{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:LTFOEYITQEPOAKELPYCC3IDBBE","short_pith_number":"pith:LTFOEYIT","canonical_record":{"source":{"id":"1904.08653","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-04-18T09:46:03Z","cross_cats_sorted":[],"title_canon_sha256":"f067b5c5bfaf64209285c73a550f37e73fe96d887eb1029bcff6fe3c42d62404","abstract_canon_sha256":"92487ea2024ff82caac7d3984a86d9234ed8e27236f8f66607cb8c3eee0e8585"},"schema_version":"1.0"},"canonical_sha256":"5ccae26113811ee0288b7e042da06109176e63df75d6be1d7b553087422a2e6a","source":{"kind":"arxiv","id":"1904.08653","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1904.08653","created_at":"2026-05-17T23:48:13Z"},{"alias_kind":"arxiv_version","alias_value":"1904.08653v1","created_at":"2026-05-17T23:48:13Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1904.08653","created_at":"2026-05-17T23:48:13Z"},{"alias_kind":"pith_short_12","alias_value":"LTFOEYITQEPO","created_at":"2026-05-18T12:33:21Z"},{"alias_kind":"pith_short_16","alias_value":"LTFOEYITQEPOAKEL","created_at":"2026-05-18T12:33:21Z"},{"alias_kind":"pith_short_8","alias_value":"LTFOEYIT","created_at":"2026-05-18T12:33:21Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:LTFOEYITQEPOAKELPYCC3IDBBE","target":"record","payload":{"canonical_record":{"source":{"id":"1904.08653","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-04-18T09:46:03Z","cross_cats_sorted":[],"title_canon_sha256":"f067b5c5bfaf64209285c73a550f37e73fe96d887eb1029bcff6fe3c42d62404","abstract_canon_sha256":"92487ea2024ff82caac7d3984a86d9234ed8e27236f8f66607cb8c3eee0e8585"},"schema_version":"1.0"},"canonical_sha256":"5ccae26113811ee0288b7e042da06109176e63df75d6be1d7b553087422a2e6a","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:48:13.526823Z","signature_b64":"m6wMSuihEw7+0XAoRTbO306CaaPff2LSo6OwkdPAZ9i1myU306lASwn8KbDvQrCemwwSawGTLM0IcnH9OraCBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"5ccae26113811ee0288b7e042da06109176e63df75d6be1d7b553087422a2e6a","last_reissued_at":"2026-05-17T23:48:13.526120Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:48:13.526120Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1904.08653","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:48:13Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ZQWCouWV0MgcKDLVeJqRfDCJAdw6jENRM0IoSOIqsugPjMQhwVcfFloZ53lOBUQKMk4tidoqk9cWpD9pURBACA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T23:30:41.378009Z"},"content_sha256":"4b9bdffb1e1d708768c1947889e877a626e118952b4c3caf4220f13bdb559b6e","schema_version":"1.0","event_id":"sha256:4b9bdffb1e1d708768c1947889e877a626e118952b4c3caf4220f13bdb559b6e"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:LTFOEYITQEPOAKELPYCC3IDBBE","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Fooling automated surveillance cameras: adversarial patches to attack person detection","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CV","authors_text":"Simen Thys, Toon Goedem\\'e, Wiebe Van Ranst","submitted_at":"2019-04-18T09:46:03Z","abstract_excerpt":"Adversarial attacks on machine learning models have seen increasing interest in the past years. By making only subtle changes to the input of a convolutional neural network, the output of the network can be swayed to output a completely different result. The first attacks did this by changing pixel values of an input image slightly to fool a classifier to output the wrong class. Other approaches have tried to learn \"patches\" that can be applied to an object to fool detectors and classifiers. Some of these approaches have also shown that these attacks are feasible in the real-world, i.e. by mod"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1904.08653","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:48:13Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"1Mus1kQxd5jzhu/wVcOZWe7PFYGUF8dyjrgaDvXyPyegLRWgYaNWvkZNOlT7IxxNEFt6D94DZeI1rNCnFfZuBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T23:30:41.378724Z"},"content_sha256":"b28230b506173b5068fc704bc45f581da6f3d3f8e60568009c88b3420ce32d5c","schema_version":"1.0","event_id":"sha256:b28230b506173b5068fc704bc45f581da6f3d3f8e60568009c88b3420ce32d5c"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/LTFOEYITQEPOAKELPYCC3IDBBE/bundle.json","state_url":"https://pith.science/pith/LTFOEYITQEPOAKELPYCC3IDBBE/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/LTFOEYITQEPOAKELPYCC3IDBBE/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T23:30:41Z","links":{"resolver":"https://pith.science/pith/LTFOEYITQEPOAKELPYCC3IDBBE","bundle":"https://pith.science/pith/LTFOEYITQEPOAKELPYCC3IDBBE/bundle.json","state":"https://pith.science/pith/LTFOEYITQEPOAKELPYCC3IDBBE/state.json","well_known_bundle":"https://pith.science/.well-known/pith/LTFOEYITQEPOAKELPYCC3IDBBE/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:LTFOEYITQEPOAKELPYCC3IDBBE","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"92487ea2024ff82caac7d3984a86d9234ed8e27236f8f66607cb8c3eee0e8585","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-04-18T09:46:03Z","title_canon_sha256":"f067b5c5bfaf64209285c73a550f37e73fe96d887eb1029bcff6fe3c42d62404"},"schema_version":"1.0","source":{"id":"1904.08653","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1904.08653","created_at":"2026-05-17T23:48:13Z"},{"alias_kind":"arxiv_version","alias_value":"1904.08653v1","created_at":"2026-05-17T23:48:13Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1904.08653","created_at":"2026-05-17T23:48:13Z"},{"alias_kind":"pith_short_12","alias_value":"LTFOEYITQEPO","created_at":"2026-05-18T12:33:21Z"},{"alias_kind":"pith_short_16","alias_value":"LTFOEYITQEPOAKEL","created_at":"2026-05-18T12:33:21Z"},{"alias_kind":"pith_short_8","alias_value":"LTFOEYIT","created_at":"2026-05-18T12:33:21Z"}],"graph_snapshots":[{"event_id":"sha256:b28230b506173b5068fc704bc45f581da6f3d3f8e60568009c88b3420ce32d5c","target":"graph","created_at":"2026-05-17T23:48:13Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Adversarial attacks on machine learning models have seen increasing interest in the past years. By making only subtle changes to the input of a convolutional neural network, the output of the network can be swayed to output a completely different result. The first attacks did this by changing pixel values of an input image slightly to fool a classifier to output the wrong class. Other approaches have tried to learn \"patches\" that can be applied to an object to fool detectors and classifiers. Some of these approaches have also shown that these attacks are feasible in the real-world, i.e. by mod","authors_text":"Simen Thys, Toon Goedem\\'e, Wiebe Van Ranst","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-04-18T09:46:03Z","title":"Fooling automated surveillance cameras: adversarial patches to attack person detection"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1904.08653","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:4b9bdffb1e1d708768c1947889e877a626e118952b4c3caf4220f13bdb559b6e","target":"record","created_at":"2026-05-17T23:48:13Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"92487ea2024ff82caac7d3984a86d9234ed8e27236f8f66607cb8c3eee0e8585","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-04-18T09:46:03Z","title_canon_sha256":"f067b5c5bfaf64209285c73a550f37e73fe96d887eb1029bcff6fe3c42d62404"},"schema_version":"1.0","source":{"id":"1904.08653","kind":"arxiv","version":1}},"canonical_sha256":"5ccae26113811ee0288b7e042da06109176e63df75d6be1d7b553087422a2e6a","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"5ccae26113811ee0288b7e042da06109176e63df75d6be1d7b553087422a2e6a","first_computed_at":"2026-05-17T23:48:13.526120Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:48:13.526120Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"m6wMSuihEw7+0XAoRTbO306CaaPff2LSo6OwkdPAZ9i1myU306lASwn8KbDvQrCemwwSawGTLM0IcnH9OraCBg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:48:13.526823Z","signed_message":"canonical_sha256_bytes"},"source_id":"1904.08653","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:4b9bdffb1e1d708768c1947889e877a626e118952b4c3caf4220f13bdb559b6e","sha256:b28230b506173b5068fc704bc45f581da6f3d3f8e60568009c88b3420ce32d5c"],"state_sha256":"8036bac7da7e0fccc0b1c63f1f34c3e27e4f9d6c24abfc19617bf837e2ffbe51"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"6e4f2Xyra0IYKfc37JHTWrgqvlnDqYfIoTxXMV5nlunFBZdYxdVGe0RS1PqKpx0GW5YCgRXxdG+C+YKlHHHLCQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T23:30:41.382506Z","bundle_sha256":"5ac4e101df315c724aa417ff656ebfdc34b5663a3740eb4630f537ef58d93185"}}