{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:Q3F5D6KVTORLTNQEVV22VXA5NV","short_pith_number":"pith:Q3F5D6KV","canonical_record":{"source":{"id":"1711.08244","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-11-22T12:02:53Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"a5fac8414d9dfc94979826c126306f5f1fc89c49f677df81e6f618443d830a48","abstract_canon_sha256":"25a7a3b356878eb633590dc936978cf35ac2a0ce66014abeda36b6003b5f535f"},"schema_version":"1.0"},"canonical_sha256":"86cbd1f9559ba2b9b604ad75aadc1d6d45b836c46367297b9007ae8c3b3962db","source":{"kind":"arxiv","id":"1711.08244","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1711.08244","created_at":"2026-05-18T00:29:50Z"},{"alias_kind":"arxiv_version","alias_value":"1711.08244v1","created_at":"2026-05-18T00:29:50Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1711.08244","created_at":"2026-05-18T00:29:50Z"},{"alias_kind":"pith_short_12","alias_value":"Q3F5D6KVTORL","created_at":"2026-05-18T12:31:37Z"},{"alias_kind":"pith_short_16","alias_value":"Q3F5D6KVTORLTNQE","created_at":"2026-05-18T12:31:37Z"},{"alias_kind":"pith_short_8","alias_value":"Q3F5D6KV","created_at":"2026-05-18T12:31:37Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:Q3F5D6KVTORLTNQEVV22VXA5NV","target":"record","payload":{"canonical_record":{"source":{"id":"1711.08244","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-11-22T12:02:53Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"a5fac8414d9dfc94979826c126306f5f1fc89c49f677df81e6f618443d830a48","abstract_canon_sha256":"25a7a3b356878eb633590dc936978cf35ac2a0ce66014abeda36b6003b5f535f"},"schema_version":"1.0"},"canonical_sha256":"86cbd1f9559ba2b9b604ad75aadc1d6d45b836c46367297b9007ae8c3b3962db","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:29:50.306490Z","signature_b64":"LYhfbCdm2xVXne35sGpupOYc/BAuMvgQAFBN66Kzc0iKyDOnlObRM+4U6thjqX5C/I85jIqNm0J2XdZKPC8AAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"86cbd1f9559ba2b9b604ad75aadc1d6d45b836c46367297b9007ae8c3b3962db","last_reissued_at":"2026-05-18T00:29:50.305975Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:29:50.305975Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1711.08244","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:29:50Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"o0J+sFfPLQHns/K4TRUXWWf2UsTaTa7Uww6Ujo9diijxJOSYTbQsocAhfmF2mNUv7hS+bunZnSrYugh9INI5BQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T04:33:00.849410Z"},"content_sha256":"89b4654703c280586fe4d1d917c5844dfa27836082e2e18e6f32d14d775797f0","schema_version":"1.0","event_id":"sha256:89b4654703c280586fe4d1d917c5844dfa27836082e2e18e6f32d14d775797f0"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:Q3F5D6KVTORLTNQEVV22VXA5NV","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Adversarial Phenomenon in the Eyes of Bayesian Deep Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"stat.ML","authors_text":"Ambrish Rawat, Maria-Irina Nicolae, Martin Wistuba","submitted_at":"2017-11-22T12:02:53Z","abstract_excerpt":"Deep Learning models are vulnerable to adversarial examples, i.e.\\ images obtained via deliberate imperceptible perturbations, such that the model misclassifies them with high confidence. However, class confidence by itself is an incomplete picture of uncertainty. We therefore use principled Bayesian methods to capture model uncertainty in prediction for observing adversarial misclassification. We provide an extensive study with different Bayesian neural networks attacked in both white-box and black-box setups. The behaviour of the networks for noise, attacks and clean test data is compared. W"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1711.08244","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:29:50Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"q0JGlIRhFsJ/6fUp23MFuezk6AAv7Sy2AQMwwDyANrV3Tx6115+p0vRDT/9yhI+qvtesB4sEva2enwoqWUqaBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T04:33:00.849763Z"},"content_sha256":"bff15709b2d34e52fb4ad16a2138ac49b0208c66360f873e251618bdb2eeba5b","schema_version":"1.0","event_id":"sha256:bff15709b2d34e52fb4ad16a2138ac49b0208c66360f873e251618bdb2eeba5b"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/Q3F5D6KVTORLTNQEVV22VXA5NV/bundle.json","state_url":"https://pith.science/pith/Q3F5D6KVTORLTNQEVV22VXA5NV/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/Q3F5D6KVTORLTNQEVV22VXA5NV/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-28T04:33:00Z","links":{"resolver":"https://pith.science/pith/Q3F5D6KVTORLTNQEVV22VXA5NV","bundle":"https://pith.science/pith/Q3F5D6KVTORLTNQEVV22VXA5NV/bundle.json","state":"https://pith.science/pith/Q3F5D6KVTORLTNQEVV22VXA5NV/state.json","well_known_bundle":"https://pith.science/.well-known/pith/Q3F5D6KVTORLTNQEVV22VXA5NV/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:Q3F5D6KVTORLTNQEVV22VXA5NV","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"25a7a3b356878eb633590dc936978cf35ac2a0ce66014abeda36b6003b5f535f","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-11-22T12:02:53Z","title_canon_sha256":"a5fac8414d9dfc94979826c126306f5f1fc89c49f677df81e6f618443d830a48"},"schema_version":"1.0","source":{"id":"1711.08244","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1711.08244","created_at":"2026-05-18T00:29:50Z"},{"alias_kind":"arxiv_version","alias_value":"1711.08244v1","created_at":"2026-05-18T00:29:50Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1711.08244","created_at":"2026-05-18T00:29:50Z"},{"alias_kind":"pith_short_12","alias_value":"Q3F5D6KVTORL","created_at":"2026-05-18T12:31:37Z"},{"alias_kind":"pith_short_16","alias_value":"Q3F5D6KVTORLTNQE","created_at":"2026-05-18T12:31:37Z"},{"alias_kind":"pith_short_8","alias_value":"Q3F5D6KV","created_at":"2026-05-18T12:31:37Z"}],"graph_snapshots":[{"event_id":"sha256:bff15709b2d34e52fb4ad16a2138ac49b0208c66360f873e251618bdb2eeba5b","target":"graph","created_at":"2026-05-18T00:29:50Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep Learning models are vulnerable to adversarial examples, i.e.\\ images obtained via deliberate imperceptible perturbations, such that the model misclassifies them with high confidence. However, class confidence by itself is an incomplete picture of uncertainty. We therefore use principled Bayesian methods to capture model uncertainty in prediction for observing adversarial misclassification. We provide an extensive study with different Bayesian neural networks attacked in both white-box and black-box setups. The behaviour of the networks for noise, attacks and clean test data is compared. W","authors_text":"Ambrish Rawat, Maria-Irina Nicolae, Martin Wistuba","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-11-22T12:02:53Z","title":"Adversarial Phenomenon in the Eyes of Bayesian Deep Learning"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1711.08244","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:89b4654703c280586fe4d1d917c5844dfa27836082e2e18e6f32d14d775797f0","target":"record","created_at":"2026-05-18T00:29:50Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"25a7a3b356878eb633590dc936978cf35ac2a0ce66014abeda36b6003b5f535f","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-11-22T12:02:53Z","title_canon_sha256":"a5fac8414d9dfc94979826c126306f5f1fc89c49f677df81e6f618443d830a48"},"schema_version":"1.0","source":{"id":"1711.08244","kind":"arxiv","version":1}},"canonical_sha256":"86cbd1f9559ba2b9b604ad75aadc1d6d45b836c46367297b9007ae8c3b3962db","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"86cbd1f9559ba2b9b604ad75aadc1d6d45b836c46367297b9007ae8c3b3962db","first_computed_at":"2026-05-18T00:29:50.305975Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:29:50.305975Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"LYhfbCdm2xVXne35sGpupOYc/BAuMvgQAFBN66Kzc0iKyDOnlObRM+4U6thjqX5C/I85jIqNm0J2XdZKPC8AAQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:29:50.306490Z","signed_message":"canonical_sha256_bytes"},"source_id":"1711.08244","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:89b4654703c280586fe4d1d917c5844dfa27836082e2e18e6f32d14d775797f0","sha256:bff15709b2d34e52fb4ad16a2138ac49b0208c66360f873e251618bdb2eeba5b"],"state_sha256":"2bbb35b89720dc625ab3471d5d52cc3b0af9f220be071081217184183ccb24cb"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"CbX4aVm+W45ZkYOd9cZdOHM+0SmdN/+V3Z2VOXKhynzMjs8CvBFQnHg3W9ZWylfbRxqQTFO9++2gs7QvW/gSBQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-28T04:33:00.852152Z","bundle_sha256":"a9c022d1790f60ca66d3bda5655ca3551a36d6f2f30c2e57e47122ddf0aca59f"}}