{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:OXHQFYD7YAAGWY45CJABRCHFIT","short_pith_number":"pith:OXHQFYD7","canonical_record":{"source":{"id":"1904.08279","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-04-17T14:04:17Z","cross_cats_sorted":[],"title_canon_sha256":"70b80e93e168e8ff2fc5644d5053849613119e0e40184e5b9fd0f552e15d5441","abstract_canon_sha256":"eb25718a509c8c4b774b13cac2b729004493de433019a8fbf79eab85a9b04bd5"},"schema_version":"1.0"},"canonical_sha256":"75cf02e07fc0006b639d12401888e544dac684d0c535ea2a6d2b81b79ceaf27a","source":{"kind":"arxiv","id":"1904.08279","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1904.08279","created_at":"2026-05-17T23:48:18Z"},{"alias_kind":"arxiv_version","alias_value":"1904.08279v1","created_at":"2026-05-17T23:48:18Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1904.08279","created_at":"2026-05-17T23:48:18Z"},{"alias_kind":"pith_short_12","alias_value":"OXHQFYD7YAAG","created_at":"2026-05-18T12:33:24Z"},{"alias_kind":"pith_short_16","alias_value":"OXHQFYD7YAAGWY45","created_at":"2026-05-18T12:33:24Z"},{"alias_kind":"pith_short_8","alias_value":"OXHQFYD7","created_at":"2026-05-18T12:33:24Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:OXHQFYD7YAAGWY45CJABRCHFIT","target":"record","payload":{"canonical_record":{"source":{"id":"1904.08279","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-04-17T14:04:17Z","cross_cats_sorted":[],"title_canon_sha256":"70b80e93e168e8ff2fc5644d5053849613119e0e40184e5b9fd0f552e15d5441","abstract_canon_sha256":"eb25718a509c8c4b774b13cac2b729004493de433019a8fbf79eab85a9b04bd5"},"schema_version":"1.0"},"canonical_sha256":"75cf02e07fc0006b639d12401888e544dac684d0c535ea2a6d2b81b79ceaf27a","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:48:18.156927Z","signature_b64":"sib6ZuUVWcSDe/fQkDYAMCdSds5w0tsblxQk/4X9PdCKlYPkuW5PRCHKCRSJ89dkYkiwVNJqPyfRwdFzyBG+AQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"75cf02e07fc0006b639d12401888e544dac684d0c535ea2a6d2b81b79ceaf27a","last_reissued_at":"2026-05-17T23:48:18.156194Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:48:18.156194Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1904.08279","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:48:18Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"GSOC5dDFplTu1af8qkKpQfgu9XwZo0m8GvLhBeUQQmovdyGFfWu9PtbHZCpyDdRIZoMErcUkZ+aJy2sRkrWBDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T06:57:06.861201Z"},"content_sha256":"594567dc6aa89d3dc6f6a50e159f60f8bc76b2d4a186deb3e1b2aab4f92941ae","schema_version":"1.0","event_id":"sha256:594567dc6aa89d3dc6f6a50e159f60f8bc76b2d4a186deb3e1b2aab4f92941ae"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:OXHQFYD7YAAGWY45CJABRCHFIT","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Interpreting Adversarial Examples with Attributes","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CV","authors_text":"Arnold Smeulders, Jan Hendrik Metzen, Sadaf Gulshad, Zeynep Akata","submitted_at":"2019-04-17T14:04:17Z","abstract_excerpt":"Deep computer vision systems being vulnerable to imperceptible and carefully crafted noise have raised questions regarding the robustness of their decisions. We take a step back and approach this problem from an orthogonal direction. We propose to enable black-box neural networks to justify their reasoning both for clean and for adversarial examples by leveraging attributes, i.e. visually discriminative properties of objects. We rank attributes based on their class relevance, i.e. how the classification decision changes when the input is visually slightly perturbed, as well as image relevance,"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1904.08279","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:48:18Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"sW8/a7sDwej8gmQDsE7mLko/K2v3THPoDyKHyz8wxvxbnc1N6MhFdKsSof0Vqu3zZa28VKwTWltfT5jZJpnqCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T06:57:06.861554Z"},"content_sha256":"ab12c411ff227fd6e9d91bcd45dd700e5118c8d5fcd3d7e95886821821897355","schema_version":"1.0","event_id":"sha256:ab12c411ff227fd6e9d91bcd45dd700e5118c8d5fcd3d7e95886821821897355"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/OXHQFYD7YAAGWY45CJABRCHFIT/bundle.json","state_url":"https://pith.science/pith/OXHQFYD7YAAGWY45CJABRCHFIT/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/OXHQFYD7YAAGWY45CJABRCHFIT/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-01T06:57:06Z","links":{"resolver":"https://pith.science/pith/OXHQFYD7YAAGWY45CJABRCHFIT","bundle":"https://pith.science/pith/OXHQFYD7YAAGWY45CJABRCHFIT/bundle.json","state":"https://pith.science/pith/OXHQFYD7YAAGWY45CJABRCHFIT/state.json","well_known_bundle":"https://pith.science/.well-known/pith/OXHQFYD7YAAGWY45CJABRCHFIT/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:OXHQFYD7YAAGWY45CJABRCHFIT","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"eb25718a509c8c4b774b13cac2b729004493de433019a8fbf79eab85a9b04bd5","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-04-17T14:04:17Z","title_canon_sha256":"70b80e93e168e8ff2fc5644d5053849613119e0e40184e5b9fd0f552e15d5441"},"schema_version":"1.0","source":{"id":"1904.08279","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1904.08279","created_at":"2026-05-17T23:48:18Z"},{"alias_kind":"arxiv_version","alias_value":"1904.08279v1","created_at":"2026-05-17T23:48:18Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1904.08279","created_at":"2026-05-17T23:48:18Z"},{"alias_kind":"pith_short_12","alias_value":"OXHQFYD7YAAG","created_at":"2026-05-18T12:33:24Z"},{"alias_kind":"pith_short_16","alias_value":"OXHQFYD7YAAGWY45","created_at":"2026-05-18T12:33:24Z"},{"alias_kind":"pith_short_8","alias_value":"OXHQFYD7","created_at":"2026-05-18T12:33:24Z"}],"graph_snapshots":[{"event_id":"sha256:ab12c411ff227fd6e9d91bcd45dd700e5118c8d5fcd3d7e95886821821897355","target":"graph","created_at":"2026-05-17T23:48:18Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep computer vision systems being vulnerable to imperceptible and carefully crafted noise have raised questions regarding the robustness of their decisions. We take a step back and approach this problem from an orthogonal direction. We propose to enable black-box neural networks to justify their reasoning both for clean and for adversarial examples by leveraging attributes, i.e. visually discriminative properties of objects. We rank attributes based on their class relevance, i.e. how the classification decision changes when the input is visually slightly perturbed, as well as image relevance,","authors_text":"Arnold Smeulders, Jan Hendrik Metzen, Sadaf Gulshad, Zeynep Akata","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-04-17T14:04:17Z","title":"Interpreting Adversarial Examples with Attributes"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1904.08279","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:594567dc6aa89d3dc6f6a50e159f60f8bc76b2d4a186deb3e1b2aab4f92941ae","target":"record","created_at":"2026-05-17T23:48:18Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"eb25718a509c8c4b774b13cac2b729004493de433019a8fbf79eab85a9b04bd5","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-04-17T14:04:17Z","title_canon_sha256":"70b80e93e168e8ff2fc5644d5053849613119e0e40184e5b9fd0f552e15d5441"},"schema_version":"1.0","source":{"id":"1904.08279","kind":"arxiv","version":1}},"canonical_sha256":"75cf02e07fc0006b639d12401888e544dac684d0c535ea2a6d2b81b79ceaf27a","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"75cf02e07fc0006b639d12401888e544dac684d0c535ea2a6d2b81b79ceaf27a","first_computed_at":"2026-05-17T23:48:18.156194Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:48:18.156194Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"sib6ZuUVWcSDe/fQkDYAMCdSds5w0tsblxQk/4X9PdCKlYPkuW5PRCHKCRSJ89dkYkiwVNJqPyfRwdFzyBG+AQ==","signature_status":"signed_v1","signed_at":"2026-05-17T23:48:18.156927Z","signed_message":"canonical_sha256_bytes"},"source_id":"1904.08279","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:594567dc6aa89d3dc6f6a50e159f60f8bc76b2d4a186deb3e1b2aab4f92941ae","sha256:ab12c411ff227fd6e9d91bcd45dd700e5118c8d5fcd3d7e95886821821897355"],"state_sha256":"c1f9e25f8bfb295320264568ed1f000cc172d04b96a49852d461440dfbee1747"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"K/4hUwnq+EkM4qD7KFsWOo79JNDizFwfnsgiTYauCsYsKtsjUSqsf+b5UcJYQO2SDuZVkl/iyIQkytlQKr9NAQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-01T06:57:06.863515Z","bundle_sha256":"1c30bc32ef8b5c15457342df4c9213798fe3788c04f9035961eaf7562f820d4d"}}