{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2018:JRVWERKSO44DUMCLHMB2DYDYJZ","short_pith_number":"pith:JRVWERKS","schema_version":"1.0","canonical_sha256":"4c6b62455277383a304b3b03a1e0784e5b2de3e545e27823b8d08a00aef03a62","source":{"kind":"arxiv","id":"1812.00740","version":2},"attestation_state":"computed","paper":{"title":"Disentangling Adversarial Robustness and Generalization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.LG","stat.ML"],"primary_cat":"cs.CV","authors_text":"Bernt Schiele, David Stutz, Matthias Hein","submitted_at":"2018-12-03T14:04:35Z","abstract_excerpt":"Obtaining deep networks that are robust against adversarial examples and generalize well is an open problem. A recent hypothesis even states that both robust and accurate models are impossible, i.e., adversarial robustness and generalization are conflicting goals. In an effort to clarify the relationship between robustness and generalization, we assume an underlying, low-dimensional data manifold and show that: 1. regular adversarial examples leave the manifold; 2. adversarial examples constrained to the manifold, i.e., on-manifold adversarial examples, exist; 3. on-manifold adversarial exampl"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1812.00740","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-12-03T14:04:35Z","cross_cats_sorted":["cs.CR","cs.LG","stat.ML"],"title_canon_sha256":"3e9a69f9cc9f2777ddd13c07646bf7dc2cf6d6bffb104c01c87802e5d0968b2c","abstract_canon_sha256":"2ed6d6e5bad18614e43f6893c5985265e2f2c7ef0a23b8b2e930c10536fe334e"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:48:55.195180Z","signature_b64":"Z7I6gVMGGDCetspDAVz88+aBrb0RtQoMAKXB77zw36QDA/THwpQ4xCKs7oBgyCrShJLL9ZZhtAXKwt/nkcrdBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"4c6b62455277383a304b3b03a1e0784e5b2de3e545e27823b8d08a00aef03a62","last_reissued_at":"2026-05-17T23:48:55.194727Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:48:55.194727Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Disentangling Adversarial Robustness and Generalization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.LG","stat.ML"],"primary_cat":"cs.CV","authors_text":"Bernt Schiele, David Stutz, Matthias Hein","submitted_at":"2018-12-03T14:04:35Z","abstract_excerpt":"Obtaining deep networks that are robust against adversarial examples and generalize well is an open problem. A recent hypothesis even states that both robust and accurate models are impossible, i.e., adversarial robustness and generalization are conflicting goals. In an effort to clarify the relationship between robustness and generalization, we assume an underlying, low-dimensional data manifold and show that: 1. regular adversarial examples leave the manifold; 2. adversarial examples constrained to the manifold, i.e., on-manifold adversarial examples, exist; 3. on-manifold adversarial exampl"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1812.00740","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1812.00740","created_at":"2026-05-17T23:48:55.194802+00:00"},{"alias_kind":"arxiv_version","alias_value":"1812.00740v2","created_at":"2026-05-17T23:48:55.194802+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1812.00740","created_at":"2026-05-17T23:48:55.194802+00:00"},{"alias_kind":"pith_short_12","alias_value":"JRVWERKSO44D","created_at":"2026-05-18T12:32:31.084164+00:00"},{"alias_kind":"pith_short_16","alias_value":"JRVWERKSO44DUMCL","created_at":"2026-05-18T12:32:31.084164+00:00"},{"alias_kind":"pith_short_8","alias_value":"JRVWERKS","created_at":"2026-05-18T12:32:31.084164+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/JRVWERKSO44DUMCLHMB2DYDYJZ","json":"https://pith.science/pith/JRVWERKSO44DUMCLHMB2DYDYJZ.json","graph_json":"https://pith.science/api/pith-number/JRVWERKSO44DUMCLHMB2DYDYJZ/graph.json","events_json":"https://pith.science/api/pith-number/JRVWERKSO44DUMCLHMB2DYDYJZ/events.json","paper":"https://pith.science/paper/JRVWERKS"},"agent_actions":{"view_html":"https://pith.science/pith/JRVWERKSO44DUMCLHMB2DYDYJZ","download_json":"https://pith.science/pith/JRVWERKSO44DUMCLHMB2DYDYJZ.json","view_paper":"https://pith.science/paper/JRVWERKS","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1812.00740&json=true","fetch_graph":"https://pith.science/api/pith-number/JRVWERKSO44DUMCLHMB2DYDYJZ/graph.json","fetch_events":"https://pith.science/api/pith-number/JRVWERKSO44DUMCLHMB2DYDYJZ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/JRVWERKSO44DUMCLHMB2DYDYJZ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/JRVWERKSO44DUMCLHMB2DYDYJZ/action/storage_attestation","attest_author":"https://pith.science/pith/JRVWERKSO44DUMCLHMB2DYDYJZ/action/author_attestation","sign_citation":"https://pith.science/pith/JRVWERKSO44DUMCLHMB2DYDYJZ/action/citation_signature","submit_replication":"https://pith.science/pith/JRVWERKSO44DUMCLHMB2DYDYJZ/action/replication_record"}},"created_at":"2026-05-17T23:48:55.194802+00:00","updated_at":"2026-05-17T23:48:55.194802+00:00"}