{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:MZWUFSY4VGRMGQCI5MECLVKEYU","short_pith_number":"pith:MZWUFSY4","canonical_record":{"source":{"id":"1904.05734","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-03-18T20:10:13Z","cross_cats_sorted":["cs.LG","cs.SD","eess.AS"],"title_canon_sha256":"37c27f65d818ef3ff1b4220a728eef667d4aa2443745165773ce0aa62c34ab40","abstract_canon_sha256":"9d421c1a573f9a8b3333c7433b58eedce33a11f6a8e2f0bbc51cc6677e7b5c50"},"schema_version":"1.0"},"canonical_sha256":"666d42cb1ca9a2c34048eb0825d544c51bd24a0583352119ae74dc4787423490","source":{"kind":"arxiv","id":"1904.05734","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1904.05734","created_at":"2026-05-17T23:48:48Z"},{"alias_kind":"arxiv_version","alias_value":"1904.05734v1","created_at":"2026-05-17T23:48:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1904.05734","created_at":"2026-05-17T23:48:48Z"},{"alias_kind":"pith_short_12","alias_value":"MZWUFSY4VGRM","created_at":"2026-05-18T12:33:24Z"},{"alias_kind":"pith_short_16","alias_value":"MZWUFSY4VGRMGQCI","created_at":"2026-05-18T12:33:24Z"},{"alias_kind":"pith_short_8","alias_value":"MZWUFSY4","created_at":"2026-05-18T12:33:24Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:MZWUFSY4VGRMGQCI5MECLVKEYU","target":"record","payload":{"canonical_record":{"source":{"id":"1904.05734","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-03-18T20:10:13Z","cross_cats_sorted":["cs.LG","cs.SD","eess.AS"],"title_canon_sha256":"37c27f65d818ef3ff1b4220a728eef667d4aa2443745165773ce0aa62c34ab40","abstract_canon_sha256":"9d421c1a573f9a8b3333c7433b58eedce33a11f6a8e2f0bbc51cc6677e7b5c50"},"schema_version":"1.0"},"canonical_sha256":"666d42cb1ca9a2c34048eb0825d544c51bd24a0583352119ae74dc4787423490","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:48:48.626863Z","signature_b64":"/vLOItCDTOjgTPeSBbZu1vGKj7n+k+O+yiCS+ZcVLzoe6Y3t2oAwn47J9QSap6RlQah1RkqG/ixsVxjIeaPwAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"666d42cb1ca9a2c34048eb0825d544c51bd24a0583352119ae74dc4787423490","last_reissued_at":"2026-05-17T23:48:48.626283Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:48:48.626283Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1904.05734","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:48:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"E8w+q6VthsL+YhVKToHUJmdvcTEX7STumna5EDQXfPg2EU2E8C1y+0CIEY4Js5ZakQogYZCixUkGw7FXwW4ACg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T13:46:11.169440Z"},"content_sha256":"01661c98419072760c39c3261eafb410b33be8b6c1cdfcb3f68fb4e4ff034d01","schema_version":"1.0","event_id":"sha256:01661c98419072760c39c3261eafb410b33be8b6c1cdfcb3f68fb4e4ff034d01"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:MZWUFSY4VGRMGQCI5MECLVKEYU","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Practical Hidden Voice Attacks against Speech and Speaker Recognition Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG","cs.SD","eess.AS"],"primary_cat":"cs.CR","authors_text":"Christian Peeters, Hadi Abdullah, Joseph Wilson, Kevin R. B. Butler, Patrick Traynor, Washington Garcia","submitted_at":"2019-03-18T20:10:13Z","abstract_excerpt":"Voice Processing Systems (VPSes), now widely deployed, have been made significantly more accurate through the application of recent advances in machine learning. However, adversarial machine learning has similarly advanced and has been used to demonstrate that VPSes are vulnerable to the injection of hidden commands - audio obscured by noise that is correctly recognized by a VPS but not by human beings. Such attacks, though, are often highly dependent on white-box knowledge of a specific machine learning model and limited to specific microphones and speakers, making their use across different "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1904.05734","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:48:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"2dSh3YKnO546Q9Kn4Sd+Ef9g2ucQZ2IKaREcgw5l8XeYSMJqs896tLHpJWreUXhtfRzJLjiDb/TIR9WUMm0zBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T13:46:11.170111Z"},"content_sha256":"e91fe57d819997e8d7e0753fa1b7e38fbd06ccc9c79d24f5341345d6a65b8326","schema_version":"1.0","event_id":"sha256:e91fe57d819997e8d7e0753fa1b7e38fbd06ccc9c79d24f5341345d6a65b8326"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/MZWUFSY4VGRMGQCI5MECLVKEYU/bundle.json","state_url":"https://pith.science/pith/MZWUFSY4VGRMGQCI5MECLVKEYU/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/MZWUFSY4VGRMGQCI5MECLVKEYU/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T13:46:11Z","links":{"resolver":"https://pith.science/pith/MZWUFSY4VGRMGQCI5MECLVKEYU","bundle":"https://pith.science/pith/MZWUFSY4VGRMGQCI5MECLVKEYU/bundle.json","state":"https://pith.science/pith/MZWUFSY4VGRMGQCI5MECLVKEYU/state.json","well_known_bundle":"https://pith.science/.well-known/pith/MZWUFSY4VGRMGQCI5MECLVKEYU/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:MZWUFSY4VGRMGQCI5MECLVKEYU","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"9d421c1a573f9a8b3333c7433b58eedce33a11f6a8e2f0bbc51cc6677e7b5c50","cross_cats_sorted":["cs.LG","cs.SD","eess.AS"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-03-18T20:10:13Z","title_canon_sha256":"37c27f65d818ef3ff1b4220a728eef667d4aa2443745165773ce0aa62c34ab40"},"schema_version":"1.0","source":{"id":"1904.05734","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1904.05734","created_at":"2026-05-17T23:48:48Z"},{"alias_kind":"arxiv_version","alias_value":"1904.05734v1","created_at":"2026-05-17T23:48:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1904.05734","created_at":"2026-05-17T23:48:48Z"},{"alias_kind":"pith_short_12","alias_value":"MZWUFSY4VGRM","created_at":"2026-05-18T12:33:24Z"},{"alias_kind":"pith_short_16","alias_value":"MZWUFSY4VGRMGQCI","created_at":"2026-05-18T12:33:24Z"},{"alias_kind":"pith_short_8","alias_value":"MZWUFSY4","created_at":"2026-05-18T12:33:24Z"}],"graph_snapshots":[{"event_id":"sha256:e91fe57d819997e8d7e0753fa1b7e38fbd06ccc9c79d24f5341345d6a65b8326","target":"graph","created_at":"2026-05-17T23:48:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Voice Processing Systems (VPSes), now widely deployed, have been made significantly more accurate through the application of recent advances in machine learning. However, adversarial machine learning has similarly advanced and has been used to demonstrate that VPSes are vulnerable to the injection of hidden commands - audio obscured by noise that is correctly recognized by a VPS but not by human beings. Such attacks, though, are often highly dependent on white-box knowledge of a specific machine learning model and limited to specific microphones and speakers, making their use across different ","authors_text":"Christian Peeters, Hadi Abdullah, Joseph Wilson, Kevin R. B. Butler, Patrick Traynor, Washington Garcia","cross_cats":["cs.LG","cs.SD","eess.AS"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-03-18T20:10:13Z","title":"Practical Hidden Voice Attacks against Speech and Speaker Recognition Systems"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1904.05734","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:01661c98419072760c39c3261eafb410b33be8b6c1cdfcb3f68fb4e4ff034d01","target":"record","created_at":"2026-05-17T23:48:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"9d421c1a573f9a8b3333c7433b58eedce33a11f6a8e2f0bbc51cc6677e7b5c50","cross_cats_sorted":["cs.LG","cs.SD","eess.AS"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-03-18T20:10:13Z","title_canon_sha256":"37c27f65d818ef3ff1b4220a728eef667d4aa2443745165773ce0aa62c34ab40"},"schema_version":"1.0","source":{"id":"1904.05734","kind":"arxiv","version":1}},"canonical_sha256":"666d42cb1ca9a2c34048eb0825d544c51bd24a0583352119ae74dc4787423490","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"666d42cb1ca9a2c34048eb0825d544c51bd24a0583352119ae74dc4787423490","first_computed_at":"2026-05-17T23:48:48.626283Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:48:48.626283Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"/vLOItCDTOjgTPeSBbZu1vGKj7n+k+O+yiCS+ZcVLzoe6Y3t2oAwn47J9QSap6RlQah1RkqG/ixsVxjIeaPwAw==","signature_status":"signed_v1","signed_at":"2026-05-17T23:48:48.626863Z","signed_message":"canonical_sha256_bytes"},"source_id":"1904.05734","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:01661c98419072760c39c3261eafb410b33be8b6c1cdfcb3f68fb4e4ff034d01","sha256:e91fe57d819997e8d7e0753fa1b7e38fbd06ccc9c79d24f5341345d6a65b8326"],"state_sha256":"4299c072915666f04844f1383e63fe1f798058bc3877f8314a4a93a3f9c565c4"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"lgDAUa8iofVVIjYA76Ek6uSllUZ7Oxamx9qj0VjV2zpPjSMUiDz1ukB33jBXrhR70GIHEz3rbTOhAdgRBsrOCg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T13:46:11.173472Z","bundle_sha256":"7afc2bb5d2d3bd6ecc4dbf8a4103a6df1f41607dc9f2d68cfefb359420b20681"}}