{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:OECDCGEGT56R6WXIP7MMSVDAR6","short_pith_number":"pith:OECDCGEG","canonical_record":{"source":{"id":"1704.08006","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-04-26T08:17:34Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"c608e8f725b55d99ac08029bd51941d12550c4f168fdfcd429642ea6f0f37ffe","abstract_canon_sha256":"38463a1edb98330ad1c9f279d084c2a75e4678bd239be293eb4804998ea15b54"},"schema_version":"1.0"},"canonical_sha256":"71043118869f7d1f5ae87fd8c954608f873d1b1e1597750fd8c67af7537ca72b","source":{"kind":"arxiv","id":"1704.08006","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1704.08006","created_at":"2026-05-17T23:56:55Z"},{"alias_kind":"arxiv_version","alias_value":"1704.08006v2","created_at":"2026-05-17T23:56:55Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1704.08006","created_at":"2026-05-17T23:56:55Z"},{"alias_kind":"pith_short_12","alias_value":"OECDCGEGT56R","created_at":"2026-05-18T12:31:34Z"},{"alias_kind":"pith_short_16","alias_value":"OECDCGEGT56R6WXI","created_at":"2026-05-18T12:31:34Z"},{"alias_kind":"pith_short_8","alias_value":"OECDCGEG","created_at":"2026-05-18T12:31:34Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:OECDCGEGT56R6WXIP7MMSVDAR6","target":"record","payload":{"canonical_record":{"source":{"id":"1704.08006","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-04-26T08:17:34Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"c608e8f725b55d99ac08029bd51941d12550c4f168fdfcd429642ea6f0f37ffe","abstract_canon_sha256":"38463a1edb98330ad1c9f279d084c2a75e4678bd239be293eb4804998ea15b54"},"schema_version":"1.0"},"canonical_sha256":"71043118869f7d1f5ae87fd8c954608f873d1b1e1597750fd8c67af7537ca72b","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:56:55.987945Z","signature_b64":"WBDnytE1PmfYD2gLPgUOY/EJ1md0dU5fGWiTEO6JqKmvl3gK/Q0BlyZ0Zjm7txMijIviXQUIN6YflFEqgjllCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"71043118869f7d1f5ae87fd8c954608f873d1b1e1597750fd8c67af7537ca72b","last_reissued_at":"2026-05-17T23:56:55.987408Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:56:55.987408Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1704.08006","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:56:55Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"hCZlYtC4Ep9GqNOU9C61TOnYxTenaeFPF98cMbSNkHVWSsuImxsXMyaJ4AqHJ4TzV3S/23hqN3XWtHmuAhyRBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T16:36:28.955887Z"},"content_sha256":"2c53ec3d62017a474ff9bdc90d4cef6683a5fbe611b71ab6f850bfc06de13d0c","schema_version":"1.0","event_id":"sha256:2c53ec3d62017a474ff9bdc90d4cef6683a5fbe611b71ab6f850bfc06de13d0c"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:OECDCGEGT56R6WXIP7MMSVDAR6","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Deep Text Classification Can be Fooled","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Bin Liang, Hongcheng Li, Miaoqiang Su, Pan Bian, Wenchang Shi, Xirong Li","submitted_at":"2017-04-26T08:17:34Z","abstract_excerpt":"In this paper, we present an effective method to craft text adversarial samples, revealing one important yet underestimated fact that DNN-based text classifiers are also prone to adversarial sample attack. Specifically, confronted with different adversarial scenarios, the text items that are important for classification are identified by computing the cost gradients of the input (white-box attack) or generating a series of occluded test samples (black-box attack). Based on these items, we design three perturbation strategies, namely insertion, modification, and removal, to generate adversarial"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1704.08006","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:56:55Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"kNqyo40vJ7CnwKx1SvggKA7uK9ifhB8xwoO8qfqx62P4jxhxxbulrdFOem146awxnAECQzGnGKTrUDLXardzBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T16:36:28.956240Z"},"content_sha256":"1a1ea3e9736be39ca6dafbd7b8f3c594cc009675ae83062bd7bf5f57d9036c12","schema_version":"1.0","event_id":"sha256:1a1ea3e9736be39ca6dafbd7b8f3c594cc009675ae83062bd7bf5f57d9036c12"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/OECDCGEGT56R6WXIP7MMSVDAR6/bundle.json","state_url":"https://pith.science/pith/OECDCGEGT56R6WXIP7MMSVDAR6/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/OECDCGEGT56R6WXIP7MMSVDAR6/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-03T16:36:28Z","links":{"resolver":"https://pith.science/pith/OECDCGEGT56R6WXIP7MMSVDAR6","bundle":"https://pith.science/pith/OECDCGEGT56R6WXIP7MMSVDAR6/bundle.json","state":"https://pith.science/pith/OECDCGEGT56R6WXIP7MMSVDAR6/state.json","well_known_bundle":"https://pith.science/.well-known/pith/OECDCGEGT56R6WXIP7MMSVDAR6/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:OECDCGEGT56R6WXIP7MMSVDAR6","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"38463a1edb98330ad1c9f279d084c2a75e4678bd239be293eb4804998ea15b54","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-04-26T08:17:34Z","title_canon_sha256":"c608e8f725b55d99ac08029bd51941d12550c4f168fdfcd429642ea6f0f37ffe"},"schema_version":"1.0","source":{"id":"1704.08006","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1704.08006","created_at":"2026-05-17T23:56:55Z"},{"alias_kind":"arxiv_version","alias_value":"1704.08006v2","created_at":"2026-05-17T23:56:55Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1704.08006","created_at":"2026-05-17T23:56:55Z"},{"alias_kind":"pith_short_12","alias_value":"OECDCGEGT56R","created_at":"2026-05-18T12:31:34Z"},{"alias_kind":"pith_short_16","alias_value":"OECDCGEGT56R6WXI","created_at":"2026-05-18T12:31:34Z"},{"alias_kind":"pith_short_8","alias_value":"OECDCGEG","created_at":"2026-05-18T12:31:34Z"}],"graph_snapshots":[{"event_id":"sha256:1a1ea3e9736be39ca6dafbd7b8f3c594cc009675ae83062bd7bf5f57d9036c12","target":"graph","created_at":"2026-05-17T23:56:55Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"In this paper, we present an effective method to craft text adversarial samples, revealing one important yet underestimated fact that DNN-based text classifiers are also prone to adversarial sample attack. Specifically, confronted with different adversarial scenarios, the text items that are important for classification are identified by computing the cost gradients of the input (white-box attack) or generating a series of occluded test samples (black-box attack). Based on these items, we design three perturbation strategies, namely insertion, modification, and removal, to generate adversarial","authors_text":"Bin Liang, Hongcheng Li, Miaoqiang Su, Pan Bian, Wenchang Shi, Xirong Li","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-04-26T08:17:34Z","title":"Deep Text Classification Can be Fooled"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1704.08006","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:2c53ec3d62017a474ff9bdc90d4cef6683a5fbe611b71ab6f850bfc06de13d0c","target":"record","created_at":"2026-05-17T23:56:55Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"38463a1edb98330ad1c9f279d084c2a75e4678bd239be293eb4804998ea15b54","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-04-26T08:17:34Z","title_canon_sha256":"c608e8f725b55d99ac08029bd51941d12550c4f168fdfcd429642ea6f0f37ffe"},"schema_version":"1.0","source":{"id":"1704.08006","kind":"arxiv","version":2}},"canonical_sha256":"71043118869f7d1f5ae87fd8c954608f873d1b1e1597750fd8c67af7537ca72b","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"71043118869f7d1f5ae87fd8c954608f873d1b1e1597750fd8c67af7537ca72b","first_computed_at":"2026-05-17T23:56:55.987408Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:56:55.987408Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"WBDnytE1PmfYD2gLPgUOY/EJ1md0dU5fGWiTEO6JqKmvl3gK/Q0BlyZ0Zjm7txMijIviXQUIN6YflFEqgjllCA==","signature_status":"signed_v1","signed_at":"2026-05-17T23:56:55.987945Z","signed_message":"canonical_sha256_bytes"},"source_id":"1704.08006","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:2c53ec3d62017a474ff9bdc90d4cef6683a5fbe611b71ab6f850bfc06de13d0c","sha256:1a1ea3e9736be39ca6dafbd7b8f3c594cc009675ae83062bd7bf5f57d9036c12"],"state_sha256":"796207399435b3600feb1e5683dae98394f56c69b1a758dd839047d09d8f7853"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"PSoCHfP3TK3tz/AxQ/7Fge7gQaAt/B04j08kILnYPPPv1IoKo8Q/gYvYtrUKhhIWnOzwkCwUEt4wnt3nT9PGAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-03T16:36:28.971897Z","bundle_sha256":"65125ef89c93c07b6456d5f273f2ffe05bba3161d0347cd70a2d437d0ea144f7"}}