{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:OYAEHYJB3UQQKYPLKDN6RXZXJE","short_pith_number":"pith:OYAEHYJB","canonical_record":{"source":{"id":"1811.09043","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-22T07:17:32Z","cross_cats_sorted":["cs.CV"],"title_canon_sha256":"a294db029b51f0b80b05e9dad95fa0681c5329f14aa7a5ccf0ffd2465323e438","abstract_canon_sha256":"435a6486e8e8f6df407cda05673ed958498e300ae3fbfcd42cfedff57b9ba74c"},"schema_version":"1.0"},"canonical_sha256":"760043e121dd210561eb50dbe8df374911ec1cfccbf8d4df45eae353330e0e7e","source":{"kind":"arxiv","id":"1811.09043","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1811.09043","created_at":"2026-05-17T23:59:13Z"},{"alias_kind":"arxiv_version","alias_value":"1811.09043v2","created_at":"2026-05-17T23:59:13Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.09043","created_at":"2026-05-17T23:59:13Z"},{"alias_kind":"pith_short_12","alias_value":"OYAEHYJB3UQQ","created_at":"2026-05-18T12:32:43Z"},{"alias_kind":"pith_short_16","alias_value":"OYAEHYJB3UQQKYPL","created_at":"2026-05-18T12:32:43Z"},{"alias_kind":"pith_short_8","alias_value":"OYAEHYJB","created_at":"2026-05-18T12:32:43Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:OYAEHYJB3UQQKYPLKDN6RXZXJE","target":"record","payload":{"canonical_record":{"source":{"id":"1811.09043","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-22T07:17:32Z","cross_cats_sorted":["cs.CV"],"title_canon_sha256":"a294db029b51f0b80b05e9dad95fa0681c5329f14aa7a5ccf0ffd2465323e438","abstract_canon_sha256":"435a6486e8e8f6df407cda05673ed958498e300ae3fbfcd42cfedff57b9ba74c"},"schema_version":"1.0"},"canonical_sha256":"760043e121dd210561eb50dbe8df374911ec1cfccbf8d4df45eae353330e0e7e","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:59:13.669395Z","signature_b64":"qlvxKIf6DUA+5HoZCHDsP+TpTzOKg8Idf/15MPCGUrb0ZFVo6cvClTVQRNULNEp4AlW+apVtpCrKoS2whyiDBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"760043e121dd210561eb50dbe8df374911ec1cfccbf8d4df45eae353330e0e7e","last_reissued_at":"2026-05-17T23:59:13.668989Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:59:13.668989Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1811.09043","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:59:13Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"xgDzOuRkJPMB2NaWuffsDnM0tVS8l4/xqseCfavYjYlIgfYwoBDnluXtooBTIQx9MhqmCOzueANDhwuXS2oDBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-06T14:22:12.112366Z"},"content_sha256":"56ded981aa50fa95c34babc73d4cdce640602e82460a224dc501754f9a069afb","schema_version":"1.0","event_id":"sha256:56ded981aa50fa95c34babc73d4cdce640602e82460a224dc501754f9a069afb"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:OYAEHYJB3UQQKYPLKDN6RXZXJE","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Detecting Adversarial Perturbations Through Spatial Behavior in Activation Spaces","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV"],"primary_cat":"cs.LG","authors_text":"Yuval Elovici, Ziv Katzir","submitted_at":"2018-11-22T07:17:32Z","abstract_excerpt":"Neural network based classifiers are still prone to manipulation through adversarial perturbations. State of the art attacks can overcome most of the defense or detection mechanisms suggested so far, and adversaries have the upper hand in this arms race. Adversarial examples are designed to resemble the normal input from which they were constructed, while triggering an incorrect classification. This basic design goal leads to a characteristic spatial behavior within the context of Activation Spaces, a term coined by the authors to refer to the hyperspaces formed by the activation values of the"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.09043","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:59:13Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"f2CoFNqhk60JoMfTznodTxvqHgYeWTDFv78MAP9DVJnTTO9HPolSFSTxlCRDw/dkuFDhENpzXrIj7nu6qtudBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-06T14:22:12.113055Z"},"content_sha256":"cde0012b2fc405d14304d1220d2007c5ad5529f624144eb35dffffa02e173cd9","schema_version":"1.0","event_id":"sha256:cde0012b2fc405d14304d1220d2007c5ad5529f624144eb35dffffa02e173cd9"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/OYAEHYJB3UQQKYPLKDN6RXZXJE/bundle.json","state_url":"https://pith.science/pith/OYAEHYJB3UQQKYPLKDN6RXZXJE/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/OYAEHYJB3UQQKYPLKDN6RXZXJE/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-06T14:22:12Z","links":{"resolver":"https://pith.science/pith/OYAEHYJB3UQQKYPLKDN6RXZXJE","bundle":"https://pith.science/pith/OYAEHYJB3UQQKYPLKDN6RXZXJE/bundle.json","state":"https://pith.science/pith/OYAEHYJB3UQQKYPLKDN6RXZXJE/state.json","well_known_bundle":"https://pith.science/.well-known/pith/OYAEHYJB3UQQKYPLKDN6RXZXJE/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:OYAEHYJB3UQQKYPLKDN6RXZXJE","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"435a6486e8e8f6df407cda05673ed958498e300ae3fbfcd42cfedff57b9ba74c","cross_cats_sorted":["cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-22T07:17:32Z","title_canon_sha256":"a294db029b51f0b80b05e9dad95fa0681c5329f14aa7a5ccf0ffd2465323e438"},"schema_version":"1.0","source":{"id":"1811.09043","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1811.09043","created_at":"2026-05-17T23:59:13Z"},{"alias_kind":"arxiv_version","alias_value":"1811.09043v2","created_at":"2026-05-17T23:59:13Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.09043","created_at":"2026-05-17T23:59:13Z"},{"alias_kind":"pith_short_12","alias_value":"OYAEHYJB3UQQ","created_at":"2026-05-18T12:32:43Z"},{"alias_kind":"pith_short_16","alias_value":"OYAEHYJB3UQQKYPL","created_at":"2026-05-18T12:32:43Z"},{"alias_kind":"pith_short_8","alias_value":"OYAEHYJB","created_at":"2026-05-18T12:32:43Z"}],"graph_snapshots":[{"event_id":"sha256:cde0012b2fc405d14304d1220d2007c5ad5529f624144eb35dffffa02e173cd9","target":"graph","created_at":"2026-05-17T23:59:13Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Neural network based classifiers are still prone to manipulation through adversarial perturbations. State of the art attacks can overcome most of the defense or detection mechanisms suggested so far, and adversaries have the upper hand in this arms race. Adversarial examples are designed to resemble the normal input from which they were constructed, while triggering an incorrect classification. This basic design goal leads to a characteristic spatial behavior within the context of Activation Spaces, a term coined by the authors to refer to the hyperspaces formed by the activation values of the","authors_text":"Yuval Elovici, Ziv Katzir","cross_cats":["cs.CV"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-22T07:17:32Z","title":"Detecting Adversarial Perturbations Through Spatial Behavior in Activation Spaces"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.09043","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:56ded981aa50fa95c34babc73d4cdce640602e82460a224dc501754f9a069afb","target":"record","created_at":"2026-05-17T23:59:13Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"435a6486e8e8f6df407cda05673ed958498e300ae3fbfcd42cfedff57b9ba74c","cross_cats_sorted":["cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-22T07:17:32Z","title_canon_sha256":"a294db029b51f0b80b05e9dad95fa0681c5329f14aa7a5ccf0ffd2465323e438"},"schema_version":"1.0","source":{"id":"1811.09043","kind":"arxiv","version":2}},"canonical_sha256":"760043e121dd210561eb50dbe8df374911ec1cfccbf8d4df45eae353330e0e7e","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"760043e121dd210561eb50dbe8df374911ec1cfccbf8d4df45eae353330e0e7e","first_computed_at":"2026-05-17T23:59:13.668989Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:59:13.668989Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"qlvxKIf6DUA+5HoZCHDsP+TpTzOKg8Idf/15MPCGUrb0ZFVo6cvClTVQRNULNEp4AlW+apVtpCrKoS2whyiDBg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:59:13.669395Z","signed_message":"canonical_sha256_bytes"},"source_id":"1811.09043","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:56ded981aa50fa95c34babc73d4cdce640602e82460a224dc501754f9a069afb","sha256:cde0012b2fc405d14304d1220d2007c5ad5529f624144eb35dffffa02e173cd9"],"state_sha256":"5be7c84c70fa514e6b0276d8f4f40762c6db30ecd65dc3e66fc2f70257c274a0"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"G9YzQRgf1eLrzVXbIwhQP7QE5rQlPRC3HqaupX9W/AjwwjYUfMO5UEZptf+VsephbuHI8oSoycOiEOjeM15dDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-06T14:22:12.117630Z","bundle_sha256":"ef56d871479b3ca669cdd0a92ba492cd85fdf856ec18e5e9fc2e5b60718aeb93"}}