{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:QI4FIHKPKYQIKWG4ZEUYH7BGOC","short_pith_number":"pith:QI4FIHKP","canonical_record":{"source":{"id":"1705.09064","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-05-25T06:49:57Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"b36851f7851da0219f049248b4cec057394baee9bb74dc1067490a78efc96f5d","abstract_canon_sha256":"c8b97909fb61db0086656628d3cfb76c3baeb499d80ee237c575c78b02c10e2a"},"schema_version":"1.0"},"canonical_sha256":"8238541d4f56208558dcc92983fc2670916719d2d10c7eae8d01c1a9423b3192","source":{"kind":"arxiv","id":"1705.09064","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1705.09064","created_at":"2026-05-18T00:35:41Z"},{"alias_kind":"arxiv_version","alias_value":"1705.09064v2","created_at":"2026-05-18T00:35:41Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1705.09064","created_at":"2026-05-18T00:35:41Z"},{"alias_kind":"pith_short_12","alias_value":"QI4FIHKPKYQI","created_at":"2026-05-18T12:31:39Z"},{"alias_kind":"pith_short_16","alias_value":"QI4FIHKPKYQIKWG4","created_at":"2026-05-18T12:31:39Z"},{"alias_kind":"pith_short_8","alias_value":"QI4FIHKP","created_at":"2026-05-18T12:31:39Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:QI4FIHKPKYQIKWG4ZEUYH7BGOC","target":"record","payload":{"canonical_record":{"source":{"id":"1705.09064","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-05-25T06:49:57Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"b36851f7851da0219f049248b4cec057394baee9bb74dc1067490a78efc96f5d","abstract_canon_sha256":"c8b97909fb61db0086656628d3cfb76c3baeb499d80ee237c575c78b02c10e2a"},"schema_version":"1.0"},"canonical_sha256":"8238541d4f56208558dcc92983fc2670916719d2d10c7eae8d01c1a9423b3192","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:35:41.230531Z","signature_b64":"wsBAildKi0cqQ3DVsQ0vcHZ86aDQCTIDwPd3Yfh5+oQjd3fZbDCbhKFn9Y3uomeT2bH7xycdyxylhTNwwwuYBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"8238541d4f56208558dcc92983fc2670916719d2d10c7eae8d01c1a9423b3192","last_reissued_at":"2026-05-18T00:35:41.229925Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:35:41.229925Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1705.09064","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:35:41Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"PmiASc2w9WQ9arya/K4+0r8OqVBM97d19f2f7LYABeHwM8Nyhz1qkEmbdcXusDhgN+k3QGrtjtsuASSElxmhDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-06T23:07:05.838934Z"},"content_sha256":"60fa1996c9addf9bbbe80b745198fc75b0dd2d26f069d3d201427a417ba9ed9d","schema_version":"1.0","event_id":"sha256:60fa1996c9addf9bbbe80b745198fc75b0dd2d26f069d3d201427a417ba9ed9d"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:QI4FIHKPKYQIKWG4ZEUYH7BGOC","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"MagNet: a Two-Pronged Defense against Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Dongyu Meng, Hao Chen","submitted_at":"2017-05-25T06:49:57Z","abstract_excerpt":"Deep learning has shown promising results on hard perceptual problems in recent years. However, deep learning systems are found to be vulnerable to small adversarial perturbations that are nearly imperceptible to human. Such specially crafted perturbations cause deep learning systems to output incorrect decisions, with potentially disastrous consequences. These vulnerabilities hinder the deployment of deep learning systems where safety or security is important. Attempts to secure deep learning systems either target specific attacks or have been shown to be ineffective.\n  In this paper, we prop"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1705.09064","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:35:41Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"jdzyl4Lw6GwyZksgKZe2oGGuxm+BcEAD03cqsD5+TFvzVorRoSMHMHp7rG/MWKBrsc96paNDVmB/EI8ZC3xyCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-06T23:07:05.839663Z"},"content_sha256":"8f2cfc8475025a31503cc9a1d1341d9e5c8161a24cb5d9278491d75cfe1f4b5d","schema_version":"1.0","event_id":"sha256:8f2cfc8475025a31503cc9a1d1341d9e5c8161a24cb5d9278491d75cfe1f4b5d"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/QI4FIHKPKYQIKWG4ZEUYH7BGOC/bundle.json","state_url":"https://pith.science/pith/QI4FIHKPKYQIKWG4ZEUYH7BGOC/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/QI4FIHKPKYQIKWG4ZEUYH7BGOC/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-06T23:07:05Z","links":{"resolver":"https://pith.science/pith/QI4FIHKPKYQIKWG4ZEUYH7BGOC","bundle":"https://pith.science/pith/QI4FIHKPKYQIKWG4ZEUYH7BGOC/bundle.json","state":"https://pith.science/pith/QI4FIHKPKYQIKWG4ZEUYH7BGOC/state.json","well_known_bundle":"https://pith.science/.well-known/pith/QI4FIHKPKYQIKWG4ZEUYH7BGOC/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:QI4FIHKPKYQIKWG4ZEUYH7BGOC","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"c8b97909fb61db0086656628d3cfb76c3baeb499d80ee237c575c78b02c10e2a","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-05-25T06:49:57Z","title_canon_sha256":"b36851f7851da0219f049248b4cec057394baee9bb74dc1067490a78efc96f5d"},"schema_version":"1.0","source":{"id":"1705.09064","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1705.09064","created_at":"2026-05-18T00:35:41Z"},{"alias_kind":"arxiv_version","alias_value":"1705.09064v2","created_at":"2026-05-18T00:35:41Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1705.09064","created_at":"2026-05-18T00:35:41Z"},{"alias_kind":"pith_short_12","alias_value":"QI4FIHKPKYQI","created_at":"2026-05-18T12:31:39Z"},{"alias_kind":"pith_short_16","alias_value":"QI4FIHKPKYQIKWG4","created_at":"2026-05-18T12:31:39Z"},{"alias_kind":"pith_short_8","alias_value":"QI4FIHKP","created_at":"2026-05-18T12:31:39Z"}],"graph_snapshots":[{"event_id":"sha256:8f2cfc8475025a31503cc9a1d1341d9e5c8161a24cb5d9278491d75cfe1f4b5d","target":"graph","created_at":"2026-05-18T00:35:41Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep learning has shown promising results on hard perceptual problems in recent years. However, deep learning systems are found to be vulnerable to small adversarial perturbations that are nearly imperceptible to human. Such specially crafted perturbations cause deep learning systems to output incorrect decisions, with potentially disastrous consequences. These vulnerabilities hinder the deployment of deep learning systems where safety or security is important. Attempts to secure deep learning systems either target specific attacks or have been shown to be ineffective.\n  In this paper, we prop","authors_text":"Dongyu Meng, Hao Chen","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-05-25T06:49:57Z","title":"MagNet: a Two-Pronged Defense against Adversarial Examples"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1705.09064","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:60fa1996c9addf9bbbe80b745198fc75b0dd2d26f069d3d201427a417ba9ed9d","target":"record","created_at":"2026-05-18T00:35:41Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"c8b97909fb61db0086656628d3cfb76c3baeb499d80ee237c575c78b02c10e2a","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-05-25T06:49:57Z","title_canon_sha256":"b36851f7851da0219f049248b4cec057394baee9bb74dc1067490a78efc96f5d"},"schema_version":"1.0","source":{"id":"1705.09064","kind":"arxiv","version":2}},"canonical_sha256":"8238541d4f56208558dcc92983fc2670916719d2d10c7eae8d01c1a9423b3192","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"8238541d4f56208558dcc92983fc2670916719d2d10c7eae8d01c1a9423b3192","first_computed_at":"2026-05-18T00:35:41.229925Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:35:41.229925Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"wsBAildKi0cqQ3DVsQ0vcHZ86aDQCTIDwPd3Yfh5+oQjd3fZbDCbhKFn9Y3uomeT2bH7xycdyxylhTNwwwuYBQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:35:41.230531Z","signed_message":"canonical_sha256_bytes"},"source_id":"1705.09064","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:60fa1996c9addf9bbbe80b745198fc75b0dd2d26f069d3d201427a417ba9ed9d","sha256:8f2cfc8475025a31503cc9a1d1341d9e5c8161a24cb5d9278491d75cfe1f4b5d"],"state_sha256":"136350f966b526776fb79a6e1900c79e15a3b75c4c0c2e7a7f2ff283c4acdec2"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"QQjYBq0WCA+dfoKmu0jrUJTlm90SxzJFV3NIrk/Wht8inp+jwCnE2jwEhWA43FQsjdMUblAyCFO6kQ4+fNK5DA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-06T23:07:05.843687Z","bundle_sha256":"ae2ccecbe8cefe3a80131caa666f9dfc64a1e99a3e6645a9f6cabca834651f0b"}}