{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:TGRDQKDP3SJ7YZHJCIA3H662PR","short_pith_number":"pith:TGRDQKDP","canonical_record":{"source":{"id":"1804.00750","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-04-02T22:23:04Z","cross_cats_sorted":[],"title_canon_sha256":"3fce0ace7113f5f07b7b4e2efa16263e744bd3cdf4802b1f77b75c3aa8c1be6f","abstract_canon_sha256":"30b7fc53ef883cd2a9a2e4ffea87204a254190b44a138cc4ea3ea323cc71d773"},"schema_version":"1.0"},"canonical_sha256":"99a238286fdc93fc64e91201b3fbda7c5f729bb20db2afdd59c727ff0ae00517","source":{"kind":"arxiv","id":"1804.00750","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1804.00750","created_at":"2026-05-18T00:14:28Z"},{"alias_kind":"arxiv_version","alias_value":"1804.00750v2","created_at":"2026-05-18T00:14:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1804.00750","created_at":"2026-05-18T00:14:28Z"},{"alias_kind":"pith_short_12","alias_value":"TGRDQKDP3SJ7","created_at":"2026-05-18T12:32:53Z"},{"alias_kind":"pith_short_16","alias_value":"TGRDQKDP3SJ7YZHJ","created_at":"2026-05-18T12:32:53Z"},{"alias_kind":"pith_short_8","alias_value":"TGRDQKDP","created_at":"2026-05-18T12:32:53Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:TGRDQKDP3SJ7YZHJCIA3H662PR","target":"record","payload":{"canonical_record":{"source":{"id":"1804.00750","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-04-02T22:23:04Z","cross_cats_sorted":[],"title_canon_sha256":"3fce0ace7113f5f07b7b4e2efa16263e744bd3cdf4802b1f77b75c3aa8c1be6f","abstract_canon_sha256":"30b7fc53ef883cd2a9a2e4ffea87204a254190b44a138cc4ea3ea323cc71d773"},"schema_version":"1.0"},"canonical_sha256":"99a238286fdc93fc64e91201b3fbda7c5f729bb20db2afdd59c727ff0ae00517","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:14:28.285889Z","signature_b64":"g2MMnE4TQcc4lbaIN8PcYxhv7SKT6ZjG6iFZSp8ls3v95VSAZFt/VV2+451y04Hx7Z8TYRxPqpUDJ2El3aU1BA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"99a238286fdc93fc64e91201b3fbda7c5f729bb20db2afdd59c727ff0ae00517","last_reissued_at":"2026-05-18T00:14:28.285156Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:14:28.285156Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1804.00750","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:14:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"wMOgEoyTP60QnXxz2etLUV9SQUFaNsDfjzrOg4Fo23010pRGXmtX8JBJPwulysSoyTjtdcTItRB7Rs3J0Fu1Cg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T07:44:35.174638Z"},"content_sha256":"9f36a46124f134c57e70c7b2214193feccc8ae4424a9ec24804db60c87385657","schema_version":"1.0","event_id":"sha256:9f36a46124f134c57e70c7b2214193feccc8ae4424a9ec24804db60c87385657"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:TGRDQKDP3SJ7YZHJCIA3H662PR","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"DeepSigns: A Generic Watermarking Framework for IP Protection of Deep Learning Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Bita Darvish Rouhani, Farinaz Koushanfar, Huili Chen","submitted_at":"2018-04-02T22:23:04Z","abstract_excerpt":"Deep Learning (DL) models have caused a paradigm shift in our ability to comprehend raw data in various important fields, ranging from intelligence warfare and healthcare to autonomous transportation and automated manufacturing. A practical concern, in the rush to adopt DL models as a service, is protecting the models against Intellectual Property (IP) infringement. The DL models are commonly built by allocating significant computational resources that process vast amounts of proprietary training data. The resulting models are therefore considered to be the IP of the model builder and need to "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1804.00750","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:14:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"jRZmCtpYoqHEKJWJEC6f6vdM3YbXxjpvd8FYijLUNXk8mQNz04eknjMHBfcdGvIAt0AiK712NUor4Lc6rJiMCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T07:44:35.175023Z"},"content_sha256":"093cb25e612a0d15d7abf2eb26f5728d9b732cc19c551f7442042ec810079683","schema_version":"1.0","event_id":"sha256:093cb25e612a0d15d7abf2eb26f5728d9b732cc19c551f7442042ec810079683"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/TGRDQKDP3SJ7YZHJCIA3H662PR/bundle.json","state_url":"https://pith.science/pith/TGRDQKDP3SJ7YZHJCIA3H662PR/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/TGRDQKDP3SJ7YZHJCIA3H662PR/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-30T07:44:35Z","links":{"resolver":"https://pith.science/pith/TGRDQKDP3SJ7YZHJCIA3H662PR","bundle":"https://pith.science/pith/TGRDQKDP3SJ7YZHJCIA3H662PR/bundle.json","state":"https://pith.science/pith/TGRDQKDP3SJ7YZHJCIA3H662PR/state.json","well_known_bundle":"https://pith.science/.well-known/pith/TGRDQKDP3SJ7YZHJCIA3H662PR/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:TGRDQKDP3SJ7YZHJCIA3H662PR","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"30b7fc53ef883cd2a9a2e4ffea87204a254190b44a138cc4ea3ea323cc71d773","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-04-02T22:23:04Z","title_canon_sha256":"3fce0ace7113f5f07b7b4e2efa16263e744bd3cdf4802b1f77b75c3aa8c1be6f"},"schema_version":"1.0","source":{"id":"1804.00750","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1804.00750","created_at":"2026-05-18T00:14:28Z"},{"alias_kind":"arxiv_version","alias_value":"1804.00750v2","created_at":"2026-05-18T00:14:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1804.00750","created_at":"2026-05-18T00:14:28Z"},{"alias_kind":"pith_short_12","alias_value":"TGRDQKDP3SJ7","created_at":"2026-05-18T12:32:53Z"},{"alias_kind":"pith_short_16","alias_value":"TGRDQKDP3SJ7YZHJ","created_at":"2026-05-18T12:32:53Z"},{"alias_kind":"pith_short_8","alias_value":"TGRDQKDP","created_at":"2026-05-18T12:32:53Z"}],"graph_snapshots":[{"event_id":"sha256:093cb25e612a0d15d7abf2eb26f5728d9b732cc19c551f7442042ec810079683","target":"graph","created_at":"2026-05-18T00:14:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep Learning (DL) models have caused a paradigm shift in our ability to comprehend raw data in various important fields, ranging from intelligence warfare and healthcare to autonomous transportation and automated manufacturing. A practical concern, in the rush to adopt DL models as a service, is protecting the models against Intellectual Property (IP) infringement. The DL models are commonly built by allocating significant computational resources that process vast amounts of proprietary training data. The resulting models are therefore considered to be the IP of the model builder and need to ","authors_text":"Bita Darvish Rouhani, Farinaz Koushanfar, Huili Chen","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-04-02T22:23:04Z","title":"DeepSigns: A Generic Watermarking Framework for IP Protection of Deep Learning Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1804.00750","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:9f36a46124f134c57e70c7b2214193feccc8ae4424a9ec24804db60c87385657","target":"record","created_at":"2026-05-18T00:14:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"30b7fc53ef883cd2a9a2e4ffea87204a254190b44a138cc4ea3ea323cc71d773","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-04-02T22:23:04Z","title_canon_sha256":"3fce0ace7113f5f07b7b4e2efa16263e744bd3cdf4802b1f77b75c3aa8c1be6f"},"schema_version":"1.0","source":{"id":"1804.00750","kind":"arxiv","version":2}},"canonical_sha256":"99a238286fdc93fc64e91201b3fbda7c5f729bb20db2afdd59c727ff0ae00517","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"99a238286fdc93fc64e91201b3fbda7c5f729bb20db2afdd59c727ff0ae00517","first_computed_at":"2026-05-18T00:14:28.285156Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:14:28.285156Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"g2MMnE4TQcc4lbaIN8PcYxhv7SKT6ZjG6iFZSp8ls3v95VSAZFt/VV2+451y04Hx7Z8TYRxPqpUDJ2El3aU1BA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:14:28.285889Z","signed_message":"canonical_sha256_bytes"},"source_id":"1804.00750","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:9f36a46124f134c57e70c7b2214193feccc8ae4424a9ec24804db60c87385657","sha256:093cb25e612a0d15d7abf2eb26f5728d9b732cc19c551f7442042ec810079683"],"state_sha256":"4296cd8a555be6094dae10c4b2ac6ef43ad39ab143b3290e0f5daeb7743ada7b"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"gl6CBfrVBuFn/fJuhwVwxTOgIDZsPHB4RhFHxXW1xEqNO6zBLgWA60TrWO30THGKFl/zmQ6foaSgOIZpdR+xDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-30T07:44:35.177126Z","bundle_sha256":"1de13b170dd18372e8c1e216d1b2b73293d0043fcf4fe3291dfbbaaebcacfb87"}}