{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:TDIPKG2SBBV6WWORMFC6PNVGQX","short_pith_number":"pith:TDIPKG2S","canonical_record":{"source":{"id":"1901.07132","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-01-22T00:54:30Z","cross_cats_sorted":["cs.CL","cs.CR","stat.ML"],"title_canon_sha256":"d745cbf031181514cfd30181082df5d47af67a8123ca1240668dee76bde5ad67","abstract_canon_sha256":"6072dd662785a4121e2664acc822795c74a6fc97bc447e102bfb2072553bdbfb"},"schema_version":"1.0"},"canonical_sha256":"98d0f51b52086beb59d16145e7b6a685dc764ea062ac732d36477f5bb89d36fd","source":{"kind":"arxiv","id":"1901.07132","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1901.07132","created_at":"2026-05-17T23:49:32Z"},{"alias_kind":"arxiv_version","alias_value":"1901.07132v2","created_at":"2026-05-17T23:49:32Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1901.07132","created_at":"2026-05-17T23:49:32Z"},{"alias_kind":"pith_short_12","alias_value":"TDIPKG2SBBV6","created_at":"2026-05-18T12:33:27Z"},{"alias_kind":"pith_short_16","alias_value":"TDIPKG2SBBV6WWOR","created_at":"2026-05-18T12:33:27Z"},{"alias_kind":"pith_short_8","alias_value":"TDIPKG2S","created_at":"2026-05-18T12:33:27Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:TDIPKG2SBBV6WWORMFC6PNVGQX","target":"record","payload":{"canonical_record":{"source":{"id":"1901.07132","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-01-22T00:54:30Z","cross_cats_sorted":["cs.CL","cs.CR","stat.ML"],"title_canon_sha256":"d745cbf031181514cfd30181082df5d47af67a8123ca1240668dee76bde5ad67","abstract_canon_sha256":"6072dd662785a4121e2664acc822795c74a6fc97bc447e102bfb2072553bdbfb"},"schema_version":"1.0"},"canonical_sha256":"98d0f51b52086beb59d16145e7b6a685dc764ea062ac732d36477f5bb89d36fd","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:49:32.884166Z","signature_b64":"jONiUuh7DFx/GB7uCVfOP4ki3A2KSbKzeyDu9vY0LFsosAr6C6jxnXwLS+ieI4Y/JDUy3NhGOnL9Y1MMRz+mDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"98d0f51b52086beb59d16145e7b6a685dc764ea062ac732d36477f5bb89d36fd","last_reissued_at":"2026-05-17T23:49:32.883563Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:49:32.883563Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1901.07132","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:49:32Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"dR+uf9DaOE2ACOBDAwXux8GqjVyFLUeJFemiJhPP58cYjZmvE0ukUueP1nw0sDfVHujrLuh7R89BoBQ7nSzdBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T21:05:32.716524Z"},"content_sha256":"4b6b26d3bc47f73d6e0016790e64480f54193de4133fc4f6eb1f70291bafa315","schema_version":"1.0","event_id":"sha256:4b6b26d3bc47f73d6e0016790e64480f54193de4133fc4f6eb1f70291bafa315"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:TDIPKG2SBBV6WWORMFC6PNVGQX","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Universal Rules for Fooling Deep Neural Networks based Text Classification","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CL","cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Danilo Vasconcellos Vargas, Di Li, Sakurai Kouichi","submitted_at":"2019-01-22T00:54:30Z","abstract_excerpt":"Recently, deep learning based natural language processing techniques are being extensively used to deal with spam mail, censorship evaluation in social networks, among others. However, there is only a couple of works evaluating the vulnerabilities of such deep neural networks. Here, we go beyond attacks to investigate, for the first time, universal rules, i.e., rules that are sample agnostic and therefore could turn any text sample in an adversarial one. In fact, the universal rules do not use any information from the method itself (no information from the method, gradient information or train"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1901.07132","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:49:32Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"vHpFKMjgyl3FqrE15dGm0CZPLEgQilbGsCmPk3k2HfYJBuuL3EXlJH0TVix2W2KPTRGlXXCKY0ZPj6WRTVbYAw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T21:05:32.717212Z"},"content_sha256":"630b2c7d9d9490f000c70aa1e9c9ca9d54fe735fdcfda52c009464b468b64bb0","schema_version":"1.0","event_id":"sha256:630b2c7d9d9490f000c70aa1e9c9ca9d54fe735fdcfda52c009464b468b64bb0"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/TDIPKG2SBBV6WWORMFC6PNVGQX/bundle.json","state_url":"https://pith.science/pith/TDIPKG2SBBV6WWORMFC6PNVGQX/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/TDIPKG2SBBV6WWORMFC6PNVGQX/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-28T21:05:32Z","links":{"resolver":"https://pith.science/pith/TDIPKG2SBBV6WWORMFC6PNVGQX","bundle":"https://pith.science/pith/TDIPKG2SBBV6WWORMFC6PNVGQX/bundle.json","state":"https://pith.science/pith/TDIPKG2SBBV6WWORMFC6PNVGQX/state.json","well_known_bundle":"https://pith.science/.well-known/pith/TDIPKG2SBBV6WWORMFC6PNVGQX/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:TDIPKG2SBBV6WWORMFC6PNVGQX","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"6072dd662785a4121e2664acc822795c74a6fc97bc447e102bfb2072553bdbfb","cross_cats_sorted":["cs.CL","cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-01-22T00:54:30Z","title_canon_sha256":"d745cbf031181514cfd30181082df5d47af67a8123ca1240668dee76bde5ad67"},"schema_version":"1.0","source":{"id":"1901.07132","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1901.07132","created_at":"2026-05-17T23:49:32Z"},{"alias_kind":"arxiv_version","alias_value":"1901.07132v2","created_at":"2026-05-17T23:49:32Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1901.07132","created_at":"2026-05-17T23:49:32Z"},{"alias_kind":"pith_short_12","alias_value":"TDIPKG2SBBV6","created_at":"2026-05-18T12:33:27Z"},{"alias_kind":"pith_short_16","alias_value":"TDIPKG2SBBV6WWOR","created_at":"2026-05-18T12:33:27Z"},{"alias_kind":"pith_short_8","alias_value":"TDIPKG2S","created_at":"2026-05-18T12:33:27Z"}],"graph_snapshots":[{"event_id":"sha256:630b2c7d9d9490f000c70aa1e9c9ca9d54fe735fdcfda52c009464b468b64bb0","target":"graph","created_at":"2026-05-17T23:49:32Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Recently, deep learning based natural language processing techniques are being extensively used to deal with spam mail, censorship evaluation in social networks, among others. However, there is only a couple of works evaluating the vulnerabilities of such deep neural networks. Here, we go beyond attacks to investigate, for the first time, universal rules, i.e., rules that are sample agnostic and therefore could turn any text sample in an adversarial one. In fact, the universal rules do not use any information from the method itself (no information from the method, gradient information or train","authors_text":"Danilo Vasconcellos Vargas, Di Li, Sakurai Kouichi","cross_cats":["cs.CL","cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-01-22T00:54:30Z","title":"Universal Rules for Fooling Deep Neural Networks based Text Classification"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1901.07132","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:4b6b26d3bc47f73d6e0016790e64480f54193de4133fc4f6eb1f70291bafa315","target":"record","created_at":"2026-05-17T23:49:32Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"6072dd662785a4121e2664acc822795c74a6fc97bc447e102bfb2072553bdbfb","cross_cats_sorted":["cs.CL","cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-01-22T00:54:30Z","title_canon_sha256":"d745cbf031181514cfd30181082df5d47af67a8123ca1240668dee76bde5ad67"},"schema_version":"1.0","source":{"id":"1901.07132","kind":"arxiv","version":2}},"canonical_sha256":"98d0f51b52086beb59d16145e7b6a685dc764ea062ac732d36477f5bb89d36fd","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"98d0f51b52086beb59d16145e7b6a685dc764ea062ac732d36477f5bb89d36fd","first_computed_at":"2026-05-17T23:49:32.883563Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:49:32.883563Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"jONiUuh7DFx/GB7uCVfOP4ki3A2KSbKzeyDu9vY0LFsosAr6C6jxnXwLS+ieI4Y/JDUy3NhGOnL9Y1MMRz+mDw==","signature_status":"signed_v1","signed_at":"2026-05-17T23:49:32.884166Z","signed_message":"canonical_sha256_bytes"},"source_id":"1901.07132","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:4b6b26d3bc47f73d6e0016790e64480f54193de4133fc4f6eb1f70291bafa315","sha256:630b2c7d9d9490f000c70aa1e9c9ca9d54fe735fdcfda52c009464b468b64bb0"],"state_sha256":"726a8bfc2f2104fae3b7eda4951534e8badc5c0bb284f6b940062573197c80a3"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"mBVVUMRBByCvHceqO4tn2EOV3vyClOs66BbhEBnV7ex+dp+7nAXzwMZSLADw/+d84RaIFO6/BdFu+/Y+k85iAQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-28T21:05:32.721414Z","bundle_sha256":"072e44ff2719a10546285ae97c53de8277874dbfd17a687fd883340f44d086ee"}}