{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:SXNQ6BAPX6IXLHBOOXT36E26ZL","short_pith_number":"pith:SXNQ6BAP","canonical_record":{"source":{"id":"1811.03456","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-11-07T07:36:55Z","cross_cats_sorted":["cs.CR","cs.LG"],"title_canon_sha256":"91b8f2fe557f5c655c5f32adf07270957b7c0635519aca663d44ce1567fb9920","abstract_canon_sha256":"e99b0ccb957644c7f3fd7ff2722af38daa277462519f85861f3add4a295e27e0"},"schema_version":"1.0"},"canonical_sha256":"95db0f040fbf91759c2e75e7bf135ecaeb0502a2172b5922146cf9268824d6e2","source":{"kind":"arxiv","id":"1811.03456","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1811.03456","created_at":"2026-05-18T00:01:15Z"},{"alias_kind":"arxiv_version","alias_value":"1811.03456v1","created_at":"2026-05-18T00:01:15Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.03456","created_at":"2026-05-18T00:01:15Z"},{"alias_kind":"pith_short_12","alias_value":"SXNQ6BAPX6IX","created_at":"2026-05-18T12:32:53Z"},{"alias_kind":"pith_short_16","alias_value":"SXNQ6BAPX6IXLHBO","created_at":"2026-05-18T12:32:53Z"},{"alias_kind":"pith_short_8","alias_value":"SXNQ6BAP","created_at":"2026-05-18T12:32:53Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:SXNQ6BAPX6IXLHBOOXT36E26ZL","target":"record","payload":{"canonical_record":{"source":{"id":"1811.03456","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-11-07T07:36:55Z","cross_cats_sorted":["cs.CR","cs.LG"],"title_canon_sha256":"91b8f2fe557f5c655c5f32adf07270957b7c0635519aca663d44ce1567fb9920","abstract_canon_sha256":"e99b0ccb957644c7f3fd7ff2722af38daa277462519f85861f3add4a295e27e0"},"schema_version":"1.0"},"canonical_sha256":"95db0f040fbf91759c2e75e7bf135ecaeb0502a2172b5922146cf9268824d6e2","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:01:15.666378Z","signature_b64":"eTFwBeej30Puq16/M9MqtUCyOEgobgqAWj91SNbhRUerOB/XBSWXl1X0J0yicSSlymF7+2cMkhpaFUKyJPJrDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"95db0f040fbf91759c2e75e7bf135ecaeb0502a2172b5922146cf9268824d6e2","last_reissued_at":"2026-05-18T00:01:15.665924Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:01:15.665924Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1811.03456","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:01:15Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"a+ZV53lyVUV9dthVSSvq91uCiJjPc4zROCY8P6MahEajOfczh2LJCEohvgjP1YLskHqIIpr8PUVM7ZykYy1bBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T06:52:42.838247Z"},"content_sha256":"55315511351365f071ad06e43fc7986356c190255c7b66c3d3830e8a2d5c786b","schema_version":"1.0","event_id":"sha256:55315511351365f071ad06e43fc7986356c190255c7b66c3d3830e8a2d5c786b"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:SXNQ6BAPX6IXLHBOOXT36E26ZL","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"CAAD 2018: Iterative Ensemble Adversarial Attack","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.LG"],"primary_cat":"cs.CV","authors_text":"Jiayang Liu, Nenghai Yu, Weiming Zhang","submitted_at":"2018-11-07T07:36:55Z","abstract_excerpt":"Deep Neural Networks (DNNs) have recently led to significant improvements in many fields. However, DNNs are vulnerable to adversarial examples which are samples with imperceptible perturbations while dramatically misleading the DNNs. Adversarial attacks can be used to evaluate the robustness of deep learning models before they are deployed. Unfortunately, most of existing adversarial attacks can only fool a black-box model with a low success rate. To improve the success rates for black-box adversarial attacks, we proposed an iterated adversarial attack against an ensemble of image classifiers."},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.03456","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:01:15Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"vN58PxGq5IBWYfNcquDeeHKs2Jczzv1icuFaYGRKgww9Jrf9vJTZPrhMUgE+WXXqIlQuy9G+2vPDTjfILJEsDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T06:52:42.838899Z"},"content_sha256":"2269b0216dc4459517ce0632740e3cc318ffaded28844239bf2d65ca7f6b2d26","schema_version":"1.0","event_id":"sha256:2269b0216dc4459517ce0632740e3cc318ffaded28844239bf2d65ca7f6b2d26"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/SXNQ6BAPX6IXLHBOOXT36E26ZL/bundle.json","state_url":"https://pith.science/pith/SXNQ6BAPX6IXLHBOOXT36E26ZL/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/SXNQ6BAPX6IXLHBOOXT36E26ZL/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T06:52:42Z","links":{"resolver":"https://pith.science/pith/SXNQ6BAPX6IXLHBOOXT36E26ZL","bundle":"https://pith.science/pith/SXNQ6BAPX6IXLHBOOXT36E26ZL/bundle.json","state":"https://pith.science/pith/SXNQ6BAPX6IXLHBOOXT36E26ZL/state.json","well_known_bundle":"https://pith.science/.well-known/pith/SXNQ6BAPX6IXLHBOOXT36E26ZL/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:SXNQ6BAPX6IXLHBOOXT36E26ZL","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e99b0ccb957644c7f3fd7ff2722af38daa277462519f85861f3add4a295e27e0","cross_cats_sorted":["cs.CR","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-11-07T07:36:55Z","title_canon_sha256":"91b8f2fe557f5c655c5f32adf07270957b7c0635519aca663d44ce1567fb9920"},"schema_version":"1.0","source":{"id":"1811.03456","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1811.03456","created_at":"2026-05-18T00:01:15Z"},{"alias_kind":"arxiv_version","alias_value":"1811.03456v1","created_at":"2026-05-18T00:01:15Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.03456","created_at":"2026-05-18T00:01:15Z"},{"alias_kind":"pith_short_12","alias_value":"SXNQ6BAPX6IX","created_at":"2026-05-18T12:32:53Z"},{"alias_kind":"pith_short_16","alias_value":"SXNQ6BAPX6IXLHBO","created_at":"2026-05-18T12:32:53Z"},{"alias_kind":"pith_short_8","alias_value":"SXNQ6BAP","created_at":"2026-05-18T12:32:53Z"}],"graph_snapshots":[{"event_id":"sha256:2269b0216dc4459517ce0632740e3cc318ffaded28844239bf2d65ca7f6b2d26","target":"graph","created_at":"2026-05-18T00:01:15Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep Neural Networks (DNNs) have recently led to significant improvements in many fields. However, DNNs are vulnerable to adversarial examples which are samples with imperceptible perturbations while dramatically misleading the DNNs. Adversarial attacks can be used to evaluate the robustness of deep learning models before they are deployed. Unfortunately, most of existing adversarial attacks can only fool a black-box model with a low success rate. To improve the success rates for black-box adversarial attacks, we proposed an iterated adversarial attack against an ensemble of image classifiers.","authors_text":"Jiayang Liu, Nenghai Yu, Weiming Zhang","cross_cats":["cs.CR","cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-11-07T07:36:55Z","title":"CAAD 2018: Iterative Ensemble Adversarial Attack"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.03456","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:55315511351365f071ad06e43fc7986356c190255c7b66c3d3830e8a2d5c786b","target":"record","created_at":"2026-05-18T00:01:15Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e99b0ccb957644c7f3fd7ff2722af38daa277462519f85861f3add4a295e27e0","cross_cats_sorted":["cs.CR","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-11-07T07:36:55Z","title_canon_sha256":"91b8f2fe557f5c655c5f32adf07270957b7c0635519aca663d44ce1567fb9920"},"schema_version":"1.0","source":{"id":"1811.03456","kind":"arxiv","version":1}},"canonical_sha256":"95db0f040fbf91759c2e75e7bf135ecaeb0502a2172b5922146cf9268824d6e2","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"95db0f040fbf91759c2e75e7bf135ecaeb0502a2172b5922146cf9268824d6e2","first_computed_at":"2026-05-18T00:01:15.665924Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:01:15.665924Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"eTFwBeej30Puq16/M9MqtUCyOEgobgqAWj91SNbhRUerOB/XBSWXl1X0J0yicSSlymF7+2cMkhpaFUKyJPJrDA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:01:15.666378Z","signed_message":"canonical_sha256_bytes"},"source_id":"1811.03456","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:55315511351365f071ad06e43fc7986356c190255c7b66c3d3830e8a2d5c786b","sha256:2269b0216dc4459517ce0632740e3cc318ffaded28844239bf2d65ca7f6b2d26"],"state_sha256":"85ca635e0ae2c6b51f7a931deab9746b22a8f9535661cbc2e126fdf89f1277e8"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Ew8jI7Pqzq4uqmDUA392RdenxnUsBOuj2wt9tHESKD8U28pscoAapni7CHiqRsiRfNlrkozo6tsc2T0qsBw8BQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T06:52:42.842593Z","bundle_sha256":"72f455c4c77a71cc1c4e33cb733959cfaa39a46ee390b7c565ec07da6d6750a6"}}