{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:QDOSHUILLOHBKCQNXY6Q7RJK7A","short_pith_number":"pith:QDOSHUIL","canonical_record":{"source":{"id":"1903.01612","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-03-05T00:53:56Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"0d2092b84042be99c0b3a024b22820e40f9a7e494a636546968c5fd070406fd5","abstract_canon_sha256":"5753991f5d9d729e86c8a8f5332acc415c4375721a3badc2d13c64dbf5bd8e4e"},"schema_version":"1.0"},"canonical_sha256":"80dd23d10b5b8e150a0dbe3d0fc52af82d76e82079179fad7b5d86eda074df3c","source":{"kind":"arxiv","id":"1903.01612","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1903.01612","created_at":"2026-05-17T23:47:01Z"},{"alias_kind":"arxiv_version","alias_value":"1903.01612v2","created_at":"2026-05-17T23:47:01Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1903.01612","created_at":"2026-05-17T23:47:01Z"},{"alias_kind":"pith_short_12","alias_value":"QDOSHUILLOHB","created_at":"2026-05-18T12:33:27Z"},{"alias_kind":"pith_short_16","alias_value":"QDOSHUILLOHBKCQN","created_at":"2026-05-18T12:33:27Z"},{"alias_kind":"pith_short_8","alias_value":"QDOSHUIL","created_at":"2026-05-18T12:33:27Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:QDOSHUILLOHBKCQNXY6Q7RJK7A","target":"record","payload":{"canonical_record":{"source":{"id":"1903.01612","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-03-05T00:53:56Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"0d2092b84042be99c0b3a024b22820e40f9a7e494a636546968c5fd070406fd5","abstract_canon_sha256":"5753991f5d9d729e86c8a8f5332acc415c4375721a3badc2d13c64dbf5bd8e4e"},"schema_version":"1.0"},"canonical_sha256":"80dd23d10b5b8e150a0dbe3d0fc52af82d76e82079179fad7b5d86eda074df3c","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:47:01.711044Z","signature_b64":"KKbgT+rAM3/PlBSuXVfwwNOCZMX+fvbNCZ/Ko2xu+teLtys0H/utGhVYV/qzhmoARgnYulfBN/tOlztnYTLJBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"80dd23d10b5b8e150a0dbe3d0fc52af82d76e82079179fad7b5d86eda074df3c","last_reissued_at":"2026-05-17T23:47:01.710276Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:47:01.710276Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1903.01612","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:47:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Y8bcClRuerOQVTEthCkP47XstW1IUh+ArhqyBNUE+mEH6jz5g1imBDcHTh+eMeC16PhpRXhxrKC987Z6AlojDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T06:58:47.333086Z"},"content_sha256":"bf8460c479dcdf7cf8b2762943d81306b99c3f7b72bcc9f1c2b0877563955414","schema_version":"1.0","event_id":"sha256:bf8460c479dcdf7cf8b2762943d81306b99c3f7b72bcc9f1c2b0877563955414"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:QDOSHUILLOHBKCQNXY6Q7RJK7A","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Defense Against Adversarial Images using Web-Scale Nearest-Neighbor Search","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CV","authors_text":"Abhimanyu Dubey, Dhruv Mahajan, Laurens van der Maaten, Yixuan Li, Zeki Yalniz","submitted_at":"2019-03-05T00:53:56Z","abstract_excerpt":"A plethora of recent work has shown that convolutional networks are not robust to adversarial images: images that are created by perturbing a sample from the data distribution as to maximize the loss on the perturbed example. In this work, we hypothesize that adversarial perturbations move the image away from the image manifold in the sense that there exists no physical process that could have produced the adversarial image. This hypothesis suggests that a successful defense mechanism against adversarial images should aim to project the images back onto the image manifold. We study such defens"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1903.01612","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:47:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"DLoNZfP0m5NdtO3TfzaXix9N/sTM838PUnR8k9IIuiGhnsiXsSZZ6emqG1IZB2kSTvCRMgAr850AzDZRETILAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T06:58:47.333447Z"},"content_sha256":"ff73d0b4486421094c8dc4cd1dd13e8f77977045e12afa66f2d0d2875e3a7cb2","schema_version":"1.0","event_id":"sha256:ff73d0b4486421094c8dc4cd1dd13e8f77977045e12afa66f2d0d2875e3a7cb2"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/QDOSHUILLOHBKCQNXY6Q7RJK7A/bundle.json","state_url":"https://pith.science/pith/QDOSHUILLOHBKCQNXY6Q7RJK7A/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/QDOSHUILLOHBKCQNXY6Q7RJK7A/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-01T06:58:47Z","links":{"resolver":"https://pith.science/pith/QDOSHUILLOHBKCQNXY6Q7RJK7A","bundle":"https://pith.science/pith/QDOSHUILLOHBKCQNXY6Q7RJK7A/bundle.json","state":"https://pith.science/pith/QDOSHUILLOHBKCQNXY6Q7RJK7A/state.json","well_known_bundle":"https://pith.science/.well-known/pith/QDOSHUILLOHBKCQNXY6Q7RJK7A/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:QDOSHUILLOHBKCQNXY6Q7RJK7A","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"5753991f5d9d729e86c8a8f5332acc415c4375721a3badc2d13c64dbf5bd8e4e","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-03-05T00:53:56Z","title_canon_sha256":"0d2092b84042be99c0b3a024b22820e40f9a7e494a636546968c5fd070406fd5"},"schema_version":"1.0","source":{"id":"1903.01612","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1903.01612","created_at":"2026-05-17T23:47:01Z"},{"alias_kind":"arxiv_version","alias_value":"1903.01612v2","created_at":"2026-05-17T23:47:01Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1903.01612","created_at":"2026-05-17T23:47:01Z"},{"alias_kind":"pith_short_12","alias_value":"QDOSHUILLOHB","created_at":"2026-05-18T12:33:27Z"},{"alias_kind":"pith_short_16","alias_value":"QDOSHUILLOHBKCQN","created_at":"2026-05-18T12:33:27Z"},{"alias_kind":"pith_short_8","alias_value":"QDOSHUIL","created_at":"2026-05-18T12:33:27Z"}],"graph_snapshots":[{"event_id":"sha256:ff73d0b4486421094c8dc4cd1dd13e8f77977045e12afa66f2d0d2875e3a7cb2","target":"graph","created_at":"2026-05-17T23:47:01Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"A plethora of recent work has shown that convolutional networks are not robust to adversarial images: images that are created by perturbing a sample from the data distribution as to maximize the loss on the perturbed example. In this work, we hypothesize that adversarial perturbations move the image away from the image manifold in the sense that there exists no physical process that could have produced the adversarial image. This hypothesis suggests that a successful defense mechanism against adversarial images should aim to project the images back onto the image manifold. We study such defens","authors_text":"Abhimanyu Dubey, Dhruv Mahajan, Laurens van der Maaten, Yixuan Li, Zeki Yalniz","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-03-05T00:53:56Z","title":"Defense Against Adversarial Images using Web-Scale Nearest-Neighbor Search"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1903.01612","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:bf8460c479dcdf7cf8b2762943d81306b99c3f7b72bcc9f1c2b0877563955414","target":"record","created_at":"2026-05-17T23:47:01Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"5753991f5d9d729e86c8a8f5332acc415c4375721a3badc2d13c64dbf5bd8e4e","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-03-05T00:53:56Z","title_canon_sha256":"0d2092b84042be99c0b3a024b22820e40f9a7e494a636546968c5fd070406fd5"},"schema_version":"1.0","source":{"id":"1903.01612","kind":"arxiv","version":2}},"canonical_sha256":"80dd23d10b5b8e150a0dbe3d0fc52af82d76e82079179fad7b5d86eda074df3c","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"80dd23d10b5b8e150a0dbe3d0fc52af82d76e82079179fad7b5d86eda074df3c","first_computed_at":"2026-05-17T23:47:01.710276Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:47:01.710276Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"KKbgT+rAM3/PlBSuXVfwwNOCZMX+fvbNCZ/Ko2xu+teLtys0H/utGhVYV/qzhmoARgnYulfBN/tOlztnYTLJBg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:47:01.711044Z","signed_message":"canonical_sha256_bytes"},"source_id":"1903.01612","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:bf8460c479dcdf7cf8b2762943d81306b99c3f7b72bcc9f1c2b0877563955414","sha256:ff73d0b4486421094c8dc4cd1dd13e8f77977045e12afa66f2d0d2875e3a7cb2"],"state_sha256":"e3412762b0908f6f4fbbe940413d2df88c23ab85fd0d5a721373c016fc4311b4"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"SlZDC54dYt+OnwDz4oi6VnJ2+K+JZ8FuM44V+oKzVJ9p1EX0k9BmA/n7Sg6WlSOeVJYVHiu+Ia6Fmk98DywzAw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-01T06:58:47.335416Z","bundle_sha256":"eb6800f087ddb48bce1bd15170edf4a116e5cd15a3e7a30787d52f3b67c619e6"}}