{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:LES6TEVBFCQV6IODOIB6433MB7","short_pith_number":"pith:LES6TEVB","canonical_record":{"source":{"id":"1811.09985","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-25T10:31:53Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"c426ef0e39516c5509af19eaf8283597309929e8b565dfc472052b884a250d5b","abstract_canon_sha256":"029195332444c55cc86a126b647a48f3a753f4814006355da5966da7eac50143"},"schema_version":"1.0"},"canonical_sha256":"5925e992a128a15f21c37203ee6f6c0ff6e82829c0d1c0c13f19f5c8bd6ba973","source":{"kind":"arxiv","id":"1811.09985","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1811.09985","created_at":"2026-05-17T23:59:58Z"},{"alias_kind":"arxiv_version","alias_value":"1811.09985v1","created_at":"2026-05-17T23:59:58Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.09985","created_at":"2026-05-17T23:59:58Z"},{"alias_kind":"pith_short_12","alias_value":"LES6TEVBFCQV","created_at":"2026-05-18T12:32:37Z"},{"alias_kind":"pith_short_16","alias_value":"LES6TEVBFCQV6IOD","created_at":"2026-05-18T12:32:37Z"},{"alias_kind":"pith_short_8","alias_value":"LES6TEVB","created_at":"2026-05-18T12:32:37Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:LES6TEVBFCQV6IODOIB6433MB7","target":"record","payload":{"canonical_record":{"source":{"id":"1811.09985","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-25T10:31:53Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"c426ef0e39516c5509af19eaf8283597309929e8b565dfc472052b884a250d5b","abstract_canon_sha256":"029195332444c55cc86a126b647a48f3a753f4814006355da5966da7eac50143"},"schema_version":"1.0"},"canonical_sha256":"5925e992a128a15f21c37203ee6f6c0ff6e82829c0d1c0c13f19f5c8bd6ba973","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:59:58.927282Z","signature_b64":"Qb02Pswv78uJMplLdOqS167N48ZJlW4Ps7/WP7Z9XJLY956ceVTD29No9LwowLRuZ4L8bxX3LaV8KrUOdZunAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"5925e992a128a15f21c37203ee6f6c0ff6e82829c0d1c0c13f19f5c8bd6ba973","last_reissued_at":"2026-05-17T23:59:58.926808Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:59:58.926808Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1811.09985","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:59:58Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"FchmDLMYXtqTiw4CahXhE9FczUsrMswaFxzXxV+4Yde+tz32OzjsfDodkzfXoQqVjwhta/Z/v3J9eMLB7+XTBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-07T05:58:57.123210Z"},"content_sha256":"2076a0193a8dd28180d02a9f72631371ebe5bc535f6c5f9fb58f212b50dfdfdc","schema_version":"1.0","event_id":"sha256:2076a0193a8dd28180d02a9f72631371ebe5bc535f6c5f9fb58f212b50dfdfdc"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:LES6TEVBFCQV6IODOIB6433MB7","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Poisoning Behavioral Malware Clustering","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Battista Biggio, Christian Wressnegger, Davide Ariu, Fabio Roli, Giorgio Giacinto, Igino Corona, Konrad Rieck","submitted_at":"2018-11-25T10:31:53Z","abstract_excerpt":"Clustering algorithms have become a popular tool in computer security to analyze the behavior of malware variants, identify novel malware families, and generate signatures for antivirus systems. However, the suitability of clustering algorithms for security-sensitive settings has been recently questioned by showing that they can be significantly compromised if an attacker can exercise some control over the input data. In this paper, we revisit this problem by focusing on behavioral malware clustering approaches, and investigate whether and to what extent an attacker may be able to subvert thes"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.09985","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:59:58Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"+0k01EgX6+0SGPZYFtzNaaozM8gcuSvnP05y6BV5CH5kacI6H4oi61ES6IsQxC3ZO590cobvKt63A20QNAMFAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-07T05:58:57.123883Z"},"content_sha256":"0687e7499df0a8e0369300ad5f8fdce4b59f3a8190187d3617951cbc3078cc58","schema_version":"1.0","event_id":"sha256:0687e7499df0a8e0369300ad5f8fdce4b59f3a8190187d3617951cbc3078cc58"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/LES6TEVBFCQV6IODOIB6433MB7/bundle.json","state_url":"https://pith.science/pith/LES6TEVBFCQV6IODOIB6433MB7/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/LES6TEVBFCQV6IODOIB6433MB7/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-07T05:58:57Z","links":{"resolver":"https://pith.science/pith/LES6TEVBFCQV6IODOIB6433MB7","bundle":"https://pith.science/pith/LES6TEVBFCQV6IODOIB6433MB7/bundle.json","state":"https://pith.science/pith/LES6TEVBFCQV6IODOIB6433MB7/state.json","well_known_bundle":"https://pith.science/.well-known/pith/LES6TEVBFCQV6IODOIB6433MB7/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:LES6TEVBFCQV6IODOIB6433MB7","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"029195332444c55cc86a126b647a48f3a753f4814006355da5966da7eac50143","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-25T10:31:53Z","title_canon_sha256":"c426ef0e39516c5509af19eaf8283597309929e8b565dfc472052b884a250d5b"},"schema_version":"1.0","source":{"id":"1811.09985","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1811.09985","created_at":"2026-05-17T23:59:58Z"},{"alias_kind":"arxiv_version","alias_value":"1811.09985v1","created_at":"2026-05-17T23:59:58Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.09985","created_at":"2026-05-17T23:59:58Z"},{"alias_kind":"pith_short_12","alias_value":"LES6TEVBFCQV","created_at":"2026-05-18T12:32:37Z"},{"alias_kind":"pith_short_16","alias_value":"LES6TEVBFCQV6IOD","created_at":"2026-05-18T12:32:37Z"},{"alias_kind":"pith_short_8","alias_value":"LES6TEVB","created_at":"2026-05-18T12:32:37Z"}],"graph_snapshots":[{"event_id":"sha256:0687e7499df0a8e0369300ad5f8fdce4b59f3a8190187d3617951cbc3078cc58","target":"graph","created_at":"2026-05-17T23:59:58Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Clustering algorithms have become a popular tool in computer security to analyze the behavior of malware variants, identify novel malware families, and generate signatures for antivirus systems. However, the suitability of clustering algorithms for security-sensitive settings has been recently questioned by showing that they can be significantly compromised if an attacker can exercise some control over the input data. In this paper, we revisit this problem by focusing on behavioral malware clustering approaches, and investigate whether and to what extent an attacker may be able to subvert thes","authors_text":"Battista Biggio, Christian Wressnegger, Davide Ariu, Fabio Roli, Giorgio Giacinto, Igino Corona, Konrad Rieck","cross_cats":["cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-25T10:31:53Z","title":"Poisoning Behavioral Malware Clustering"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.09985","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:2076a0193a8dd28180d02a9f72631371ebe5bc535f6c5f9fb58f212b50dfdfdc","target":"record","created_at":"2026-05-17T23:59:58Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"029195332444c55cc86a126b647a48f3a753f4814006355da5966da7eac50143","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-25T10:31:53Z","title_canon_sha256":"c426ef0e39516c5509af19eaf8283597309929e8b565dfc472052b884a250d5b"},"schema_version":"1.0","source":{"id":"1811.09985","kind":"arxiv","version":1}},"canonical_sha256":"5925e992a128a15f21c37203ee6f6c0ff6e82829c0d1c0c13f19f5c8bd6ba973","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"5925e992a128a15f21c37203ee6f6c0ff6e82829c0d1c0c13f19f5c8bd6ba973","first_computed_at":"2026-05-17T23:59:58.926808Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:59:58.926808Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Qb02Pswv78uJMplLdOqS167N48ZJlW4Ps7/WP7Z9XJLY956ceVTD29No9LwowLRuZ4L8bxX3LaV8KrUOdZunAg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:59:58.927282Z","signed_message":"canonical_sha256_bytes"},"source_id":"1811.09985","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:2076a0193a8dd28180d02a9f72631371ebe5bc535f6c5f9fb58f212b50dfdfdc","sha256:0687e7499df0a8e0369300ad5f8fdce4b59f3a8190187d3617951cbc3078cc58"],"state_sha256":"6d1f2ad66b69c2cb64d87b65bca7d4cd3031af60dd8bf7201be059ba23d3f933"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ZQlEcc8ZlCLZTNpBqLE3jJnRk5YXrkTD9qEVcqHknxe2tpouT6ZIJzBjBBhsayTMeejC+Un5fuxSWZEq28l9Aw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-07T05:58:57.127089Z","bundle_sha256":"67d019fdb0c4f96526e7dcfcb19b7c4e292343d050e7192041259affad1108aa"}}