{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:UBUUVGX24D5VJ76GZWXT4S5Q77","short_pith_number":"pith:UBUUVGX2","canonical_record":{"source":{"id":"1802.01549","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-02-05T18:21:31Z","cross_cats_sorted":["cs.AI","stat.ML"],"title_canon_sha256":"c759a4179d6d20a9164bd84ade3a17797a4bb303394c9f8503989e7745697f08","abstract_canon_sha256":"6f26a180c2a5be2d22fcfc4ed2756ec880c243e41235bd3fbb4785aac16d4eab"},"schema_version":"1.0"},"canonical_sha256":"a0694a9afae0fb54ffc6cdaf3e4bb0ffe867ea6d289c10f1ff74cd8991138a6c","source":{"kind":"arxiv","id":"1802.01549","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1802.01549","created_at":"2026-05-18T00:24:09Z"},{"alias_kind":"arxiv_version","alias_value":"1802.01549v2","created_at":"2026-05-18T00:24:09Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1802.01549","created_at":"2026-05-18T00:24:09Z"},{"alias_kind":"pith_short_12","alias_value":"UBUUVGX24D5V","created_at":"2026-05-18T12:32:56Z"},{"alias_kind":"pith_short_16","alias_value":"UBUUVGX24D5VJ76G","created_at":"2026-05-18T12:32:56Z"},{"alias_kind":"pith_short_8","alias_value":"UBUUVGX2","created_at":"2026-05-18T12:32:56Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:UBUUVGX24D5VJ76GZWXT4S5Q77","target":"record","payload":{"canonical_record":{"source":{"id":"1802.01549","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-02-05T18:21:31Z","cross_cats_sorted":["cs.AI","stat.ML"],"title_canon_sha256":"c759a4179d6d20a9164bd84ade3a17797a4bb303394c9f8503989e7745697f08","abstract_canon_sha256":"6f26a180c2a5be2d22fcfc4ed2756ec880c243e41235bd3fbb4785aac16d4eab"},"schema_version":"1.0"},"canonical_sha256":"a0694a9afae0fb54ffc6cdaf3e4bb0ffe867ea6d289c10f1ff74cd8991138a6c","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:24:09.275958Z","signature_b64":"D78sFIlt2xXLLjxnQp6Ku2unTeXaTwc9gP056Hc87602BRzPsywqnUXna60PizU2lzvfa2O9PJ/YyZ48CEFrAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a0694a9afae0fb54ffc6cdaf3e4bb0ffe867ea6d289c10f1ff74cd8991138a6c","last_reissued_at":"2026-05-18T00:24:09.275306Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:24:09.275306Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1802.01549","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:24:09Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"avcoLP4ZKZISAStTrR8qJYYGSaqQm6iLNnEXp1+eM6YPrb/KC5ovhgJDSieFnPVJa1DdUtDKwvb2JY2Ie78BAw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T01:45:38.640552Z"},"content_sha256":"8f2cced870d4486a1a788e6339a7a7a36038f62b292f347ba6111d0d917b7c41","schema_version":"1.0","event_id":"sha256:8f2cced870d4486a1a788e6339a7a7a36038f62b292f347ba6111d0d917b7c41"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:UBUUVGX24D5VJ76GZWXT4S5Q77","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Blind Pre-Processing: A Robust Defense Method Against Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","stat.ML"],"primary_cat":"cs.LG","authors_text":"Adnan Siraj Rakin, Boqing Gong, Deliang Fan, Zhezhi He","submitted_at":"2018-02-05T18:21:31Z","abstract_excerpt":"Deep learning algorithms and networks are vulnerable to perturbed inputs which is known as the adversarial attack. Many defense methodologies have been investigated to defend against such adversarial attack. In this work, we propose a novel methodology to defend the existing powerful attack model. We for the first time introduce a new attacking scheme for the attacker and set a practical constraint for white box attack. Under this proposed attacking scheme, we present the best defense ever reported against some of the recent strong attacks. It consists of a set of nonlinear function to process"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1802.01549","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:24:09Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Eviy+R82KlLjdJBqaZRDCr+XJNC1si3MoBs38/Irxi4ik5MyzKkml65/RBaApgFUYuajC19JtsJtMmj8MRvJAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T01:45:38.641003Z"},"content_sha256":"b8f3ad7129204c9a48a591dea7b17dcadc6e67022b899c2fff442b024a382b34","schema_version":"1.0","event_id":"sha256:b8f3ad7129204c9a48a591dea7b17dcadc6e67022b899c2fff442b024a382b34"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/UBUUVGX24D5VJ76GZWXT4S5Q77/bundle.json","state_url":"https://pith.science/pith/UBUUVGX24D5VJ76GZWXT4S5Q77/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/UBUUVGX24D5VJ76GZWXT4S5Q77/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T01:45:38Z","links":{"resolver":"https://pith.science/pith/UBUUVGX24D5VJ76GZWXT4S5Q77","bundle":"https://pith.science/pith/UBUUVGX24D5VJ76GZWXT4S5Q77/bundle.json","state":"https://pith.science/pith/UBUUVGX24D5VJ76GZWXT4S5Q77/state.json","well_known_bundle":"https://pith.science/.well-known/pith/UBUUVGX24D5VJ76GZWXT4S5Q77/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:UBUUVGX24D5VJ76GZWXT4S5Q77","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"6f26a180c2a5be2d22fcfc4ed2756ec880c243e41235bd3fbb4785aac16d4eab","cross_cats_sorted":["cs.AI","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-02-05T18:21:31Z","title_canon_sha256":"c759a4179d6d20a9164bd84ade3a17797a4bb303394c9f8503989e7745697f08"},"schema_version":"1.0","source":{"id":"1802.01549","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1802.01549","created_at":"2026-05-18T00:24:09Z"},{"alias_kind":"arxiv_version","alias_value":"1802.01549v2","created_at":"2026-05-18T00:24:09Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1802.01549","created_at":"2026-05-18T00:24:09Z"},{"alias_kind":"pith_short_12","alias_value":"UBUUVGX24D5V","created_at":"2026-05-18T12:32:56Z"},{"alias_kind":"pith_short_16","alias_value":"UBUUVGX24D5VJ76G","created_at":"2026-05-18T12:32:56Z"},{"alias_kind":"pith_short_8","alias_value":"UBUUVGX2","created_at":"2026-05-18T12:32:56Z"}],"graph_snapshots":[{"event_id":"sha256:b8f3ad7129204c9a48a591dea7b17dcadc6e67022b899c2fff442b024a382b34","target":"graph","created_at":"2026-05-18T00:24:09Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep learning algorithms and networks are vulnerable to perturbed inputs which is known as the adversarial attack. Many defense methodologies have been investigated to defend against such adversarial attack. In this work, we propose a novel methodology to defend the existing powerful attack model. We for the first time introduce a new attacking scheme for the attacker and set a practical constraint for white box attack. Under this proposed attacking scheme, we present the best defense ever reported against some of the recent strong attacks. It consists of a set of nonlinear function to process","authors_text":"Adnan Siraj Rakin, Boqing Gong, Deliang Fan, Zhezhi He","cross_cats":["cs.AI","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-02-05T18:21:31Z","title":"Blind Pre-Processing: A Robust Defense Method Against Adversarial Examples"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1802.01549","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:8f2cced870d4486a1a788e6339a7a7a36038f62b292f347ba6111d0d917b7c41","target":"record","created_at":"2026-05-18T00:24:09Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"6f26a180c2a5be2d22fcfc4ed2756ec880c243e41235bd3fbb4785aac16d4eab","cross_cats_sorted":["cs.AI","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-02-05T18:21:31Z","title_canon_sha256":"c759a4179d6d20a9164bd84ade3a17797a4bb303394c9f8503989e7745697f08"},"schema_version":"1.0","source":{"id":"1802.01549","kind":"arxiv","version":2}},"canonical_sha256":"a0694a9afae0fb54ffc6cdaf3e4bb0ffe867ea6d289c10f1ff74cd8991138a6c","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a0694a9afae0fb54ffc6cdaf3e4bb0ffe867ea6d289c10f1ff74cd8991138a6c","first_computed_at":"2026-05-18T00:24:09.275306Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:24:09.275306Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"D78sFIlt2xXLLjxnQp6Ku2unTeXaTwc9gP056Hc87602BRzPsywqnUXna60PizU2lzvfa2O9PJ/YyZ48CEFrAA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:24:09.275958Z","signed_message":"canonical_sha256_bytes"},"source_id":"1802.01549","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:8f2cced870d4486a1a788e6339a7a7a36038f62b292f347ba6111d0d917b7c41","sha256:b8f3ad7129204c9a48a591dea7b17dcadc6e67022b899c2fff442b024a382b34"],"state_sha256":"a7f9adb8d190e05b7a5cf834c6bcc56ef0a7cbdcdda1fb3b6719f517518020c9"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"IHbufYTcMJ38ce5Xo37FsDAtr5gqwWm45M7FxXtzJWj7MMgZWKSFTCSmgWabUo4sesIeLseylS7CNJd85dKaCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T01:45:38.644254Z","bundle_sha256":"6f0206cff24b9d0d25b4fe09be640f9f143a12081123c22b194bc9ed6194433e"}}