{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:UHLWA4275PEP4LCB5GAFGTDTOS","short_pith_number":"pith:UHLWA427","canonical_record":{"source":{"id":"1905.12797","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-30T00:34:50Z","cross_cats_sorted":["cs.CR","cs.CV","cs.NE","stat.ML"],"title_canon_sha256":"2b65678da489da35d5e627e51e1177255dbdfd7c1cf1405291e55816a63faf9e","abstract_canon_sha256":"e9d541e0dc00eff045773d96d1b46bd013a1c7a758b7a6f40b5a91548fe9f489"},"schema_version":"1.0"},"canonical_sha256":"a1d760735febc8fe2c41e980534c7374819ed35208952bebd3442f6443674589","source":{"kind":"arxiv","id":"1905.12797","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.12797","created_at":"2026-05-17T23:44:39Z"},{"alias_kind":"arxiv_version","alias_value":"1905.12797v1","created_at":"2026-05-17T23:44:39Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.12797","created_at":"2026-05-17T23:44:39Z"},{"alias_kind":"pith_short_12","alias_value":"UHLWA4275PEP","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_16","alias_value":"UHLWA4275PEP4LCB","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_8","alias_value":"UHLWA427","created_at":"2026-05-18T12:33:30Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:UHLWA4275PEP4LCB5GAFGTDTOS","target":"record","payload":{"canonical_record":{"source":{"id":"1905.12797","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-30T00:34:50Z","cross_cats_sorted":["cs.CR","cs.CV","cs.NE","stat.ML"],"title_canon_sha256":"2b65678da489da35d5e627e51e1177255dbdfd7c1cf1405291e55816a63faf9e","abstract_canon_sha256":"e9d541e0dc00eff045773d96d1b46bd013a1c7a758b7a6f40b5a91548fe9f489"},"schema_version":"1.0"},"canonical_sha256":"a1d760735febc8fe2c41e980534c7374819ed35208952bebd3442f6443674589","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:44:39.641092Z","signature_b64":"xoWmjC0wOwV+JgqKPbKjtti6XYc+2vOrSkWTtfK3H7nMlH1vcID5vwqtTOpMraQMci6JnGGl8OSRXyZHZQLCAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a1d760735febc8fe2c41e980534c7374819ed35208952bebd3442f6443674589","last_reissued_at":"2026-05-17T23:44:39.640591Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:44:39.640591Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1905.12797","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:44:39Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"uuhBBllcChQHzZarFeJKUADqzRrWQivtLXLtQwKxJ1i2E7e5qagPiAzh06b8AQ/gQ9rKr1WkfMFc6VGvZ5M1CQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T17:47:59.652389Z"},"content_sha256":"ca8406d846d071aedf93a65946f94d6c1f571e2d4864b870955d77591a35c6d7","schema_version":"1.0","event_id":"sha256:ca8406d846d071aedf93a65946f94d6c1f571e2d4864b870955d77591a35c6d7"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:UHLWA4275PEP4LCB5GAFGTDTOS","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Bandlimiting Neural Networks Against Adversarial Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","cs.NE","stat.ML"],"primary_cat":"cs.LG","authors_text":"Hui Jiang, Kasra Ahmadi K. A., Yuping Lin","submitted_at":"2019-05-30T00:34:50Z","abstract_excerpt":"In this paper, we study the adversarial attack and defence problem in deep learning from the perspective of Fourier analysis. We first explicitly compute the Fourier transform of deep ReLU neural networks and show that there exist decaying but non-zero high frequency components in the Fourier spectrum of neural networks. We demonstrate that the vulnerability of neural networks towards adversarial samples can be attributed to these insignificant but non-zero high frequency components. Based on this analysis, we propose to use a simple post-averaging technique to smooth out these high frequency "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.12797","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:44:39Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"MfUlVunP1QMxNLZNtE4se2RfRosVjzfXsdZay9PwypqtwAaF3RqwqGUCg43QtzLogiDokFHBzTqQj4/pAeDYBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T17:47:59.652746Z"},"content_sha256":"73cf58db4213fb31bc59143cd31de677a8e62256bbe39707d867eed713bb251f","schema_version":"1.0","event_id":"sha256:73cf58db4213fb31bc59143cd31de677a8e62256bbe39707d867eed713bb251f"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/UHLWA4275PEP4LCB5GAFGTDTOS/bundle.json","state_url":"https://pith.science/pith/UHLWA4275PEP4LCB5GAFGTDTOS/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/UHLWA4275PEP4LCB5GAFGTDTOS/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-03T17:47:59Z","links":{"resolver":"https://pith.science/pith/UHLWA4275PEP4LCB5GAFGTDTOS","bundle":"https://pith.science/pith/UHLWA4275PEP4LCB5GAFGTDTOS/bundle.json","state":"https://pith.science/pith/UHLWA4275PEP4LCB5GAFGTDTOS/state.json","well_known_bundle":"https://pith.science/.well-known/pith/UHLWA4275PEP4LCB5GAFGTDTOS/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:UHLWA4275PEP4LCB5GAFGTDTOS","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e9d541e0dc00eff045773d96d1b46bd013a1c7a758b7a6f40b5a91548fe9f489","cross_cats_sorted":["cs.CR","cs.CV","cs.NE","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-30T00:34:50Z","title_canon_sha256":"2b65678da489da35d5e627e51e1177255dbdfd7c1cf1405291e55816a63faf9e"},"schema_version":"1.0","source":{"id":"1905.12797","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.12797","created_at":"2026-05-17T23:44:39Z"},{"alias_kind":"arxiv_version","alias_value":"1905.12797v1","created_at":"2026-05-17T23:44:39Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.12797","created_at":"2026-05-17T23:44:39Z"},{"alias_kind":"pith_short_12","alias_value":"UHLWA4275PEP","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_16","alias_value":"UHLWA4275PEP4LCB","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_8","alias_value":"UHLWA427","created_at":"2026-05-18T12:33:30Z"}],"graph_snapshots":[{"event_id":"sha256:73cf58db4213fb31bc59143cd31de677a8e62256bbe39707d867eed713bb251f","target":"graph","created_at":"2026-05-17T23:44:39Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"In this paper, we study the adversarial attack and defence problem in deep learning from the perspective of Fourier analysis. We first explicitly compute the Fourier transform of deep ReLU neural networks and show that there exist decaying but non-zero high frequency components in the Fourier spectrum of neural networks. We demonstrate that the vulnerability of neural networks towards adversarial samples can be attributed to these insignificant but non-zero high frequency components. Based on this analysis, we propose to use a simple post-averaging technique to smooth out these high frequency ","authors_text":"Hui Jiang, Kasra Ahmadi K. A., Yuping Lin","cross_cats":["cs.CR","cs.CV","cs.NE","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-30T00:34:50Z","title":"Bandlimiting Neural Networks Against Adversarial Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.12797","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:ca8406d846d071aedf93a65946f94d6c1f571e2d4864b870955d77591a35c6d7","target":"record","created_at":"2026-05-17T23:44:39Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e9d541e0dc00eff045773d96d1b46bd013a1c7a758b7a6f40b5a91548fe9f489","cross_cats_sorted":["cs.CR","cs.CV","cs.NE","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-30T00:34:50Z","title_canon_sha256":"2b65678da489da35d5e627e51e1177255dbdfd7c1cf1405291e55816a63faf9e"},"schema_version":"1.0","source":{"id":"1905.12797","kind":"arxiv","version":1}},"canonical_sha256":"a1d760735febc8fe2c41e980534c7374819ed35208952bebd3442f6443674589","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a1d760735febc8fe2c41e980534c7374819ed35208952bebd3442f6443674589","first_computed_at":"2026-05-17T23:44:39.640591Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:44:39.640591Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"xoWmjC0wOwV+JgqKPbKjtti6XYc+2vOrSkWTtfK3H7nMlH1vcID5vwqtTOpMraQMci6JnGGl8OSRXyZHZQLCAA==","signature_status":"signed_v1","signed_at":"2026-05-17T23:44:39.641092Z","signed_message":"canonical_sha256_bytes"},"source_id":"1905.12797","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:ca8406d846d071aedf93a65946f94d6c1f571e2d4864b870955d77591a35c6d7","sha256:73cf58db4213fb31bc59143cd31de677a8e62256bbe39707d867eed713bb251f"],"state_sha256":"aded5c07ec3b3b59247b59bc56d19d21da1eeb185bec51cbecf325c9566f4c30"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"M+Uc1YhBE/rY08pt1dzX9p+jRsX71YTr+FgEaGWLoDrQ/45EAU5MEVRD1844DvsH+DwrHapGPoDRybSa4neECA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-03T17:47:59.654846Z","bundle_sha256":"bd760fcdff54aae36f941954569005852a023034c9e1cfea3be9ebff82e26eb4"}}