{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:LRF3K7ZFVPACCTV2PZPTHY2W3D","short_pith_number":"pith:LRF3K7ZF","canonical_record":{"source":{"id":"1702.02284","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-02-08T04:33:55Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"e2e2ae06fb1ec29c45acc4f0ba2f6117f331eb1eda0552f8cc96fc209608fa4e","abstract_canon_sha256":"2ad7cf7a05e277008b4f03a8c0d36d7af058f6effce6714a3582bcf4d4f02409"},"schema_version":"1.0"},"canonical_sha256":"5c4bb57f25abc0214eba7e5f33e356d8ef9b8ce2135bbc917f0986dc8a9c38e4","source":{"kind":"arxiv","id":"1702.02284","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1702.02284","created_at":"2026-05-18T00:51:06Z"},{"alias_kind":"arxiv_version","alias_value":"1702.02284v1","created_at":"2026-05-18T00:51:06Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1702.02284","created_at":"2026-05-18T00:51:06Z"},{"alias_kind":"pith_short_12","alias_value":"LRF3K7ZFVPAC","created_at":"2026-05-18T12:31:28Z"},{"alias_kind":"pith_short_16","alias_value":"LRF3K7ZFVPACCTV2","created_at":"2026-05-18T12:31:28Z"},{"alias_kind":"pith_short_8","alias_value":"LRF3K7ZF","created_at":"2026-05-18T12:31:28Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:LRF3K7ZFVPACCTV2PZPTHY2W3D","target":"record","payload":{"canonical_record":{"source":{"id":"1702.02284","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-02-08T04:33:55Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"e2e2ae06fb1ec29c45acc4f0ba2f6117f331eb1eda0552f8cc96fc209608fa4e","abstract_canon_sha256":"2ad7cf7a05e277008b4f03a8c0d36d7af058f6effce6714a3582bcf4d4f02409"},"schema_version":"1.0"},"canonical_sha256":"5c4bb57f25abc0214eba7e5f33e356d8ef9b8ce2135bbc917f0986dc8a9c38e4","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:51:06.296871Z","signature_b64":"PGHBU0OkuS91uhA8cbGk3N/3P4ltBFw9gWWQ5bcRoZJRAl2E7srlwsowIm/7RN15RnBcTPYNPPiqtHyu/h7JCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"5c4bb57f25abc0214eba7e5f33e356d8ef9b8ce2135bbc917f0986dc8a9c38e4","last_reissued_at":"2026-05-18T00:51:06.296291Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:51:06.296291Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1702.02284","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:51:06Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"P0UCHRbbeZXp1ZvIs/l1muIKVVxRp0dvpkTGNG4SNlbeLyEt406B3wum7coVqypty43rQbxZu3hf9McxXy2kAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T14:41:40.567281Z"},"content_sha256":"8bf8ea9ced176a172d1afb5d8d46384d0f1372810e4068359fd8c60a0cd28a88","schema_version":"1.0","event_id":"sha256:8bf8ea9ced176a172d1afb5d8d46384d0f1372810e4068359fd8c60a0cd28a88"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:LRF3K7ZFVPACCTV2PZPTHY2W3D","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Adversarial Attacks on Neural Network Policies","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Ian Goodfellow, Nicolas Papernot, Pieter Abbeel, Sandy Huang, Yan Duan","submitted_at":"2017-02-08T04:33:55Z","abstract_excerpt":"Machine learning classifiers are known to be vulnerable to inputs maliciously constructed by adversaries to force misclassification. Such adversarial examples have been extensively studied in the context of computer vision applications. In this work, we show adversarial attacks are also effective when targeting neural network policies in reinforcement learning. Specifically, we show existing adversarial example crafting techniques can be used to significantly degrade test-time performance of trained policies. Our threat model considers adversaries capable of introducing small perturbations to "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1702.02284","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:51:06Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"lSj6HjCMXTQ9vfkTuWPrLPfvvu8IMyEpC2cvbTZ0L6IuWBxziAGx2Psk4UpEgJewNk4NBozIBNXlc6c4JDA0Cw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T14:41:40.567970Z"},"content_sha256":"9b0940d9759782d3ce2d3401c0dd1b323019f54434c251aa74eb5152eb3f4b8c","schema_version":"1.0","event_id":"sha256:9b0940d9759782d3ce2d3401c0dd1b323019f54434c251aa74eb5152eb3f4b8c"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/LRF3K7ZFVPACCTV2PZPTHY2W3D/bundle.json","state_url":"https://pith.science/pith/LRF3K7ZFVPACCTV2PZPTHY2W3D/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/LRF3K7ZFVPACCTV2PZPTHY2W3D/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T14:41:40Z","links":{"resolver":"https://pith.science/pith/LRF3K7ZFVPACCTV2PZPTHY2W3D","bundle":"https://pith.science/pith/LRF3K7ZFVPACCTV2PZPTHY2W3D/bundle.json","state":"https://pith.science/pith/LRF3K7ZFVPACCTV2PZPTHY2W3D/state.json","well_known_bundle":"https://pith.science/.well-known/pith/LRF3K7ZFVPACCTV2PZPTHY2W3D/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:LRF3K7ZFVPACCTV2PZPTHY2W3D","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"2ad7cf7a05e277008b4f03a8c0d36d7af058f6effce6714a3582bcf4d4f02409","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-02-08T04:33:55Z","title_canon_sha256":"e2e2ae06fb1ec29c45acc4f0ba2f6117f331eb1eda0552f8cc96fc209608fa4e"},"schema_version":"1.0","source":{"id":"1702.02284","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1702.02284","created_at":"2026-05-18T00:51:06Z"},{"alias_kind":"arxiv_version","alias_value":"1702.02284v1","created_at":"2026-05-18T00:51:06Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1702.02284","created_at":"2026-05-18T00:51:06Z"},{"alias_kind":"pith_short_12","alias_value":"LRF3K7ZFVPAC","created_at":"2026-05-18T12:31:28Z"},{"alias_kind":"pith_short_16","alias_value":"LRF3K7ZFVPACCTV2","created_at":"2026-05-18T12:31:28Z"},{"alias_kind":"pith_short_8","alias_value":"LRF3K7ZF","created_at":"2026-05-18T12:31:28Z"}],"graph_snapshots":[{"event_id":"sha256:9b0940d9759782d3ce2d3401c0dd1b323019f54434c251aa74eb5152eb3f4b8c","target":"graph","created_at":"2026-05-18T00:51:06Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Machine learning classifiers are known to be vulnerable to inputs maliciously constructed by adversaries to force misclassification. Such adversarial examples have been extensively studied in the context of computer vision applications. In this work, we show adversarial attacks are also effective when targeting neural network policies in reinforcement learning. Specifically, we show existing adversarial example crafting techniques can be used to significantly degrade test-time performance of trained policies. Our threat model considers adversaries capable of introducing small perturbations to ","authors_text":"Ian Goodfellow, Nicolas Papernot, Pieter Abbeel, Sandy Huang, Yan Duan","cross_cats":["cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-02-08T04:33:55Z","title":"Adversarial Attacks on Neural Network Policies"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1702.02284","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:8bf8ea9ced176a172d1afb5d8d46384d0f1372810e4068359fd8c60a0cd28a88","target":"record","created_at":"2026-05-18T00:51:06Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"2ad7cf7a05e277008b4f03a8c0d36d7af058f6effce6714a3582bcf4d4f02409","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-02-08T04:33:55Z","title_canon_sha256":"e2e2ae06fb1ec29c45acc4f0ba2f6117f331eb1eda0552f8cc96fc209608fa4e"},"schema_version":"1.0","source":{"id":"1702.02284","kind":"arxiv","version":1}},"canonical_sha256":"5c4bb57f25abc0214eba7e5f33e356d8ef9b8ce2135bbc917f0986dc8a9c38e4","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"5c4bb57f25abc0214eba7e5f33e356d8ef9b8ce2135bbc917f0986dc8a9c38e4","first_computed_at":"2026-05-18T00:51:06.296291Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:51:06.296291Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"PGHBU0OkuS91uhA8cbGk3N/3P4ltBFw9gWWQ5bcRoZJRAl2E7srlwsowIm/7RN15RnBcTPYNPPiqtHyu/h7JCg==","signature_status":"signed_v1","signed_at":"2026-05-18T00:51:06.296871Z","signed_message":"canonical_sha256_bytes"},"source_id":"1702.02284","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:8bf8ea9ced176a172d1afb5d8d46384d0f1372810e4068359fd8c60a0cd28a88","sha256:9b0940d9759782d3ce2d3401c0dd1b323019f54434c251aa74eb5152eb3f4b8c"],"state_sha256":"052f99b73172b40abd428b8e2b2555cbab97c5f7d90d964a14462d0f90ed937a"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"SsBDq/UTK/9KTevduz0Bvc3DB7UlZW5VFlu8AeRWu/F04M5WH8h7898j3rDlzZNlhc6Z0MVoxtlRzQkOK7JiAQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T14:41:40.571030Z","bundle_sha256":"f089d825d166c22ee14136784ae5395f3eb389cb507f5e59657c838b913cf25b"}}