{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:P3CWHSIR7MOGZO3BS3Z66DQ6R7","short_pith_number":"pith:P3CWHSIR","schema_version":"1.0","canonical_sha256":"7ec563c911fb1c6cbb6196f3ef0e1e8fc93d65895d9b68996bd522f9bee51623","source":{"kind":"arxiv","id":"2103.11257","version":3},"attestation_state":"computed","paper":{"title":"Robust Models Are More Interpretable Because Attributions Look Normal","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV"],"primary_cat":"cs.LG","authors_text":"Anupam Datta, Matt Fredrikson, Zifan Wang","submitted_at":"2021-03-20T22:36:39Z","abstract_excerpt":"Recent work has found that adversarially-robust deep networks used for image classification are more interpretable: their feature attributions tend to be sharper, and are more concentrated on the objects associated with the image's ground-truth class. We show that smooth decision boundaries play an important role in this enhanced interpretability, as the model's input gradients around data points will more closely align with boundaries' normal vectors when they are smooth. Thus, because robust models have smoother boundaries, the results of gradient-based attribution methods, like Integrated G"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2103.11257","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2021-03-20T22:36:39Z","cross_cats_sorted":["cs.CV"],"title_canon_sha256":"7f030dd7fc89cdb6f9af8832f0a746d15b41583c0157ace8cdb32f96fe7edeb2","abstract_canon_sha256":"e055e3161e535f9427e9c3a5b0b5df6cbcf5feef27f5ff5f30a601c593bd5acf"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T03:20:20.233187Z","signature_b64":"YxgU1DePw4yz7Rb27x7GrF+8ZLio+c01cMShmyTSaGzdpNx6PpnKyaZHSY/MR33YcL1acdxKHur02HMv0sGEDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"7ec563c911fb1c6cbb6196f3ef0e1e8fc93d65895d9b68996bd522f9bee51623","last_reissued_at":"2026-07-05T03:20:20.232684Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T03:20:20.232684Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Robust Models Are More Interpretable Because Attributions Look Normal","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV"],"primary_cat":"cs.LG","authors_text":"Anupam Datta, Matt Fredrikson, Zifan Wang","submitted_at":"2021-03-20T22:36:39Z","abstract_excerpt":"Recent work has found that adversarially-robust deep networks used for image classification are more interpretable: their feature attributions tend to be sharper, and are more concentrated on the objects associated with the image's ground-truth class. We show that smooth decision boundaries play an important role in this enhanced interpretability, as the model's input gradients around data points will more closely align with boundaries' normal vectors when they are smooth. Thus, because robust models have smoother boundaries, the results of gradient-based attribution methods, like Integrated G"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2103.11257","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2103.11257/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2103.11257","created_at":"2026-07-05T03:20:20.232735+00:00"},{"alias_kind":"arxiv_version","alias_value":"2103.11257v3","created_at":"2026-07-05T03:20:20.232735+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2103.11257","created_at":"2026-07-05T03:20:20.232735+00:00"},{"alias_kind":"pith_short_12","alias_value":"P3CWHSIR7MOG","created_at":"2026-07-05T03:20:20.232735+00:00"},{"alias_kind":"pith_short_16","alias_value":"P3CWHSIR7MOGZO3B","created_at":"2026-07-05T03:20:20.232735+00:00"},{"alias_kind":"pith_short_8","alias_value":"P3CWHSIR","created_at":"2026-07-05T03:20:20.232735+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2510.03245","citing_title":"Frequency-Aware Model Parameter Explorer: A new attribution method for improving explainability","ref_index":16,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/P3CWHSIR7MOGZO3BS3Z66DQ6R7","json":"https://pith.science/pith/P3CWHSIR7MOGZO3BS3Z66DQ6R7.json","graph_json":"https://pith.science/api/pith-number/P3CWHSIR7MOGZO3BS3Z66DQ6R7/graph.json","events_json":"https://pith.science/api/pith-number/P3CWHSIR7MOGZO3BS3Z66DQ6R7/events.json","paper":"https://pith.science/paper/P3CWHSIR"},"agent_actions":{"view_html":"https://pith.science/pith/P3CWHSIR7MOGZO3BS3Z66DQ6R7","download_json":"https://pith.science/pith/P3CWHSIR7MOGZO3BS3Z66DQ6R7.json","view_paper":"https://pith.science/paper/P3CWHSIR","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2103.11257&json=true","fetch_graph":"https://pith.science/api/pith-number/P3CWHSIR7MOGZO3BS3Z66DQ6R7/graph.json","fetch_events":"https://pith.science/api/pith-number/P3CWHSIR7MOGZO3BS3Z66DQ6R7/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/P3CWHSIR7MOGZO3BS3Z66DQ6R7/action/timestamp_anchor","attest_storage":"https://pith.science/pith/P3CWHSIR7MOGZO3BS3Z66DQ6R7/action/storage_attestation","attest_author":"https://pith.science/pith/P3CWHSIR7MOGZO3BS3Z66DQ6R7/action/author_attestation","sign_citation":"https://pith.science/pith/P3CWHSIR7MOGZO3BS3Z66DQ6R7/action/citation_signature","submit_replication":"https://pith.science/pith/P3CWHSIR7MOGZO3BS3Z66DQ6R7/action/replication_record"}},"created_at":"2026-07-05T03:20:20.232735+00:00","updated_at":"2026-07-05T03:20:20.232735+00:00"}