{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:Q4MXKWTT422WJYR6FRE57VHU74","short_pith_number":"pith:Q4MXKWTT","canonical_record":{"source":{"id":"1807.07769","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-07-20T10:14:27Z","cross_cats_sorted":["cs.CV","cs.LG"],"title_canon_sha256":"e70e0f5dccae4724735d652f0ffe537119c39c3c4b1e7998ba4ee9af97acef5d","abstract_canon_sha256":"7100f1aacde97f2a1408c377e8a59d366df40bc186c232ee99bc243832e2d11b"},"schema_version":"1.0"},"canonical_sha256":"8719755a73e6b564e23e2c49dfd4f4ff03ebbcd554640cfbc3697762cfc5d05e","source":{"kind":"arxiv","id":"1807.07769","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1807.07769","created_at":"2026-05-18T00:04:00Z"},{"alias_kind":"arxiv_version","alias_value":"1807.07769v2","created_at":"2026-05-18T00:04:00Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1807.07769","created_at":"2026-05-18T00:04:00Z"},{"alias_kind":"pith_short_12","alias_value":"Q4MXKWTT422W","created_at":"2026-05-18T12:32:46Z"},{"alias_kind":"pith_short_16","alias_value":"Q4MXKWTT422WJYR6","created_at":"2026-05-18T12:32:46Z"},{"alias_kind":"pith_short_8","alias_value":"Q4MXKWTT","created_at":"2026-05-18T12:32:46Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:Q4MXKWTT422WJYR6FRE57VHU74","target":"record","payload":{"canonical_record":{"source":{"id":"1807.07769","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-07-20T10:14:27Z","cross_cats_sorted":["cs.CV","cs.LG"],"title_canon_sha256":"e70e0f5dccae4724735d652f0ffe537119c39c3c4b1e7998ba4ee9af97acef5d","abstract_canon_sha256":"7100f1aacde97f2a1408c377e8a59d366df40bc186c232ee99bc243832e2d11b"},"schema_version":"1.0"},"canonical_sha256":"8719755a73e6b564e23e2c49dfd4f4ff03ebbcd554640cfbc3697762cfc5d05e","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:04:00.323795Z","signature_b64":"cREnA9UrpzCChz6UAGH0Lu6k7DUw3GiNGPZ0BbrNPVflFSJpHk2RIjW3zBUM9P24dsInr0qhwWWiWWdvSXFWAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"8719755a73e6b564e23e2c49dfd4f4ff03ebbcd554640cfbc3697762cfc5d05e","last_reissued_at":"2026-05-18T00:04:00.323253Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:04:00.323253Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1807.07769","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:04:00Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"euvNmczsx1NIlWDCB4r9k56qWzls//uqyW7fnbG6tCheYLMIlPGxVXYntUYAtqYeTDQHH8Y4mchQ/DKBABIJDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T13:24:51.990460Z"},"content_sha256":"f9eacb2212945d4ca4828f64bdb83fe3dce2b640868f48ae22dd981d0d3733d2","schema_version":"1.0","event_id":"sha256:f9eacb2212945d4ca4828f64bdb83fe3dce2b640868f48ae22dd981d0d3733d2"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:Q4MXKWTT422WJYR6FRE57VHU74","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Physical Adversarial Examples for Object Detectors","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","cs.LG"],"primary_cat":"cs.CR","authors_text":"Amir Rahmati, Atul Prakash, Bo Li, Dawn Song, Earlence Fernandes, Florian Tramer, Ivan Evtimov, Kevin Eykholt, Tadayoshi Kohno","submitted_at":"2018-07-20T10:14:27Z","abstract_excerpt":"Deep neural networks (DNNs) are vulnerable to adversarial examples-maliciously crafted inputs that cause DNNs to make incorrect predictions. Recent work has shown that these attacks generalize to the physical domain, to create perturbations on physical objects that fool image classifiers under a variety of real-world conditions. Such attacks pose a risk to deep learning models used in safety-critical cyber-physical systems. In this work, we extend physical attacks to more challenging object detection models, a broader class of deep learning algorithms widely used to detect and label multiple o"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1807.07769","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:04:00Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"LQGq6lGxtrr9e/AdcwVw3z8P+Lk7J/8syug5EE6f0cKD7sBbJoCq/Ce01j/zzTUEY0aCd2SoBD8bI3FwtQ7vAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T13:24:51.991140Z"},"content_sha256":"d23a93648c358ca06817519151cebab31f220dcab43294f07dd9291ad640426d","schema_version":"1.0","event_id":"sha256:d23a93648c358ca06817519151cebab31f220dcab43294f07dd9291ad640426d"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/Q4MXKWTT422WJYR6FRE57VHU74/bundle.json","state_url":"https://pith.science/pith/Q4MXKWTT422WJYR6FRE57VHU74/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/Q4MXKWTT422WJYR6FRE57VHU74/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T13:24:51Z","links":{"resolver":"https://pith.science/pith/Q4MXKWTT422WJYR6FRE57VHU74","bundle":"https://pith.science/pith/Q4MXKWTT422WJYR6FRE57VHU74/bundle.json","state":"https://pith.science/pith/Q4MXKWTT422WJYR6FRE57VHU74/state.json","well_known_bundle":"https://pith.science/.well-known/pith/Q4MXKWTT422WJYR6FRE57VHU74/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:Q4MXKWTT422WJYR6FRE57VHU74","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"7100f1aacde97f2a1408c377e8a59d366df40bc186c232ee99bc243832e2d11b","cross_cats_sorted":["cs.CV","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-07-20T10:14:27Z","title_canon_sha256":"e70e0f5dccae4724735d652f0ffe537119c39c3c4b1e7998ba4ee9af97acef5d"},"schema_version":"1.0","source":{"id":"1807.07769","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1807.07769","created_at":"2026-05-18T00:04:00Z"},{"alias_kind":"arxiv_version","alias_value":"1807.07769v2","created_at":"2026-05-18T00:04:00Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1807.07769","created_at":"2026-05-18T00:04:00Z"},{"alias_kind":"pith_short_12","alias_value":"Q4MXKWTT422W","created_at":"2026-05-18T12:32:46Z"},{"alias_kind":"pith_short_16","alias_value":"Q4MXKWTT422WJYR6","created_at":"2026-05-18T12:32:46Z"},{"alias_kind":"pith_short_8","alias_value":"Q4MXKWTT","created_at":"2026-05-18T12:32:46Z"}],"graph_snapshots":[{"event_id":"sha256:d23a93648c358ca06817519151cebab31f220dcab43294f07dd9291ad640426d","target":"graph","created_at":"2026-05-18T00:04:00Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep neural networks (DNNs) are vulnerable to adversarial examples-maliciously crafted inputs that cause DNNs to make incorrect predictions. Recent work has shown that these attacks generalize to the physical domain, to create perturbations on physical objects that fool image classifiers under a variety of real-world conditions. Such attacks pose a risk to deep learning models used in safety-critical cyber-physical systems. In this work, we extend physical attacks to more challenging object detection models, a broader class of deep learning algorithms widely used to detect and label multiple o","authors_text":"Amir Rahmati, Atul Prakash, Bo Li, Dawn Song, Earlence Fernandes, Florian Tramer, Ivan Evtimov, Kevin Eykholt, Tadayoshi Kohno","cross_cats":["cs.CV","cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-07-20T10:14:27Z","title":"Physical Adversarial Examples for Object Detectors"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1807.07769","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:f9eacb2212945d4ca4828f64bdb83fe3dce2b640868f48ae22dd981d0d3733d2","target":"record","created_at":"2026-05-18T00:04:00Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"7100f1aacde97f2a1408c377e8a59d366df40bc186c232ee99bc243832e2d11b","cross_cats_sorted":["cs.CV","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-07-20T10:14:27Z","title_canon_sha256":"e70e0f5dccae4724735d652f0ffe537119c39c3c4b1e7998ba4ee9af97acef5d"},"schema_version":"1.0","source":{"id":"1807.07769","kind":"arxiv","version":2}},"canonical_sha256":"8719755a73e6b564e23e2c49dfd4f4ff03ebbcd554640cfbc3697762cfc5d05e","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"8719755a73e6b564e23e2c49dfd4f4ff03ebbcd554640cfbc3697762cfc5d05e","first_computed_at":"2026-05-18T00:04:00.323253Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:04:00.323253Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"cREnA9UrpzCChz6UAGH0Lu6k7DUw3GiNGPZ0BbrNPVflFSJpHk2RIjW3zBUM9P24dsInr0qhwWWiWWdvSXFWAA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:04:00.323795Z","signed_message":"canonical_sha256_bytes"},"source_id":"1807.07769","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:f9eacb2212945d4ca4828f64bdb83fe3dce2b640868f48ae22dd981d0d3733d2","sha256:d23a93648c358ca06817519151cebab31f220dcab43294f07dd9291ad640426d"],"state_sha256":"538bea2e2f4e7395b06f8c7ce5411604af68391a715cfa7b06d6fc732e4db68b"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"hgQvipXdtyCy2qYCti/lEqDkVE7JzCgC90yYfhZiyDIJzz1etXHaqrl5bcPAgPrsr/dCb50gxNoSHPt3WlpcBg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T13:24:51.994194Z","bundle_sha256":"ddcad0acf45b749070d2a187b8cdb0f1a50ee8a459768d86d5d177122b1bc24a"}}