{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:IWDFEEYAGYKQPBEDVPK2TKWW7X","short_pith_number":"pith:IWDFEEYA","canonical_record":{"source":{"id":"1902.08265","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2019-02-21T21:02:58Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"1fcbe2b90a07cd9387a74b0c273eff5dfc85ebae3b72c45d256bc22dfc20330b","abstract_canon_sha256":"1cf284764d9edab43554937c2fd5a7ce4fb0a4c520ff29cf01618c4f2a002f6d"},"schema_version":"1.0"},"canonical_sha256":"45865213003615078483abd5a9aad6fdd53c06d31bbf70ca426ade1ac5c335eb","source":{"kind":"arxiv","id":"1902.08265","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1902.08265","created_at":"2026-05-17T23:52:57Z"},{"alias_kind":"arxiv_version","alias_value":"1902.08265v1","created_at":"2026-05-17T23:52:57Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1902.08265","created_at":"2026-05-17T23:52:57Z"},{"alias_kind":"pith_short_12","alias_value":"IWDFEEYAGYKQ","created_at":"2026-05-18T12:33:18Z"},{"alias_kind":"pith_short_16","alias_value":"IWDFEEYAGYKQPBED","created_at":"2026-05-18T12:33:18Z"},{"alias_kind":"pith_short_8","alias_value":"IWDFEEYA","created_at":"2026-05-18T12:33:18Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:IWDFEEYAGYKQPBEDVPK2TKWW7X","target":"record","payload":{"canonical_record":{"source":{"id":"1902.08265","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2019-02-21T21:02:58Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"1fcbe2b90a07cd9387a74b0c273eff5dfc85ebae3b72c45d256bc22dfc20330b","abstract_canon_sha256":"1cf284764d9edab43554937c2fd5a7ce4fb0a4c520ff29cf01618c4f2a002f6d"},"schema_version":"1.0"},"canonical_sha256":"45865213003615078483abd5a9aad6fdd53c06d31bbf70ca426ade1ac5c335eb","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:52:57.817310Z","signature_b64":"C5gDxinh/HXMgWx9bhq0bDnQuUwtMVsP8nz0VD2+JXYmQCBzBNV2pme55P0wUvrO6CAcSJWmeqmKe0YHIv8GCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"45865213003615078483abd5a9aad6fdd53c06d31bbf70ca426ade1ac5c335eb","last_reissued_at":"2026-05-17T23:52:57.816786Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:52:57.816786Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1902.08265","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:52:57Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"kAgaZur/VIOhhgau/KAliMsH3Og0ndxDIxQmc1z7Qe8NfaR+YdKBAY3ogKpu62h4oC7lkcZsuKRFzBIaxOeXDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-05T08:59:49.154973Z"},"content_sha256":"12c9371ac8c1921ce20ba9acf66d6bfc9a98beb4f341eb90a7c56cfbf59d27a9","schema_version":"1.0","event_id":"sha256:12c9371ac8c1921ce20ba9acf66d6bfc9a98beb4f341eb90a7c56cfbf59d27a9"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:IWDFEEYAGYKQPBEDVPK2TKWW7X","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Quantifying Perceptual Distortion of Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"stat.ML","authors_text":"Alexandros G. Dimakis, Matt Jordan, Naren Manoj, Surbhi Goel","submitted_at":"2019-02-21T21:02:58Z","abstract_excerpt":"Recent work has shown that additive threat models, which only permit the addition of bounded noise to the pixels of an image, are insufficient for fully capturing the space of imperceivable adversarial examples. For example, small rotations and spatial transformations can fool classifiers, remain imperceivable to humans, but have large additive distance from the original images. In this work, we leverage quantitative perceptual metrics like LPIPS and SSIM to define a novel threat model for adversarial attacks.\n  To demonstrate the value of quantifying the perceptual distortion of adversarial e"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1902.08265","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:52:57Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"iu9IIDdpz07lZ4mhGztg3j6pbg9O3N0pvfKTYFLIhC+UFI3NvrMwHjxna6+r7gYEE3KbdrtCPk4FsfFk2RWoBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-05T08:59:49.155583Z"},"content_sha256":"57edad24ca8b4373f34dab168d1d5205a7aae8f5554ee8ad12885c464bff6f80","schema_version":"1.0","event_id":"sha256:57edad24ca8b4373f34dab168d1d5205a7aae8f5554ee8ad12885c464bff6f80"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/IWDFEEYAGYKQPBEDVPK2TKWW7X/bundle.json","state_url":"https://pith.science/pith/IWDFEEYAGYKQPBEDVPK2TKWW7X/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/IWDFEEYAGYKQPBEDVPK2TKWW7X/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-05T08:59:49Z","links":{"resolver":"https://pith.science/pith/IWDFEEYAGYKQPBEDVPK2TKWW7X","bundle":"https://pith.science/pith/IWDFEEYAGYKQPBEDVPK2TKWW7X/bundle.json","state":"https://pith.science/pith/IWDFEEYAGYKQPBEDVPK2TKWW7X/state.json","well_known_bundle":"https://pith.science/.well-known/pith/IWDFEEYAGYKQPBEDVPK2TKWW7X/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:IWDFEEYAGYKQPBEDVPK2TKWW7X","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"1cf284764d9edab43554937c2fd5a7ce4fb0a4c520ff29cf01618c4f2a002f6d","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2019-02-21T21:02:58Z","title_canon_sha256":"1fcbe2b90a07cd9387a74b0c273eff5dfc85ebae3b72c45d256bc22dfc20330b"},"schema_version":"1.0","source":{"id":"1902.08265","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1902.08265","created_at":"2026-05-17T23:52:57Z"},{"alias_kind":"arxiv_version","alias_value":"1902.08265v1","created_at":"2026-05-17T23:52:57Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1902.08265","created_at":"2026-05-17T23:52:57Z"},{"alias_kind":"pith_short_12","alias_value":"IWDFEEYAGYKQ","created_at":"2026-05-18T12:33:18Z"},{"alias_kind":"pith_short_16","alias_value":"IWDFEEYAGYKQPBED","created_at":"2026-05-18T12:33:18Z"},{"alias_kind":"pith_short_8","alias_value":"IWDFEEYA","created_at":"2026-05-18T12:33:18Z"}],"graph_snapshots":[{"event_id":"sha256:57edad24ca8b4373f34dab168d1d5205a7aae8f5554ee8ad12885c464bff6f80","target":"graph","created_at":"2026-05-17T23:52:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Recent work has shown that additive threat models, which only permit the addition of bounded noise to the pixels of an image, are insufficient for fully capturing the space of imperceivable adversarial examples. For example, small rotations and spatial transformations can fool classifiers, remain imperceivable to humans, but have large additive distance from the original images. In this work, we leverage quantitative perceptual metrics like LPIPS and SSIM to define a novel threat model for adversarial attacks.\n  To demonstrate the value of quantifying the perceptual distortion of adversarial e","authors_text":"Alexandros G. Dimakis, Matt Jordan, Naren Manoj, Surbhi Goel","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2019-02-21T21:02:58Z","title":"Quantifying Perceptual Distortion of Adversarial Examples"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1902.08265","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:12c9371ac8c1921ce20ba9acf66d6bfc9a98beb4f341eb90a7c56cfbf59d27a9","target":"record","created_at":"2026-05-17T23:52:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"1cf284764d9edab43554937c2fd5a7ce4fb0a4c520ff29cf01618c4f2a002f6d","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2019-02-21T21:02:58Z","title_canon_sha256":"1fcbe2b90a07cd9387a74b0c273eff5dfc85ebae3b72c45d256bc22dfc20330b"},"schema_version":"1.0","source":{"id":"1902.08265","kind":"arxiv","version":1}},"canonical_sha256":"45865213003615078483abd5a9aad6fdd53c06d31bbf70ca426ade1ac5c335eb","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"45865213003615078483abd5a9aad6fdd53c06d31bbf70ca426ade1ac5c335eb","first_computed_at":"2026-05-17T23:52:57.816786Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:52:57.816786Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"C5gDxinh/HXMgWx9bhq0bDnQuUwtMVsP8nz0VD2+JXYmQCBzBNV2pme55P0wUvrO6CAcSJWmeqmKe0YHIv8GCQ==","signature_status":"signed_v1","signed_at":"2026-05-17T23:52:57.817310Z","signed_message":"canonical_sha256_bytes"},"source_id":"1902.08265","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:12c9371ac8c1921ce20ba9acf66d6bfc9a98beb4f341eb90a7c56cfbf59d27a9","sha256:57edad24ca8b4373f34dab168d1d5205a7aae8f5554ee8ad12885c464bff6f80"],"state_sha256":"43312785442a08d1f0afc9a3fcc550c5e22e4a4c6eee0d336eef496a11ea0fad"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"OnyOulf+qDorwL/RSH5BOHpg5inWQCD+bMEdHbmvcr1ZjSZWuXQJt9STLkeWtCA2QGXt592vavtkumjlLjX0BQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-05T08:59:49.158329Z","bundle_sha256":"d41063dc076cf9054f30fe696cf411f4912227ffc3219949f909d03178f8b68e"}}