{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:IGQGK72X7RG3QOA53YQS3FHDEN","short_pith_number":"pith:IGQGK72X","canonical_record":{"source":{"id":"1809.00065","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-08-31T21:22:52Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"3c0839966ddcd0d76e3db5ebab7aba9488883ac1974459111bece08a475b64fc","abstract_canon_sha256":"e94dfe49c56fec222e1b5ccabf7fea8e019582fa63d6973096e164ac4a7847f9"},"schema_version":"1.0"},"canonical_sha256":"41a0657f57fc4db8381dde212d94e323798dd34b3dfd6d109e0a849ca92d26c5","source":{"kind":"arxiv","id":"1809.00065","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1809.00065","created_at":"2026-05-17T23:39:27Z"},{"alias_kind":"arxiv_version","alias_value":"1809.00065v3","created_at":"2026-05-17T23:39:27Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1809.00065","created_at":"2026-05-17T23:39:27Z"},{"alias_kind":"pith_short_12","alias_value":"IGQGK72X7RG3","created_at":"2026-05-18T12:32:28Z"},{"alias_kind":"pith_short_16","alias_value":"IGQGK72X7RG3QOA5","created_at":"2026-05-18T12:32:28Z"},{"alias_kind":"pith_short_8","alias_value":"IGQGK72X","created_at":"2026-05-18T12:32:28Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:IGQGK72X7RG3QOA53YQS3FHDEN","target":"record","payload":{"canonical_record":{"source":{"id":"1809.00065","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-08-31T21:22:52Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"3c0839966ddcd0d76e3db5ebab7aba9488883ac1974459111bece08a475b64fc","abstract_canon_sha256":"e94dfe49c56fec222e1b5ccabf7fea8e019582fa63d6973096e164ac4a7847f9"},"schema_version":"1.0"},"canonical_sha256":"41a0657f57fc4db8381dde212d94e323798dd34b3dfd6d109e0a849ca92d26c5","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:39:27.110997Z","signature_b64":"hw7bftzumcyzoqxmfwUMXus/VyMawNpt5X+5e20vzH709U2oWZuwevTcmo/S9WwIiIXTX9uyYaQYT8gP/HcpDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"41a0657f57fc4db8381dde212d94e323798dd34b3dfd6d109e0a849ca92d26c5","last_reissued_at":"2026-05-17T23:39:27.110286Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:39:27.110286Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1809.00065","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:39:27Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"xTWH35kJWsvzjqJZwdRXoPWFLw7WHhVvJJC6WSvOwtPFkZT+TzhUTzbH2Kg00LKqdQs2lpiSKeCkPGM/si7BCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T01:09:38.006564Z"},"content_sha256":"8be2975a5d14b4917d10086b2588daa5318c149ff5411399c0976bba88dc4f62","schema_version":"1.0","event_id":"sha256:8be2975a5d14b4917d10086b2588daa5318c149ff5411399c0976bba88dc4f62"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:IGQGK72X7RG3QOA53YQS3FHDEN","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"MULDEF: Multi-model-based Defense Against Adversarial Examples for Neural Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Bo Li, Siwakorn Srisakaokul, Tao Xie, Wei Yang, Yuhao Zhang, Zexuan Zhong","submitted_at":"2018-08-31T21:22:52Z","abstract_excerpt":"Despite being popularly used in many applications, neural network models have been found to be vulnerable to adversarial examples, i.e., carefully crafted examples aiming to mislead machine learning models. Adversarial examples can pose potential risks on safety and security critical applications. However, existing defense approaches are still vulnerable to attacks, especially in a white-box attack scenario. To address this issue, we propose a new defense approach, named MulDef, based on robustness diversity. Our approach consists of (1) a general defense framework based on multiple models and"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1809.00065","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:39:27Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"B6HApapYNhVbSa4bc+aQhsLg7NTkEWYUk2yqPOuR3zHREIImPVx1+yO0gNDlWy8EbaIHJ4OBTkPC/vZWkqu/Aw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T01:09:38.007218Z"},"content_sha256":"24f37719f9757d7d598d0d9abdeff2f8c8a93e5256c6978a2a3f7ccbac1014c3","schema_version":"1.0","event_id":"sha256:24f37719f9757d7d598d0d9abdeff2f8c8a93e5256c6978a2a3f7ccbac1014c3"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/IGQGK72X7RG3QOA53YQS3FHDEN/bundle.json","state_url":"https://pith.science/pith/IGQGK72X7RG3QOA53YQS3FHDEN/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/IGQGK72X7RG3QOA53YQS3FHDEN/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T01:09:38Z","links":{"resolver":"https://pith.science/pith/IGQGK72X7RG3QOA53YQS3FHDEN","bundle":"https://pith.science/pith/IGQGK72X7RG3QOA53YQS3FHDEN/bundle.json","state":"https://pith.science/pith/IGQGK72X7RG3QOA53YQS3FHDEN/state.json","well_known_bundle":"https://pith.science/.well-known/pith/IGQGK72X7RG3QOA53YQS3FHDEN/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:IGQGK72X7RG3QOA53YQS3FHDEN","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e94dfe49c56fec222e1b5ccabf7fea8e019582fa63d6973096e164ac4a7847f9","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-08-31T21:22:52Z","title_canon_sha256":"3c0839966ddcd0d76e3db5ebab7aba9488883ac1974459111bece08a475b64fc"},"schema_version":"1.0","source":{"id":"1809.00065","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1809.00065","created_at":"2026-05-17T23:39:27Z"},{"alias_kind":"arxiv_version","alias_value":"1809.00065v3","created_at":"2026-05-17T23:39:27Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1809.00065","created_at":"2026-05-17T23:39:27Z"},{"alias_kind":"pith_short_12","alias_value":"IGQGK72X7RG3","created_at":"2026-05-18T12:32:28Z"},{"alias_kind":"pith_short_16","alias_value":"IGQGK72X7RG3QOA5","created_at":"2026-05-18T12:32:28Z"},{"alias_kind":"pith_short_8","alias_value":"IGQGK72X","created_at":"2026-05-18T12:32:28Z"}],"graph_snapshots":[{"event_id":"sha256:24f37719f9757d7d598d0d9abdeff2f8c8a93e5256c6978a2a3f7ccbac1014c3","target":"graph","created_at":"2026-05-17T23:39:27Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Despite being popularly used in many applications, neural network models have been found to be vulnerable to adversarial examples, i.e., carefully crafted examples aiming to mislead machine learning models. Adversarial examples can pose potential risks on safety and security critical applications. However, existing defense approaches are still vulnerable to attacks, especially in a white-box attack scenario. To address this issue, we propose a new defense approach, named MulDef, based on robustness diversity. Our approach consists of (1) a general defense framework based on multiple models and","authors_text":"Bo Li, Siwakorn Srisakaokul, Tao Xie, Wei Yang, Yuhao Zhang, Zexuan Zhong","cross_cats":["cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-08-31T21:22:52Z","title":"MULDEF: Multi-model-based Defense Against Adversarial Examples for Neural Networks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1809.00065","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:8be2975a5d14b4917d10086b2588daa5318c149ff5411399c0976bba88dc4f62","target":"record","created_at":"2026-05-17T23:39:27Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e94dfe49c56fec222e1b5ccabf7fea8e019582fa63d6973096e164ac4a7847f9","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-08-31T21:22:52Z","title_canon_sha256":"3c0839966ddcd0d76e3db5ebab7aba9488883ac1974459111bece08a475b64fc"},"schema_version":"1.0","source":{"id":"1809.00065","kind":"arxiv","version":3}},"canonical_sha256":"41a0657f57fc4db8381dde212d94e323798dd34b3dfd6d109e0a849ca92d26c5","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"41a0657f57fc4db8381dde212d94e323798dd34b3dfd6d109e0a849ca92d26c5","first_computed_at":"2026-05-17T23:39:27.110286Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:39:27.110286Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"hw7bftzumcyzoqxmfwUMXus/VyMawNpt5X+5e20vzH709U2oWZuwevTcmo/S9WwIiIXTX9uyYaQYT8gP/HcpDw==","signature_status":"signed_v1","signed_at":"2026-05-17T23:39:27.110997Z","signed_message":"canonical_sha256_bytes"},"source_id":"1809.00065","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:8be2975a5d14b4917d10086b2588daa5318c149ff5411399c0976bba88dc4f62","sha256:24f37719f9757d7d598d0d9abdeff2f8c8a93e5256c6978a2a3f7ccbac1014c3"],"state_sha256":"6f7aa03665772d0a79dd7dab1551a206e6959bc129b232aa56a85c2ae964f112"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"CLDj5JX5NjuzR4zHu44JeYKPvump6zUqLmARjlPCV2VJK7IWx9ogYgrBe8L33JzsErOxXiikQtBmtDh0AC1QAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T01:09:38.010463Z","bundle_sha256":"916c25439f65742cdca067035d514a7d4a2565642f82e7a26d3dd73980387919"}}