{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:MHJJ67VDG36B6FYJUQ4VZH3ZTR","short_pith_number":"pith:MHJJ67VD","canonical_record":{"source":{"id":"1708.08327","kind":"arxiv","version":5},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-28T14:18:35Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"fc24c5227a8219b3308f01a01917bb7bf0cd19028bbbaf156e30089679d656f5","abstract_canon_sha256":"99c1f6203b69d6039c53d313bc1df788a46aa967086009b415efb24af6f47a00"},"schema_version":"1.0"},"canonical_sha256":"61d29f7ea336fc1f1709a4395c9f799c7cfc867f5a5bce2035ad12f45a77fca8","source":{"kind":"arxiv","id":"1708.08327","version":5},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1708.08327","created_at":"2026-05-17T23:46:31Z"},{"alias_kind":"arxiv_version","alias_value":"1708.08327v5","created_at":"2026-05-17T23:46:31Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1708.08327","created_at":"2026-05-17T23:46:31Z"},{"alias_kind":"pith_short_12","alias_value":"MHJJ67VDG36B","created_at":"2026-05-18T12:31:31Z"},{"alias_kind":"pith_short_16","alias_value":"MHJJ67VDG36B6FYJ","created_at":"2026-05-18T12:31:31Z"},{"alias_kind":"pith_short_8","alias_value":"MHJJ67VD","created_at":"2026-05-18T12:31:31Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:MHJJ67VDG36B6FYJUQ4VZH3ZTR","target":"record","payload":{"canonical_record":{"source":{"id":"1708.08327","kind":"arxiv","version":5},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-28T14:18:35Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"fc24c5227a8219b3308f01a01917bb7bf0cd19028bbbaf156e30089679d656f5","abstract_canon_sha256":"99c1f6203b69d6039c53d313bc1df788a46aa967086009b415efb24af6f47a00"},"schema_version":"1.0"},"canonical_sha256":"61d29f7ea336fc1f1709a4395c9f799c7cfc867f5a5bce2035ad12f45a77fca8","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:46:31.007186Z","signature_b64":"qRp9YT2S2vYdWT8TPLti64akePcdAa/BTp6kw1fB6r+6LCfBnTQObntZcCKHBOZLWmhv2316KnNQmYojDOKCBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"61d29f7ea336fc1f1709a4395c9f799c7cfc867f5a5bce2035ad12f45a77fca8","last_reissued_at":"2026-05-17T23:46:31.006405Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:46:31.006405Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1708.08327","source_version":5,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:46:31Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"BPgi3viRcHZXxZIjyYcKeB1K9a72Q/gMBWffh8VJfOSdYPm7CgiIyl9Wo6PBsb3ELsguHYGX8cp1ieDX3oF3BQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-08T21:31:04.877619Z"},"content_sha256":"d186cdef392a8ab68b16e137f810476dfe1e4c51d1d4011067395fbbe9379bec","schema_version":"1.0","event_id":"sha256:d186cdef392a8ab68b16e137f810476dfe1e4c51d1d4011067395fbbe9379bec"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:MHJJ67VDG36B6FYJUQ4VZH3ZTR","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Improving Robustness of ML Classifiers against Realizable Evasion Attacks Using Conserved Features","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Bo Li, Chaowei Xiao, Chen Hajaj, Liang Tong, Ning Zhang, Yevgeniy Vorobeychik","submitted_at":"2017-08-28T14:18:35Z","abstract_excerpt":"Machine learning (ML) techniques are increasingly common in security applications, such as malware and intrusion detection. However, ML models are often susceptible to evasion attacks, in which an adversary makes changes to the input (such as malware) in order to avoid being detected. A conventional approach to evaluate ML robustness to such attacks, as well as to design robust ML, is by considering simplified feature-space models of attacks, where the attacker changes ML features directly to effect evasion, while minimizing or constraining the magnitude of this change. We investigate the effe"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1708.08327","kind":"arxiv","version":5},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:46:31Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"rSZwRcPpBcvxOP6O9zrs+9tVbyutJV5VNvX8oPdNaYLpJ3qdVFEWACArkQLrqhkumeKeGQ5gz7/UFEWHIABpAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-08T21:31:04.878280Z"},"content_sha256":"f3913c9bca12b3200ad163b7584fa37387e50a4af769aa7fff5f06e4a033b4ed","schema_version":"1.0","event_id":"sha256:f3913c9bca12b3200ad163b7584fa37387e50a4af769aa7fff5f06e4a033b4ed"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/MHJJ67VDG36B6FYJUQ4VZH3ZTR/bundle.json","state_url":"https://pith.science/pith/MHJJ67VDG36B6FYJUQ4VZH3ZTR/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/MHJJ67VDG36B6FYJUQ4VZH3ZTR/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-08T21:31:04Z","links":{"resolver":"https://pith.science/pith/MHJJ67VDG36B6FYJUQ4VZH3ZTR","bundle":"https://pith.science/pith/MHJJ67VDG36B6FYJUQ4VZH3ZTR/bundle.json","state":"https://pith.science/pith/MHJJ67VDG36B6FYJUQ4VZH3ZTR/state.json","well_known_bundle":"https://pith.science/.well-known/pith/MHJJ67VDG36B6FYJUQ4VZH3ZTR/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:MHJJ67VDG36B6FYJUQ4VZH3ZTR","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"99c1f6203b69d6039c53d313bc1df788a46aa967086009b415efb24af6f47a00","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-28T14:18:35Z","title_canon_sha256":"fc24c5227a8219b3308f01a01917bb7bf0cd19028bbbaf156e30089679d656f5"},"schema_version":"1.0","source":{"id":"1708.08327","kind":"arxiv","version":5}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1708.08327","created_at":"2026-05-17T23:46:31Z"},{"alias_kind":"arxiv_version","alias_value":"1708.08327v5","created_at":"2026-05-17T23:46:31Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1708.08327","created_at":"2026-05-17T23:46:31Z"},{"alias_kind":"pith_short_12","alias_value":"MHJJ67VDG36B","created_at":"2026-05-18T12:31:31Z"},{"alias_kind":"pith_short_16","alias_value":"MHJJ67VDG36B6FYJ","created_at":"2026-05-18T12:31:31Z"},{"alias_kind":"pith_short_8","alias_value":"MHJJ67VD","created_at":"2026-05-18T12:31:31Z"}],"graph_snapshots":[{"event_id":"sha256:f3913c9bca12b3200ad163b7584fa37387e50a4af769aa7fff5f06e4a033b4ed","target":"graph","created_at":"2026-05-17T23:46:31Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Machine learning (ML) techniques are increasingly common in security applications, such as malware and intrusion detection. However, ML models are often susceptible to evasion attacks, in which an adversary makes changes to the input (such as malware) in order to avoid being detected. A conventional approach to evaluate ML robustness to such attacks, as well as to design robust ML, is by considering simplified feature-space models of attacks, where the attacker changes ML features directly to effect evasion, while minimizing or constraining the magnitude of this change. We investigate the effe","authors_text":"Bo Li, Chaowei Xiao, Chen Hajaj, Liang Tong, Ning Zhang, Yevgeniy Vorobeychik","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-28T14:18:35Z","title":"Improving Robustness of ML Classifiers against Realizable Evasion Attacks Using Conserved Features"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1708.08327","kind":"arxiv","version":5},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:d186cdef392a8ab68b16e137f810476dfe1e4c51d1d4011067395fbbe9379bec","target":"record","created_at":"2026-05-17T23:46:31Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"99c1f6203b69d6039c53d313bc1df788a46aa967086009b415efb24af6f47a00","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-28T14:18:35Z","title_canon_sha256":"fc24c5227a8219b3308f01a01917bb7bf0cd19028bbbaf156e30089679d656f5"},"schema_version":"1.0","source":{"id":"1708.08327","kind":"arxiv","version":5}},"canonical_sha256":"61d29f7ea336fc1f1709a4395c9f799c7cfc867f5a5bce2035ad12f45a77fca8","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"61d29f7ea336fc1f1709a4395c9f799c7cfc867f5a5bce2035ad12f45a77fca8","first_computed_at":"2026-05-17T23:46:31.006405Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:46:31.006405Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"qRp9YT2S2vYdWT8TPLti64akePcdAa/BTp6kw1fB6r+6LCfBnTQObntZcCKHBOZLWmhv2316KnNQmYojDOKCBA==","signature_status":"signed_v1","signed_at":"2026-05-17T23:46:31.007186Z","signed_message":"canonical_sha256_bytes"},"source_id":"1708.08327","source_kind":"arxiv","source_version":5}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:d186cdef392a8ab68b16e137f810476dfe1e4c51d1d4011067395fbbe9379bec","sha256:f3913c9bca12b3200ad163b7584fa37387e50a4af769aa7fff5f06e4a033b4ed"],"state_sha256":"3aaf85fcda8ad8170d3127421808cf3c495f992c5394cf9ade14c85c2df627f7"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8TkVUQGiEvoZfa0bpFseqhJ5p4OSYNvytwWvNoKuD/Dmt5sbwkxWD2DqqRvrjBTiBub78y6DSINFUSWoSibbBg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-08T21:31:04.881430Z","bundle_sha256":"25b8f48c4ebc9172a9b42b101a7248c97527cdd3b46fbab3fc10792d8c05714a"}}