{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:N6H2ICVDAINEZODCSJOVHW46GM","short_pith_number":"pith:N6H2ICVD","canonical_record":{"source":{"id":"1804.05296","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-04-15T02:33:08Z","cross_cats_sorted":["cs.CY","cs.LG","stat.ML"],"title_canon_sha256":"2e5140038634c85b8eddd0f11cbc97daf715bf57118bcd4713c88c15ab65ae9b","abstract_canon_sha256":"c86e86a2b8cd9f82115e25ec4ab5024b18dd26ed14c73caa5b67d5494c822070"},"schema_version":"1.0"},"canonical_sha256":"6f8fa40aa3021a4cb862925d53db9e332ca8cc70e7ee89d06c0a8e7dad5642c0","source":{"kind":"arxiv","id":"1804.05296","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1804.05296","created_at":"2026-05-17T23:54:54Z"},{"alias_kind":"arxiv_version","alias_value":"1804.05296v3","created_at":"2026-05-17T23:54:54Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1804.05296","created_at":"2026-05-17T23:54:54Z"},{"alias_kind":"pith_short_12","alias_value":"N6H2ICVDAINE","created_at":"2026-05-18T12:32:40Z"},{"alias_kind":"pith_short_16","alias_value":"N6H2ICVDAINEZODC","created_at":"2026-05-18T12:32:40Z"},{"alias_kind":"pith_short_8","alias_value":"N6H2ICVD","created_at":"2026-05-18T12:32:40Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:N6H2ICVDAINEZODCSJOVHW46GM","target":"record","payload":{"canonical_record":{"source":{"id":"1804.05296","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-04-15T02:33:08Z","cross_cats_sorted":["cs.CY","cs.LG","stat.ML"],"title_canon_sha256":"2e5140038634c85b8eddd0f11cbc97daf715bf57118bcd4713c88c15ab65ae9b","abstract_canon_sha256":"c86e86a2b8cd9f82115e25ec4ab5024b18dd26ed14c73caa5b67d5494c822070"},"schema_version":"1.0"},"canonical_sha256":"6f8fa40aa3021a4cb862925d53db9e332ca8cc70e7ee89d06c0a8e7dad5642c0","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:54:54.441287Z","signature_b64":"8BrcgB1YzFzwalpN7d61MpHt5xkA5degCTkcrigior+TUHaIZ3lWgfy33Z1qllQidxfvDskslZtNT8naYTvyBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"6f8fa40aa3021a4cb862925d53db9e332ca8cc70e7ee89d06c0a8e7dad5642c0","last_reissued_at":"2026-05-17T23:54:54.440724Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:54:54.440724Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1804.05296","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:54:54Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ZhuM5kfvelndwTYZzPlzPsXRnC0FSfyClnAXuWJAcWSu6R/Ipq2UI6XCt/HCxjcekQ9uEBPk9eWL/egm6lqHCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T19:17:51.312864Z"},"content_sha256":"5f216018c6c63de7fec5af28620d7355b21675ec4908a4bacf6d26a563847a45","schema_version":"1.0","event_id":"sha256:5f216018c6c63de7fec5af28620d7355b21675ec4908a4bacf6d26a563847a45"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:N6H2ICVDAINEZODCSJOVHW46GM","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Adversarial Attacks Against Medical Deep Learning Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CY","cs.LG","stat.ML"],"primary_cat":"cs.CR","authors_text":"Andrew L. Beam, Hyung Won Chung, Isaac S. Kohane, Samuel G. Finlayson","submitted_at":"2018-04-15T02:33:08Z","abstract_excerpt":"The discovery of adversarial examples has raised concerns about the practical deployment of deep learning systems. In this paper, we demonstrate that adversarial examples are capable of manipulating deep learning systems across three clinical domains. For each of our representative medical deep learning classifiers, both white and black box attacks were highly successful. Our models are representative of the current state of the art in medical computer vision and, in some cases, directly reflect architectures already seeing deployment in real world clinical settings. In addition to the technic"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1804.05296","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:54:54Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"j3cc4MbtiIT2A/7aiQs5iB5fJVTwGzVbLTmzF8EAzh0bmaaRGuack+Sw57jirRlyYQUTf2ogW9UlK9+dAaTmAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T19:17:51.313307Z"},"content_sha256":"47870a0ae8ffd64a002ad9283225c3fa112e1322dbeb1d765f998ead7cbe1df3","schema_version":"1.0","event_id":"sha256:47870a0ae8ffd64a002ad9283225c3fa112e1322dbeb1d765f998ead7cbe1df3"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/N6H2ICVDAINEZODCSJOVHW46GM/bundle.json","state_url":"https://pith.science/pith/N6H2ICVDAINEZODCSJOVHW46GM/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/N6H2ICVDAINEZODCSJOVHW46GM/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T19:17:51Z","links":{"resolver":"https://pith.science/pith/N6H2ICVDAINEZODCSJOVHW46GM","bundle":"https://pith.science/pith/N6H2ICVDAINEZODCSJOVHW46GM/bundle.json","state":"https://pith.science/pith/N6H2ICVDAINEZODCSJOVHW46GM/state.json","well_known_bundle":"https://pith.science/.well-known/pith/N6H2ICVDAINEZODCSJOVHW46GM/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:N6H2ICVDAINEZODCSJOVHW46GM","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"c86e86a2b8cd9f82115e25ec4ab5024b18dd26ed14c73caa5b67d5494c822070","cross_cats_sorted":["cs.CY","cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-04-15T02:33:08Z","title_canon_sha256":"2e5140038634c85b8eddd0f11cbc97daf715bf57118bcd4713c88c15ab65ae9b"},"schema_version":"1.0","source":{"id":"1804.05296","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1804.05296","created_at":"2026-05-17T23:54:54Z"},{"alias_kind":"arxiv_version","alias_value":"1804.05296v3","created_at":"2026-05-17T23:54:54Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1804.05296","created_at":"2026-05-17T23:54:54Z"},{"alias_kind":"pith_short_12","alias_value":"N6H2ICVDAINE","created_at":"2026-05-18T12:32:40Z"},{"alias_kind":"pith_short_16","alias_value":"N6H2ICVDAINEZODC","created_at":"2026-05-18T12:32:40Z"},{"alias_kind":"pith_short_8","alias_value":"N6H2ICVD","created_at":"2026-05-18T12:32:40Z"}],"graph_snapshots":[{"event_id":"sha256:47870a0ae8ffd64a002ad9283225c3fa112e1322dbeb1d765f998ead7cbe1df3","target":"graph","created_at":"2026-05-17T23:54:54Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"The discovery of adversarial examples has raised concerns about the practical deployment of deep learning systems. In this paper, we demonstrate that adversarial examples are capable of manipulating deep learning systems across three clinical domains. For each of our representative medical deep learning classifiers, both white and black box attacks were highly successful. Our models are representative of the current state of the art in medical computer vision and, in some cases, directly reflect architectures already seeing deployment in real world clinical settings. In addition to the technic","authors_text":"Andrew L. Beam, Hyung Won Chung, Isaac S. Kohane, Samuel G. Finlayson","cross_cats":["cs.CY","cs.LG","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-04-15T02:33:08Z","title":"Adversarial Attacks Against Medical Deep Learning Systems"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1804.05296","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:5f216018c6c63de7fec5af28620d7355b21675ec4908a4bacf6d26a563847a45","target":"record","created_at":"2026-05-17T23:54:54Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"c86e86a2b8cd9f82115e25ec4ab5024b18dd26ed14c73caa5b67d5494c822070","cross_cats_sorted":["cs.CY","cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-04-15T02:33:08Z","title_canon_sha256":"2e5140038634c85b8eddd0f11cbc97daf715bf57118bcd4713c88c15ab65ae9b"},"schema_version":"1.0","source":{"id":"1804.05296","kind":"arxiv","version":3}},"canonical_sha256":"6f8fa40aa3021a4cb862925d53db9e332ca8cc70e7ee89d06c0a8e7dad5642c0","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"6f8fa40aa3021a4cb862925d53db9e332ca8cc70e7ee89d06c0a8e7dad5642c0","first_computed_at":"2026-05-17T23:54:54.440724Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:54:54.440724Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"8BrcgB1YzFzwalpN7d61MpHt5xkA5degCTkcrigior+TUHaIZ3lWgfy33Z1qllQidxfvDskslZtNT8naYTvyBA==","signature_status":"signed_v1","signed_at":"2026-05-17T23:54:54.441287Z","signed_message":"canonical_sha256_bytes"},"source_id":"1804.05296","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:5f216018c6c63de7fec5af28620d7355b21675ec4908a4bacf6d26a563847a45","sha256:47870a0ae8ffd64a002ad9283225c3fa112e1322dbeb1d765f998ead7cbe1df3"],"state_sha256":"e70384720a52564702b4235f3d0afd95bd76d94777f1512901e31154e883a549"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"fbIk+LHvJdUJRgIaK3m4eXKcSxquu4oftk2sIPvcr+h4uRbpJHx5wjd+zFG3ZHxYA6KM6BxhScGU/v2+2UzbAw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T19:17:51.316771Z","bundle_sha256":"3d86c78ed7e42ed7781aa76481fcc0c4f0e34bd6d04c4f42cbb8a0ac2fc43c27"}}