{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:T2GELXKRCSRXATBN5JYQGPJKCL","short_pith_number":"pith:T2GELXKR","schema_version":"1.0","canonical_sha256":"9e8c45dd5114a3704c2dea71033d2a12dd24506f13a6d3f382decf34b5907346","source":{"kind":"arxiv","id":"2306.08656","version":3},"attestation_state":"computed","paper":{"title":"Augment then Smooth: Reconciling Differential Privacy with Certified Robustness","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Atiyeh Ashari Ghomi, David Glukhov, Franziska Boenisch, Jesse C. Cresswell, Jiapeng Wu, Nicolas Papernot","submitted_at":"2023-06-14T17:52:02Z","abstract_excerpt":"Machine learning models are susceptible to a variety of attacks that can erode trust, including attacks against the privacy of training data, and adversarial examples that jeopardize model accuracy. Differential privacy and certified robustness are effective frameworks for combating these two threats respectively, as they each provide future-proof guarantees. However, we show that standard differentially private model training is insufficient for providing strong certified robustness guarantees. Indeed, combining differential privacy and certified robustness in a single system is non-trivial, "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2306.08656","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2023-06-14T17:52:02Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"0d15a574bdc46e1365f13332e3c401a70fd61f7d30debc13126a6abbd4589643","abstract_canon_sha256":"112ea935e6edbb323f6e6c2d417b7481db1ca39a6c2065cd38d94dcf5660f6b9"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:52:07.903808Z","signature_b64":"HEdVW3hGkvsdjdjm+U900Kix1AL+SENNJChNyRvQYYVreugtIE9J8Hc0HrZUYYYI82Dqe9rKIBKWykHsP5lFBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9e8c45dd5114a3704c2dea71033d2a12dd24506f13a6d3f382decf34b5907346","last_reissued_at":"2026-07-05T09:52:07.903364Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:52:07.903364Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Augment then Smooth: Reconciling Differential Privacy with Certified Robustness","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Atiyeh Ashari Ghomi, David Glukhov, Franziska Boenisch, Jesse C. Cresswell, Jiapeng Wu, Nicolas Papernot","submitted_at":"2023-06-14T17:52:02Z","abstract_excerpt":"Machine learning models are susceptible to a variety of attacks that can erode trust, including attacks against the privacy of training data, and adversarial examples that jeopardize model accuracy. Differential privacy and certified robustness are effective frameworks for combating these two threats respectively, as they each provide future-proof guarantees. However, we show that standard differentially private model training is insufficient for providing strong certified robustness guarantees. Indeed, combining differential privacy and certified robustness in a single system is non-trivial, "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2306.08656","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2306.08656/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2306.08656","created_at":"2026-07-05T09:52:07.903421+00:00"},{"alias_kind":"arxiv_version","alias_value":"2306.08656v3","created_at":"2026-07-05T09:52:07.903421+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2306.08656","created_at":"2026-07-05T09:52:07.903421+00:00"},{"alias_kind":"pith_short_12","alias_value":"T2GELXKRCSRX","created_at":"2026-07-05T09:52:07.903421+00:00"},{"alias_kind":"pith_short_16","alias_value":"T2GELXKRCSRXATBN","created_at":"2026-07-05T09:52:07.903421+00:00"},{"alias_kind":"pith_short_8","alias_value":"T2GELXKR","created_at":"2026-07-05T09:52:07.903421+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/T2GELXKRCSRXATBN5JYQGPJKCL","json":"https://pith.science/pith/T2GELXKRCSRXATBN5JYQGPJKCL.json","graph_json":"https://pith.science/api/pith-number/T2GELXKRCSRXATBN5JYQGPJKCL/graph.json","events_json":"https://pith.science/api/pith-number/T2GELXKRCSRXATBN5JYQGPJKCL/events.json","paper":"https://pith.science/paper/T2GELXKR"},"agent_actions":{"view_html":"https://pith.science/pith/T2GELXKRCSRXATBN5JYQGPJKCL","download_json":"https://pith.science/pith/T2GELXKRCSRXATBN5JYQGPJKCL.json","view_paper":"https://pith.science/paper/T2GELXKR","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2306.08656&json=true","fetch_graph":"https://pith.science/api/pith-number/T2GELXKRCSRXATBN5JYQGPJKCL/graph.json","fetch_events":"https://pith.science/api/pith-number/T2GELXKRCSRXATBN5JYQGPJKCL/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/T2GELXKRCSRXATBN5JYQGPJKCL/action/timestamp_anchor","attest_storage":"https://pith.science/pith/T2GELXKRCSRXATBN5JYQGPJKCL/action/storage_attestation","attest_author":"https://pith.science/pith/T2GELXKRCSRXATBN5JYQGPJKCL/action/author_attestation","sign_citation":"https://pith.science/pith/T2GELXKRCSRXATBN5JYQGPJKCL/action/citation_signature","submit_replication":"https://pith.science/pith/T2GELXKRCSRXATBN5JYQGPJKCL/action/replication_record"}},"created_at":"2026-07-05T09:52:07.903421+00:00","updated_at":"2026-07-05T09:52:07.903421+00:00"}