{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:JU2BUEHCSKQDCUVCRORHE74MMO","short_pith_number":"pith:JU2BUEHC","canonical_record":{"source":{"id":"1904.01160","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-04-02T01:16:01Z","cross_cats_sorted":[],"title_canon_sha256":"af6c04dfe4d42cc463f27c3618157adeffcbb297bfe02bda4cb5a06214f15fd4","abstract_canon_sha256":"1576096ea6f8c63fdece4cbad1ede15a68d2737d3f3073afcbc2a6e009bc722a"},"schema_version":"1.0"},"canonical_sha256":"4d341a10e292a03152a28ba2727f8c63a6659d45bb0d8c281dfa57583fa7ba8c","source":{"kind":"arxiv","id":"1904.01160","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1904.01160","created_at":"2026-05-17T23:49:35Z"},{"alias_kind":"arxiv_version","alias_value":"1904.01160v1","created_at":"2026-05-17T23:49:35Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1904.01160","created_at":"2026-05-17T23:49:35Z"},{"alias_kind":"pith_short_12","alias_value":"JU2BUEHCSKQD","created_at":"2026-05-18T12:33:21Z"},{"alias_kind":"pith_short_16","alias_value":"JU2BUEHCSKQDCUVC","created_at":"2026-05-18T12:33:21Z"},{"alias_kind":"pith_short_8","alias_value":"JU2BUEHC","created_at":"2026-05-18T12:33:21Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:JU2BUEHCSKQDCUVCRORHE74MMO","target":"record","payload":{"canonical_record":{"source":{"id":"1904.01160","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-04-02T01:16:01Z","cross_cats_sorted":[],"title_canon_sha256":"af6c04dfe4d42cc463f27c3618157adeffcbb297bfe02bda4cb5a06214f15fd4","abstract_canon_sha256":"1576096ea6f8c63fdece4cbad1ede15a68d2737d3f3073afcbc2a6e009bc722a"},"schema_version":"1.0"},"canonical_sha256":"4d341a10e292a03152a28ba2727f8c63a6659d45bb0d8c281dfa57583fa7ba8c","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:49:35.728517Z","signature_b64":"2GEmBWh1zf66t/jd2LsHSuBroafamIBq1kgU7uXnZjpQ5xWQTI0xf5HAHluMEenPdFaRWfBZsgUtb9pScAp0Dg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"4d341a10e292a03152a28ba2727f8c63a6659d45bb0d8c281dfa57583fa7ba8c","last_reissued_at":"2026-05-17T23:49:35.727860Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:49:35.727860Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1904.01160","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:49:35Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"HLlWrOhPTHfSbCP9AejHACXvdguF52JOVyuTNm9nqaQA41fn2lvVdQ7FeR9TwNwms78UjOVmC0teKpAJXXfXDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-04T23:14:08.566696Z"},"content_sha256":"7a0a1d0b6db5080a92ca153d6fd0da69ab77e329535554b508abf2c297cabb8d","schema_version":"1.0","event_id":"sha256:7a0a1d0b6db5080a92ca153d6fd0da69ab77e329535554b508abf2c297cabb8d"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:JU2BUEHCSKQDCUVCRORHE74MMO","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Curls & Whey: Boosting Black-Box Adversarial Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CV","authors_text":"Siyu Wang, Yahong Han, Yucheng Shi","submitted_at":"2019-04-02T01:16:01Z","abstract_excerpt":"Image classifiers based on deep neural networks suffer from harassment caused by adversarial examples. Two defects exist in black-box iterative attacks that generate adversarial examples by incrementally adjusting the noise-adding direction for each step. On the one hand, existing iterative attacks add noises monotonically along the direction of gradient ascent, resulting in a lack of diversity and adaptability of the generated iterative trajectories. On the other hand, it is trivial to perform adversarial attack by adding excessive noises, but currently there is no refinement mechanism to squ"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1904.01160","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:49:35Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"XOaXrhlNR5qNnyLPys6HgQRYL3QqMwSMUXQ/ZCQgW8NQZrra04igunl/6DMT5lvuOarVxgvn6Yotj2yBvGtWBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-04T23:14:08.567029Z"},"content_sha256":"4c22800110a6135a91bd7b6c9f7bd3f34d6c38eaea012f2014ebe2fbfd4c1c48","schema_version":"1.0","event_id":"sha256:4c22800110a6135a91bd7b6c9f7bd3f34d6c38eaea012f2014ebe2fbfd4c1c48"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/JU2BUEHCSKQDCUVCRORHE74MMO/bundle.json","state_url":"https://pith.science/pith/JU2BUEHCSKQDCUVCRORHE74MMO/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/JU2BUEHCSKQDCUVCRORHE74MMO/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-04T23:14:08Z","links":{"resolver":"https://pith.science/pith/JU2BUEHCSKQDCUVCRORHE74MMO","bundle":"https://pith.science/pith/JU2BUEHCSKQDCUVCRORHE74MMO/bundle.json","state":"https://pith.science/pith/JU2BUEHCSKQDCUVCRORHE74MMO/state.json","well_known_bundle":"https://pith.science/.well-known/pith/JU2BUEHCSKQDCUVCRORHE74MMO/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:JU2BUEHCSKQDCUVCRORHE74MMO","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"1576096ea6f8c63fdece4cbad1ede15a68d2737d3f3073afcbc2a6e009bc722a","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-04-02T01:16:01Z","title_canon_sha256":"af6c04dfe4d42cc463f27c3618157adeffcbb297bfe02bda4cb5a06214f15fd4"},"schema_version":"1.0","source":{"id":"1904.01160","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1904.01160","created_at":"2026-05-17T23:49:35Z"},{"alias_kind":"arxiv_version","alias_value":"1904.01160v1","created_at":"2026-05-17T23:49:35Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1904.01160","created_at":"2026-05-17T23:49:35Z"},{"alias_kind":"pith_short_12","alias_value":"JU2BUEHCSKQD","created_at":"2026-05-18T12:33:21Z"},{"alias_kind":"pith_short_16","alias_value":"JU2BUEHCSKQDCUVC","created_at":"2026-05-18T12:33:21Z"},{"alias_kind":"pith_short_8","alias_value":"JU2BUEHC","created_at":"2026-05-18T12:33:21Z"}],"graph_snapshots":[{"event_id":"sha256:4c22800110a6135a91bd7b6c9f7bd3f34d6c38eaea012f2014ebe2fbfd4c1c48","target":"graph","created_at":"2026-05-17T23:49:35Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Image classifiers based on deep neural networks suffer from harassment caused by adversarial examples. Two defects exist in black-box iterative attacks that generate adversarial examples by incrementally adjusting the noise-adding direction for each step. On the one hand, existing iterative attacks add noises monotonically along the direction of gradient ascent, resulting in a lack of diversity and adaptability of the generated iterative trajectories. On the other hand, it is trivial to perform adversarial attack by adding excessive noises, but currently there is no refinement mechanism to squ","authors_text":"Siyu Wang, Yahong Han, Yucheng Shi","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-04-02T01:16:01Z","title":"Curls & Whey: Boosting Black-Box Adversarial Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1904.01160","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:7a0a1d0b6db5080a92ca153d6fd0da69ab77e329535554b508abf2c297cabb8d","target":"record","created_at":"2026-05-17T23:49:35Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"1576096ea6f8c63fdece4cbad1ede15a68d2737d3f3073afcbc2a6e009bc722a","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-04-02T01:16:01Z","title_canon_sha256":"af6c04dfe4d42cc463f27c3618157adeffcbb297bfe02bda4cb5a06214f15fd4"},"schema_version":"1.0","source":{"id":"1904.01160","kind":"arxiv","version":1}},"canonical_sha256":"4d341a10e292a03152a28ba2727f8c63a6659d45bb0d8c281dfa57583fa7ba8c","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"4d341a10e292a03152a28ba2727f8c63a6659d45bb0d8c281dfa57583fa7ba8c","first_computed_at":"2026-05-17T23:49:35.727860Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:49:35.727860Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"2GEmBWh1zf66t/jd2LsHSuBroafamIBq1kgU7uXnZjpQ5xWQTI0xf5HAHluMEenPdFaRWfBZsgUtb9pScAp0Dg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:49:35.728517Z","signed_message":"canonical_sha256_bytes"},"source_id":"1904.01160","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:7a0a1d0b6db5080a92ca153d6fd0da69ab77e329535554b508abf2c297cabb8d","sha256:4c22800110a6135a91bd7b6c9f7bd3f34d6c38eaea012f2014ebe2fbfd4c1c48"],"state_sha256":"4685149da7ab0bf47eb275fba6a28655bcba0aed1c1bd7d2cbfa52583ea6b7e1"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"4YQIxvlc9zTnI6jFqbEU6scN1bQ6HokGIKpOu+oo3Ri3kCbGQFDvdI7Nfuok0MK7MceAJjzmqrXazNOye3Y4BA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-04T23:14:08.568914Z","bundle_sha256":"30ec9948ce4dce92c431f5ee6e670cbecf5dc7e5f5b5a3fd1280f8ed681ca59a"}}