{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:MMZPTCDLWL7C2TDU4NMT6MRVKC","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e21d78d16389b895b4ea169aa8fc17590d8cf62b33f823b06aef854753481039","cross_cats_sorted":["cs.LG"],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CV","submitted_at":"2026-05-16T00:07:49Z","title_canon_sha256":"32098b1d61bbccc52f58e42266a60da30292f8c20146674bc793fc4f37d5051d"},"schema_version":"1.0","source":{"id":"2605.16720","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.16720","created_at":"2026-05-20T00:02:38Z"},{"alias_kind":"arxiv_version","alias_value":"2605.16720v1","created_at":"2026-05-20T00:02:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.16720","created_at":"2026-05-20T00:02:38Z"},{"alias_kind":"pith_short_12","alias_value":"MMZPTCDLWL7C","created_at":"2026-05-20T00:02:38Z"},{"alias_kind":"pith_short_16","alias_value":"MMZPTCDLWL7C2TDU","created_at":"2026-05-20T00:02:38Z"},{"alias_kind":"pith_short_8","alias_value":"MMZPTCDL","created_at":"2026-05-20T00:02:38Z"}],"graph_snapshots":[{"event_id":"sha256:64f2f1d3b823bb562ca60afb3cb8596e0b00893b939c1d8936c621d15393371e","target":"graph","created_at":"2026-05-20T00:02:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"CAT consistently outperforms random-augmentation baselines trained with the same augmentation budget, with the largest gains on hard composed attacks and OOD evaluations; improving overall watermark capacity by up to 63.5% in the single-step attack setting and 13.0% in the compositional setting."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"The assumption that a learned sequential adversary with Gumbel-Softmax selection can reliably cover the combinatorial space of realistic attack pipelines without mode collapse or missing critical compositions that break detection, as stated in the formulation of watermark robustness as a min-max problem over structured transformations."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"CAT trains watermark detectors against adaptive compositional adversaries using differentiable attack selection, yielding up to 63.5% capacity gains on hard attacks versus random-augmentation baselines."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"Training visual watermarks against learned sequences of attacks produces higher robustness than random augmentation."}],"snapshot_sha256":"6d661ae522d43a673bcd71932135b82d6b250ef0248428d00fcf5bdc1f9c75a5"},"formal_canon":{"evidence_count":2,"snapshot_sha256":"92fb511b204b96f7b2284ab2ba54a41c91f9c91237383ab4563c251b94394d57"},"integrity":{"available":true,"clean":true,"detectors_run":[{"findings_count":0,"name":"doi_title_agreement","ran_at":"2026-05-19T22:01:23.114676Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"doi_compliance","ran_at":"2026-05-19T22:01:02.969727Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"claim_evidence","ran_at":"2026-05-19T19:01:56.351566Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"ai_meta_artifact","ran_at":"2026-05-19T18:33:26.476181Z","status":"skipped","version":"1.0.0"}],"endpoint":"/pith/2605.16720/integrity.json","findings":[],"snapshot_sha256":"7a68e28924ba5e011786e47ea0ff448a614bc98389aaa8600469423c318fdda3","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Robust watermarking is typically trained with random post-processing augmentation, but random sampling under-covers the combinatorial space of realistic attack pipelines and rarely encounters the rare compositions that actually break detection. This leads to unstable training and poor sample efficiency. We instead formulate watermark robustness as a min-max problem over a structured space of compositional transformations. We propose Compositional Adversarial Training (CAT), a plug-in framework that learns a sequential differentiable adversary that observes the current watermarked image and sel","authors_text":"Andrew Xu, Anirudh Satheesh, Furong Huang, Georgios Milis, Heng Huang, Michael-Andrei Panaitescu-Liess, Zikui Cai","cross_cats":["cs.LG"],"headline":"Training visual watermarks against learned sequences of attacks produces higher robustness than random augmentation.","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CV","submitted_at":"2026-05-16T00:07:49Z","title":"Compositional Adversarial Training for Robust Visual Watermarking"},"references":{"count":61,"internal_anchors":6,"resolved_work":61,"sample":[{"cited_arxiv_id":"1412.6572","doi":"","is_internal_anchor":true,"ref_index":1,"title":"Explaining and Harnessing Adversarial Examples","work_id":"2cedf8f6-7539-4c49-8136-f42a20487146","year":null},{"cited_arxiv_id":"1706.06083","doi":"","is_internal_anchor":true,"ref_index":2,"title":"Towards Deep Learning Models Resistant to Adversarial Attacks","work_id":"b20a57fa-4b7d-40ec-8b6a-ce48234630de","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":3,"title":"arXiv preprint arXiv:2210.02577 , year=","work_id":"fe1deabd-e10e-4837-a779-10a069e21311","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":4,"title":"International conference on machine learning , pages=","work_id":"84193c6b-5aa5-4ec5-a7aa-e00df8143c0b","year":2019},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":5,"title":"Proceedings of the IEEE/CVF international conference on computer vision , pages=","work_id":"503dd7ba-3ffc-4047-b4ab-3e9e6ddf89f0","year":null}],"snapshot_sha256":"e50d01f3fa9061deaabf3dab0f5b03e20a6869819f65f1256ded0e510f9c2074"},"source":{"id":"2605.16720","kind":"arxiv","version":1},"verdict":{"created_at":"2026-05-19T21:49:34.038254Z","id":"94793438-5a9f-4bb5-b83b-61cfb6a86d31","model_set":{"reader":"grok-4.3"},"one_line_summary":"CAT trains watermark detectors against adaptive compositional adversaries using differentiable attack selection, yielding up to 63.5% capacity gains on hard attacks versus random-augmentation baselines.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"Training visual watermarks against learned sequences of attacks produces higher robustness than random augmentation.","strongest_claim":"CAT consistently outperforms random-augmentation baselines trained with the same augmentation budget, with the largest gains on hard composed attacks and OOD evaluations; improving overall watermark capacity by up to 63.5% in the single-step attack setting and 13.0% in the compositional setting.","weakest_assumption":"The assumption that a learned sequential adversary with Gumbel-Softmax selection can reliably cover the combinatorial space of realistic attack pipelines without mode collapse or missing critical compositions that break detection, as stated in the formulation of watermark robustness as a min-max problem over structured transformations."}},"verdict_id":"94793438-5a9f-4bb5-b83b-61cfb6a86d31"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:4a76c447bc3f15961c61872d90905abbde943ddc0d68121a619c9c044148be47","target":"record","created_at":"2026-05-20T00:02:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e21d78d16389b895b4ea169aa8fc17590d8cf62b33f823b06aef854753481039","cross_cats_sorted":["cs.LG"],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CV","submitted_at":"2026-05-16T00:07:49Z","title_canon_sha256":"32098b1d61bbccc52f58e42266a60da30292f8c20146674bc793fc4f37d5051d"},"schema_version":"1.0","source":{"id":"2605.16720","kind":"arxiv","version":1}},"canonical_sha256":"6332f9886bb2fe2d4c74e3593f323550954c0764f33b8d048620f2d91c7d6d37","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"6332f9886bb2fe2d4c74e3593f323550954c0764f33b8d048620f2d91c7d6d37","first_computed_at":"2026-05-20T00:02:38.331566Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-20T00:02:38.331566Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"OMRQ6O5i47FDRsKZjW0yrcbwsz36hsE/fVP/R8BrD9j7KmWu54/DXCmZS8+XtfLvtFuCn9JKu+y7XxmaxsX1Bw==","signature_status":"signed_v1","signed_at":"2026-05-20T00:02:38.332297Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.16720","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:4a76c447bc3f15961c61872d90905abbde943ddc0d68121a619c9c044148be47","sha256:64f2f1d3b823bb562ca60afb3cb8596e0b00893b939c1d8936c621d15393371e"],"state_sha256":"04dfa4eaf3f7aa886e040dde55b09a2a4505fe6eed513e3b170d5b73de6e1b37"}