{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:OZ5WDGJ6LAGPW5A5D4DA5MAD6Y","short_pith_number":"pith:OZ5WDGJ6","schema_version":"1.0","canonical_sha256":"767b61993e580cfb741d1f060eb003f616926af00b6ffe066fc938f9da369a89","source":{"kind":"arxiv","id":"2106.10151","version":2},"attestation_state":"computed","paper":{"title":"The Dimpled Manifold Model of Adversarial Examples in Machine Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Adi Shamir, Odelia Melamed, Oriel BenShmuel","submitted_at":"2021-06-18T14:32:55Z","abstract_excerpt":"The extreme fragility of deep neural networks, when presented with tiny perturbations in their inputs, was independently discovered by several research groups in 2013. However, despite enormous effort, these adversarial examples remained a counterintuitive phenomenon with no simple testable explanation. In this paper, we introduce a new conceptual framework for how the decision boundary between classes evolves during training, which we call the {\\em Dimpled Manifold Model}. In particular, we demonstrate that training is divided into two distinct phases. The first phase is a (typically fast) cl"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2106.10151","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2021-06-18T14:32:55Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"d6036885899550d995bf049ad95db7235d3321c6b068b95438621cd44ef80073","abstract_canon_sha256":"c32b120d984a341f8c29a2c23359a1e3a6a3b4a82a7280b96bf24412da0fc2c8"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T04:28:07.000362Z","signature_b64":"7akJZyK3P2tJxnBFuZ3WQ4sYM3QPiVhQ0mBZi4+fL8xHusaRxrpqaQbRYrZSB18hL+w1uqu1V2i2kxpUnhWSCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"767b61993e580cfb741d1f060eb003f616926af00b6ffe066fc938f9da369a89","last_reissued_at":"2026-07-05T04:28:06.999923Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T04:28:06.999923Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"The Dimpled Manifold Model of Adversarial Examples in Machine Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Adi Shamir, Odelia Melamed, Oriel BenShmuel","submitted_at":"2021-06-18T14:32:55Z","abstract_excerpt":"The extreme fragility of deep neural networks, when presented with tiny perturbations in their inputs, was independently discovered by several research groups in 2013. However, despite enormous effort, these adversarial examples remained a counterintuitive phenomenon with no simple testable explanation. In this paper, we introduce a new conceptual framework for how the decision boundary between classes evolves during training, which we call the {\\em Dimpled Manifold Model}. In particular, we demonstrate that training is divided into two distinct phases. The first phase is a (typically fast) cl"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2106.10151","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2106.10151/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2106.10151","created_at":"2026-07-05T04:28:06.999979+00:00"},{"alias_kind":"arxiv_version","alias_value":"2106.10151v2","created_at":"2026-07-05T04:28:06.999979+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2106.10151","created_at":"2026-07-05T04:28:06.999979+00:00"},{"alias_kind":"pith_short_12","alias_value":"OZ5WDGJ6LAGP","created_at":"2026-07-05T04:28:06.999979+00:00"},{"alias_kind":"pith_short_16","alias_value":"OZ5WDGJ6LAGPW5A5","created_at":"2026-07-05T04:28:06.999979+00:00"},{"alias_kind":"pith_short_8","alias_value":"OZ5WDGJ6","created_at":"2026-07-05T04:28:06.999979+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.02267","citing_title":"A combination of noise and bilateral filters achieve supralinear and scalable adversarial robustness in CNNs","ref_index":47,"is_internal_anchor":false},{"citing_arxiv_id":"2509.07673","citing_title":"Nearest Neighbor Projection Removal Adversarial Training","ref_index":32,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/OZ5WDGJ6LAGPW5A5D4DA5MAD6Y","json":"https://pith.science/pith/OZ5WDGJ6LAGPW5A5D4DA5MAD6Y.json","graph_json":"https://pith.science/api/pith-number/OZ5WDGJ6LAGPW5A5D4DA5MAD6Y/graph.json","events_json":"https://pith.science/api/pith-number/OZ5WDGJ6LAGPW5A5D4DA5MAD6Y/events.json","paper":"https://pith.science/paper/OZ5WDGJ6"},"agent_actions":{"view_html":"https://pith.science/pith/OZ5WDGJ6LAGPW5A5D4DA5MAD6Y","download_json":"https://pith.science/pith/OZ5WDGJ6LAGPW5A5D4DA5MAD6Y.json","view_paper":"https://pith.science/paper/OZ5WDGJ6","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2106.10151&json=true","fetch_graph":"https://pith.science/api/pith-number/OZ5WDGJ6LAGPW5A5D4DA5MAD6Y/graph.json","fetch_events":"https://pith.science/api/pith-number/OZ5WDGJ6LAGPW5A5D4DA5MAD6Y/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/OZ5WDGJ6LAGPW5A5D4DA5MAD6Y/action/timestamp_anchor","attest_storage":"https://pith.science/pith/OZ5WDGJ6LAGPW5A5D4DA5MAD6Y/action/storage_attestation","attest_author":"https://pith.science/pith/OZ5WDGJ6LAGPW5A5D4DA5MAD6Y/action/author_attestation","sign_citation":"https://pith.science/pith/OZ5WDGJ6LAGPW5A5D4DA5MAD6Y/action/citation_signature","submit_replication":"https://pith.science/pith/OZ5WDGJ6LAGPW5A5D4DA5MAD6Y/action/replication_record"}},"created_at":"2026-07-05T04:28:06.999979+00:00","updated_at":"2026-07-05T04:28:06.999979+00:00"}