{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2021:JYOHGSL4C6QHYLWCNJO222KTDY","short_pith_number":"pith:JYOHGSL4","canonical_record":{"source":{"id":"2106.11420","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2021-06-21T21:42:08Z","cross_cats_sorted":[],"title_canon_sha256":"e29bca6fa770a68667944c306915f775edec9dfd6f85c6fbe634f25c49e2d8b2","abstract_canon_sha256":"2c23d915982a2cb0976cb8fc0d88206d70ce9a52c4da5583a5e8c9ceffa1b2f7"},"schema_version":"1.0"},"canonical_sha256":"4e1c73497c17a07c2ec26a5dad69531e20dd3609cb155c280509a6bfd3257adf","source":{"kind":"arxiv","id":"2106.11420","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2106.11420","created_at":"2026-07-05T04:27:06Z"},{"alias_kind":"arxiv_version","alias_value":"2106.11420v3","created_at":"2026-07-05T04:27:06Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2106.11420","created_at":"2026-07-05T04:27:06Z"},{"alias_kind":"pith_short_12","alias_value":"JYOHGSL4C6QH","created_at":"2026-07-05T04:27:06Z"},{"alias_kind":"pith_short_16","alias_value":"JYOHGSL4C6QHYLWC","created_at":"2026-07-05T04:27:06Z"},{"alias_kind":"pith_short_8","alias_value":"JYOHGSL4","created_at":"2026-07-05T04:27:06Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2021:JYOHGSL4C6QHYLWCNJO222KTDY","target":"record","payload":{"canonical_record":{"source":{"id":"2106.11420","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2021-06-21T21:42:08Z","cross_cats_sorted":[],"title_canon_sha256":"e29bca6fa770a68667944c306915f775edec9dfd6f85c6fbe634f25c49e2d8b2","abstract_canon_sha256":"2c23d915982a2cb0976cb8fc0d88206d70ce9a52c4da5583a5e8c9ceffa1b2f7"},"schema_version":"1.0"},"canonical_sha256":"4e1c73497c17a07c2ec26a5dad69531e20dd3609cb155c280509a6bfd3257adf","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T04:27:06.179904Z","signature_b64":"LL2wR/a5Dx5KMVCzm5bxt3dN+VY5RkoJLO5A1sP58cl8rViruWFaKVAMQHAZhh7FLXgpN58cwb0kbzZzCGSoCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"4e1c73497c17a07c2ec26a5dad69531e20dd3609cb155c280509a6bfd3257adf","last_reissued_at":"2026-07-05T04:27:06.179442Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T04:27:06.179442Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2106.11420","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T04:27:06Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"z8iZGGSCHLp32MIw26BO2NWNOIibMM0CDrYAmGRDhUsnY/M9a9g7Ng9RaUpr71wAwyBXPD68PHDJwVP8vDq+Dg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-23T09:40:43.801556Z"},"content_sha256":"9a616658cabaf4a8fc69c7a610e3ab3a8eb37b124ff77c8abfcc3c6f710730de","schema_version":"1.0","event_id":"sha256:9a616658cabaf4a8fc69c7a610e3ab3a8eb37b124ff77c8abfcc3c6f710730de"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2021:JYOHGSL4C6QHYLWCNJO222KTDY","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Policy Smoothing for Provably Robust Reinforcement Learning","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Alexander Levine, Aounon Kumar, Soheil Feizi","submitted_at":"2021-06-21T21:42:08Z","abstract_excerpt":"The study of provable adversarial robustness for deep neural networks (DNNs) has mainly focused on static supervised learning tasks such as image classification. However, DNNs have been used extensively in real-world adaptive tasks such as reinforcement learning (RL), making such systems vulnerable to adversarial attacks as well. Prior works in provable robustness in RL seek to certify the behaviour of the victim policy at every time-step against a non-adaptive adversary using methods developed for the static setting. But in the real world, an RL adversary can infer the defense strategy used b"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2106.11420","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2106.11420/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T04:27:06Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"G/Q5YR7/Gf9XZ8LBDdZ8tXVM1kcvUZnPjnbP0n1LM1OhkEI5M5aS4k7rmw486dtjQw9WJy6uZDCGtnLONEd3Dg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-23T09:40:43.802124Z"},"content_sha256":"1d138d9181b7a226189e1e472d2cc15dd0ac142e04a08a17d9623098f0cd8873","schema_version":"1.0","event_id":"sha256:1d138d9181b7a226189e1e472d2cc15dd0ac142e04a08a17d9623098f0cd8873"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/JYOHGSL4C6QHYLWCNJO222KTDY/bundle.json","state_url":"https://pith.science/pith/JYOHGSL4C6QHYLWCNJO222KTDY/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/JYOHGSL4C6QHYLWCNJO222KTDY/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-23T09:40:43Z","links":{"resolver":"https://pith.science/pith/JYOHGSL4C6QHYLWCNJO222KTDY","bundle":"https://pith.science/pith/JYOHGSL4C6QHYLWCNJO222KTDY/bundle.json","state":"https://pith.science/pith/JYOHGSL4C6QHYLWCNJO222KTDY/state.json","well_known_bundle":"https://pith.science/.well-known/pith/JYOHGSL4C6QHYLWCNJO222KTDY/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2021:JYOHGSL4C6QHYLWCNJO222KTDY","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"2c23d915982a2cb0976cb8fc0d88206d70ce9a52c4da5583a5e8c9ceffa1b2f7","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2021-06-21T21:42:08Z","title_canon_sha256":"e29bca6fa770a68667944c306915f775edec9dfd6f85c6fbe634f25c49e2d8b2"},"schema_version":"1.0","source":{"id":"2106.11420","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2106.11420","created_at":"2026-07-05T04:27:06Z"},{"alias_kind":"arxiv_version","alias_value":"2106.11420v3","created_at":"2026-07-05T04:27:06Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2106.11420","created_at":"2026-07-05T04:27:06Z"},{"alias_kind":"pith_short_12","alias_value":"JYOHGSL4C6QH","created_at":"2026-07-05T04:27:06Z"},{"alias_kind":"pith_short_16","alias_value":"JYOHGSL4C6QHYLWC","created_at":"2026-07-05T04:27:06Z"},{"alias_kind":"pith_short_8","alias_value":"JYOHGSL4","created_at":"2026-07-05T04:27:06Z"}],"graph_snapshots":[{"event_id":"sha256:1d138d9181b7a226189e1e472d2cc15dd0ac142e04a08a17d9623098f0cd8873","target":"graph","created_at":"2026-07-05T04:27:06Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2106.11420/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"The study of provable adversarial robustness for deep neural networks (DNNs) has mainly focused on static supervised learning tasks such as image classification. However, DNNs have been used extensively in real-world adaptive tasks such as reinforcement learning (RL), making such systems vulnerable to adversarial attacks as well. Prior works in provable robustness in RL seek to certify the behaviour of the victim policy at every time-step against a non-adaptive adversary using methods developed for the static setting. But in the real world, an RL adversary can infer the defense strategy used b","authors_text":"Alexander Levine, Aounon Kumar, Soheil Feizi","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2021-06-21T21:42:08Z","title":"Policy Smoothing for Provably Robust Reinforcement Learning"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2106.11420","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:9a616658cabaf4a8fc69c7a610e3ab3a8eb37b124ff77c8abfcc3c6f710730de","target":"record","created_at":"2026-07-05T04:27:06Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"2c23d915982a2cb0976cb8fc0d88206d70ce9a52c4da5583a5e8c9ceffa1b2f7","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2021-06-21T21:42:08Z","title_canon_sha256":"e29bca6fa770a68667944c306915f775edec9dfd6f85c6fbe634f25c49e2d8b2"},"schema_version":"1.0","source":{"id":"2106.11420","kind":"arxiv","version":3}},"canonical_sha256":"4e1c73497c17a07c2ec26a5dad69531e20dd3609cb155c280509a6bfd3257adf","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"4e1c73497c17a07c2ec26a5dad69531e20dd3609cb155c280509a6bfd3257adf","first_computed_at":"2026-07-05T04:27:06.179442Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T04:27:06.179442Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"LL2wR/a5Dx5KMVCzm5bxt3dN+VY5RkoJLO5A1sP58cl8rViruWFaKVAMQHAZhh7FLXgpN58cwb0kbzZzCGSoCg==","signature_status":"signed_v1","signed_at":"2026-07-05T04:27:06.179904Z","signed_message":"canonical_sha256_bytes"},"source_id":"2106.11420","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:9a616658cabaf4a8fc69c7a610e3ab3a8eb37b124ff77c8abfcc3c6f710730de","sha256:1d138d9181b7a226189e1e472d2cc15dd0ac142e04a08a17d9623098f0cd8873"],"state_sha256":"e08419eef6e2295d8d8556445251aa352178928e2bbc4560337e645e55165a92"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"BLD6Or91pl0cddVFjJ1CKv0TRlq6r0hGP+clEY4yIADyiAWx+JzQmqkxbe0iJz8+RdQ+sG2eHD9F+E13vv4pDg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-23T09:40:43.806310Z","bundle_sha256":"6d5bb7996be28ff1c78a6fb26aded35eeabd36d5d2afa3bf16413a47b1875c13"}}