{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:KTYQUPZIBSDEOX7DETYWUY2AJQ","short_pith_number":"pith:KTYQUPZI","canonical_record":{"source":{"id":"1906.03972","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-06-10T13:38:23Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"d2325e9118260486021320d751e22403a12ea558850669c511be9c146241beb4","abstract_canon_sha256":"e6c3da3aa246dc59f69596e42716693a39d12743cbfa81d92f5d905712b190d1"},"schema_version":"1.0"},"canonical_sha256":"54f10a3f280c86475fe324f16a63404c2027df74c0aec68a85f27a9186329aa1","source":{"kind":"arxiv","id":"1906.03972","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1906.03972","created_at":"2026-05-17T23:43:44Z"},{"alias_kind":"arxiv_version","alias_value":"1906.03972v1","created_at":"2026-05-17T23:43:44Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1906.03972","created_at":"2026-05-17T23:43:44Z"},{"alias_kind":"pith_short_12","alias_value":"KTYQUPZIBSDE","created_at":"2026-05-18T12:33:21Z"},{"alias_kind":"pith_short_16","alias_value":"KTYQUPZIBSDEOX7D","created_at":"2026-05-18T12:33:21Z"},{"alias_kind":"pith_short_8","alias_value":"KTYQUPZI","created_at":"2026-05-18T12:33:21Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:KTYQUPZIBSDEOX7DETYWUY2AJQ","target":"record","payload":{"canonical_record":{"source":{"id":"1906.03972","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-06-10T13:38:23Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"d2325e9118260486021320d751e22403a12ea558850669c511be9c146241beb4","abstract_canon_sha256":"e6c3da3aa246dc59f69596e42716693a39d12743cbfa81d92f5d905712b190d1"},"schema_version":"1.0"},"canonical_sha256":"54f10a3f280c86475fe324f16a63404c2027df74c0aec68a85f27a9186329aa1","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:43:44.345162Z","signature_b64":"2lfpGoHE925fac2+IWL3UJDwpIllXfArrCsuHQfafZRNuz8+1rFVFLFBvd2fr06eVqRGDNKogh+wVhp/n7DAAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"54f10a3f280c86475fe324f16a63404c2027df74c0aec68a85f27a9186329aa1","last_reissued_at":"2026-05-17T23:43:44.344443Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:43:44.344443Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1906.03972","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:43:44Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"6ysPJEJmNNFZjIvhjrx979U6WP0UvUndHUbQw6wSpdcbfbC2Ch/8lEUIc+uiOxJqd6kM7UEkQGzDshugJwWlDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-31T03:18:18.848723Z"},"content_sha256":"5d77ce88ddc7674979aa84cf49f690a2d56ba81ce2d4a1e32ef258c554965e1e","schema_version":"1.0","event_id":"sha256:5d77ce88ddc7674979aa84cf49f690a2d56ba81ce2d4a1e32ef258c554965e1e"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:KTYQUPZIBSDEOX7DETYWUY2AJQ","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Evaluating the Robustness of Nearest Neighbor Classifiers: A Primal-Dual Perspective","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Cho-Jui Hsieh, Jinfeng Yi, Lu Wang, Xuanqing Liu, Zhi-Hua Zhou","submitted_at":"2019-06-10T13:38:23Z","abstract_excerpt":"We study the problem of computing the minimum adversarial perturbation of the Nearest Neighbor (NN) classifiers. Previous attempts either conduct attacks on continuous approximations of NN models or search for the perturbation by some heuristic methods. In this paper, we propose the first algorithm that is able to compute the minimum adversarial perturbation. The main idea is to formulate the problem as a list of convex quadratic programming (QP) problems that can be efficiently solved by the proposed algorithms for 1-NN models. Furthermore, we show that dual solutions for these QP problems co"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1906.03972","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:43:44Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"/kfpbwO0LrS7aYmT3CuBHT5eoM2j08EIY4/LiRpPdmPDrg9QkpwQJl6zilZL1b/ljYcWho3wFnK29eG27x4yDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-31T03:18:18.849070Z"},"content_sha256":"d27093be0132798935b6eda5201e34e473bb9820bc9f869c89802fb6f27c101b","schema_version":"1.0","event_id":"sha256:d27093be0132798935b6eda5201e34e473bb9820bc9f869c89802fb6f27c101b"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/KTYQUPZIBSDEOX7DETYWUY2AJQ/bundle.json","state_url":"https://pith.science/pith/KTYQUPZIBSDEOX7DETYWUY2AJQ/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/KTYQUPZIBSDEOX7DETYWUY2AJQ/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-31T03:18:18Z","links":{"resolver":"https://pith.science/pith/KTYQUPZIBSDEOX7DETYWUY2AJQ","bundle":"https://pith.science/pith/KTYQUPZIBSDEOX7DETYWUY2AJQ/bundle.json","state":"https://pith.science/pith/KTYQUPZIBSDEOX7DETYWUY2AJQ/state.json","well_known_bundle":"https://pith.science/.well-known/pith/KTYQUPZIBSDEOX7DETYWUY2AJQ/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:KTYQUPZIBSDEOX7DETYWUY2AJQ","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e6c3da3aa246dc59f69596e42716693a39d12743cbfa81d92f5d905712b190d1","cross_cats_sorted":["stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-06-10T13:38:23Z","title_canon_sha256":"d2325e9118260486021320d751e22403a12ea558850669c511be9c146241beb4"},"schema_version":"1.0","source":{"id":"1906.03972","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1906.03972","created_at":"2026-05-17T23:43:44Z"},{"alias_kind":"arxiv_version","alias_value":"1906.03972v1","created_at":"2026-05-17T23:43:44Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1906.03972","created_at":"2026-05-17T23:43:44Z"},{"alias_kind":"pith_short_12","alias_value":"KTYQUPZIBSDE","created_at":"2026-05-18T12:33:21Z"},{"alias_kind":"pith_short_16","alias_value":"KTYQUPZIBSDEOX7D","created_at":"2026-05-18T12:33:21Z"},{"alias_kind":"pith_short_8","alias_value":"KTYQUPZI","created_at":"2026-05-18T12:33:21Z"}],"graph_snapshots":[{"event_id":"sha256:d27093be0132798935b6eda5201e34e473bb9820bc9f869c89802fb6f27c101b","target":"graph","created_at":"2026-05-17T23:43:44Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We study the problem of computing the minimum adversarial perturbation of the Nearest Neighbor (NN) classifiers. Previous attempts either conduct attacks on continuous approximations of NN models or search for the perturbation by some heuristic methods. In this paper, we propose the first algorithm that is able to compute the minimum adversarial perturbation. The main idea is to formulate the problem as a list of convex quadratic programming (QP) problems that can be efficiently solved by the proposed algorithms for 1-NN models. Furthermore, we show that dual solutions for these QP problems co","authors_text":"Cho-Jui Hsieh, Jinfeng Yi, Lu Wang, Xuanqing Liu, Zhi-Hua Zhou","cross_cats":["stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-06-10T13:38:23Z","title":"Evaluating the Robustness of Nearest Neighbor Classifiers: A Primal-Dual Perspective"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1906.03972","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:5d77ce88ddc7674979aa84cf49f690a2d56ba81ce2d4a1e32ef258c554965e1e","target":"record","created_at":"2026-05-17T23:43:44Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e6c3da3aa246dc59f69596e42716693a39d12743cbfa81d92f5d905712b190d1","cross_cats_sorted":["stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-06-10T13:38:23Z","title_canon_sha256":"d2325e9118260486021320d751e22403a12ea558850669c511be9c146241beb4"},"schema_version":"1.0","source":{"id":"1906.03972","kind":"arxiv","version":1}},"canonical_sha256":"54f10a3f280c86475fe324f16a63404c2027df74c0aec68a85f27a9186329aa1","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"54f10a3f280c86475fe324f16a63404c2027df74c0aec68a85f27a9186329aa1","first_computed_at":"2026-05-17T23:43:44.344443Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:43:44.344443Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"2lfpGoHE925fac2+IWL3UJDwpIllXfArrCsuHQfafZRNuz8+1rFVFLFBvd2fr06eVqRGDNKogh+wVhp/n7DAAQ==","signature_status":"signed_v1","signed_at":"2026-05-17T23:43:44.345162Z","signed_message":"canonical_sha256_bytes"},"source_id":"1906.03972","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:5d77ce88ddc7674979aa84cf49f690a2d56ba81ce2d4a1e32ef258c554965e1e","sha256:d27093be0132798935b6eda5201e34e473bb9820bc9f869c89802fb6f27c101b"],"state_sha256":"fabb4f0ed97a0b87229f7b0da8d9d18329eace1be491a32aedfc29db21aecd38"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Acp7AJfhJSI0l74jNz27IBVe/hAAHwRmC0uK968fEusM1nb+LHAIbwFHVi27MIOeNAETreJlkG3Bu3NcLpExAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-31T03:18:18.851259Z","bundle_sha256":"903f357f70699a1b27139f9dc1f579919fb1c20c410cbec00f352672447406b3"}}