{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:NH7JHNSUQ5K5PEL3372KMBCBF3","short_pith_number":"pith:NH7JHNSU","canonical_record":{"source":{"id":"1711.02846","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-11-08T06:54:49Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"39ba755e0ad33a0fc604f1fa7688c88ae75f5da7e078723a94a172eb803af102","abstract_canon_sha256":"3c9baf7cd18a0fab0c13e269f9d9a34985dcf5c3254164d64d954627f040de09"},"schema_version":"1.0"},"canonical_sha256":"69fe93b6548755d7917bdff4a604412efbffc7f8e2e2f5c9145524d31c8f4980","source":{"kind":"arxiv","id":"1711.02846","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1711.02846","created_at":"2026-05-18T00:31:01Z"},{"alias_kind":"arxiv_version","alias_value":"1711.02846v1","created_at":"2026-05-18T00:31:01Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1711.02846","created_at":"2026-05-18T00:31:01Z"},{"alias_kind":"pith_short_12","alias_value":"NH7JHNSUQ5K5","created_at":"2026-05-18T12:31:31Z"},{"alias_kind":"pith_short_16","alias_value":"NH7JHNSUQ5K5PEL3","created_at":"2026-05-18T12:31:31Z"},{"alias_kind":"pith_short_8","alias_value":"NH7JHNSU","created_at":"2026-05-18T12:31:31Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:NH7JHNSUQ5K5PEL3372KMBCBF3","target":"record","payload":{"canonical_record":{"source":{"id":"1711.02846","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-11-08T06:54:49Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"39ba755e0ad33a0fc604f1fa7688c88ae75f5da7e078723a94a172eb803af102","abstract_canon_sha256":"3c9baf7cd18a0fab0c13e269f9d9a34985dcf5c3254164d64d954627f040de09"},"schema_version":"1.0"},"canonical_sha256":"69fe93b6548755d7917bdff4a604412efbffc7f8e2e2f5c9145524d31c8f4980","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:31:01.548289Z","signature_b64":"Oy9I7Dk7cMnaWuODOtH3W33fN774FQdrhAShh7W3ZEnV60AZg1Tqf0ZI6NZjesEyvntZrDlSk7fJnJWo1g3nAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"69fe93b6548755d7917bdff4a604412efbffc7f8e2e2f5c9145524d31c8f4980","last_reissued_at":"2026-05-18T00:31:01.547670Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:31:01.547670Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1711.02846","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:31:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"n7WeLtScCSkGJ7ZpF2tPisNJ3wv8MiDyJeXsAFMBZ2J3ITVw0LhbwaDkoOLnPSZgm90vF1noFEdHS7vZXQFEDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-31T14:52:39.519450Z"},"content_sha256":"5c320c1b408ae9250c6260eb8c6409772997d4a6aa8f630b4a027446a734e7ad","schema_version":"1.0","event_id":"sha256:5c320c1b408ae9250c6260eb8c6409772997d4a6aa8f630b4a027446a734e7ad"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:NH7JHNSUQ5K5PEL3372KMBCBF3","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Intriguing Properties of Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"stat.ML","authors_text":"Barret Zoph, Ekin D. Cubuk, Quoc V. Le, Samuel S. Schoenholz","submitted_at":"2017-11-08T06:54:49Z","abstract_excerpt":"It is becoming increasingly clear that many machine learning classifiers are vulnerable to adversarial examples. In attempting to explain the origin of adversarial examples, previous studies have typically focused on the fact that neural networks operate on high dimensional data, they overfit, or they are too linear. Here we argue that the origin of adversarial examples is primarily due to an inherent uncertainty that neural networks have about their predictions. We show that the functional form of this uncertainty is independent of architecture, dataset, and training protocol; and depends onl"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1711.02846","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:31:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"m8M6gGKycA1zhM+O3P40zaEjF3w/usu3PX/MF49Fvu/s4487jmzrnepX8BRfRLUwf/4amiDKj1lKzb5WtUZcDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-31T14:52:39.520234Z"},"content_sha256":"40a662bc536ee9d6ef43eff260bb732be57b855a1429745567bab782766ee7a1","schema_version":"1.0","event_id":"sha256:40a662bc536ee9d6ef43eff260bb732be57b855a1429745567bab782766ee7a1"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/NH7JHNSUQ5K5PEL3372KMBCBF3/bundle.json","state_url":"https://pith.science/pith/NH7JHNSUQ5K5PEL3372KMBCBF3/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/NH7JHNSUQ5K5PEL3372KMBCBF3/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-31T14:52:39Z","links":{"resolver":"https://pith.science/pith/NH7JHNSUQ5K5PEL3372KMBCBF3","bundle":"https://pith.science/pith/NH7JHNSUQ5K5PEL3372KMBCBF3/bundle.json","state":"https://pith.science/pith/NH7JHNSUQ5K5PEL3372KMBCBF3/state.json","well_known_bundle":"https://pith.science/.well-known/pith/NH7JHNSUQ5K5PEL3372KMBCBF3/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:NH7JHNSUQ5K5PEL3372KMBCBF3","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"3c9baf7cd18a0fab0c13e269f9d9a34985dcf5c3254164d64d954627f040de09","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-11-08T06:54:49Z","title_canon_sha256":"39ba755e0ad33a0fc604f1fa7688c88ae75f5da7e078723a94a172eb803af102"},"schema_version":"1.0","source":{"id":"1711.02846","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1711.02846","created_at":"2026-05-18T00:31:01Z"},{"alias_kind":"arxiv_version","alias_value":"1711.02846v1","created_at":"2026-05-18T00:31:01Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1711.02846","created_at":"2026-05-18T00:31:01Z"},{"alias_kind":"pith_short_12","alias_value":"NH7JHNSUQ5K5","created_at":"2026-05-18T12:31:31Z"},{"alias_kind":"pith_short_16","alias_value":"NH7JHNSUQ5K5PEL3","created_at":"2026-05-18T12:31:31Z"},{"alias_kind":"pith_short_8","alias_value":"NH7JHNSU","created_at":"2026-05-18T12:31:31Z"}],"graph_snapshots":[{"event_id":"sha256:40a662bc536ee9d6ef43eff260bb732be57b855a1429745567bab782766ee7a1","target":"graph","created_at":"2026-05-18T00:31:01Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"It is becoming increasingly clear that many machine learning classifiers are vulnerable to adversarial examples. In attempting to explain the origin of adversarial examples, previous studies have typically focused on the fact that neural networks operate on high dimensional data, they overfit, or they are too linear. Here we argue that the origin of adversarial examples is primarily due to an inherent uncertainty that neural networks have about their predictions. We show that the functional form of this uncertainty is independent of architecture, dataset, and training protocol; and depends onl","authors_text":"Barret Zoph, Ekin D. Cubuk, Quoc V. Le, Samuel S. Schoenholz","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-11-08T06:54:49Z","title":"Intriguing Properties of Adversarial Examples"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1711.02846","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:5c320c1b408ae9250c6260eb8c6409772997d4a6aa8f630b4a027446a734e7ad","target":"record","created_at":"2026-05-18T00:31:01Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"3c9baf7cd18a0fab0c13e269f9d9a34985dcf5c3254164d64d954627f040de09","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-11-08T06:54:49Z","title_canon_sha256":"39ba755e0ad33a0fc604f1fa7688c88ae75f5da7e078723a94a172eb803af102"},"schema_version":"1.0","source":{"id":"1711.02846","kind":"arxiv","version":1}},"canonical_sha256":"69fe93b6548755d7917bdff4a604412efbffc7f8e2e2f5c9145524d31c8f4980","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"69fe93b6548755d7917bdff4a604412efbffc7f8e2e2f5c9145524d31c8f4980","first_computed_at":"2026-05-18T00:31:01.547670Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:31:01.547670Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Oy9I7Dk7cMnaWuODOtH3W33fN774FQdrhAShh7W3ZEnV60AZg1Tqf0ZI6NZjesEyvntZrDlSk7fJnJWo1g3nAg==","signature_status":"signed_v1","signed_at":"2026-05-18T00:31:01.548289Z","signed_message":"canonical_sha256_bytes"},"source_id":"1711.02846","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:5c320c1b408ae9250c6260eb8c6409772997d4a6aa8f630b4a027446a734e7ad","sha256:40a662bc536ee9d6ef43eff260bb732be57b855a1429745567bab782766ee7a1"],"state_sha256":"eff172aead5b57e6a224715facc866864c575958ca8b8d25a25810f9e34492c2"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"2r3JlEl+cdryEzzG8uS9dbW5iVKlweCyjws9ezG77ErIQuhPoU5XvsGWaxBBEHtAJG0+ybmMyCr+rYU0oejKDg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-31T14:52:39.525596Z","bundle_sha256":"27de33312f39803ac67c17a2d70140113169f70ae04ce82227fb606289d96f98"}}