{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:PO3S6YQRSNY3UMDXVJWACOPN3E","short_pith_number":"pith:PO3S6YQR","canonical_record":{"source":{"id":"1809.00615","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-09-03T14:25:46Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"eeacfa9e7943943f6bd8819733f02a8ffc405214eb5bf4edbe09a828dc282d59","abstract_canon_sha256":"0c2451c81c242ef31f884516c944fc6dab6de5e4bb1eb5d697df30ed25e29206"},"schema_version":"1.0"},"canonical_sha256":"7bb72f62119371ba3077aa6c0139edd907a1c1a23febac8d9a6e159244b80f38","source":{"kind":"arxiv","id":"1809.00615","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1809.00615","created_at":"2026-05-18T00:06:33Z"},{"alias_kind":"arxiv_version","alias_value":"1809.00615v1","created_at":"2026-05-18T00:06:33Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1809.00615","created_at":"2026-05-18T00:06:33Z"},{"alias_kind":"pith_short_12","alias_value":"PO3S6YQRSNY3","created_at":"2026-05-18T12:32:46Z"},{"alias_kind":"pith_short_16","alias_value":"PO3S6YQRSNY3UMDX","created_at":"2026-05-18T12:32:46Z"},{"alias_kind":"pith_short_8","alias_value":"PO3S6YQR","created_at":"2026-05-18T12:32:46Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:PO3S6YQRSNY3UMDXVJWACOPN3E","target":"record","payload":{"canonical_record":{"source":{"id":"1809.00615","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-09-03T14:25:46Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"eeacfa9e7943943f6bd8819733f02a8ffc405214eb5bf4edbe09a828dc282d59","abstract_canon_sha256":"0c2451c81c242ef31f884516c944fc6dab6de5e4bb1eb5d697df30ed25e29206"},"schema_version":"1.0"},"canonical_sha256":"7bb72f62119371ba3077aa6c0139edd907a1c1a23febac8d9a6e159244b80f38","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:06:33.019599Z","signature_b64":"DqdxTsRLKsuGHexJXm86/VwInllS8FGsBG8XVgIQwiogf3aLKx1cJA2pB3xvco/IumOdPQ+wg+QtT93nX8tJDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"7bb72f62119371ba3077aa6c0139edd907a1c1a23febac8d9a6e159244b80f38","last_reissued_at":"2026-05-18T00:06:33.018893Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:06:33.018893Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1809.00615","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:06:33Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"DANv3fi/lgZOH77mwvZy0HFIsfKNbYI+AyoQtBBr+fO/NI9X29OjUun8c/hKdN/kd5/K2N5GCbcHg1f4L0tXCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T21:24:49.579058Z"},"content_sha256":"f88ab9972be3bb3fa847b8648572eb4d30c84bf18aae037fcb8b8b7a5e0d1726","schema_version":"1.0","event_id":"sha256:f88ab9972be3bb3fa847b8648572eb4d30c84bf18aae037fcb8b8b7a5e0d1726"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:PO3S6YQRSNY3UMDXVJWACOPN3E","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Have You Stolen My Model? Evasion Attacks Against Deep Neural Network Watermarking Techniques","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Dorjan Hitaj, Luigi V. Mancini","submitted_at":"2018-09-03T14:25:46Z","abstract_excerpt":"Deep neural networks have had enormous impact on various domains of computer science, considerably outperforming previous state of the art machine learning techniques. To achieve this performance, neural networks need large quantities of data and huge computational resources, which heavily increases their construction costs. The increased cost of building a good deep neural network model gives rise to a need for protecting this investment from potential copyright infringements. Legitimate owners of a machine learning model want to be able to reliably track and detect a malicious adversary that"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1809.00615","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:06:33Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"qkZB0uDzBVZURzO/3QHh/0oDn3OICCpHQVryb5XVqobX/zOHScCrQFDHHtlbIYN4UqZMw6TfBDqxlttLEt/oBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T21:24:49.579684Z"},"content_sha256":"95ef23564668e3407cfab26b4387b9a01a5dfc0083762e1b6cffe717e4a89544","schema_version":"1.0","event_id":"sha256:95ef23564668e3407cfab26b4387b9a01a5dfc0083762e1b6cffe717e4a89544"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/PO3S6YQRSNY3UMDXVJWACOPN3E/bundle.json","state_url":"https://pith.science/pith/PO3S6YQRSNY3UMDXVJWACOPN3E/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/PO3S6YQRSNY3UMDXVJWACOPN3E/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-28T21:24:49Z","links":{"resolver":"https://pith.science/pith/PO3S6YQRSNY3UMDXVJWACOPN3E","bundle":"https://pith.science/pith/PO3S6YQRSNY3UMDXVJWACOPN3E/bundle.json","state":"https://pith.science/pith/PO3S6YQRSNY3UMDXVJWACOPN3E/state.json","well_known_bundle":"https://pith.science/.well-known/pith/PO3S6YQRSNY3UMDXVJWACOPN3E/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:PO3S6YQRSNY3UMDXVJWACOPN3E","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"0c2451c81c242ef31f884516c944fc6dab6de5e4bb1eb5d697df30ed25e29206","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-09-03T14:25:46Z","title_canon_sha256":"eeacfa9e7943943f6bd8819733f02a8ffc405214eb5bf4edbe09a828dc282d59"},"schema_version":"1.0","source":{"id":"1809.00615","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1809.00615","created_at":"2026-05-18T00:06:33Z"},{"alias_kind":"arxiv_version","alias_value":"1809.00615v1","created_at":"2026-05-18T00:06:33Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1809.00615","created_at":"2026-05-18T00:06:33Z"},{"alias_kind":"pith_short_12","alias_value":"PO3S6YQRSNY3","created_at":"2026-05-18T12:32:46Z"},{"alias_kind":"pith_short_16","alias_value":"PO3S6YQRSNY3UMDX","created_at":"2026-05-18T12:32:46Z"},{"alias_kind":"pith_short_8","alias_value":"PO3S6YQR","created_at":"2026-05-18T12:32:46Z"}],"graph_snapshots":[{"event_id":"sha256:95ef23564668e3407cfab26b4387b9a01a5dfc0083762e1b6cffe717e4a89544","target":"graph","created_at":"2026-05-18T00:06:33Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep neural networks have had enormous impact on various domains of computer science, considerably outperforming previous state of the art machine learning techniques. To achieve this performance, neural networks need large quantities of data and huge computational resources, which heavily increases their construction costs. The increased cost of building a good deep neural network model gives rise to a need for protecting this investment from potential copyright infringements. Legitimate owners of a machine learning model want to be able to reliably track and detect a malicious adversary that","authors_text":"Dorjan Hitaj, Luigi V. Mancini","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-09-03T14:25:46Z","title":"Have You Stolen My Model? Evasion Attacks Against Deep Neural Network Watermarking Techniques"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1809.00615","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:f88ab9972be3bb3fa847b8648572eb4d30c84bf18aae037fcb8b8b7a5e0d1726","target":"record","created_at":"2026-05-18T00:06:33Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"0c2451c81c242ef31f884516c944fc6dab6de5e4bb1eb5d697df30ed25e29206","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-09-03T14:25:46Z","title_canon_sha256":"eeacfa9e7943943f6bd8819733f02a8ffc405214eb5bf4edbe09a828dc282d59"},"schema_version":"1.0","source":{"id":"1809.00615","kind":"arxiv","version":1}},"canonical_sha256":"7bb72f62119371ba3077aa6c0139edd907a1c1a23febac8d9a6e159244b80f38","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"7bb72f62119371ba3077aa6c0139edd907a1c1a23febac8d9a6e159244b80f38","first_computed_at":"2026-05-18T00:06:33.018893Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:06:33.018893Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"DqdxTsRLKsuGHexJXm86/VwInllS8FGsBG8XVgIQwiogf3aLKx1cJA2pB3xvco/IumOdPQ+wg+QtT93nX8tJDg==","signature_status":"signed_v1","signed_at":"2026-05-18T00:06:33.019599Z","signed_message":"canonical_sha256_bytes"},"source_id":"1809.00615","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:f88ab9972be3bb3fa847b8648572eb4d30c84bf18aae037fcb8b8b7a5e0d1726","sha256:95ef23564668e3407cfab26b4387b9a01a5dfc0083762e1b6cffe717e4a89544"],"state_sha256":"eeffcb3f5011c5ef8b1d0c15340ba6cdf045870e04a2c6965fbaa639ebeaf29c"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"eh9wDGFBPwf0SbIUzV6GSQuMd00bAxp0adqPibxu/F3iXZ+HWcf8BEXO5TCZHMkWZv8FaETjvDNui0pxO26wCA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-28T21:24:49.583115Z","bundle_sha256":"1d54fc2307df88809cc19d3ba71d2eb9f7c528b1e49fd7ea50160194014658ea"}}