{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:UP4KIHULV457U5V7ZVK6LTZX24","short_pith_number":"pith:UP4KIHUL","canonical_record":{"source":{"id":"1710.11342","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-10-31T06:22:26Z","cross_cats_sorted":["cs.AI","cs.CL","cs.CV"],"title_canon_sha256":"09fa16209273bb38a078038ef0403939387468d461ca5d328432d2f539155870","abstract_canon_sha256":"6413d1b63220f491297262cccd8dd2573f812ffd38c149e3350add03ab0fb1b4"},"schema_version":"1.0"},"canonical_sha256":"a3f8a41e8baf3bfa76bfcd55e5cf37d71203781f6a0826c244b1fdd9a35af546","source":{"kind":"arxiv","id":"1710.11342","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1710.11342","created_at":"2026-05-18T00:22:39Z"},{"alias_kind":"arxiv_version","alias_value":"1710.11342v2","created_at":"2026-05-18T00:22:39Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1710.11342","created_at":"2026-05-18T00:22:39Z"},{"alias_kind":"pith_short_12","alias_value":"UP4KIHULV457","created_at":"2026-05-18T12:31:46Z"},{"alias_kind":"pith_short_16","alias_value":"UP4KIHULV457U5V7","created_at":"2026-05-18T12:31:46Z"},{"alias_kind":"pith_short_8","alias_value":"UP4KIHUL","created_at":"2026-05-18T12:31:46Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:UP4KIHULV457U5V7ZVK6LTZX24","target":"record","payload":{"canonical_record":{"source":{"id":"1710.11342","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-10-31T06:22:26Z","cross_cats_sorted":["cs.AI","cs.CL","cs.CV"],"title_canon_sha256":"09fa16209273bb38a078038ef0403939387468d461ca5d328432d2f539155870","abstract_canon_sha256":"6413d1b63220f491297262cccd8dd2573f812ffd38c149e3350add03ab0fb1b4"},"schema_version":"1.0"},"canonical_sha256":"a3f8a41e8baf3bfa76bfcd55e5cf37d71203781f6a0826c244b1fdd9a35af546","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:22:39.303308Z","signature_b64":"ndpCMsmOBZggCZrUOs86UJCCnE9ikUJgCBlkro7Ce1g6yRQMuMkPWvsaU9Ou2KZp2mzOQDHbfDvIMmYZuHZiAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a3f8a41e8baf3bfa76bfcd55e5cf37d71203781f6a0826c244b1fdd9a35af546","last_reissued_at":"2026-05-18T00:22:39.302697Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:22:39.302697Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1710.11342","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:22:39Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Kbt1AMoaGcXjDObYDRWo8wsuOYPUF2DvXx9vJrKg8+BbZPIEuSe+DIU71CIwL31cPkATcZ7a62BK2j3HqkO6Bw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-31T12:55:49.871499Z"},"content_sha256":"a9b7f849827c47c070845ec2b9236b4eb5c5745428f82c887eb970d327954e64","schema_version":"1.0","event_id":"sha256:a9b7f849827c47c070845ec2b9236b4eb5c5745428f82c887eb970d327954e64"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:UP4KIHULV457U5V7ZVK6LTZX24","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Generating Natural Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.CV"],"primary_cat":"cs.LG","authors_text":"Dheeru Dua, Sameer Singh, Zhengli Zhao","submitted_at":"2017-10-31T06:22:26Z","abstract_excerpt":"Due to their complex nature, it is hard to characterize the ways in which machine learning models can misbehave or be exploited when deployed. Recent work on adversarial examples, i.e. inputs with minor perturbations that result in substantially different model predictions, is helpful in evaluating the robustness of these models by exposing the adversarial scenarios where they fail. However, these malicious perturbations are often unnatural, not semantically meaningful, and not applicable to complicated domains such as language. In this paper, we propose a framework to generate natural and leg"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1710.11342","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:22:39Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Gz+hHnh4JsYDShwsckgBJ1isGTSSNX0hXBPhoMGB7c8T9+Q52GMbZ0NNwObAyK2binRLNQHzhZVHXh9Pg9eYAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-31T12:55:49.872148Z"},"content_sha256":"bf411a2a52a3d41fa2260e9f5da37c87253b8c81125c9b4b0e260add2c8e79df","schema_version":"1.0","event_id":"sha256:bf411a2a52a3d41fa2260e9f5da37c87253b8c81125c9b4b0e260add2c8e79df"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/UP4KIHULV457U5V7ZVK6LTZX24/bundle.json","state_url":"https://pith.science/pith/UP4KIHULV457U5V7ZVK6LTZX24/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/UP4KIHULV457U5V7ZVK6LTZX24/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-31T12:55:49Z","links":{"resolver":"https://pith.science/pith/UP4KIHULV457U5V7ZVK6LTZX24","bundle":"https://pith.science/pith/UP4KIHULV457U5V7ZVK6LTZX24/bundle.json","state":"https://pith.science/pith/UP4KIHULV457U5V7ZVK6LTZX24/state.json","well_known_bundle":"https://pith.science/.well-known/pith/UP4KIHULV457U5V7ZVK6LTZX24/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:UP4KIHULV457U5V7ZVK6LTZX24","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"6413d1b63220f491297262cccd8dd2573f812ffd38c149e3350add03ab0fb1b4","cross_cats_sorted":["cs.AI","cs.CL","cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-10-31T06:22:26Z","title_canon_sha256":"09fa16209273bb38a078038ef0403939387468d461ca5d328432d2f539155870"},"schema_version":"1.0","source":{"id":"1710.11342","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1710.11342","created_at":"2026-05-18T00:22:39Z"},{"alias_kind":"arxiv_version","alias_value":"1710.11342v2","created_at":"2026-05-18T00:22:39Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1710.11342","created_at":"2026-05-18T00:22:39Z"},{"alias_kind":"pith_short_12","alias_value":"UP4KIHULV457","created_at":"2026-05-18T12:31:46Z"},{"alias_kind":"pith_short_16","alias_value":"UP4KIHULV457U5V7","created_at":"2026-05-18T12:31:46Z"},{"alias_kind":"pith_short_8","alias_value":"UP4KIHUL","created_at":"2026-05-18T12:31:46Z"}],"graph_snapshots":[{"event_id":"sha256:bf411a2a52a3d41fa2260e9f5da37c87253b8c81125c9b4b0e260add2c8e79df","target":"graph","created_at":"2026-05-18T00:22:39Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Due to their complex nature, it is hard to characterize the ways in which machine learning models can misbehave or be exploited when deployed. Recent work on adversarial examples, i.e. inputs with minor perturbations that result in substantially different model predictions, is helpful in evaluating the robustness of these models by exposing the adversarial scenarios where they fail. However, these malicious perturbations are often unnatural, not semantically meaningful, and not applicable to complicated domains such as language. In this paper, we propose a framework to generate natural and leg","authors_text":"Dheeru Dua, Sameer Singh, Zhengli Zhao","cross_cats":["cs.AI","cs.CL","cs.CV"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-10-31T06:22:26Z","title":"Generating Natural Adversarial Examples"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1710.11342","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:a9b7f849827c47c070845ec2b9236b4eb5c5745428f82c887eb970d327954e64","target":"record","created_at":"2026-05-18T00:22:39Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"6413d1b63220f491297262cccd8dd2573f812ffd38c149e3350add03ab0fb1b4","cross_cats_sorted":["cs.AI","cs.CL","cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-10-31T06:22:26Z","title_canon_sha256":"09fa16209273bb38a078038ef0403939387468d461ca5d328432d2f539155870"},"schema_version":"1.0","source":{"id":"1710.11342","kind":"arxiv","version":2}},"canonical_sha256":"a3f8a41e8baf3bfa76bfcd55e5cf37d71203781f6a0826c244b1fdd9a35af546","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a3f8a41e8baf3bfa76bfcd55e5cf37d71203781f6a0826c244b1fdd9a35af546","first_computed_at":"2026-05-18T00:22:39.302697Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:22:39.302697Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"ndpCMsmOBZggCZrUOs86UJCCnE9ikUJgCBlkro7Ce1g6yRQMuMkPWvsaU9Ou2KZp2mzOQDHbfDvIMmYZuHZiAQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:22:39.303308Z","signed_message":"canonical_sha256_bytes"},"source_id":"1710.11342","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:a9b7f849827c47c070845ec2b9236b4eb5c5745428f82c887eb970d327954e64","sha256:bf411a2a52a3d41fa2260e9f5da37c87253b8c81125c9b4b0e260add2c8e79df"],"state_sha256":"e3ea3ca12cb3156922d5161f68d9392433d7a3e6c787dfa6edfc3dca31ec29ed"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"EdMd9zFJAIuKGKZ386N2SBshtI87Hvm3MPQfn/FrmZrQ6MuODCxjFzhhufP9qq0iwocWD3j/xDMQIPjRVdOdDA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-31T12:55:49.875923Z","bundle_sha256":"2c398cbe15266df08bab95fd92ef8aeb2c09ce7a39beaf1c2ccd16f7ce04d148"}}