{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:ODUDRPJTGRFP2MZQE6ZU46EOJ6","short_pith_number":"pith:ODUDRPJT","schema_version":"1.0","canonical_sha256":"70e838bd33344afd333027b34e788e4fbe3497566670b6a5b53ec7710da8ee46","source":{"kind":"arxiv","id":"1907.05587","version":1},"attestation_state":"computed","paper":{"title":"Stateful Detection of Black-Box Adversarial Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"David Wagner, Nicholas Carlini, Steven Chen","submitted_at":"2019-07-12T06:12:18Z","abstract_excerpt":"The problem of adversarial examples, evasion attacks on machine learning classifiers, has proven extremely difficult to solve. This is true even when, as is the case in many practical settings, the classifier is hosted as a remote service and so the adversary does not have direct access to the model parameters.\n  This paper argues that in such settings, defenders have a much larger space of actions than have been previously explored. Specifically, we deviate from the implicit assumption made by prior work that a defense must be a stateless function that operates on individual examples, and exp"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1907.05587","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-07-12T06:12:18Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"cb7830e9e049e85342efec97bd2182d425f594dbeded6d39719d5e6e2e0e65d3","abstract_canon_sha256":"e25d91e4fd7c08b3924a88ab9779513c215410eeae98480fd9c9de0cb7d1979a"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:40:47.779578Z","signature_b64":"zcfZ3/mYhLiv04xSI89fI6jpBkHgn3IAEx+gSGm2pC6TOG6X3Gmf9JIId+x+YiL0xhJJPmZx6VhKxF6tCVp1Cw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"70e838bd33344afd333027b34e788e4fbe3497566670b6a5b53ec7710da8ee46","last_reissued_at":"2026-05-17T23:40:47.778839Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:40:47.778839Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Stateful Detection of Black-Box Adversarial Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"David Wagner, Nicholas Carlini, Steven Chen","submitted_at":"2019-07-12T06:12:18Z","abstract_excerpt":"The problem of adversarial examples, evasion attacks on machine learning classifiers, has proven extremely difficult to solve. This is true even when, as is the case in many practical settings, the classifier is hosted as a remote service and so the adversary does not have direct access to the model parameters.\n  This paper argues that in such settings, defenders have a much larger space of actions than have been previously explored. Specifically, we deviate from the implicit assumption made by prior work that a defense must be a stateless function that operates on individual examples, and exp"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1907.05587","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1907.05587","created_at":"2026-05-17T23:40:47.778972+00:00"},{"alias_kind":"arxiv_version","alias_value":"1907.05587v1","created_at":"2026-05-17T23:40:47.778972+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1907.05587","created_at":"2026-05-17T23:40:47.778972+00:00"},{"alias_kind":"pith_short_12","alias_value":"ODUDRPJTGRFP","created_at":"2026-05-18T12:33:24.271573+00:00"},{"alias_kind":"pith_short_16","alias_value":"ODUDRPJTGRFP2MZQ","created_at":"2026-05-18T12:33:24.271573+00:00"},{"alias_kind":"pith_short_8","alias_value":"ODUDRPJT","created_at":"2026-05-18T12:33:24.271573+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2506.06414","citing_title":"Benchmarking Misuse Mitigation Against Covert Adversaries","ref_index":34,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/ODUDRPJTGRFP2MZQE6ZU46EOJ6","json":"https://pith.science/pith/ODUDRPJTGRFP2MZQE6ZU46EOJ6.json","graph_json":"https://pith.science/api/pith-number/ODUDRPJTGRFP2MZQE6ZU46EOJ6/graph.json","events_json":"https://pith.science/api/pith-number/ODUDRPJTGRFP2MZQE6ZU46EOJ6/events.json","paper":"https://pith.science/paper/ODUDRPJT"},"agent_actions":{"view_html":"https://pith.science/pith/ODUDRPJTGRFP2MZQE6ZU46EOJ6","download_json":"https://pith.science/pith/ODUDRPJTGRFP2MZQE6ZU46EOJ6.json","view_paper":"https://pith.science/paper/ODUDRPJT","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1907.05587&json=true","fetch_graph":"https://pith.science/api/pith-number/ODUDRPJTGRFP2MZQE6ZU46EOJ6/graph.json","fetch_events":"https://pith.science/api/pith-number/ODUDRPJTGRFP2MZQE6ZU46EOJ6/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/ODUDRPJTGRFP2MZQE6ZU46EOJ6/action/timestamp_anchor","attest_storage":"https://pith.science/pith/ODUDRPJTGRFP2MZQE6ZU46EOJ6/action/storage_attestation","attest_author":"https://pith.science/pith/ODUDRPJTGRFP2MZQE6ZU46EOJ6/action/author_attestation","sign_citation":"https://pith.science/pith/ODUDRPJTGRFP2MZQE6ZU46EOJ6/action/citation_signature","submit_replication":"https://pith.science/pith/ODUDRPJTGRFP2MZQE6ZU46EOJ6/action/replication_record"}},"created_at":"2026-05-17T23:40:47.778972+00:00","updated_at":"2026-05-17T23:40:47.778972+00:00"}