{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:VALOSZTCERTNW56EEOXMK3VXGQ","short_pith_number":"pith:VALOSZTC","canonical_record":{"source":{"id":"1905.13399","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-31T03:32:10Z","cross_cats_sorted":["cs.LG","cs.SD","eess.AS"],"title_canon_sha256":"3151c9e7c47c0af069841b98b1f515206dc8080724f5efd5d3df67daef43b271","abstract_canon_sha256":"94e203a9916fc2593879f85072e1cb7a5d96a839696d0a9181bdbed24bd2770f"},"schema_version":"1.0"},"canonical_sha256":"a816e966622466db77c423aec56eb73426fb02e11743112f6d0a42004412cce5","source":{"kind":"arxiv","id":"1905.13399","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.13399","created_at":"2026-05-17T23:42:41Z"},{"alias_kind":"arxiv_version","alias_value":"1905.13399v2","created_at":"2026-05-17T23:42:41Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.13399","created_at":"2026-05-17T23:42:41Z"},{"alias_kind":"pith_short_12","alias_value":"VALOSZTCERTN","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_16","alias_value":"VALOSZTCERTNW56E","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_8","alias_value":"VALOSZTC","created_at":"2026-05-18T12:33:30Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:VALOSZTCERTNW56EEOXMK3VXGQ","target":"record","payload":{"canonical_record":{"source":{"id":"1905.13399","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-31T03:32:10Z","cross_cats_sorted":["cs.LG","cs.SD","eess.AS"],"title_canon_sha256":"3151c9e7c47c0af069841b98b1f515206dc8080724f5efd5d3df67daef43b271","abstract_canon_sha256":"94e203a9916fc2593879f85072e1cb7a5d96a839696d0a9181bdbed24bd2770f"},"schema_version":"1.0"},"canonical_sha256":"a816e966622466db77c423aec56eb73426fb02e11743112f6d0a42004412cce5","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:42:41.512673Z","signature_b64":"R9MgnZ3l4zqqtIehs81TnnyyLh+Qg1CCH2UKEdWwIJt4psUE2ALRQio0X2wkSZmqxzeGCSbSEybBgNrvhzRBAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a816e966622466db77c423aec56eb73426fb02e11743112f6d0a42004412cce5","last_reissued_at":"2026-05-17T23:42:41.511951Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:42:41.511951Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1905.13399","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:42:41Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"I9YqG0gp5PNvFLKcAyUfbhHWuRrs/A8MQjaX/m3PbrglPzSWF7qPW433L+svF23bZPoK6eaOpKbEgtb+kXTAAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T20:56:07.128334Z"},"content_sha256":"073820bad560229095728556aa88fdf0b06992fcbb0142ff6187a7b71ce72232","schema_version":"1.0","event_id":"sha256:073820bad560229095728556aa88fdf0b06992fcbb0142ff6187a7b71ce72232"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:VALOSZTCERTNW56EEOXMK3VXGQ","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Real-Time Adversarial Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG","cs.SD","eess.AS"],"primary_cat":"cs.CR","authors_text":"Boyang Li, Christian Poellabauer, Yiyu Shi, Yuan Gong","submitted_at":"2019-05-31T03:32:10Z","abstract_excerpt":"In recent years, many efforts have demonstrated that modern machine learning algorithms are vulnerable to adversarial attacks, where small, but carefully crafted, perturbations on the input can make them fail. While these attack methods are very effective, they only focus on scenarios where the target model takes static input, i.e., an attacker can observe the entire original sample and then add a perturbation at any point of the sample. These attack approaches are not applicable to situations where the target model takes streaming input, i.e., an attacker is only able to observe past data poi"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.13399","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:42:41Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"SYHj85mLLPrYwopi/PY41pR7oY9yKb5QHH7VTNR7mvalxrXe+FVjqlWfw7d/AoKCB6RL0Y9Rn9NMakFIp+2QBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T20:56:07.128728Z"},"content_sha256":"64be194b5986f0e146ff35fcb70bea76da592686562c68124b2946f2b0f093ca","schema_version":"1.0","event_id":"sha256:64be194b5986f0e146ff35fcb70bea76da592686562c68124b2946f2b0f093ca"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/VALOSZTCERTNW56EEOXMK3VXGQ/bundle.json","state_url":"https://pith.science/pith/VALOSZTCERTNW56EEOXMK3VXGQ/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/VALOSZTCERTNW56EEOXMK3VXGQ/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-30T20:56:07Z","links":{"resolver":"https://pith.science/pith/VALOSZTCERTNW56EEOXMK3VXGQ","bundle":"https://pith.science/pith/VALOSZTCERTNW56EEOXMK3VXGQ/bundle.json","state":"https://pith.science/pith/VALOSZTCERTNW56EEOXMK3VXGQ/state.json","well_known_bundle":"https://pith.science/.well-known/pith/VALOSZTCERTNW56EEOXMK3VXGQ/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:VALOSZTCERTNW56EEOXMK3VXGQ","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"94e203a9916fc2593879f85072e1cb7a5d96a839696d0a9181bdbed24bd2770f","cross_cats_sorted":["cs.LG","cs.SD","eess.AS"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-31T03:32:10Z","title_canon_sha256":"3151c9e7c47c0af069841b98b1f515206dc8080724f5efd5d3df67daef43b271"},"schema_version":"1.0","source":{"id":"1905.13399","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.13399","created_at":"2026-05-17T23:42:41Z"},{"alias_kind":"arxiv_version","alias_value":"1905.13399v2","created_at":"2026-05-17T23:42:41Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.13399","created_at":"2026-05-17T23:42:41Z"},{"alias_kind":"pith_short_12","alias_value":"VALOSZTCERTN","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_16","alias_value":"VALOSZTCERTNW56E","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_8","alias_value":"VALOSZTC","created_at":"2026-05-18T12:33:30Z"}],"graph_snapshots":[{"event_id":"sha256:64be194b5986f0e146ff35fcb70bea76da592686562c68124b2946f2b0f093ca","target":"graph","created_at":"2026-05-17T23:42:41Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"In recent years, many efforts have demonstrated that modern machine learning algorithms are vulnerable to adversarial attacks, where small, but carefully crafted, perturbations on the input can make them fail. While these attack methods are very effective, they only focus on scenarios where the target model takes static input, i.e., an attacker can observe the entire original sample and then add a perturbation at any point of the sample. These attack approaches are not applicable to situations where the target model takes streaming input, i.e., an attacker is only able to observe past data poi","authors_text":"Boyang Li, Christian Poellabauer, Yiyu Shi, Yuan Gong","cross_cats":["cs.LG","cs.SD","eess.AS"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-31T03:32:10Z","title":"Real-Time Adversarial Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.13399","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:073820bad560229095728556aa88fdf0b06992fcbb0142ff6187a7b71ce72232","target":"record","created_at":"2026-05-17T23:42:41Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"94e203a9916fc2593879f85072e1cb7a5d96a839696d0a9181bdbed24bd2770f","cross_cats_sorted":["cs.LG","cs.SD","eess.AS"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-05-31T03:32:10Z","title_canon_sha256":"3151c9e7c47c0af069841b98b1f515206dc8080724f5efd5d3df67daef43b271"},"schema_version":"1.0","source":{"id":"1905.13399","kind":"arxiv","version":2}},"canonical_sha256":"a816e966622466db77c423aec56eb73426fb02e11743112f6d0a42004412cce5","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a816e966622466db77c423aec56eb73426fb02e11743112f6d0a42004412cce5","first_computed_at":"2026-05-17T23:42:41.511951Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:42:41.511951Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"R9MgnZ3l4zqqtIehs81TnnyyLh+Qg1CCH2UKEdWwIJt4psUE2ALRQio0X2wkSZmqxzeGCSbSEybBgNrvhzRBAg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:42:41.512673Z","signed_message":"canonical_sha256_bytes"},"source_id":"1905.13399","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:073820bad560229095728556aa88fdf0b06992fcbb0142ff6187a7b71ce72232","sha256:64be194b5986f0e146ff35fcb70bea76da592686562c68124b2946f2b0f093ca"],"state_sha256":"6e0507af21fa204185fc19af969d504b02f719bc0bc5c23a5e3cce48c024d393"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"R6zfTqcAVL7/TICFg7wKp00bwqlwiL1c51WEBu4KZe4mtoK3UNiKF13PutDf3z31FPphOSpC17AvreHVvyOBCQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-30T20:56:07.130914Z","bundle_sha256":"d0f68e20c91e70428d583ef0f4a51def68411a2a141a160c97e0dcac41ec4908"}}