{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:TFPQOGKYZ3MLJ4EZXSNJXV34CJ","short_pith_number":"pith:TFPQOGKY","canonical_record":{"source":{"id":"1808.06645","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-08-20T18:39:04Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"92f236a886bd17882a8bb2dc9dd82e42fc5bebfce9cdc08d5d7b576458807ff2","abstract_canon_sha256":"6885c0533e3f06862ef005778949bb411041eefa17ee6291bcd3c35b7b7468ba"},"schema_version":"1.0"},"canonical_sha256":"995f071958ced8b4f099bc9a9bd77c1272bfeec22724405e69cfd5e17690986d","source":{"kind":"arxiv","id":"1808.06645","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1808.06645","created_at":"2026-05-18T00:06:15Z"},{"alias_kind":"arxiv_version","alias_value":"1808.06645v2","created_at":"2026-05-18T00:06:15Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1808.06645","created_at":"2026-05-18T00:06:15Z"},{"alias_kind":"pith_short_12","alias_value":"TFPQOGKYZ3ML","created_at":"2026-05-18T12:32:53Z"},{"alias_kind":"pith_short_16","alias_value":"TFPQOGKYZ3MLJ4EZ","created_at":"2026-05-18T12:32:53Z"},{"alias_kind":"pith_short_8","alias_value":"TFPQOGKY","created_at":"2026-05-18T12:32:53Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:TFPQOGKYZ3MLJ4EZXSNJXV34CJ","target":"record","payload":{"canonical_record":{"source":{"id":"1808.06645","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-08-20T18:39:04Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"92f236a886bd17882a8bb2dc9dd82e42fc5bebfce9cdc08d5d7b576458807ff2","abstract_canon_sha256":"6885c0533e3f06862ef005778949bb411041eefa17ee6291bcd3c35b7b7468ba"},"schema_version":"1.0"},"canonical_sha256":"995f071958ced8b4f099bc9a9bd77c1272bfeec22724405e69cfd5e17690986d","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:06:15.923849Z","signature_b64":"1koV5Bow4Avet+fad0CTwoPnKLbu07pcWB43FjECPfGznG3DfOjdpGVdTQIm/LPt+//bO66uam2S+pE1/+dBCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"995f071958ced8b4f099bc9a9bd77c1272bfeec22724405e69cfd5e17690986d","last_reissued_at":"2026-05-18T00:06:15.923205Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:06:15.923205Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1808.06645","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:06:15Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ZQz9YWGSNd+8gxV1TVKn7Iu7IOIlfSu30kkQ9xa3v3WzggFFSOGx0HWtj7F0y5o0whhUSpGLZWS9SQCQpD+FCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T12:40:23.718429Z"},"content_sha256":"ff1d29cd2887bf0c0f6ba372fb02243f9a6df8b4fe834606c2b188a9f6326c55","schema_version":"1.0","event_id":"sha256:ff1d29cd2887bf0c0f6ba372fb02243f9a6df8b4fe834606c2b188a9f6326c55"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:TFPQOGKYZ3MLJ4EZXSNJXV34CJ","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Stochastic Combinatorial Ensembles for Defending Against Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Anna Goldenberg, Benjamin Haibe-Kains, David Duvenaud, George A. Adam, Petr Smirnov","submitted_at":"2018-08-20T18:39:04Z","abstract_excerpt":"Many deep learning algorithms can be easily fooled with simple adversarial examples. To address the limitations of existing defenses, we devised a probabilistic framework that can generate an exponentially large ensemble of models from a single model with just a linear cost. This framework takes advantage of neural network depth and stochastically decides whether or not to insert noise removal operators such as VAEs between layers. We show empirically the important role that model gradients have when it comes to determining transferability of adversarial examples, and take advantage of this re"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1808.06645","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:06:15Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"JUerNuTEtYhPlKGVYvL1tntP2eTlAEBnAatFNUcHM6msStStZ7FcAcuuLvh0asy2kt9gHr9aK/wcf0HpCVwCCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T12:40:23.718792Z"},"content_sha256":"0799adc5055ce5d7b76444559f7fea159b4673375df1ef028cdd3c7af3c940d2","schema_version":"1.0","event_id":"sha256:0799adc5055ce5d7b76444559f7fea159b4673375df1ef028cdd3c7af3c940d2"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/TFPQOGKYZ3MLJ4EZXSNJXV34CJ/bundle.json","state_url":"https://pith.science/pith/TFPQOGKYZ3MLJ4EZXSNJXV34CJ/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/TFPQOGKYZ3MLJ4EZXSNJXV34CJ/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-01T12:40:23Z","links":{"resolver":"https://pith.science/pith/TFPQOGKYZ3MLJ4EZXSNJXV34CJ","bundle":"https://pith.science/pith/TFPQOGKYZ3MLJ4EZXSNJXV34CJ/bundle.json","state":"https://pith.science/pith/TFPQOGKYZ3MLJ4EZXSNJXV34CJ/state.json","well_known_bundle":"https://pith.science/.well-known/pith/TFPQOGKYZ3MLJ4EZXSNJXV34CJ/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:TFPQOGKYZ3MLJ4EZXSNJXV34CJ","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"6885c0533e3f06862ef005778949bb411041eefa17ee6291bcd3c35b7b7468ba","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-08-20T18:39:04Z","title_canon_sha256":"92f236a886bd17882a8bb2dc9dd82e42fc5bebfce9cdc08d5d7b576458807ff2"},"schema_version":"1.0","source":{"id":"1808.06645","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1808.06645","created_at":"2026-05-18T00:06:15Z"},{"alias_kind":"arxiv_version","alias_value":"1808.06645v2","created_at":"2026-05-18T00:06:15Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1808.06645","created_at":"2026-05-18T00:06:15Z"},{"alias_kind":"pith_short_12","alias_value":"TFPQOGKYZ3ML","created_at":"2026-05-18T12:32:53Z"},{"alias_kind":"pith_short_16","alias_value":"TFPQOGKYZ3MLJ4EZ","created_at":"2026-05-18T12:32:53Z"},{"alias_kind":"pith_short_8","alias_value":"TFPQOGKY","created_at":"2026-05-18T12:32:53Z"}],"graph_snapshots":[{"event_id":"sha256:0799adc5055ce5d7b76444559f7fea159b4673375df1ef028cdd3c7af3c940d2","target":"graph","created_at":"2026-05-18T00:06:15Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Many deep learning algorithms can be easily fooled with simple adversarial examples. To address the limitations of existing defenses, we devised a probabilistic framework that can generate an exponentially large ensemble of models from a single model with just a linear cost. This framework takes advantage of neural network depth and stochastically decides whether or not to insert noise removal operators such as VAEs between layers. We show empirically the important role that model gradients have when it comes to determining transferability of adversarial examples, and take advantage of this re","authors_text":"Anna Goldenberg, Benjamin Haibe-Kains, David Duvenaud, George A. Adam, Petr Smirnov","cross_cats":["cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-08-20T18:39:04Z","title":"Stochastic Combinatorial Ensembles for Defending Against Adversarial Examples"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1808.06645","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:ff1d29cd2887bf0c0f6ba372fb02243f9a6df8b4fe834606c2b188a9f6326c55","target":"record","created_at":"2026-05-18T00:06:15Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"6885c0533e3f06862ef005778949bb411041eefa17ee6291bcd3c35b7b7468ba","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-08-20T18:39:04Z","title_canon_sha256":"92f236a886bd17882a8bb2dc9dd82e42fc5bebfce9cdc08d5d7b576458807ff2"},"schema_version":"1.0","source":{"id":"1808.06645","kind":"arxiv","version":2}},"canonical_sha256":"995f071958ced8b4f099bc9a9bd77c1272bfeec22724405e69cfd5e17690986d","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"995f071958ced8b4f099bc9a9bd77c1272bfeec22724405e69cfd5e17690986d","first_computed_at":"2026-05-18T00:06:15.923205Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:06:15.923205Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"1koV5Bow4Avet+fad0CTwoPnKLbu07pcWB43FjECPfGznG3DfOjdpGVdTQIm/LPt+//bO66uam2S+pE1/+dBCQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:06:15.923849Z","signed_message":"canonical_sha256_bytes"},"source_id":"1808.06645","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:ff1d29cd2887bf0c0f6ba372fb02243f9a6df8b4fe834606c2b188a9f6326c55","sha256:0799adc5055ce5d7b76444559f7fea159b4673375df1ef028cdd3c7af3c940d2"],"state_sha256":"c7d6e5f2778099e18448bce975b7471809a4625e837f28091ba3b9cb842a66c2"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"lj6s9hTFg2NGcmx5qzHd5NEM++XpQUWfHs8AOh0LvwZIdKz88Z5cqh4QQ9oNo0GH3iPl6ZeE5xrLGPGdcr/ECw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-01T12:40:23.720865Z","bundle_sha256":"00e0cb620ec33d19272028ce1989455058387c0244c124a904a06ee3b2ceddbe"}}