{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:LHW3UGZ4U5AYGQRQSTNHV6SVQJ","short_pith_number":"pith:LHW3UGZ4","canonical_record":{"source":{"id":"1707.04131","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-07-13T13:59:15Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"96b748498a2c95c26c9699cf06b9b7c2817966af4c99e2b118811e7e6f81bc12","abstract_canon_sha256":"f7c32e5fe4d3a533bb4075e0fb29c73b7d3997e1b8c4f6c83a4d4622b49129a9"},"schema_version":"1.0"},"canonical_sha256":"59edba1b3ca74183423094da7afa55825b8f28abd294c89bf2f527c7a505bcfd","source":{"kind":"arxiv","id":"1707.04131","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1707.04131","created_at":"2026-05-18T00:20:39Z"},{"alias_kind":"arxiv_version","alias_value":"1707.04131v3","created_at":"2026-05-18T00:20:39Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1707.04131","created_at":"2026-05-18T00:20:39Z"},{"alias_kind":"pith_short_12","alias_value":"LHW3UGZ4U5AY","created_at":"2026-05-18T12:31:28Z"},{"alias_kind":"pith_short_16","alias_value":"LHW3UGZ4U5AYGQRQ","created_at":"2026-05-18T12:31:28Z"},{"alias_kind":"pith_short_8","alias_value":"LHW3UGZ4","created_at":"2026-05-18T12:31:28Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:LHW3UGZ4U5AYGQRQSTNHV6SVQJ","target":"record","payload":{"canonical_record":{"source":{"id":"1707.04131","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-07-13T13:59:15Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"96b748498a2c95c26c9699cf06b9b7c2817966af4c99e2b118811e7e6f81bc12","abstract_canon_sha256":"f7c32e5fe4d3a533bb4075e0fb29c73b7d3997e1b8c4f6c83a4d4622b49129a9"},"schema_version":"1.0"},"canonical_sha256":"59edba1b3ca74183423094da7afa55825b8f28abd294c89bf2f527c7a505bcfd","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:20:39.423218Z","signature_b64":"1VzcYcmFIWovoEGF6yRFeyd6xaQkpyM2FIFUnQMiht58ajfnwmB4C8Uygg89ofNknWKvbKxuB5CNRdHWOnvZDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"59edba1b3ca74183423094da7afa55825b8f28abd294c89bf2f527c7a505bcfd","last_reissued_at":"2026-05-18T00:20:39.422640Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:20:39.422640Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1707.04131","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:20:39Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"zq24vuuMnWLmWnU4/Yhf93nZNwIfLIv3czRHD8XL03d7HM8pVPXuMSR7MYRfWBPW13YEaVo/hBEyS9JSdLX5DA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T00:40:25.712068Z"},"content_sha256":"239e4e4df28ce7ec64381b46e871d1e5f37834be617cbef108e3b0a7b4cc0c23","schema_version":"1.0","event_id":"sha256:239e4e4df28ce7ec64381b46e871d1e5f37834be617cbef108e3b0a7b4cc0c23"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:LHW3UGZ4U5AYGQRQSTNHV6SVQJ","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Foolbox: A Python toolbox to benchmark the robustness of machine learning models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Jonas Rauber, Matthias Bethge, Wieland Brendel","submitted_at":"2017-07-13T13:59:15Z","abstract_excerpt":"Even todays most advanced machine learning models are easily fooled by almost imperceptible perturbations of their inputs. Foolbox is a new Python package to generate such adversarial perturbations and to quantify and compare the robustness of machine learning models. It is build around the idea that the most comparable robustness measure is the minimum perturbation needed to craft an adversarial example. To this end, Foolbox provides reference implementations of most published adversarial attack methods alongside some new ones, all of which perform internal hyperparameter tuning to find the m"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1707.04131","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:20:39Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Nuz7J3zcXP7Hb+RggiCLOImdZxUSfORM85fT6h7ynlsXKNUJnenlKA1qE6OzCPDLT4kWsysDB0zFc9NFTZBcBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T00:40:25.712745Z"},"content_sha256":"9ba8305bed6dab9cbf6cf6d50e12d2db5fcb508624206bb9647736e22f042f6c","schema_version":"1.0","event_id":"sha256:9ba8305bed6dab9cbf6cf6d50e12d2db5fcb508624206bb9647736e22f042f6c"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/LHW3UGZ4U5AYGQRQSTNHV6SVQJ/bundle.json","state_url":"https://pith.science/pith/LHW3UGZ4U5AYGQRQSTNHV6SVQJ/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/LHW3UGZ4U5AYGQRQSTNHV6SVQJ/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T00:40:25Z","links":{"resolver":"https://pith.science/pith/LHW3UGZ4U5AYGQRQSTNHV6SVQJ","bundle":"https://pith.science/pith/LHW3UGZ4U5AYGQRQSTNHV6SVQJ/bundle.json","state":"https://pith.science/pith/LHW3UGZ4U5AYGQRQSTNHV6SVQJ/state.json","well_known_bundle":"https://pith.science/.well-known/pith/LHW3UGZ4U5AYGQRQSTNHV6SVQJ/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:LHW3UGZ4U5AYGQRQSTNHV6SVQJ","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"f7c32e5fe4d3a533bb4075e0fb29c73b7d3997e1b8c4f6c83a4d4622b49129a9","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-07-13T13:59:15Z","title_canon_sha256":"96b748498a2c95c26c9699cf06b9b7c2817966af4c99e2b118811e7e6f81bc12"},"schema_version":"1.0","source":{"id":"1707.04131","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1707.04131","created_at":"2026-05-18T00:20:39Z"},{"alias_kind":"arxiv_version","alias_value":"1707.04131v3","created_at":"2026-05-18T00:20:39Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1707.04131","created_at":"2026-05-18T00:20:39Z"},{"alias_kind":"pith_short_12","alias_value":"LHW3UGZ4U5AY","created_at":"2026-05-18T12:31:28Z"},{"alias_kind":"pith_short_16","alias_value":"LHW3UGZ4U5AYGQRQ","created_at":"2026-05-18T12:31:28Z"},{"alias_kind":"pith_short_8","alias_value":"LHW3UGZ4","created_at":"2026-05-18T12:31:28Z"}],"graph_snapshots":[{"event_id":"sha256:9ba8305bed6dab9cbf6cf6d50e12d2db5fcb508624206bb9647736e22f042f6c","target":"graph","created_at":"2026-05-18T00:20:39Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Even todays most advanced machine learning models are easily fooled by almost imperceptible perturbations of their inputs. Foolbox is a new Python package to generate such adversarial perturbations and to quantify and compare the robustness of machine learning models. It is build around the idea that the most comparable robustness measure is the minimum perturbation needed to craft an adversarial example. To this end, Foolbox provides reference implementations of most published adversarial attack methods alongside some new ones, all of which perform internal hyperparameter tuning to find the m","authors_text":"Jonas Rauber, Matthias Bethge, Wieland Brendel","cross_cats":["cs.CR","cs.CV","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-07-13T13:59:15Z","title":"Foolbox: A Python toolbox to benchmark the robustness of machine learning models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1707.04131","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:239e4e4df28ce7ec64381b46e871d1e5f37834be617cbef108e3b0a7b4cc0c23","target":"record","created_at":"2026-05-18T00:20:39Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"f7c32e5fe4d3a533bb4075e0fb29c73b7d3997e1b8c4f6c83a4d4622b49129a9","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-07-13T13:59:15Z","title_canon_sha256":"96b748498a2c95c26c9699cf06b9b7c2817966af4c99e2b118811e7e6f81bc12"},"schema_version":"1.0","source":{"id":"1707.04131","kind":"arxiv","version":3}},"canonical_sha256":"59edba1b3ca74183423094da7afa55825b8f28abd294c89bf2f527c7a505bcfd","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"59edba1b3ca74183423094da7afa55825b8f28abd294c89bf2f527c7a505bcfd","first_computed_at":"2026-05-18T00:20:39.422640Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:20:39.422640Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"1VzcYcmFIWovoEGF6yRFeyd6xaQkpyM2FIFUnQMiht58ajfnwmB4C8Uygg89ofNknWKvbKxuB5CNRdHWOnvZDA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:20:39.423218Z","signed_message":"canonical_sha256_bytes"},"source_id":"1707.04131","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:239e4e4df28ce7ec64381b46e871d1e5f37834be617cbef108e3b0a7b4cc0c23","sha256:9ba8305bed6dab9cbf6cf6d50e12d2db5fcb508624206bb9647736e22f042f6c"],"state_sha256":"4b93abb4eb471ac688ea4f3b35df1f11b361639520996783a0e1cf3d238ea2a3"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"sfH87r4plwhvsXLogqp6kfmhl8Pxq7vO7jkVKEEqvhQcoddXHNG3GzERysLxe7+qZGvowk+ABavd/u4mSeduAA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T00:40:25.716368Z","bundle_sha256":"e769325551daee0de8375d8ad434f2c28821ac84f0f07f31ae1d873559a08b98"}}