{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:RNHZ4U4IG5QMHZL2EHU2TH7V55","short_pith_number":"pith:RNHZ4U4I","schema_version":"1.0","canonical_sha256":"8b4f9e53883760c3e57a21e9a99ff5ef69f6bc250d6ea32d48cf38fb3bfd3f1d","source":{"kind":"arxiv","id":"1904.00887","version":4},"attestation_state":"computed","paper":{"title":"Adversarial Defense by Restricting the Hidden Space of Deep Neural Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CV","authors_text":"Aamir Mustafa, Jianbing Shen, Ling Shao, Munawar Hayat, Roland Goecke, Salman Khan","submitted_at":"2019-04-01T14:42:38Z","abstract_excerpt":"Deep neural networks are vulnerable to adversarial attacks, which can fool them by adding minuscule perturbations to the input images. The robustness of existing defenses suffers greatly under white-box attack settings, where an adversary has full knowledge about the network and can iterate several times to find strong perturbations. We observe that the main reason for the existence of such perturbations is the close proximity of different class samples in the learned feature space. This allows model decisions to be totally changed by adding an imperceptible perturbation in the inputs. To coun"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1904.00887","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-04-01T14:42:38Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"aadb99c7112218f2f3ddb200f3528621e164cf9facd99f66fb6362cafdc187ae","abstract_canon_sha256":"1227253e6899edbcf8cfbe55140f3acd993bee23712cb0b530024e6d14c45a68"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:39:24.520005Z","signature_b64":"Lb5iTRKHnLwrW4D0+62vv41WUbp7lExpLviiT2lpbcBv1MNzymi1EE1xWcHVh9bop2op24w9iPwWe7Nmr9F6Ag==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"8b4f9e53883760c3e57a21e9a99ff5ef69f6bc250d6ea32d48cf38fb3bfd3f1d","last_reissued_at":"2026-05-17T23:39:24.519492Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:39:24.519492Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Adversarial Defense by Restricting the Hidden Space of Deep Neural Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CV","authors_text":"Aamir Mustafa, Jianbing Shen, Ling Shao, Munawar Hayat, Roland Goecke, Salman Khan","submitted_at":"2019-04-01T14:42:38Z","abstract_excerpt":"Deep neural networks are vulnerable to adversarial attacks, which can fool them by adding minuscule perturbations to the input images. The robustness of existing defenses suffers greatly under white-box attack settings, where an adversary has full knowledge about the network and can iterate several times to find strong perturbations. We observe that the main reason for the existence of such perturbations is the close proximity of different class samples in the learned feature space. This allows model decisions to be totally changed by adding an imperceptible perturbation in the inputs. To coun"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1904.00887","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1904.00887","created_at":"2026-05-17T23:39:24.519574+00:00"},{"alias_kind":"arxiv_version","alias_value":"1904.00887v4","created_at":"2026-05-17T23:39:24.519574+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1904.00887","created_at":"2026-05-17T23:39:24.519574+00:00"},{"alias_kind":"pith_short_12","alias_value":"RNHZ4U4IG5QM","created_at":"2026-05-18T12:33:27.125529+00:00"},{"alias_kind":"pith_short_16","alias_value":"RNHZ4U4IG5QMHZL2","created_at":"2026-05-18T12:33:27.125529+00:00"},{"alias_kind":"pith_short_8","alias_value":"RNHZ4U4I","created_at":"2026-05-18T12:33:27.125529+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/RNHZ4U4IG5QMHZL2EHU2TH7V55","json":"https://pith.science/pith/RNHZ4U4IG5QMHZL2EHU2TH7V55.json","graph_json":"https://pith.science/api/pith-number/RNHZ4U4IG5QMHZL2EHU2TH7V55/graph.json","events_json":"https://pith.science/api/pith-number/RNHZ4U4IG5QMHZL2EHU2TH7V55/events.json","paper":"https://pith.science/paper/RNHZ4U4I"},"agent_actions":{"view_html":"https://pith.science/pith/RNHZ4U4IG5QMHZL2EHU2TH7V55","download_json":"https://pith.science/pith/RNHZ4U4IG5QMHZL2EHU2TH7V55.json","view_paper":"https://pith.science/paper/RNHZ4U4I","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1904.00887&json=true","fetch_graph":"https://pith.science/api/pith-number/RNHZ4U4IG5QMHZL2EHU2TH7V55/graph.json","fetch_events":"https://pith.science/api/pith-number/RNHZ4U4IG5QMHZL2EHU2TH7V55/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/RNHZ4U4IG5QMHZL2EHU2TH7V55/action/timestamp_anchor","attest_storage":"https://pith.science/pith/RNHZ4U4IG5QMHZL2EHU2TH7V55/action/storage_attestation","attest_author":"https://pith.science/pith/RNHZ4U4IG5QMHZL2EHU2TH7V55/action/author_attestation","sign_citation":"https://pith.science/pith/RNHZ4U4IG5QMHZL2EHU2TH7V55/action/citation_signature","submit_replication":"https://pith.science/pith/RNHZ4U4IG5QMHZL2EHU2TH7V55/action/replication_record"}},"created_at":"2026-05-17T23:39:24.519574+00:00","updated_at":"2026-05-17T23:39:24.519574+00:00"}