{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:QIEUZMGEDZAIVXVLNP54DGHKQ2","short_pith_number":"pith:QIEUZMGE","schema_version":"1.0","canonical_sha256":"82094cb0c41e408adeab6bfbc198ea868d955ff6a5f6b5333f6080e280e4c1ba","source":{"kind":"arxiv","id":"2402.15152","version":2},"attestation_state":"computed","paper":{"title":"On the Duality Between Sharpness-Aware Minimization and Adversarial Training","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CR","math.OC"],"primary_cat":"cs.LG","authors_text":"Hangzhou He, Huanran Chen, Jingyu Zhu, Yifei Wang, Yihao Zhang, Zeming Wei","submitted_at":"2024-02-23T07:22:55Z","abstract_excerpt":"Adversarial Training (AT), which adversarially perturb the input samples during training, has been acknowledged as one of the most effective defenses against adversarial attacks, yet suffers from inevitably decreased clean accuracy. Instead of perturbing the samples, Sharpness-Aware Minimization (SAM) perturbs the model weights during training to find a more flat loss landscape and improve generalization. However, as SAM is designed for better clean accuracy, its effectiveness in enhancing adversarial robustness remains unexplored. In this work, considering the duality between SAM and AT, we i"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2402.15152","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2024-02-23T07:22:55Z","cross_cats_sorted":["cs.AI","cs.CR","math.OC"],"title_canon_sha256":"8b79295380e4fd3d8595afae1eedd01c2a317194eaaa8e7cf91c1f0138ef6cff","abstract_canon_sha256":"141d586174092646444d6221058acd3511416ad838eb2523b817fa5f9399ce40"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:27:46.609680Z","signature_b64":"yeY+hpDe4GS8Ceg7KOq/tgUXQVaYFt8zWOwbrfsWjh4Bpgxt8H98PtWL6Qf8b9YgBVdooATFYou+B7Xs4UslCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"82094cb0c41e408adeab6bfbc198ea868d955ff6a5f6b5333f6080e280e4c1ba","last_reissued_at":"2026-07-05T08:27:46.609117Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:27:46.609117Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"On the Duality Between Sharpness-Aware Minimization and Adversarial Training","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CR","math.OC"],"primary_cat":"cs.LG","authors_text":"Hangzhou He, Huanran Chen, Jingyu Zhu, Yifei Wang, Yihao Zhang, Zeming Wei","submitted_at":"2024-02-23T07:22:55Z","abstract_excerpt":"Adversarial Training (AT), which adversarially perturb the input samples during training, has been acknowledged as one of the most effective defenses against adversarial attacks, yet suffers from inevitably decreased clean accuracy. Instead of perturbing the samples, Sharpness-Aware Minimization (SAM) perturbs the model weights during training to find a more flat loss landscape and improve generalization. However, as SAM is designed for better clean accuracy, its effectiveness in enhancing adversarial robustness remains unexplored. In this work, considering the duality between SAM and AT, we i"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2402.15152","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2402.15152/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2402.15152","created_at":"2026-07-05T08:27:46.609180+00:00"},{"alias_kind":"arxiv_version","alias_value":"2402.15152v2","created_at":"2026-07-05T08:27:46.609180+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.15152","created_at":"2026-07-05T08:27:46.609180+00:00"},{"alias_kind":"pith_short_12","alias_value":"QIEUZMGEDZAI","created_at":"2026-07-05T08:27:46.609180+00:00"},{"alias_kind":"pith_short_16","alias_value":"QIEUZMGEDZAIVXVL","created_at":"2026-07-05T08:27:46.609180+00:00"},{"alias_kind":"pith_short_8","alias_value":"QIEUZMGE","created_at":"2026-07-05T08:27:46.609180+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.10183","citing_title":"Fix the Loss, Not the Radius: Rethinking the Adversarial Perturbation of Sharpness-Aware Minimization","ref_index":3,"is_internal_anchor":false},{"citing_arxiv_id":"2604.09258","citing_title":"Nexus: Same Pretraining Loss, Better Downstream Generalization via Common Minima","ref_index":49,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/QIEUZMGEDZAIVXVLNP54DGHKQ2","json":"https://pith.science/pith/QIEUZMGEDZAIVXVLNP54DGHKQ2.json","graph_json":"https://pith.science/api/pith-number/QIEUZMGEDZAIVXVLNP54DGHKQ2/graph.json","events_json":"https://pith.science/api/pith-number/QIEUZMGEDZAIVXVLNP54DGHKQ2/events.json","paper":"https://pith.science/paper/QIEUZMGE"},"agent_actions":{"view_html":"https://pith.science/pith/QIEUZMGEDZAIVXVLNP54DGHKQ2","download_json":"https://pith.science/pith/QIEUZMGEDZAIVXVLNP54DGHKQ2.json","view_paper":"https://pith.science/paper/QIEUZMGE","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2402.15152&json=true","fetch_graph":"https://pith.science/api/pith-number/QIEUZMGEDZAIVXVLNP54DGHKQ2/graph.json","fetch_events":"https://pith.science/api/pith-number/QIEUZMGEDZAIVXVLNP54DGHKQ2/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/QIEUZMGEDZAIVXVLNP54DGHKQ2/action/timestamp_anchor","attest_storage":"https://pith.science/pith/QIEUZMGEDZAIVXVLNP54DGHKQ2/action/storage_attestation","attest_author":"https://pith.science/pith/QIEUZMGEDZAIVXVLNP54DGHKQ2/action/author_attestation","sign_citation":"https://pith.science/pith/QIEUZMGEDZAIVXVLNP54DGHKQ2/action/citation_signature","submit_replication":"https://pith.science/pith/QIEUZMGEDZAIVXVLNP54DGHKQ2/action/replication_record"}},"created_at":"2026-07-05T08:27:46.609180+00:00","updated_at":"2026-07-05T08:27:46.609180+00:00"}