{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:V2TIFKXQJ5C5M7DA23KCLPFPNX","short_pith_number":"pith:V2TIFKXQ","canonical_record":{"source":{"id":"1801.08926","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-01-26T18:24:59Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"b8b6642fb93ed7751cf512a31e8cc5b284194a39b1b41e59b4d9b354f66a4888","abstract_canon_sha256":"282d7daee3ae2e85ce7b555cf15a3fb7af99f1138d3068fd2580e2c29f7013cf"},"schema_version":"1.0"},"canonical_sha256":"aea682aaf04f45d67c60d6d425bcaf6de43cce68b566f20e2b80bb4725468809","source":{"kind":"arxiv","id":"1801.08926","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1801.08926","created_at":"2026-05-18T00:19:41Z"},{"alias_kind":"arxiv_version","alias_value":"1801.08926v3","created_at":"2026-05-18T00:19:41Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1801.08926","created_at":"2026-05-18T00:19:41Z"},{"alias_kind":"pith_short_12","alias_value":"V2TIFKXQJ5C5","created_at":"2026-05-18T12:32:56Z"},{"alias_kind":"pith_short_16","alias_value":"V2TIFKXQJ5C5M7DA","created_at":"2026-05-18T12:32:56Z"},{"alias_kind":"pith_short_8","alias_value":"V2TIFKXQ","created_at":"2026-05-18T12:32:56Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:V2TIFKXQJ5C5M7DA23KCLPFPNX","target":"record","payload":{"canonical_record":{"source":{"id":"1801.08926","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-01-26T18:24:59Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"b8b6642fb93ed7751cf512a31e8cc5b284194a39b1b41e59b4d9b354f66a4888","abstract_canon_sha256":"282d7daee3ae2e85ce7b555cf15a3fb7af99f1138d3068fd2580e2c29f7013cf"},"schema_version":"1.0"},"canonical_sha256":"aea682aaf04f45d67c60d6d425bcaf6de43cce68b566f20e2b80bb4725468809","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:19:41.176733Z","signature_b64":"3ZEbrO6r4OfodkzfGhxZC4J144GlBilLVVjafFkN0ib8LBrBYtXDsZjpY7tSdeIU5W28+7SnHmjQ2objoEA7CA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"aea682aaf04f45d67c60d6d425bcaf6de43cce68b566f20e2b80bb4725468809","last_reissued_at":"2026-05-18T00:19:41.176016Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:19:41.176016Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1801.08926","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:19:41Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"sYPAfsxmN0q2KN0e7n9ayIjxoCIGKrYG4G9PURKiZ5E9PbhehC0bzit7SWVbLAcvyeWsJ7GpezTHHqceHVURDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T21:39:51.631293Z"},"content_sha256":"1664b851ab469a7f740a7f8e533bb904e02f7c4ac7b81b74244ade6dcedf7270","schema_version":"1.0","event_id":"sha256:1664b851ab469a7f740a7f8e533bb904e02f7c4ac7b81b74244ade6dcedf7270"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:V2TIFKXQJ5C5M7DA23KCLPFPNX","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Deflecting Adversarial Attacks with Pixel Deflection","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.CV","authors_text":"Aaditya Prakash, Antonella DiLillo, James Storer, Nick Moran, Solomon Garber","submitted_at":"2018-01-26T18:24:59Z","abstract_excerpt":"CNNs are poised to become integral parts of many critical systems. Despite their robustness to natural variations, image pixel values can be manipulated, via small, carefully crafted, imperceptible perturbations, to cause a model to misclassify images. We present an algorithm to process an image so that classification accuracy is significantly preserved in the presence of such adversarial manipulations. Image classifiers tend to be robust to natural noise, and adversarial attacks tend to be agnostic to object location. These observations motivate our strategy, which leverages model robustness "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1801.08926","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:19:41Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"9QruKolV4YdpdE9lIpqGokb+128giwnq7CzuUXUHrrNvwyuWy9bpZipY93+Z5udvhDgyJV7fJtfGisVZptvrBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T21:39:51.632010Z"},"content_sha256":"f0f1f608c46952e5dd2a3754aa2c93bbc1fe90e72b40602cb77e48cf2e231816","schema_version":"1.0","event_id":"sha256:f0f1f608c46952e5dd2a3754aa2c93bbc1fe90e72b40602cb77e48cf2e231816"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/V2TIFKXQJ5C5M7DA23KCLPFPNX/bundle.json","state_url":"https://pith.science/pith/V2TIFKXQJ5C5M7DA23KCLPFPNX/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/V2TIFKXQJ5C5M7DA23KCLPFPNX/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T21:39:51Z","links":{"resolver":"https://pith.science/pith/V2TIFKXQJ5C5M7DA23KCLPFPNX","bundle":"https://pith.science/pith/V2TIFKXQJ5C5M7DA23KCLPFPNX/bundle.json","state":"https://pith.science/pith/V2TIFKXQJ5C5M7DA23KCLPFPNX/state.json","well_known_bundle":"https://pith.science/.well-known/pith/V2TIFKXQJ5C5M7DA23KCLPFPNX/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:V2TIFKXQJ5C5M7DA23KCLPFPNX","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"282d7daee3ae2e85ce7b555cf15a3fb7af99f1138d3068fd2580e2c29f7013cf","cross_cats_sorted":["cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-01-26T18:24:59Z","title_canon_sha256":"b8b6642fb93ed7751cf512a31e8cc5b284194a39b1b41e59b4d9b354f66a4888"},"schema_version":"1.0","source":{"id":"1801.08926","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1801.08926","created_at":"2026-05-18T00:19:41Z"},{"alias_kind":"arxiv_version","alias_value":"1801.08926v3","created_at":"2026-05-18T00:19:41Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1801.08926","created_at":"2026-05-18T00:19:41Z"},{"alias_kind":"pith_short_12","alias_value":"V2TIFKXQJ5C5","created_at":"2026-05-18T12:32:56Z"},{"alias_kind":"pith_short_16","alias_value":"V2TIFKXQJ5C5M7DA","created_at":"2026-05-18T12:32:56Z"},{"alias_kind":"pith_short_8","alias_value":"V2TIFKXQ","created_at":"2026-05-18T12:32:56Z"}],"graph_snapshots":[{"event_id":"sha256:f0f1f608c46952e5dd2a3754aa2c93bbc1fe90e72b40602cb77e48cf2e231816","target":"graph","created_at":"2026-05-18T00:19:41Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"CNNs are poised to become integral parts of many critical systems. Despite their robustness to natural variations, image pixel values can be manipulated, via small, carefully crafted, imperceptible perturbations, to cause a model to misclassify images. We present an algorithm to process an image so that classification accuracy is significantly preserved in the presence of such adversarial manipulations. Image classifiers tend to be robust to natural noise, and adversarial attacks tend to be agnostic to object location. These observations motivate our strategy, which leverages model robustness ","authors_text":"Aaditya Prakash, Antonella DiLillo, James Storer, Nick Moran, Solomon Garber","cross_cats":["cs.CR"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-01-26T18:24:59Z","title":"Deflecting Adversarial Attacks with Pixel Deflection"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1801.08926","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:1664b851ab469a7f740a7f8e533bb904e02f7c4ac7b81b74244ade6dcedf7270","target":"record","created_at":"2026-05-18T00:19:41Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"282d7daee3ae2e85ce7b555cf15a3fb7af99f1138d3068fd2580e2c29f7013cf","cross_cats_sorted":["cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2018-01-26T18:24:59Z","title_canon_sha256":"b8b6642fb93ed7751cf512a31e8cc5b284194a39b1b41e59b4d9b354f66a4888"},"schema_version":"1.0","source":{"id":"1801.08926","kind":"arxiv","version":3}},"canonical_sha256":"aea682aaf04f45d67c60d6d425bcaf6de43cce68b566f20e2b80bb4725468809","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"aea682aaf04f45d67c60d6d425bcaf6de43cce68b566f20e2b80bb4725468809","first_computed_at":"2026-05-18T00:19:41.176016Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:19:41.176016Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"3ZEbrO6r4OfodkzfGhxZC4J144GlBilLVVjafFkN0ib8LBrBYtXDsZjpY7tSdeIU5W28+7SnHmjQ2objoEA7CA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:19:41.176733Z","signed_message":"canonical_sha256_bytes"},"source_id":"1801.08926","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:1664b851ab469a7f740a7f8e533bb904e02f7c4ac7b81b74244ade6dcedf7270","sha256:f0f1f608c46952e5dd2a3754aa2c93bbc1fe90e72b40602cb77e48cf2e231816"],"state_sha256":"81e8c657a683c5f690bac6576c43848cce5075e3554d0a7bea37def3074b318c"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"0YJsxSjVeQzL+XubTm/yWEoVR1NBCz+lkn9wcLLMHQ9i/rQqeRiTOLez5gVDLUXcuCKJSFEcoH9g8CyCUydnAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T21:39:51.635824Z","bundle_sha256":"f5bf823aab8d39ba39c58a22d9b584e4f6ee060e06c5f16624c9dcbb9af480f4"}}