{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2018:OT2CWZSQQMICF7YUZZCVYNE7BV","short_pith_number":"pith:OT2CWZSQ","schema_version":"1.0","canonical_sha256":"74f42b6650831022ff14ce455c349f0d5f23571ef15830d6a0cc31bba4e74a03","source":{"kind":"arxiv","id":"1806.11146","version":2},"attestation_state":"computed","paper":{"title":"Adversarial Reprogramming of Neural Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Gamaleldin F. Elsayed, Ian Goodfellow, Jascha Sohl-Dickstein","submitted_at":"2018-06-28T19:06:26Z","abstract_excerpt":"Deep neural networks are susceptible to \\emph{adversarial} attacks. In computer vision, well-crafted perturbations to images can cause neural networks to make mistakes such as confusing a cat with a computer. Previous adversarial attacks have been designed to degrade performance of models or cause machine learning models to produce specific outputs chosen ahead of time by the attacker. We introduce attacks that instead {\\em reprogram} the target model to perform a task chosen by the attacker---without the attacker needing to specify or compute the desired output for each test-time input. This "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1806.11146","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-06-28T19:06:26Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"abad630cf945b49e210a17812a85f044120e435bd43022a28cd465bbd701764b","abstract_canon_sha256":"2577c0aba8dd60edd81d9cef9bd54458b99e38cb57c5c361ec0f77ae3b6faff2"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:03:53.772954Z","signature_b64":"l+mE5ROD2Op7/Wuz6n6A3Rp/Einmto73XcxwgRDwURQ4hyA40urQLFFGAQle/01/VvFXwNQF0MBElvUi3ApUCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"74f42b6650831022ff14ce455c349f0d5f23571ef15830d6a0cc31bba4e74a03","last_reissued_at":"2026-07-05T00:03:53.772489Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:03:53.772489Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Adversarial Reprogramming of Neural Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Gamaleldin F. Elsayed, Ian Goodfellow, Jascha Sohl-Dickstein","submitted_at":"2018-06-28T19:06:26Z","abstract_excerpt":"Deep neural networks are susceptible to \\emph{adversarial} attacks. In computer vision, well-crafted perturbations to images can cause neural networks to make mistakes such as confusing a cat with a computer. Previous adversarial attacks have been designed to degrade performance of models or cause machine learning models to produce specific outputs chosen ahead of time by the attacker. We introduce attacks that instead {\\em reprogram} the target model to perform a task chosen by the attacker---without the attacker needing to specify or compute the desired output for each test-time input. This "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1806.11146","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1806.11146/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1806.11146","created_at":"2026-07-05T00:03:53.772546+00:00"},{"alias_kind":"arxiv_version","alias_value":"1806.11146v2","created_at":"2026-07-05T00:03:53.772546+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1806.11146","created_at":"2026-07-05T00:03:53.772546+00:00"},{"alias_kind":"pith_short_12","alias_value":"OT2CWZSQQMIC","created_at":"2026-07-05T00:03:53.772546+00:00"},{"alias_kind":"pith_short_16","alias_value":"OT2CWZSQQMICF7YU","created_at":"2026-07-05T00:03:53.772546+00:00"},{"alias_kind":"pith_short_8","alias_value":"OT2CWZSQ","created_at":"2026-07-05T00:03:53.772546+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2407.17491","citing_title":"Robust Adaptation of Foundation Models with Black-Box Visual Prompting","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2604.06440","citing_title":"Visual prompting reimagined: The power of the Activation Prompts","ref_index":17,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/OT2CWZSQQMICF7YUZZCVYNE7BV","json":"https://pith.science/pith/OT2CWZSQQMICF7YUZZCVYNE7BV.json","graph_json":"https://pith.science/api/pith-number/OT2CWZSQQMICF7YUZZCVYNE7BV/graph.json","events_json":"https://pith.science/api/pith-number/OT2CWZSQQMICF7YUZZCVYNE7BV/events.json","paper":"https://pith.science/paper/OT2CWZSQ"},"agent_actions":{"view_html":"https://pith.science/pith/OT2CWZSQQMICF7YUZZCVYNE7BV","download_json":"https://pith.science/pith/OT2CWZSQQMICF7YUZZCVYNE7BV.json","view_paper":"https://pith.science/paper/OT2CWZSQ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1806.11146&json=true","fetch_graph":"https://pith.science/api/pith-number/OT2CWZSQQMICF7YUZZCVYNE7BV/graph.json","fetch_events":"https://pith.science/api/pith-number/OT2CWZSQQMICF7YUZZCVYNE7BV/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/OT2CWZSQQMICF7YUZZCVYNE7BV/action/timestamp_anchor","attest_storage":"https://pith.science/pith/OT2CWZSQQMICF7YUZZCVYNE7BV/action/storage_attestation","attest_author":"https://pith.science/pith/OT2CWZSQQMICF7YUZZCVYNE7BV/action/author_attestation","sign_citation":"https://pith.science/pith/OT2CWZSQQMICF7YUZZCVYNE7BV/action/citation_signature","submit_replication":"https://pith.science/pith/OT2CWZSQQMICF7YUZZCVYNE7BV/action/replication_record"}},"created_at":"2026-07-05T00:03:53.772546+00:00","updated_at":"2026-07-05T00:03:53.772546+00:00"}