{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:IWDFEEYAGYKQPBEDVPK2TKWW7X","short_pith_number":"pith:IWDFEEYA","schema_version":"1.0","canonical_sha256":"45865213003615078483abd5a9aad6fdd53c06d31bbf70ca426ade1ac5c335eb","source":{"kind":"arxiv","id":"1902.08265","version":1},"attestation_state":"computed","paper":{"title":"Quantifying Perceptual Distortion of Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"stat.ML","authors_text":"Alexandros G. Dimakis, Matt Jordan, Naren Manoj, Surbhi Goel","submitted_at":"2019-02-21T21:02:58Z","abstract_excerpt":"Recent work has shown that additive threat models, which only permit the addition of bounded noise to the pixels of an image, are insufficient for fully capturing the space of imperceivable adversarial examples. For example, small rotations and spatial transformations can fool classifiers, remain imperceivable to humans, but have large additive distance from the original images. In this work, we leverage quantitative perceptual metrics like LPIPS and SSIM to define a novel threat model for adversarial attacks.\n  To demonstrate the value of quantifying the perceptual distortion of adversarial e"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1902.08265","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2019-02-21T21:02:58Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"1fcbe2b90a07cd9387a74b0c273eff5dfc85ebae3b72c45d256bc22dfc20330b","abstract_canon_sha256":"1cf284764d9edab43554937c2fd5a7ce4fb0a4c520ff29cf01618c4f2a002f6d"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:52:57.817310Z","signature_b64":"C5gDxinh/HXMgWx9bhq0bDnQuUwtMVsP8nz0VD2+JXYmQCBzBNV2pme55P0wUvrO6CAcSJWmeqmKe0YHIv8GCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"45865213003615078483abd5a9aad6fdd53c06d31bbf70ca426ade1ac5c335eb","last_reissued_at":"2026-05-17T23:52:57.816786Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:52:57.816786Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Quantifying Perceptual Distortion of Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"stat.ML","authors_text":"Alexandros G. Dimakis, Matt Jordan, Naren Manoj, Surbhi Goel","submitted_at":"2019-02-21T21:02:58Z","abstract_excerpt":"Recent work has shown that additive threat models, which only permit the addition of bounded noise to the pixels of an image, are insufficient for fully capturing the space of imperceivable adversarial examples. For example, small rotations and spatial transformations can fool classifiers, remain imperceivable to humans, but have large additive distance from the original images. In this work, we leverage quantitative perceptual metrics like LPIPS and SSIM to define a novel threat model for adversarial attacks.\n  To demonstrate the value of quantifying the perceptual distortion of adversarial e"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1902.08265","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1902.08265","created_at":"2026-05-17T23:52:57.816887+00:00"},{"alias_kind":"arxiv_version","alias_value":"1902.08265v1","created_at":"2026-05-17T23:52:57.816887+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1902.08265","created_at":"2026-05-17T23:52:57.816887+00:00"},{"alias_kind":"pith_short_12","alias_value":"IWDFEEYAGYKQ","created_at":"2026-05-18T12:33:18.533446+00:00"},{"alias_kind":"pith_short_16","alias_value":"IWDFEEYAGYKQPBED","created_at":"2026-05-18T12:33:18.533446+00:00"},{"alias_kind":"pith_short_8","alias_value":"IWDFEEYA","created_at":"2026-05-18T12:33:18.533446+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/IWDFEEYAGYKQPBEDVPK2TKWW7X","json":"https://pith.science/pith/IWDFEEYAGYKQPBEDVPK2TKWW7X.json","graph_json":"https://pith.science/api/pith-number/IWDFEEYAGYKQPBEDVPK2TKWW7X/graph.json","events_json":"https://pith.science/api/pith-number/IWDFEEYAGYKQPBEDVPK2TKWW7X/events.json","paper":"https://pith.science/paper/IWDFEEYA"},"agent_actions":{"view_html":"https://pith.science/pith/IWDFEEYAGYKQPBEDVPK2TKWW7X","download_json":"https://pith.science/pith/IWDFEEYAGYKQPBEDVPK2TKWW7X.json","view_paper":"https://pith.science/paper/IWDFEEYA","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1902.08265&json=true","fetch_graph":"https://pith.science/api/pith-number/IWDFEEYAGYKQPBEDVPK2TKWW7X/graph.json","fetch_events":"https://pith.science/api/pith-number/IWDFEEYAGYKQPBEDVPK2TKWW7X/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/IWDFEEYAGYKQPBEDVPK2TKWW7X/action/timestamp_anchor","attest_storage":"https://pith.science/pith/IWDFEEYAGYKQPBEDVPK2TKWW7X/action/storage_attestation","attest_author":"https://pith.science/pith/IWDFEEYAGYKQPBEDVPK2TKWW7X/action/author_attestation","sign_citation":"https://pith.science/pith/IWDFEEYAGYKQPBEDVPK2TKWW7X/action/citation_signature","submit_replication":"https://pith.science/pith/IWDFEEYAGYKQPBEDVPK2TKWW7X/action/replication_record"}},"created_at":"2026-05-17T23:52:57.816887+00:00","updated_at":"2026-05-17T23:52:57.816887+00:00"}