{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:LFOPWFHH72GFBGHJ4HTXISBESS","short_pith_number":"pith:LFOPWFHH","canonical_record":{"source":{"id":"1907.00374","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-06-30T12:42:09Z","cross_cats_sorted":["cs.CV","eess.IV"],"title_canon_sha256":"e45a6580e0a07fa8f0019d069671a5c77b3eb80e7fce62ae4bb9ec38714f6e38","abstract_canon_sha256":"0a5b64f5e410b91e3123adf99d7cdf196bb53c942e778d5e102ca685a5fd08fc"},"schema_version":"1.0"},"canonical_sha256":"595cfb14e7fe8c5098e9e1e77448249496341d15f542013aaaa89820aa4b4300","source":{"kind":"arxiv","id":"1907.00374","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1907.00374","created_at":"2026-05-17T23:41:51Z"},{"alias_kind":"arxiv_version","alias_value":"1907.00374v1","created_at":"2026-05-17T23:41:51Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1907.00374","created_at":"2026-05-17T23:41:51Z"},{"alias_kind":"pith_short_12","alias_value":"LFOPWFHH72GF","created_at":"2026-05-18T12:33:21Z"},{"alias_kind":"pith_short_16","alias_value":"LFOPWFHH72GFBGHJ","created_at":"2026-05-18T12:33:21Z"},{"alias_kind":"pith_short_8","alias_value":"LFOPWFHH","created_at":"2026-05-18T12:33:21Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:LFOPWFHH72GFBGHJ4HTXISBESS","target":"record","payload":{"canonical_record":{"source":{"id":"1907.00374","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-06-30T12:42:09Z","cross_cats_sorted":["cs.CV","eess.IV"],"title_canon_sha256":"e45a6580e0a07fa8f0019d069671a5c77b3eb80e7fce62ae4bb9ec38714f6e38","abstract_canon_sha256":"0a5b64f5e410b91e3123adf99d7cdf196bb53c942e778d5e102ca685a5fd08fc"},"schema_version":"1.0"},"canonical_sha256":"595cfb14e7fe8c5098e9e1e77448249496341d15f542013aaaa89820aa4b4300","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:41:51.950194Z","signature_b64":"/3X8iHr7KMrskq7isCuHM2tlJdkOyJgYzK8+9pl3Xd3j+c16A1K9LNyY94PZaE5EsYEh4gOKdyRpe/h3Ug1YAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"595cfb14e7fe8c5098e9e1e77448249496341d15f542013aaaa89820aa4b4300","last_reissued_at":"2026-05-17T23:41:51.947101Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:41:51.947101Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1907.00374","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:41:51Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"as5/65uj1hKNOWLCFtu0ruLyV3jSSBySawUN8pW0ladB4ZDQ6x6xKsyaRDWialPr140DpRyBVkchfm62nzm+Bw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T23:02:55.703556Z"},"content_sha256":"a59080bb39c0028352646d650189f5b9168270ceb5c708aaf63c573fd278f456","schema_version":"1.0","event_id":"sha256:a59080bb39c0028352646d650189f5b9168270ceb5c708aaf63c573fd278f456"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:LFOPWFHH72GFBGHJ4HTXISBESS","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Fooling a Real Car with Adversarial Traffic Signs","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","eess.IV"],"primary_cat":"cs.CR","authors_text":"Alexander Kreines, Nir Morgulis, Shachar Mendelowitz, Yuval Weisglass","submitted_at":"2019-06-30T12:42:09Z","abstract_excerpt":"The attacks on the neural-network-based classifiers using adversarial images have gained a lot of attention recently. An adversary can purposely generate an image that is indistinguishable from a innocent image for a human being but is incorrectly classified by the neural networks. The adversarial images do not need to be tuned to a particular architecture of the classifier - an image that fools one network can fool another one with a certain success rate.The published works mostly concentrate on the use of modified image files for attacks against the classifiers trained on the model databases"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1907.00374","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:41:51Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"041MovBWishXeQ+xhEDfvBIwhOtsLkZJMpAqiKmJwj246jubKyQtNA2ODhYeLkL8pd/E6K6yK9kV7yO6oyyTBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T23:02:55.704244Z"},"content_sha256":"9d4f014c621694757d0e38aa1404833fae00fb2e933d15bc3fb123de9b391b61","schema_version":"1.0","event_id":"sha256:9d4f014c621694757d0e38aa1404833fae00fb2e933d15bc3fb123de9b391b61"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/LFOPWFHH72GFBGHJ4HTXISBESS/bundle.json","state_url":"https://pith.science/pith/LFOPWFHH72GFBGHJ4HTXISBESS/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/LFOPWFHH72GFBGHJ4HTXISBESS/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T23:02:55Z","links":{"resolver":"https://pith.science/pith/LFOPWFHH72GFBGHJ4HTXISBESS","bundle":"https://pith.science/pith/LFOPWFHH72GFBGHJ4HTXISBESS/bundle.json","state":"https://pith.science/pith/LFOPWFHH72GFBGHJ4HTXISBESS/state.json","well_known_bundle":"https://pith.science/.well-known/pith/LFOPWFHH72GFBGHJ4HTXISBESS/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:LFOPWFHH72GFBGHJ4HTXISBESS","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"0a5b64f5e410b91e3123adf99d7cdf196bb53c942e778d5e102ca685a5fd08fc","cross_cats_sorted":["cs.CV","eess.IV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-06-30T12:42:09Z","title_canon_sha256":"e45a6580e0a07fa8f0019d069671a5c77b3eb80e7fce62ae4bb9ec38714f6e38"},"schema_version":"1.0","source":{"id":"1907.00374","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1907.00374","created_at":"2026-05-17T23:41:51Z"},{"alias_kind":"arxiv_version","alias_value":"1907.00374v1","created_at":"2026-05-17T23:41:51Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1907.00374","created_at":"2026-05-17T23:41:51Z"},{"alias_kind":"pith_short_12","alias_value":"LFOPWFHH72GF","created_at":"2026-05-18T12:33:21Z"},{"alias_kind":"pith_short_16","alias_value":"LFOPWFHH72GFBGHJ","created_at":"2026-05-18T12:33:21Z"},{"alias_kind":"pith_short_8","alias_value":"LFOPWFHH","created_at":"2026-05-18T12:33:21Z"}],"graph_snapshots":[{"event_id":"sha256:9d4f014c621694757d0e38aa1404833fae00fb2e933d15bc3fb123de9b391b61","target":"graph","created_at":"2026-05-17T23:41:51Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"The attacks on the neural-network-based classifiers using adversarial images have gained a lot of attention recently. An adversary can purposely generate an image that is indistinguishable from a innocent image for a human being but is incorrectly classified by the neural networks. The adversarial images do not need to be tuned to a particular architecture of the classifier - an image that fools one network can fool another one with a certain success rate.The published works mostly concentrate on the use of modified image files for attacks against the classifiers trained on the model databases","authors_text":"Alexander Kreines, Nir Morgulis, Shachar Mendelowitz, Yuval Weisglass","cross_cats":["cs.CV","eess.IV"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-06-30T12:42:09Z","title":"Fooling a Real Car with Adversarial Traffic Signs"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1907.00374","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:a59080bb39c0028352646d650189f5b9168270ceb5c708aaf63c573fd278f456","target":"record","created_at":"2026-05-17T23:41:51Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"0a5b64f5e410b91e3123adf99d7cdf196bb53c942e778d5e102ca685a5fd08fc","cross_cats_sorted":["cs.CV","eess.IV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-06-30T12:42:09Z","title_canon_sha256":"e45a6580e0a07fa8f0019d069671a5c77b3eb80e7fce62ae4bb9ec38714f6e38"},"schema_version":"1.0","source":{"id":"1907.00374","kind":"arxiv","version":1}},"canonical_sha256":"595cfb14e7fe8c5098e9e1e77448249496341d15f542013aaaa89820aa4b4300","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"595cfb14e7fe8c5098e9e1e77448249496341d15f542013aaaa89820aa4b4300","first_computed_at":"2026-05-17T23:41:51.947101Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:41:51.947101Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"/3X8iHr7KMrskq7isCuHM2tlJdkOyJgYzK8+9pl3Xd3j+c16A1K9LNyY94PZaE5EsYEh4gOKdyRpe/h3Ug1YAQ==","signature_status":"signed_v1","signed_at":"2026-05-17T23:41:51.950194Z","signed_message":"canonical_sha256_bytes"},"source_id":"1907.00374","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:a59080bb39c0028352646d650189f5b9168270ceb5c708aaf63c573fd278f456","sha256:9d4f014c621694757d0e38aa1404833fae00fb2e933d15bc3fb123de9b391b61"],"state_sha256":"623bcfce12fc833a182b540029c8456c04a4fad0a863bde8f7dccc427723f9b1"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"r0cwl8lmUiz5QL9wSShGNa69qnQRbyhhDam8TTcwNipH7t1XBGY/KNskCux10Fi0WBZuakXAd1sGKJlHLgslBA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T23:02:55.708254Z","bundle_sha256":"0299873a949e03e0d0af30eb6c22a074e26edb8874a70abf28ce9205ed303eab"}}