{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:QDOSHUILLOHBKCQNXY6Q7RJK7A","short_pith_number":"pith:QDOSHUIL","schema_version":"1.0","canonical_sha256":"80dd23d10b5b8e150a0dbe3d0fc52af82d76e82079179fad7b5d86eda074df3c","source":{"kind":"arxiv","id":"1903.01612","version":2},"attestation_state":"computed","paper":{"title":"Defense Against Adversarial Images using Web-Scale Nearest-Neighbor Search","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CV","authors_text":"Abhimanyu Dubey, Dhruv Mahajan, Laurens van der Maaten, Yixuan Li, Zeki Yalniz","submitted_at":"2019-03-05T00:53:56Z","abstract_excerpt":"A plethora of recent work has shown that convolutional networks are not robust to adversarial images: images that are created by perturbing a sample from the data distribution as to maximize the loss on the perturbed example. In this work, we hypothesize that adversarial perturbations move the image away from the image manifold in the sense that there exists no physical process that could have produced the adversarial image. This hypothesis suggests that a successful defense mechanism against adversarial images should aim to project the images back onto the image manifold. We study such defens"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1903.01612","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-03-05T00:53:56Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"0d2092b84042be99c0b3a024b22820e40f9a7e494a636546968c5fd070406fd5","abstract_canon_sha256":"5753991f5d9d729e86c8a8f5332acc415c4375721a3badc2d13c64dbf5bd8e4e"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:47:01.711044Z","signature_b64":"KKbgT+rAM3/PlBSuXVfwwNOCZMX+fvbNCZ/Ko2xu+teLtys0H/utGhVYV/qzhmoARgnYulfBN/tOlztnYTLJBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"80dd23d10b5b8e150a0dbe3d0fc52af82d76e82079179fad7b5d86eda074df3c","last_reissued_at":"2026-05-17T23:47:01.710276Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:47:01.710276Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Defense Against Adversarial Images using Web-Scale Nearest-Neighbor Search","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CV","authors_text":"Abhimanyu Dubey, Dhruv Mahajan, Laurens van der Maaten, Yixuan Li, Zeki Yalniz","submitted_at":"2019-03-05T00:53:56Z","abstract_excerpt":"A plethora of recent work has shown that convolutional networks are not robust to adversarial images: images that are created by perturbing a sample from the data distribution as to maximize the loss on the perturbed example. In this work, we hypothesize that adversarial perturbations move the image away from the image manifold in the sense that there exists no physical process that could have produced the adversarial image. This hypothesis suggests that a successful defense mechanism against adversarial images should aim to project the images back onto the image manifold. We study such defens"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1903.01612","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1903.01612","created_at":"2026-05-17T23:47:01.710427+00:00"},{"alias_kind":"arxiv_version","alias_value":"1903.01612v2","created_at":"2026-05-17T23:47:01.710427+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1903.01612","created_at":"2026-05-17T23:47:01.710427+00:00"},{"alias_kind":"pith_short_12","alias_value":"QDOSHUILLOHB","created_at":"2026-05-18T12:33:27.125529+00:00"},{"alias_kind":"pith_short_16","alias_value":"QDOSHUILLOHBKCQN","created_at":"2026-05-18T12:33:27.125529+00:00"},{"alias_kind":"pith_short_8","alias_value":"QDOSHUIL","created_at":"2026-05-18T12:33:27.125529+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/QDOSHUILLOHBKCQNXY6Q7RJK7A","json":"https://pith.science/pith/QDOSHUILLOHBKCQNXY6Q7RJK7A.json","graph_json":"https://pith.science/api/pith-number/QDOSHUILLOHBKCQNXY6Q7RJK7A/graph.json","events_json":"https://pith.science/api/pith-number/QDOSHUILLOHBKCQNXY6Q7RJK7A/events.json","paper":"https://pith.science/paper/QDOSHUIL"},"agent_actions":{"view_html":"https://pith.science/pith/QDOSHUILLOHBKCQNXY6Q7RJK7A","download_json":"https://pith.science/pith/QDOSHUILLOHBKCQNXY6Q7RJK7A.json","view_paper":"https://pith.science/paper/QDOSHUIL","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1903.01612&json=true","fetch_graph":"https://pith.science/api/pith-number/QDOSHUILLOHBKCQNXY6Q7RJK7A/graph.json","fetch_events":"https://pith.science/api/pith-number/QDOSHUILLOHBKCQNXY6Q7RJK7A/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/QDOSHUILLOHBKCQNXY6Q7RJK7A/action/timestamp_anchor","attest_storage":"https://pith.science/pith/QDOSHUILLOHBKCQNXY6Q7RJK7A/action/storage_attestation","attest_author":"https://pith.science/pith/QDOSHUILLOHBKCQNXY6Q7RJK7A/action/author_attestation","sign_citation":"https://pith.science/pith/QDOSHUILLOHBKCQNXY6Q7RJK7A/action/citation_signature","submit_replication":"https://pith.science/pith/QDOSHUILLOHBKCQNXY6Q7RJK7A/action/replication_record"}},"created_at":"2026-05-17T23:47:01.710427+00:00","updated_at":"2026-05-17T23:47:01.710427+00:00"}