{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:RH5JOXD2T5SKZCZF42QLWLX6EQ","short_pith_number":"pith:RH5JOXD2","canonical_record":{"source":{"id":"1702.06832","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-02-22T15:11:25Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"843ea85e2e2fdc948b71793ad8b715b0ecddf32642e1bc635dd4842bcb65d728","abstract_canon_sha256":"0689672bf7ec5b6269fd503ae60ec089cb3c462d79b5200ea205687d77f4b719"},"schema_version":"1.0"},"canonical_sha256":"89fa975c7a9f64ac8b25e6a0bb2efe240f8eea58095277f149b71544eff69591","source":{"kind":"arxiv","id":"1702.06832","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1702.06832","created_at":"2026-05-18T00:50:10Z"},{"alias_kind":"arxiv_version","alias_value":"1702.06832v1","created_at":"2026-05-18T00:50:10Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1702.06832","created_at":"2026-05-18T00:50:10Z"},{"alias_kind":"pith_short_12","alias_value":"RH5JOXD2T5SK","created_at":"2026-05-18T12:31:39Z"},{"alias_kind":"pith_short_16","alias_value":"RH5JOXD2T5SKZCZF","created_at":"2026-05-18T12:31:39Z"},{"alias_kind":"pith_short_8","alias_value":"RH5JOXD2","created_at":"2026-05-18T12:31:39Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:RH5JOXD2T5SKZCZF42QLWLX6EQ","target":"record","payload":{"canonical_record":{"source":{"id":"1702.06832","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-02-22T15:11:25Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"843ea85e2e2fdc948b71793ad8b715b0ecddf32642e1bc635dd4842bcb65d728","abstract_canon_sha256":"0689672bf7ec5b6269fd503ae60ec089cb3c462d79b5200ea205687d77f4b719"},"schema_version":"1.0"},"canonical_sha256":"89fa975c7a9f64ac8b25e6a0bb2efe240f8eea58095277f149b71544eff69591","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:50:10.359350Z","signature_b64":"9DfTJIiL3FmSLHq6Z4rz84HX3gAt9yEePhwpnUsd4PIPLIeHykXUhV8lZSjFH8g25EyvwxNQCOXiE3LsACnWBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"89fa975c7a9f64ac8b25e6a0bb2efe240f8eea58095277f149b71544eff69591","last_reissued_at":"2026-05-18T00:50:10.358559Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:50:10.358559Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1702.06832","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:50:10Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ZLdkXt/nkDAk7/Zm8D+muA8aJccGsqrt9H+PFf0Whn0pV2KZSkDbfkQksLi/qzRRkPSZ7f8FN/j9NWxJDO/DBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T04:14:32.811753Z"},"content_sha256":"ce97762950184351fab8f40d9ee386015d1baa4f32a241bee9bcfb37c6527346","schema_version":"1.0","event_id":"sha256:ce97762950184351fab8f40d9ee386015d1baa4f32a241bee9bcfb37c6527346"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:RH5JOXD2T5SKZCZF42QLWLX6EQ","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Adversarial examples for generative models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"stat.ML","authors_text":"Dawn Song, Ian Fischer, Jernej Kos","submitted_at":"2017-02-22T15:11:25Z","abstract_excerpt":"We explore methods of producing adversarial examples on deep generative models such as the variational autoencoder (VAE) and the VAE-GAN. Deep learning architectures are known to be vulnerable to adversarial examples, but previous work has focused on the application of adversarial examples to classification tasks. Deep generative models have recently become popular due to their ability to model input data distributions and generate realistic examples from those distributions. We present three classes of attacks on the VAE and VAE-GAN architectures and demonstrate them against networks trained "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1702.06832","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:50:10Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"VOscNlStc70zPCXvz46z4TtvFscVFfuh/kOOZNoC48VoFJ2bPpHe3paIJ8TjiYUJUG4jMP/oXcU2tFog8fUbDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T04:14:32.812411Z"},"content_sha256":"e056df7a6c0c002c32fd757572be8ad75eb75e6b3791b86c7c6b33779fa40545","schema_version":"1.0","event_id":"sha256:e056df7a6c0c002c32fd757572be8ad75eb75e6b3791b86c7c6b33779fa40545"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/RH5JOXD2T5SKZCZF42QLWLX6EQ/bundle.json","state_url":"https://pith.science/pith/RH5JOXD2T5SKZCZF42QLWLX6EQ/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/RH5JOXD2T5SKZCZF42QLWLX6EQ/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T04:14:32Z","links":{"resolver":"https://pith.science/pith/RH5JOXD2T5SKZCZF42QLWLX6EQ","bundle":"https://pith.science/pith/RH5JOXD2T5SKZCZF42QLWLX6EQ/bundle.json","state":"https://pith.science/pith/RH5JOXD2T5SKZCZF42QLWLX6EQ/state.json","well_known_bundle":"https://pith.science/.well-known/pith/RH5JOXD2T5SKZCZF42QLWLX6EQ/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:RH5JOXD2T5SKZCZF42QLWLX6EQ","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"0689672bf7ec5b6269fd503ae60ec089cb3c462d79b5200ea205687d77f4b719","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-02-22T15:11:25Z","title_canon_sha256":"843ea85e2e2fdc948b71793ad8b715b0ecddf32642e1bc635dd4842bcb65d728"},"schema_version":"1.0","source":{"id":"1702.06832","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1702.06832","created_at":"2026-05-18T00:50:10Z"},{"alias_kind":"arxiv_version","alias_value":"1702.06832v1","created_at":"2026-05-18T00:50:10Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1702.06832","created_at":"2026-05-18T00:50:10Z"},{"alias_kind":"pith_short_12","alias_value":"RH5JOXD2T5SK","created_at":"2026-05-18T12:31:39Z"},{"alias_kind":"pith_short_16","alias_value":"RH5JOXD2T5SKZCZF","created_at":"2026-05-18T12:31:39Z"},{"alias_kind":"pith_short_8","alias_value":"RH5JOXD2","created_at":"2026-05-18T12:31:39Z"}],"graph_snapshots":[{"event_id":"sha256:e056df7a6c0c002c32fd757572be8ad75eb75e6b3791b86c7c6b33779fa40545","target":"graph","created_at":"2026-05-18T00:50:10Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We explore methods of producing adversarial examples on deep generative models such as the variational autoencoder (VAE) and the VAE-GAN. Deep learning architectures are known to be vulnerable to adversarial examples, but previous work has focused on the application of adversarial examples to classification tasks. Deep generative models have recently become popular due to their ability to model input data distributions and generate realistic examples from those distributions. We present three classes of attacks on the VAE and VAE-GAN architectures and demonstrate them against networks trained ","authors_text":"Dawn Song, Ian Fischer, Jernej Kos","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-02-22T15:11:25Z","title":"Adversarial examples for generative models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1702.06832","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:ce97762950184351fab8f40d9ee386015d1baa4f32a241bee9bcfb37c6527346","target":"record","created_at":"2026-05-18T00:50:10Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"0689672bf7ec5b6269fd503ae60ec089cb3c462d79b5200ea205687d77f4b719","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-02-22T15:11:25Z","title_canon_sha256":"843ea85e2e2fdc948b71793ad8b715b0ecddf32642e1bc635dd4842bcb65d728"},"schema_version":"1.0","source":{"id":"1702.06832","kind":"arxiv","version":1}},"canonical_sha256":"89fa975c7a9f64ac8b25e6a0bb2efe240f8eea58095277f149b71544eff69591","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"89fa975c7a9f64ac8b25e6a0bb2efe240f8eea58095277f149b71544eff69591","first_computed_at":"2026-05-18T00:50:10.358559Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:50:10.358559Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"9DfTJIiL3FmSLHq6Z4rz84HX3gAt9yEePhwpnUsd4PIPLIeHykXUhV8lZSjFH8g25EyvwxNQCOXiE3LsACnWBQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:50:10.359350Z","signed_message":"canonical_sha256_bytes"},"source_id":"1702.06832","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:ce97762950184351fab8f40d9ee386015d1baa4f32a241bee9bcfb37c6527346","sha256:e056df7a6c0c002c32fd757572be8ad75eb75e6b3791b86c7c6b33779fa40545"],"state_sha256":"0f4f73332920cade86b74a10c28424b2bce1a75287f73bb6025a18698fdb53b8"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ytOvkiheZ6/jWCEQQy7fINr7Vwdif6fxphg/SzLqjd/VYM91WUBpQUMrVt5+JXl8Ibv1KcyW4Nofe+shBEMzBw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T04:14:32.814819Z","bundle_sha256":"13fe749ec126fca5673d9eed52c6055827b1763dac2e4ac86441bda298afa0c6"}}