{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2016:RXFKE5PDQNHJ4EBUK5LZIYQCMR","short_pith_number":"pith:RXFKE5PD","canonical_record":{"source":{"id":"1612.00334","kind":"arxiv","version":12},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2016-12-01T16:20:39Z","cross_cats_sorted":["cs.CR","cs.CV"],"title_canon_sha256":"b0afcffafd4447e58f7b580718f6fbfc005786f88660318f7d6468610ecaf301","abstract_canon_sha256":"96b7420b31c725e857946ca1969ae11917356055f5a2dc8bb77149b48fc63444"},"schema_version":"1.0"},"canonical_sha256":"8dcaa275e3834e9e1034575794620264743476ef798c8aba739d1a0c69763c82","source":{"kind":"arxiv","id":"1612.00334","version":12},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1612.00334","created_at":"2026-05-18T00:34:15Z"},{"alias_kind":"arxiv_version","alias_value":"1612.00334v12","created_at":"2026-05-18T00:34:15Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1612.00334","created_at":"2026-05-18T00:34:15Z"},{"alias_kind":"pith_short_12","alias_value":"RXFKE5PDQNHJ","created_at":"2026-05-18T12:30:41Z"},{"alias_kind":"pith_short_16","alias_value":"RXFKE5PDQNHJ4EBU","created_at":"2026-05-18T12:30:41Z"},{"alias_kind":"pith_short_8","alias_value":"RXFKE5PD","created_at":"2026-05-18T12:30:41Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2016:RXFKE5PDQNHJ4EBUK5LZIYQCMR","target":"record","payload":{"canonical_record":{"source":{"id":"1612.00334","kind":"arxiv","version":12},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2016-12-01T16:20:39Z","cross_cats_sorted":["cs.CR","cs.CV"],"title_canon_sha256":"b0afcffafd4447e58f7b580718f6fbfc005786f88660318f7d6468610ecaf301","abstract_canon_sha256":"96b7420b31c725e857946ca1969ae11917356055f5a2dc8bb77149b48fc63444"},"schema_version":"1.0"},"canonical_sha256":"8dcaa275e3834e9e1034575794620264743476ef798c8aba739d1a0c69763c82","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:34:15.620677Z","signature_b64":"Iv6Ap00IVZBDpgRYVQ50HG7XkU3/R+oO77y2EMDr9Jkq9WwRhRHtazo117Cwj5HwBUWceEGSlbjTw6PvtYSaDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"8dcaa275e3834e9e1034575794620264743476ef798c8aba739d1a0c69763c82","last_reissued_at":"2026-05-18T00:34:15.620122Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:34:15.620122Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1612.00334","source_version":12,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:34:15Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"1G9rADy9tBUk4EZWKLUdd6LfmOaz5iZU0zjYj/MOpV/y+FO2aY4fFLdjkdOX3yZwzfCuIXZC4jFk9Wt/FrCJDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T17:58:29.617756Z"},"content_sha256":"cd4663510f49c7cbcb8a78bbb83ca0dd006d6277c4d5465671eb40eb3b8b0daa","schema_version":"1.0","event_id":"sha256:cd4663510f49c7cbcb8a78bbb83ca0dd006d6277c4d5465671eb40eb3b8b0daa"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2016:RXFKE5PDQNHJ4EBUK5LZIYQCMR","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"A Theoretical Framework for Robustness of (Deep) Classifiers against Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV"],"primary_cat":"cs.LG","authors_text":"Beilun Wang, Ji Gao, Yanjun Qi","submitted_at":"2016-12-01T16:20:39Z","abstract_excerpt":"Most machine learning classifiers, including deep neural networks, are vulnerable to adversarial examples. Such inputs are typically generated by adding small but purposeful modifications that lead to incorrect outputs while imperceptible to human eyes. The goal of this paper is not to introduce a single method, but to make theoretical steps towards fully understanding adversarial examples. By using concepts from topology, our theoretical analysis brings forth the key reasons why an adversarial example can fool a classifier ($f_1$) and adds its oracle ($f_2$, like human eyes) in such analysis."},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1612.00334","kind":"arxiv","version":12},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:34:15Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"fnTVPBttBs7ouOVFHJuRWjHbz7+pQNKlzqDCQj0/hKmArY5WQiddeaz6DTES70G6aT9dBlG02cZQUjfcpwzCCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T17:58:29.618107Z"},"content_sha256":"2b82573d254f1e9124886355d7c108f15a6fd9d8659ab9116ff6cbbad0625ab0","schema_version":"1.0","event_id":"sha256:2b82573d254f1e9124886355d7c108f15a6fd9d8659ab9116ff6cbbad0625ab0"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/RXFKE5PDQNHJ4EBUK5LZIYQCMR/bundle.json","state_url":"https://pith.science/pith/RXFKE5PDQNHJ4EBUK5LZIYQCMR/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/RXFKE5PDQNHJ4EBUK5LZIYQCMR/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-01T17:58:29Z","links":{"resolver":"https://pith.science/pith/RXFKE5PDQNHJ4EBUK5LZIYQCMR","bundle":"https://pith.science/pith/RXFKE5PDQNHJ4EBUK5LZIYQCMR/bundle.json","state":"https://pith.science/pith/RXFKE5PDQNHJ4EBUK5LZIYQCMR/state.json","well_known_bundle":"https://pith.science/.well-known/pith/RXFKE5PDQNHJ4EBUK5LZIYQCMR/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2016:RXFKE5PDQNHJ4EBUK5LZIYQCMR","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"96b7420b31c725e857946ca1969ae11917356055f5a2dc8bb77149b48fc63444","cross_cats_sorted":["cs.CR","cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2016-12-01T16:20:39Z","title_canon_sha256":"b0afcffafd4447e58f7b580718f6fbfc005786f88660318f7d6468610ecaf301"},"schema_version":"1.0","source":{"id":"1612.00334","kind":"arxiv","version":12}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1612.00334","created_at":"2026-05-18T00:34:15Z"},{"alias_kind":"arxiv_version","alias_value":"1612.00334v12","created_at":"2026-05-18T00:34:15Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1612.00334","created_at":"2026-05-18T00:34:15Z"},{"alias_kind":"pith_short_12","alias_value":"RXFKE5PDQNHJ","created_at":"2026-05-18T12:30:41Z"},{"alias_kind":"pith_short_16","alias_value":"RXFKE5PDQNHJ4EBU","created_at":"2026-05-18T12:30:41Z"},{"alias_kind":"pith_short_8","alias_value":"RXFKE5PD","created_at":"2026-05-18T12:30:41Z"}],"graph_snapshots":[{"event_id":"sha256:2b82573d254f1e9124886355d7c108f15a6fd9d8659ab9116ff6cbbad0625ab0","target":"graph","created_at":"2026-05-18T00:34:15Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Most machine learning classifiers, including deep neural networks, are vulnerable to adversarial examples. Such inputs are typically generated by adding small but purposeful modifications that lead to incorrect outputs while imperceptible to human eyes. The goal of this paper is not to introduce a single method, but to make theoretical steps towards fully understanding adversarial examples. By using concepts from topology, our theoretical analysis brings forth the key reasons why an adversarial example can fool a classifier ($f_1$) and adds its oracle ($f_2$, like human eyes) in such analysis.","authors_text":"Beilun Wang, Ji Gao, Yanjun Qi","cross_cats":["cs.CR","cs.CV"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2016-12-01T16:20:39Z","title":"A Theoretical Framework for Robustness of (Deep) Classifiers against Adversarial Examples"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1612.00334","kind":"arxiv","version":12},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:cd4663510f49c7cbcb8a78bbb83ca0dd006d6277c4d5465671eb40eb3b8b0daa","target":"record","created_at":"2026-05-18T00:34:15Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"96b7420b31c725e857946ca1969ae11917356055f5a2dc8bb77149b48fc63444","cross_cats_sorted":["cs.CR","cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2016-12-01T16:20:39Z","title_canon_sha256":"b0afcffafd4447e58f7b580718f6fbfc005786f88660318f7d6468610ecaf301"},"schema_version":"1.0","source":{"id":"1612.00334","kind":"arxiv","version":12}},"canonical_sha256":"8dcaa275e3834e9e1034575794620264743476ef798c8aba739d1a0c69763c82","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"8dcaa275e3834e9e1034575794620264743476ef798c8aba739d1a0c69763c82","first_computed_at":"2026-05-18T00:34:15.620122Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:34:15.620122Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Iv6Ap00IVZBDpgRYVQ50HG7XkU3/R+oO77y2EMDr9Jkq9WwRhRHtazo117Cwj5HwBUWceEGSlbjTw6PvtYSaDQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:34:15.620677Z","signed_message":"canonical_sha256_bytes"},"source_id":"1612.00334","source_kind":"arxiv","source_version":12}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:cd4663510f49c7cbcb8a78bbb83ca0dd006d6277c4d5465671eb40eb3b8b0daa","sha256:2b82573d254f1e9124886355d7c108f15a6fd9d8659ab9116ff6cbbad0625ab0"],"state_sha256":"d76e446ad7772cea17a166fe5fdd2fdfac8b4c1d9c4f3a6521a4740f87222fee"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"kRuIW3t41rKCgiRh2vR0Z1k2wi28w5uxtotASqzLkjDoOGyAehQumOOF75MyLNry4IOAVM3MsjW2SyDPsi+EBw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-01T17:58:29.620112Z","bundle_sha256":"4c575c65d0059f9e51190b94ff38292256c187b1618117a8a17c1e53da9bcd2b"}}