, neural networks fail catastrophically in the presence of adversarial inputs---imperceptibly but adversarially perturbed versions of natural inputs. We have witnessed an arms race between defenders who attempt to train robust networks and attackers who try to construct adversarial examples. One promise of ending the arms race is developing certified defenses, ones which are provably robust against all attackers in some family. These certified defenses are based on convex relaxations which construct an upper bound on the worst case loss over"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.01057","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:01:37Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"oQXcXycH4gt0OJnyfqHZFnnpfY7m4fl26Wk3RgMvgXyNooLHXe5FCw38H+ssJHHZAI+D2/RZerJKBw1YgIQHCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T02:18:28.115485Z"},"content_sha256":"5d6d1c990f5da648005908c5354dd72a269263b190c6662672645062467c8d74","schema_version":"1.0","event_id":"sha256:5d6d1c990f5da648005908c5354dd72a269263b190c6662672645062467c8d74"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/ICWUUKLVEPXDF67YN6IA3EVOYF/bundle.json","state_url":"https://pith.science/pith/ICWUUKLVEPXDF67YN6IA3EVOYF/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/ICWUUKLVEPXDF67YN6IA3EVOYF/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-30T02:18:28Z","links":{"resolver":"https://pith.science/pith/ICWUUKLVEPXDF67YN6IA3EVOYF","bundle":"https://pith.science/pith/ICWUUKLVEPXDF67YN6IA3EVOYF/bundle.json","state":"https://pith.science/pith/ICWUUKLVEPXDF67YN6IA3EVOYF/state.json","well_known_bundle":"https://pith.science/.well-known/pith/ICWUUKLVEPXDF67YN6IA3EVOYF/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:ICWUUKLVEPXDF67YN6IA3EVOYF","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"464986fdfe78bebfb09344017d47bc8a96f7a545d2cfd549e79ae6eb51249ec3","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-02T19:08:04Z","title_canon_sha256":"dbc36c32c7996bedd33b5a5697b9b58af83334b5821f05bdbac52721a84e0dc1"},"schema_version":"1.0","source":{"id":"1811.01057","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1811.01057","created_at":"2026-05-18T00:01:37Z"},{"alias_kind":"arxiv_version","alias_value":"1811.01057v1","created_at":"2026-05-18T00:01:37Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.01057","created_at":"2026-05-18T00:01:37Z"},{"alias_kind":"pith_short_12","alias_value":"ICWUUKLVEPXD","created_at":"2026-05-18T12:32:28Z"},{"alias_kind":"pith_short_16","alias_value":"ICWUUKLVEPXDF67Y","created_at":"2026-05-18T12:32:28Z"},{"alias_kind":"pith_short_8","alias_value":"ICWUUKLV","created_at":"2026-05-18T12:32:28Z"}],"graph_snapshots":[{"event_id":"sha256:5d6d1c990f5da648005908c5354dd72a269263b190c6662672645062467c8d74","target":"graph","created_at":"2026-05-18T00:01:37Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Despite their impressive performance on diverse tasks, neural networks fail catastrophically in the presence of adversarial inputs---imperceptibly but adversarially perturbed versions of natural inputs. We have witnessed an arms race between defenders who attempt to train robust networks and attackers who try to construct adversarial examples. One promise of ending the arms race is developing certified defenses, ones which are provably robust against all attackers in some family. These certified defenses are based on convex relaxations which construct an upper bound on the worst case loss over","authors_text":"Aditi Raghunathan, Jacob Steinhardt, Percy Liang","cross_cats":["cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-02T19:08:04Z","title":"Semidefinite relaxations for certifying robustness to adversarial examples"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.01057","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:f3e3fc5656134452c806311996ce2f475f9e3d03c5e2745a6faee838411802cb","target":"record","created_at":"2026-05-18T00:01:37Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"464986fdfe78bebfb09344017d47bc8a96f7a545d2cfd549e79ae6eb51249ec3","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-02T19:08:04Z","title_canon_sha256":"dbc36c32c7996bedd33b5a5697b9b58af83334b5821f05bdbac52721a84e0dc1"},"schema_version":"1.0","source":{"id":"1811.01057","kind":"arxiv","version":1}},"canonical_sha256":"40ad4a297523ee32fbf86f900d92aec1605b881d8890820e005ae0f13a92af11","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"40ad4a297523ee32fbf86f900d92aec1605b881d8890820e005ae0f13a92af11","first_computed_at":"2026-05-18T00:01:37.168819Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:01:37.168819Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"5r/2BbFuvVKwuFxpusrLXL58hSrKNkQ5jMMq+qQbdHk1ycOX+kmjxPW5lJyg7wb2LR1IJSHZiuTehoX6Wph2CQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:01:37.169297Z","signed_message":"canonical_sha256_bytes"},"source_id":"1811.01057","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:f3e3fc5656134452c806311996ce2f475f9e3d03c5e2745a6faee838411802cb","sha256:5d6d1c990f5da648005908c5354dd72a269263b190c6662672645062467c8d74"],"state_sha256":"c527b6cdd8fbf4090c2f091817ca900fb3bf3a610048fdb102158be54af3f2d2"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"mBxJr/WQj1bqJAQeXfHSjB0K6S81qnBAhR88Vm6FeD8Xr7mqlmIhMpnpayoFHwGW7Htw7MpISguS+6y19MoTCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-30T02:18:28.118419Z","bundle_sha256":"810c0b91a3c3618a5a173239d6f765dbebfc53a47ce4e821cce482c9b77c0017"}}