{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:MEV3SIFJ5JW7PPP733WXOLY4EA","short_pith_number":"pith:MEV3SIFJ","canonical_record":{"source":{"id":"1706.04701","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-06-15T00:13:28Z","cross_cats_sorted":[],"title_canon_sha256":"635c0598ea84485d3080ed12be67047f36d37ecd46df1b367a7d77255c3defd3","abstract_canon_sha256":"e2f55c12990b6f740d7eada076af4904facd5cf8c15202328a1c0a1b57fe8531"},"schema_version":"1.0"},"canonical_sha256":"612bb920a9ea6df7bdffdeed772f1c2022f30d028c7a845499d9b6e8fca4a4a7","source":{"kind":"arxiv","id":"1706.04701","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1706.04701","created_at":"2026-05-18T00:42:19Z"},{"alias_kind":"arxiv_version","alias_value":"1706.04701v1","created_at":"2026-05-18T00:42:19Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1706.04701","created_at":"2026-05-18T00:42:19Z"},{"alias_kind":"pith_short_12","alias_value":"MEV3SIFJ5JW7","created_at":"2026-05-18T12:31:31Z"},{"alias_kind":"pith_short_16","alias_value":"MEV3SIFJ5JW7PPP7","created_at":"2026-05-18T12:31:31Z"},{"alias_kind":"pith_short_8","alias_value":"MEV3SIFJ","created_at":"2026-05-18T12:31:31Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:MEV3SIFJ5JW7PPP733WXOLY4EA","target":"record","payload":{"canonical_record":{"source":{"id":"1706.04701","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-06-15T00:13:28Z","cross_cats_sorted":[],"title_canon_sha256":"635c0598ea84485d3080ed12be67047f36d37ecd46df1b367a7d77255c3defd3","abstract_canon_sha256":"e2f55c12990b6f740d7eada076af4904facd5cf8c15202328a1c0a1b57fe8531"},"schema_version":"1.0"},"canonical_sha256":"612bb920a9ea6df7bdffdeed772f1c2022f30d028c7a845499d9b6e8fca4a4a7","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:42:19.341904Z","signature_b64":"mXx4iTxnw14AOs6Piwtx4K3KSiUT8HuWzGxKBRYUWyiz7hTqOW++E9f40uaVY0plFKm5vW0/2uQwxTrrVZxuCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"612bb920a9ea6df7bdffdeed772f1c2022f30d028c7a845499d9b6e8fca4a4a7","last_reissued_at":"2026-05-18T00:42:19.341205Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:42:19.341205Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1706.04701","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:42:19Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"pEq6SuICegmfX6b1ik7/exClQwG3JLKCYaS3KN215+BXkM1aK5gQUJeWUZMNuM3uQLbgKV76Tr9kybOqAfPTAw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T13:52:14.561466Z"},"content_sha256":"255e7288af1a6397a7216cc39e356f65da3c76b8a011d825ce002bb018e99d9c","schema_version":"1.0","event_id":"sha256:255e7288af1a6397a7216cc39e356f65da3c76b8a011d825ce002bb018e99d9c"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:MEV3SIFJ5JW7PPP733WXOLY4EA","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Adversarial Example Defenses: Ensembles of Weak Defenses are not Strong","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Dawn Song, James Wei, Nicholas Carlini, Warren He, Xinyun Chen","submitted_at":"2017-06-15T00:13:28Z","abstract_excerpt":"Ongoing research has proposed several methods to defend neural networks against adversarial examples, many of which researchers have shown to be ineffective. We ask whether a strong defense can be created by combining multiple (possibly weak) defenses. To answer this question, we study three defenses that follow this approach. Two of these are recently proposed defenses that intentionally combine components designed to work well together. A third defense combines three independent defenses. For all the components of these defenses and the combined defenses themselves, we show that an adaptive "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1706.04701","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:42:19Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Clny3T93OnfsI/56cpPhvkE3wHQGwpREhv5lIuNFe8DAb12C+Y9h9f4dRaaDCdfr2gb6psDdYxqlavR2PEUjAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T13:52:14.561806Z"},"content_sha256":"380d87aea86009b43be6194f4bc4ca32a1f8851bea3abb48588222d170cf3936","schema_version":"1.0","event_id":"sha256:380d87aea86009b43be6194f4bc4ca32a1f8851bea3abb48588222d170cf3936"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/MEV3SIFJ5JW7PPP733WXOLY4EA/bundle.json","state_url":"https://pith.science/pith/MEV3SIFJ5JW7PPP733WXOLY4EA/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/MEV3SIFJ5JW7PPP733WXOLY4EA/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-01T13:52:14Z","links":{"resolver":"https://pith.science/pith/MEV3SIFJ5JW7PPP733WXOLY4EA","bundle":"https://pith.science/pith/MEV3SIFJ5JW7PPP733WXOLY4EA/bundle.json","state":"https://pith.science/pith/MEV3SIFJ5JW7PPP733WXOLY4EA/state.json","well_known_bundle":"https://pith.science/.well-known/pith/MEV3SIFJ5JW7PPP733WXOLY4EA/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:MEV3SIFJ5JW7PPP733WXOLY4EA","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e2f55c12990b6f740d7eada076af4904facd5cf8c15202328a1c0a1b57fe8531","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-06-15T00:13:28Z","title_canon_sha256":"635c0598ea84485d3080ed12be67047f36d37ecd46df1b367a7d77255c3defd3"},"schema_version":"1.0","source":{"id":"1706.04701","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1706.04701","created_at":"2026-05-18T00:42:19Z"},{"alias_kind":"arxiv_version","alias_value":"1706.04701v1","created_at":"2026-05-18T00:42:19Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1706.04701","created_at":"2026-05-18T00:42:19Z"},{"alias_kind":"pith_short_12","alias_value":"MEV3SIFJ5JW7","created_at":"2026-05-18T12:31:31Z"},{"alias_kind":"pith_short_16","alias_value":"MEV3SIFJ5JW7PPP7","created_at":"2026-05-18T12:31:31Z"},{"alias_kind":"pith_short_8","alias_value":"MEV3SIFJ","created_at":"2026-05-18T12:31:31Z"}],"graph_snapshots":[{"event_id":"sha256:380d87aea86009b43be6194f4bc4ca32a1f8851bea3abb48588222d170cf3936","target":"graph","created_at":"2026-05-18T00:42:19Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Ongoing research has proposed several methods to defend neural networks against adversarial examples, many of which researchers have shown to be ineffective. We ask whether a strong defense can be created by combining multiple (possibly weak) defenses. To answer this question, we study three defenses that follow this approach. Two of these are recently proposed defenses that intentionally combine components designed to work well together. A third defense combines three independent defenses. For all the components of these defenses and the combined defenses themselves, we show that an adaptive ","authors_text":"Dawn Song, James Wei, Nicholas Carlini, Warren He, Xinyun Chen","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-06-15T00:13:28Z","title":"Adversarial Example Defenses: Ensembles of Weak Defenses are not Strong"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1706.04701","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:255e7288af1a6397a7216cc39e356f65da3c76b8a011d825ce002bb018e99d9c","target":"record","created_at":"2026-05-18T00:42:19Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e2f55c12990b6f740d7eada076af4904facd5cf8c15202328a1c0a1b57fe8531","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-06-15T00:13:28Z","title_canon_sha256":"635c0598ea84485d3080ed12be67047f36d37ecd46df1b367a7d77255c3defd3"},"schema_version":"1.0","source":{"id":"1706.04701","kind":"arxiv","version":1}},"canonical_sha256":"612bb920a9ea6df7bdffdeed772f1c2022f30d028c7a845499d9b6e8fca4a4a7","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"612bb920a9ea6df7bdffdeed772f1c2022f30d028c7a845499d9b6e8fca4a4a7","first_computed_at":"2026-05-18T00:42:19.341205Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:42:19.341205Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"mXx4iTxnw14AOs6Piwtx4K3KSiUT8HuWzGxKBRYUWyiz7hTqOW++E9f40uaVY0plFKm5vW0/2uQwxTrrVZxuCA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:42:19.341904Z","signed_message":"canonical_sha256_bytes"},"source_id":"1706.04701","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:255e7288af1a6397a7216cc39e356f65da3c76b8a011d825ce002bb018e99d9c","sha256:380d87aea86009b43be6194f4bc4ca32a1f8851bea3abb48588222d170cf3936"],"state_sha256":"bfc760794f241106de577d22c878e2ea062e4f6be91004066e35e9e619b87743"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"CEhs3q9Xa4klReLSHb+lxtSyIWPevzd8EwvNdqv4GoOqtGvx7/p8tZPAwnTGW1wMmu7+vtv+tPUC/ymjfgwaCQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-01T13:52:14.563638Z","bundle_sha256":"67d557ad965ac791bd7fc29ea2e8e4e46a2f3b4e92ef6b8d2bf3c0235913c32e"}}