{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2020:OZRU4WX46EI7PMP3URI2W26HFQ","short_pith_number":"pith:OZRU4WX4","schema_version":"1.0","canonical_sha256":"76634e5afcf111f7b1fba451ab6bc72c1fc922bc653d46fc734513264534d341","source":{"kind":"arxiv","id":"2002.09364","version":1},"attestation_state":"computed","paper":{"title":"Adversarial Detection and Correction by Matching Prediction Distributions","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Arnaud Van Looveren, Giovanni Vacanti","submitted_at":"2020-02-21T15:45:42Z","abstract_excerpt":"We present a novel adversarial detection and correction method for machine learning classifiers.The detector consists of an autoencoder trained with a custom loss function based on the Kullback-Leibler divergence between the classifier predictions on the original and reconstructed instances.The method is unsupervised, easy to train and does not require any knowledge about the underlying attack. The detector almost completely neutralises powerful attacks like Carlini-Wagner or SLIDE on MNIST and Fashion-MNIST, and remains very effective on CIFAR-10 when the attack is granted full access to the "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2002.09364","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2020-02-21T15:45:42Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"4f21c7f0f663fd5423d8b7deb1f5b700429e089db48dac6047569485fcd39564","abstract_canon_sha256":"cee138dd888984fc1f0e0aebbdcc054331cc655f13a3b764ebc50df836c6519c"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:42:55.425215Z","signature_b64":"JselVUG6WvcrFu3JVb3I6Xp+8X5XWAgOP+VvY0YARCoH1J0vjei4+j96Hg5FADMCe6WT5jgmjr/vii4q16WBDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"76634e5afcf111f7b1fba451ab6bc72c1fc922bc653d46fc734513264534d341","last_reissued_at":"2026-07-05T00:42:55.424764Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:42:55.424764Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Adversarial Detection and Correction by Matching Prediction Distributions","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Arnaud Van Looveren, Giovanni Vacanti","submitted_at":"2020-02-21T15:45:42Z","abstract_excerpt":"We present a novel adversarial detection and correction method for machine learning classifiers.The detector consists of an autoencoder trained with a custom loss function based on the Kullback-Leibler divergence between the classifier predictions on the original and reconstructed instances.The method is unsupervised, easy to train and does not require any knowledge about the underlying attack. The detector almost completely neutralises powerful attacks like Carlini-Wagner or SLIDE on MNIST and Fashion-MNIST, and remains very effective on CIFAR-10 when the attack is granted full access to the "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2002.09364","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2002.09364/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2002.09364","created_at":"2026-07-05T00:42:55.424818+00:00"},{"alias_kind":"arxiv_version","alias_value":"2002.09364v1","created_at":"2026-07-05T00:42:55.424818+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2002.09364","created_at":"2026-07-05T00:42:55.424818+00:00"},{"alias_kind":"pith_short_12","alias_value":"OZRU4WX46EI7","created_at":"2026-07-05T00:42:55.424818+00:00"},{"alias_kind":"pith_short_16","alias_value":"OZRU4WX46EI7PMP3","created_at":"2026-07-05T00:42:55.424818+00:00"},{"alias_kind":"pith_short_8","alias_value":"OZRU4WX4","created_at":"2026-07-05T00:42:55.424818+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2505.14967","citing_title":"Anomaly Detection Based on Critical Paths for Deep Neural Networks","ref_index":48,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/OZRU4WX46EI7PMP3URI2W26HFQ","json":"https://pith.science/pith/OZRU4WX46EI7PMP3URI2W26HFQ.json","graph_json":"https://pith.science/api/pith-number/OZRU4WX46EI7PMP3URI2W26HFQ/graph.json","events_json":"https://pith.science/api/pith-number/OZRU4WX46EI7PMP3URI2W26HFQ/events.json","paper":"https://pith.science/paper/OZRU4WX4"},"agent_actions":{"view_html":"https://pith.science/pith/OZRU4WX46EI7PMP3URI2W26HFQ","download_json":"https://pith.science/pith/OZRU4WX46EI7PMP3URI2W26HFQ.json","view_paper":"https://pith.science/paper/OZRU4WX4","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2002.09364&json=true","fetch_graph":"https://pith.science/api/pith-number/OZRU4WX46EI7PMP3URI2W26HFQ/graph.json","fetch_events":"https://pith.science/api/pith-number/OZRU4WX46EI7PMP3URI2W26HFQ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/OZRU4WX46EI7PMP3URI2W26HFQ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/OZRU4WX46EI7PMP3URI2W26HFQ/action/storage_attestation","attest_author":"https://pith.science/pith/OZRU4WX46EI7PMP3URI2W26HFQ/action/author_attestation","sign_citation":"https://pith.science/pith/OZRU4WX46EI7PMP3URI2W26HFQ/action/citation_signature","submit_replication":"https://pith.science/pith/OZRU4WX46EI7PMP3URI2W26HFQ/action/replication_record"}},"created_at":"2026-07-05T00:42:55.424818+00:00","updated_at":"2026-07-05T00:42:55.424818+00:00"}