{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:QN35YPI6R447H4XU5CQKWKYLB7","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"88a407b4c3d28efaa6217383fd470fdec7b544ae13ebd2c704e54f359d531e98","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-16T18:52:58Z","title_canon_sha256":"5320bea376d2607eaf9180ad6deb2799683ef7af4d755fa4ac9a776f81222f3b"},"schema_version":"1.0","source":{"id":"1811.06969","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1811.06969","created_at":"2026-05-18T00:00:33Z"},{"alias_kind":"arxiv_version","alias_value":"1811.06969v1","created_at":"2026-05-18T00:00:33Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.06969","created_at":"2026-05-18T00:00:33Z"},{"alias_kind":"pith_short_12","alias_value":"QN35YPI6R447","created_at":"2026-05-18T12:32:46Z"},{"alias_kind":"pith_short_16","alias_value":"QN35YPI6R447H4XU","created_at":"2026-05-18T12:32:46Z"},{"alias_kind":"pith_short_8","alias_value":"QN35YPI6","created_at":"2026-05-18T12:32:46Z"}],"graph_snapshots":[{"event_id":"sha256:ea863ca8ce0c6c4932bb2a9e73337414479898bfe072a97c6d2924d82168809e","target":"graph","created_at":"2026-05-18T00:00:33Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We present a simple technique that allows capsule models to detect adversarial images. In addition to being trained to classify images, the capsule model is trained to reconstruct the images from the pose parameters and identity of the correct top-level capsule. Adversarial images do not look like a typical member of the predicted class and they have much larger reconstruction errors when the reconstruction is produced from the top-level capsule for that class. We show that setting a threshold on the $l2$ distance between the input image and its reconstruction from the winning capsule is very ","authors_text":"Geoffrey Hinton, Nicholas Frosst, Sara Sabour","cross_cats":["cs.CR","cs.CV","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-16T18:52:58Z","title":"DARCCC: Detecting Adversaries by Reconstruction from Class Conditional Capsules"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.06969","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:7c5564dfe1960e8a1d7ba328fa7ecb71075afa25aae2b2f6046ef4b2e708f108","target":"record","created_at":"2026-05-18T00:00:33Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"88a407b4c3d28efaa6217383fd470fdec7b544ae13ebd2c704e54f359d531e98","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-16T18:52:58Z","title_canon_sha256":"5320bea376d2607eaf9180ad6deb2799683ef7af4d755fa4ac9a776f81222f3b"},"schema_version":"1.0","source":{"id":"1811.06969","kind":"arxiv","version":1}},"canonical_sha256":"8377dc3d1e8f39f3f2f4e8a0ab2b0b0fd914cab8b0c6f9bb6c554590bb0f9eb3","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"8377dc3d1e8f39f3f2f4e8a0ab2b0b0fd914cab8b0c6f9bb6c554590bb0f9eb3","first_computed_at":"2026-05-18T00:00:33.350565Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:00:33.350565Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"396e+xVmL3XdXH4PoeqAaxSYajfkLWsnZKkg+cKuupFRfJukiYg3ZTD0lWWa854Eu5IYkHu5s+yTvux3vyOPDA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:00:33.351058Z","signed_message":"canonical_sha256_bytes"},"source_id":"1811.06969","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:7c5564dfe1960e8a1d7ba328fa7ecb71075afa25aae2b2f6046ef4b2e708f108","sha256:ea863ca8ce0c6c4932bb2a9e73337414479898bfe072a97c6d2924d82168809e"],"state_sha256":"52ce71a96a83cf81afb6adadc9928f2a12e1846b7bee4bab41f9f8b30ef8643b"}