{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:ODUDRPJTGRFP2MZQE6ZU46EOJ6","short_pith_number":"pith:ODUDRPJT","canonical_record":{"source":{"id":"1907.05587","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-07-12T06:12:18Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"cb7830e9e049e85342efec97bd2182d425f594dbeded6d39719d5e6e2e0e65d3","abstract_canon_sha256":"e25d91e4fd7c08b3924a88ab9779513c215410eeae98480fd9c9de0cb7d1979a"},"schema_version":"1.0"},"canonical_sha256":"70e838bd33344afd333027b34e788e4fbe3497566670b6a5b53ec7710da8ee46","source":{"kind":"arxiv","id":"1907.05587","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1907.05587","created_at":"2026-05-17T23:40:47Z"},{"alias_kind":"arxiv_version","alias_value":"1907.05587v1","created_at":"2026-05-17T23:40:47Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1907.05587","created_at":"2026-05-17T23:40:47Z"},{"alias_kind":"pith_short_12","alias_value":"ODUDRPJTGRFP","created_at":"2026-05-18T12:33:24Z"},{"alias_kind":"pith_short_16","alias_value":"ODUDRPJTGRFP2MZQ","created_at":"2026-05-18T12:33:24Z"},{"alias_kind":"pith_short_8","alias_value":"ODUDRPJT","created_at":"2026-05-18T12:33:24Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:ODUDRPJTGRFP2MZQE6ZU46EOJ6","target":"record","payload":{"canonical_record":{"source":{"id":"1907.05587","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-07-12T06:12:18Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"cb7830e9e049e85342efec97bd2182d425f594dbeded6d39719d5e6e2e0e65d3","abstract_canon_sha256":"e25d91e4fd7c08b3924a88ab9779513c215410eeae98480fd9c9de0cb7d1979a"},"schema_version":"1.0"},"canonical_sha256":"70e838bd33344afd333027b34e788e4fbe3497566670b6a5b53ec7710da8ee46","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:40:47.779578Z","signature_b64":"zcfZ3/mYhLiv04xSI89fI6jpBkHgn3IAEx+gSGm2pC6TOG6X3Gmf9JIId+x+YiL0xhJJPmZx6VhKxF6tCVp1Cw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"70e838bd33344afd333027b34e788e4fbe3497566670b6a5b53ec7710da8ee46","last_reissued_at":"2026-05-17T23:40:47.778839Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:40:47.778839Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1907.05587","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:40:47Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"EHtttyUBkWDaG12cKuNYxAvIcKbru+HuOkF8+ixG0mfpOngixEHxAhcbA+wAY5c7jV9EWi04O0Ckqy8vaZbKAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T20:43:28.737729Z"},"content_sha256":"2929e3a2d0cd888f6ea2d86b7a1b6db62f41269bd072d8583f1494223f6e05c3","schema_version":"1.0","event_id":"sha256:2929e3a2d0cd888f6ea2d86b7a1b6db62f41269bd072d8583f1494223f6e05c3"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:ODUDRPJTGRFP2MZQE6ZU46EOJ6","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Stateful Detection of Black-Box Adversarial Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"David Wagner, Nicholas Carlini, Steven Chen","submitted_at":"2019-07-12T06:12:18Z","abstract_excerpt":"The problem of adversarial examples, evasion attacks on machine learning classifiers, has proven extremely difficult to solve. This is true even when, as is the case in many practical settings, the classifier is hosted as a remote service and so the adversary does not have direct access to the model parameters.\n  This paper argues that in such settings, defenders have a much larger space of actions than have been previously explored. Specifically, we deviate from the implicit assumption made by prior work that a defense must be a stateless function that operates on individual examples, and exp"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1907.05587","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:40:47Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"g0YOYEskGzUHed321q17lFVsW0fl4LGUP/xrmTiOJVZkZjqKy6NshzzEd+60pWXx6q8yvniev7lZSAL54DgCDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T20:43:28.738147Z"},"content_sha256":"2288964b6f5a478ed03bec851423860657f485cbe213944a4069bd0050f7391c","schema_version":"1.0","event_id":"sha256:2288964b6f5a478ed03bec851423860657f485cbe213944a4069bd0050f7391c"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/ODUDRPJTGRFP2MZQE6ZU46EOJ6/bundle.json","state_url":"https://pith.science/pith/ODUDRPJTGRFP2MZQE6ZU46EOJ6/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/ODUDRPJTGRFP2MZQE6ZU46EOJ6/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T20:43:28Z","links":{"resolver":"https://pith.science/pith/ODUDRPJTGRFP2MZQE6ZU46EOJ6","bundle":"https://pith.science/pith/ODUDRPJTGRFP2MZQE6ZU46EOJ6/bundle.json","state":"https://pith.science/pith/ODUDRPJTGRFP2MZQE6ZU46EOJ6/state.json","well_known_bundle":"https://pith.science/.well-known/pith/ODUDRPJTGRFP2MZQE6ZU46EOJ6/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:ODUDRPJTGRFP2MZQE6ZU46EOJ6","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e25d91e4fd7c08b3924a88ab9779513c215410eeae98480fd9c9de0cb7d1979a","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-07-12T06:12:18Z","title_canon_sha256":"cb7830e9e049e85342efec97bd2182d425f594dbeded6d39719d5e6e2e0e65d3"},"schema_version":"1.0","source":{"id":"1907.05587","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1907.05587","created_at":"2026-05-17T23:40:47Z"},{"alias_kind":"arxiv_version","alias_value":"1907.05587v1","created_at":"2026-05-17T23:40:47Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1907.05587","created_at":"2026-05-17T23:40:47Z"},{"alias_kind":"pith_short_12","alias_value":"ODUDRPJTGRFP","created_at":"2026-05-18T12:33:24Z"},{"alias_kind":"pith_short_16","alias_value":"ODUDRPJTGRFP2MZQ","created_at":"2026-05-18T12:33:24Z"},{"alias_kind":"pith_short_8","alias_value":"ODUDRPJT","created_at":"2026-05-18T12:33:24Z"}],"graph_snapshots":[{"event_id":"sha256:2288964b6f5a478ed03bec851423860657f485cbe213944a4069bd0050f7391c","target":"graph","created_at":"2026-05-17T23:40:47Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"The problem of adversarial examples, evasion attacks on machine learning classifiers, has proven extremely difficult to solve. This is true even when, as is the case in many practical settings, the classifier is hosted as a remote service and so the adversary does not have direct access to the model parameters.\n  This paper argues that in such settings, defenders have a much larger space of actions than have been previously explored. Specifically, we deviate from the implicit assumption made by prior work that a defense must be a stateless function that operates on individual examples, and exp","authors_text":"David Wagner, Nicholas Carlini, Steven Chen","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-07-12T06:12:18Z","title":"Stateful Detection of Black-Box Adversarial Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1907.05587","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:2929e3a2d0cd888f6ea2d86b7a1b6db62f41269bd072d8583f1494223f6e05c3","target":"record","created_at":"2026-05-17T23:40:47Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e25d91e4fd7c08b3924a88ab9779513c215410eeae98480fd9c9de0cb7d1979a","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-07-12T06:12:18Z","title_canon_sha256":"cb7830e9e049e85342efec97bd2182d425f594dbeded6d39719d5e6e2e0e65d3"},"schema_version":"1.0","source":{"id":"1907.05587","kind":"arxiv","version":1}},"canonical_sha256":"70e838bd33344afd333027b34e788e4fbe3497566670b6a5b53ec7710da8ee46","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"70e838bd33344afd333027b34e788e4fbe3497566670b6a5b53ec7710da8ee46","first_computed_at":"2026-05-17T23:40:47.778839Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:40:47.778839Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"zcfZ3/mYhLiv04xSI89fI6jpBkHgn3IAEx+gSGm2pC6TOG6X3Gmf9JIId+x+YiL0xhJJPmZx6VhKxF6tCVp1Cw==","signature_status":"signed_v1","signed_at":"2026-05-17T23:40:47.779578Z","signed_message":"canonical_sha256_bytes"},"source_id":"1907.05587","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:2929e3a2d0cd888f6ea2d86b7a1b6db62f41269bd072d8583f1494223f6e05c3","sha256:2288964b6f5a478ed03bec851423860657f485cbe213944a4069bd0050f7391c"],"state_sha256":"39c2948858d83b07bcffa69d106c776d6312b35e50148e3f8d40d2f8cbf97f04"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"JzYo05kC93A9U92TloS5/6uMMVzvcQWBycwZF7uXT0DQnjHVqR/fYpHw9PujZVgYSDPmSzyxYSY9Ui9gfNWdDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T20:43:28.740689Z","bundle_sha256":"b2ec72bd3e80495840e225dfc7c5f266216a6c26ed49c1c842dddef9913354da"}}