{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:JUHND5XE5BKYUOKMLMLAF3HOBT","short_pith_number":"pith:JUHND5XE","canonical_record":{"source":{"id":"1703.00410","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-03-01T17:43:10Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"db6437cb7ca7ef6b6f559f54cda508bff4e67abf68e04629928f933274e16c77","abstract_canon_sha256":"2dcecc4e2ea2a83a5ad31e6d381a1d992868357818d2a97c380bee37e51523d8"},"schema_version":"1.0"},"canonical_sha256":"4d0ed1f6e4e8558a394c5b1602ecee0cc2321fe441e624ca07bfd4f879e6fbcb","source":{"kind":"arxiv","id":"1703.00410","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1703.00410","created_at":"2026-05-18T00:30:28Z"},{"alias_kind":"arxiv_version","alias_value":"1703.00410v3","created_at":"2026-05-18T00:30:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1703.00410","created_at":"2026-05-18T00:30:28Z"},{"alias_kind":"pith_short_12","alias_value":"JUHND5XE5BKY","created_at":"2026-05-18T12:31:24Z"},{"alias_kind":"pith_short_16","alias_value":"JUHND5XE5BKYUOKM","created_at":"2026-05-18T12:31:24Z"},{"alias_kind":"pith_short_8","alias_value":"JUHND5XE","created_at":"2026-05-18T12:31:24Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:JUHND5XE5BKYUOKMLMLAF3HOBT","target":"record","payload":{"canonical_record":{"source":{"id":"1703.00410","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-03-01T17:43:10Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"db6437cb7ca7ef6b6f559f54cda508bff4e67abf68e04629928f933274e16c77","abstract_canon_sha256":"2dcecc4e2ea2a83a5ad31e6d381a1d992868357818d2a97c380bee37e51523d8"},"schema_version":"1.0"},"canonical_sha256":"4d0ed1f6e4e8558a394c5b1602ecee0cc2321fe441e624ca07bfd4f879e6fbcb","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:30:28.457975Z","signature_b64":"ANBHqXOqwDb4ITfaXxYWkVXtd08/e/jpuredtlTJxAhUtyoiza6bAYUBwvNN4vrX1vhDVrkPyxtDZPyOJ0WpBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"4d0ed1f6e4e8558a394c5b1602ecee0cc2321fe441e624ca07bfd4f879e6fbcb","last_reissued_at":"2026-05-18T00:30:28.457541Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:30:28.457541Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1703.00410","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:30:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"nme+uA2HrdgrWQoKO0Nw6pex85pIbztRiWSxlojcjdiE9pd7LfxvOK66TkWJTNVzg6EILUN7yfASPuJVg2FsAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T15:08:46.864070Z"},"content_sha256":"f06738006c05e5a39eb01cecedc3aed0d06641e858b09c94250bac5659fd0977","schema_version":"1.0","event_id":"sha256:f06738006c05e5a39eb01cecedc3aed0d06641e858b09c94250bac5659fd0977"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:JUHND5XE5BKYUOKMLMLAF3HOBT","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Detecting Adversarial Samples from Artifacts","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"stat.ML","authors_text":"Andrew B. Gardner, Reuben Feinman, Ryan R. Curtin, Saurabh Shintre","submitted_at":"2017-03-01T17:43:10Z","abstract_excerpt":"Deep neural networks (DNNs) are powerful nonlinear architectures that are known to be robust to random perturbations of the input. However, these models are vulnerable to adversarial perturbations--small input changes crafted explicitly to fool the model. In this paper, we ask whether a DNN can distinguish adversarial samples from their normal and noisy counterparts. We investigate model confidence on adversarial samples by looking at Bayesian uncertainty estimates, available in dropout neural networks, and by performing density estimation in the subspace of deep features learned by the model."},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1703.00410","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:30:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"n6M+7PxyqvRvaFEjpE4PG1VL2pvfWSRwuwYfYLmIBxZNNCXy2gcyAnhpEu8H5zW66INGuU9TvLMVH5/04VRRCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T15:08:46.864740Z"},"content_sha256":"823d7ae6e797b6bfc312d0a71dd89cffeb07ac0ea9422cfc873dda63720585e4","schema_version":"1.0","event_id":"sha256:823d7ae6e797b6bfc312d0a71dd89cffeb07ac0ea9422cfc873dda63720585e4"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/JUHND5XE5BKYUOKMLMLAF3HOBT/bundle.json","state_url":"https://pith.science/pith/JUHND5XE5BKYUOKMLMLAF3HOBT/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/JUHND5XE5BKYUOKMLMLAF3HOBT/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T15:08:46Z","links":{"resolver":"https://pith.science/pith/JUHND5XE5BKYUOKMLMLAF3HOBT","bundle":"https://pith.science/pith/JUHND5XE5BKYUOKMLMLAF3HOBT/bundle.json","state":"https://pith.science/pith/JUHND5XE5BKYUOKMLMLAF3HOBT/state.json","well_known_bundle":"https://pith.science/.well-known/pith/JUHND5XE5BKYUOKMLMLAF3HOBT/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:JUHND5XE5BKYUOKMLMLAF3HOBT","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"2dcecc4e2ea2a83a5ad31e6d381a1d992868357818d2a97c380bee37e51523d8","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-03-01T17:43:10Z","title_canon_sha256":"db6437cb7ca7ef6b6f559f54cda508bff4e67abf68e04629928f933274e16c77"},"schema_version":"1.0","source":{"id":"1703.00410","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1703.00410","created_at":"2026-05-18T00:30:28Z"},{"alias_kind":"arxiv_version","alias_value":"1703.00410v3","created_at":"2026-05-18T00:30:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1703.00410","created_at":"2026-05-18T00:30:28Z"},{"alias_kind":"pith_short_12","alias_value":"JUHND5XE5BKY","created_at":"2026-05-18T12:31:24Z"},{"alias_kind":"pith_short_16","alias_value":"JUHND5XE5BKYUOKM","created_at":"2026-05-18T12:31:24Z"},{"alias_kind":"pith_short_8","alias_value":"JUHND5XE","created_at":"2026-05-18T12:31:24Z"}],"graph_snapshots":[{"event_id":"sha256:823d7ae6e797b6bfc312d0a71dd89cffeb07ac0ea9422cfc873dda63720585e4","target":"graph","created_at":"2026-05-18T00:30:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep neural networks (DNNs) are powerful nonlinear architectures that are known to be robust to random perturbations of the input. However, these models are vulnerable to adversarial perturbations--small input changes crafted explicitly to fool the model. In this paper, we ask whether a DNN can distinguish adversarial samples from their normal and noisy counterparts. We investigate model confidence on adversarial samples by looking at Bayesian uncertainty estimates, available in dropout neural networks, and by performing density estimation in the subspace of deep features learned by the model.","authors_text":"Andrew B. Gardner, Reuben Feinman, Ryan R. Curtin, Saurabh Shintre","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-03-01T17:43:10Z","title":"Detecting Adversarial Samples from Artifacts"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1703.00410","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:f06738006c05e5a39eb01cecedc3aed0d06641e858b09c94250bac5659fd0977","target":"record","created_at":"2026-05-18T00:30:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"2dcecc4e2ea2a83a5ad31e6d381a1d992868357818d2a97c380bee37e51523d8","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-03-01T17:43:10Z","title_canon_sha256":"db6437cb7ca7ef6b6f559f54cda508bff4e67abf68e04629928f933274e16c77"},"schema_version":"1.0","source":{"id":"1703.00410","kind":"arxiv","version":3}},"canonical_sha256":"4d0ed1f6e4e8558a394c5b1602ecee0cc2321fe441e624ca07bfd4f879e6fbcb","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"4d0ed1f6e4e8558a394c5b1602ecee0cc2321fe441e624ca07bfd4f879e6fbcb","first_computed_at":"2026-05-18T00:30:28.457541Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:30:28.457541Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"ANBHqXOqwDb4ITfaXxYWkVXtd08/e/jpuredtlTJxAhUtyoiza6bAYUBwvNN4vrX1vhDVrkPyxtDZPyOJ0WpBA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:30:28.457975Z","signed_message":"canonical_sha256_bytes"},"source_id":"1703.00410","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:f06738006c05e5a39eb01cecedc3aed0d06641e858b09c94250bac5659fd0977","sha256:823d7ae6e797b6bfc312d0a71dd89cffeb07ac0ea9422cfc873dda63720585e4"],"state_sha256":"54bf21d9407ead1b2d9a7c43dff301f6a587759a209ca244f0dc93666fc6c7d2"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ziHyoW4N1s9FavXsXK3MW8wpQPW4mLrNDfW4mNakX8h6Lla3UkJBbtkwHWA+o7tb08H9uKJqllp8f/2nHjHRDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T15:08:46.867938Z","bundle_sha256":"cfebdd1467f0dca680999257b18cae793af6fb3aae38bc2c96df32293d99f63f"}}