{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:VCZQVDQGBVSDU3A5IDUC7JWWYL","short_pith_number":"pith:VCZQVDQG","canonical_record":{"source":{"id":"1809.05165","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-09-13T20:26:32Z","cross_cats_sorted":["cs.CV","cs.LG","stat.ML"],"title_canon_sha256":"f0e6e9249777a42fed57f44c3dbde909f59fe418a509d950aad59daa65d2788b","abstract_canon_sha256":"27efe9462a79d408d67b8451aae7a7a1ad3564ef5b3e52c7f5990d7605670af2"},"schema_version":"1.0"},"canonical_sha256":"a8b30a8e060d643a6c1d40e82fa6d6c2ec91ff77fb3e3616997d58bb01a82fee","source":{"kind":"arxiv","id":"1809.05165","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1809.05165","created_at":"2026-05-18T00:05:44Z"},{"alias_kind":"arxiv_version","alias_value":"1809.05165v1","created_at":"2026-05-18T00:05:44Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1809.05165","created_at":"2026-05-18T00:05:44Z"},{"alias_kind":"pith_short_12","alias_value":"VCZQVDQGBVSD","created_at":"2026-05-18T12:32:59Z"},{"alias_kind":"pith_short_16","alias_value":"VCZQVDQGBVSDU3A5","created_at":"2026-05-18T12:32:59Z"},{"alias_kind":"pith_short_8","alias_value":"VCZQVDQG","created_at":"2026-05-18T12:32:59Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:VCZQVDQGBVSDU3A5IDUC7JWWYL","target":"record","payload":{"canonical_record":{"source":{"id":"1809.05165","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-09-13T20:26:32Z","cross_cats_sorted":["cs.CV","cs.LG","stat.ML"],"title_canon_sha256":"f0e6e9249777a42fed57f44c3dbde909f59fe418a509d950aad59daa65d2788b","abstract_canon_sha256":"27efe9462a79d408d67b8451aae7a7a1ad3564ef5b3e52c7f5990d7605670af2"},"schema_version":"1.0"},"canonical_sha256":"a8b30a8e060d643a6c1d40e82fa6d6c2ec91ff77fb3e3616997d58bb01a82fee","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:05:44.583804Z","signature_b64":"F6d/hBLzuZme5naMvmNIGMBJyIiH8CR8PkjVuuBAPSU551gIVPRQbrW94SNfYrXFtfWdt6tNJyTKBe/huIl2DQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a8b30a8e060d643a6c1d40e82fa6d6c2ec91ff77fb3e3616997d58bb01a82fee","last_reissued_at":"2026-05-18T00:05:44.583139Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:05:44.583139Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1809.05165","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:05:44Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"j8iExLJJKvuEVgRQox8I4jZKSCLhQF1gyM1pEQPcOpbceqvLoddD/hmKMcH08RsS+T/yCfwRsD3riUaS0yMhDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T17:41:20.350341Z"},"content_sha256":"468d0186e0cc345fe326c4b23e262f86488aebd77aecf989d484ac71ce1bdd89","schema_version":"1.0","event_id":"sha256:468d0186e0cc345fe326c4b23e262f86488aebd77aecf989d484ac71ce1bdd89"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:VCZQVDQGBVSDU3A5IDUC7JWWYL","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Defensive Dropout for Hardening Deep Neural Networks under Adversarial Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","cs.LG","stat.ML"],"primary_cat":"cs.CR","authors_text":"David Kaeli, Peter Chin, Pu Zhao, Siyue Wang, Wujie Wen, Xiao Wang, Xue Lin","submitted_at":"2018-09-13T20:26:32Z","abstract_excerpt":"Deep neural networks (DNNs) are known vulnerable to adversarial attacks. That is, adversarial examples, obtained by adding delicately crafted distortions onto original legal inputs, can mislead a DNN to classify them as any target labels. This work provides a solution to hardening DNNs under adversarial attacks through defensive dropout. Besides using dropout during training for the best test accuracy, we propose to use dropout also at test time to achieve strong defense effects. We consider the problem of building robust DNNs as an attacker-defender two-player game, where the attacker and the"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1809.05165","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:05:44Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Xkl+g6OneIO0CI828nnlOghQyCPK8EKm+ESc/LbxFkZJr58Cc2SBdELUo6WCeIwIwRLuwXi/PB3jdUzaeXONDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T17:41:20.350697Z"},"content_sha256":"97107aa96d90b04cc1e3823e19248a4bbdafbd83e237f4533fa4575ed578c621","schema_version":"1.0","event_id":"sha256:97107aa96d90b04cc1e3823e19248a4bbdafbd83e237f4533fa4575ed578c621"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/VCZQVDQGBVSDU3A5IDUC7JWWYL/bundle.json","state_url":"https://pith.science/pith/VCZQVDQGBVSDU3A5IDUC7JWWYL/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/VCZQVDQGBVSDU3A5IDUC7JWWYL/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-01T17:41:20Z","links":{"resolver":"https://pith.science/pith/VCZQVDQGBVSDU3A5IDUC7JWWYL","bundle":"https://pith.science/pith/VCZQVDQGBVSDU3A5IDUC7JWWYL/bundle.json","state":"https://pith.science/pith/VCZQVDQGBVSDU3A5IDUC7JWWYL/state.json","well_known_bundle":"https://pith.science/.well-known/pith/VCZQVDQGBVSDU3A5IDUC7JWWYL/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:VCZQVDQGBVSDU3A5IDUC7JWWYL","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"27efe9462a79d408d67b8451aae7a7a1ad3564ef5b3e52c7f5990d7605670af2","cross_cats_sorted":["cs.CV","cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-09-13T20:26:32Z","title_canon_sha256":"f0e6e9249777a42fed57f44c3dbde909f59fe418a509d950aad59daa65d2788b"},"schema_version":"1.0","source":{"id":"1809.05165","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1809.05165","created_at":"2026-05-18T00:05:44Z"},{"alias_kind":"arxiv_version","alias_value":"1809.05165v1","created_at":"2026-05-18T00:05:44Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1809.05165","created_at":"2026-05-18T00:05:44Z"},{"alias_kind":"pith_short_12","alias_value":"VCZQVDQGBVSD","created_at":"2026-05-18T12:32:59Z"},{"alias_kind":"pith_short_16","alias_value":"VCZQVDQGBVSDU3A5","created_at":"2026-05-18T12:32:59Z"},{"alias_kind":"pith_short_8","alias_value":"VCZQVDQG","created_at":"2026-05-18T12:32:59Z"}],"graph_snapshots":[{"event_id":"sha256:97107aa96d90b04cc1e3823e19248a4bbdafbd83e237f4533fa4575ed578c621","target":"graph","created_at":"2026-05-18T00:05:44Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep neural networks (DNNs) are known vulnerable to adversarial attacks. That is, adversarial examples, obtained by adding delicately crafted distortions onto original legal inputs, can mislead a DNN to classify them as any target labels. This work provides a solution to hardening DNNs under adversarial attacks through defensive dropout. Besides using dropout during training for the best test accuracy, we propose to use dropout also at test time to achieve strong defense effects. We consider the problem of building robust DNNs as an attacker-defender two-player game, where the attacker and the","authors_text":"David Kaeli, Peter Chin, Pu Zhao, Siyue Wang, Wujie Wen, Xiao Wang, Xue Lin","cross_cats":["cs.CV","cs.LG","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-09-13T20:26:32Z","title":"Defensive Dropout for Hardening Deep Neural Networks under Adversarial Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1809.05165","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:468d0186e0cc345fe326c4b23e262f86488aebd77aecf989d484ac71ce1bdd89","target":"record","created_at":"2026-05-18T00:05:44Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"27efe9462a79d408d67b8451aae7a7a1ad3564ef5b3e52c7f5990d7605670af2","cross_cats_sorted":["cs.CV","cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-09-13T20:26:32Z","title_canon_sha256":"f0e6e9249777a42fed57f44c3dbde909f59fe418a509d950aad59daa65d2788b"},"schema_version":"1.0","source":{"id":"1809.05165","kind":"arxiv","version":1}},"canonical_sha256":"a8b30a8e060d643a6c1d40e82fa6d6c2ec91ff77fb3e3616997d58bb01a82fee","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a8b30a8e060d643a6c1d40e82fa6d6c2ec91ff77fb3e3616997d58bb01a82fee","first_computed_at":"2026-05-18T00:05:44.583139Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:05:44.583139Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"F6d/hBLzuZme5naMvmNIGMBJyIiH8CR8PkjVuuBAPSU551gIVPRQbrW94SNfYrXFtfWdt6tNJyTKBe/huIl2DQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:05:44.583804Z","signed_message":"canonical_sha256_bytes"},"source_id":"1809.05165","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:468d0186e0cc345fe326c4b23e262f86488aebd77aecf989d484ac71ce1bdd89","sha256:97107aa96d90b04cc1e3823e19248a4bbdafbd83e237f4533fa4575ed578c621"],"state_sha256":"fb47ffac54461e529f19bffc76f767e9e3daf0c995ae639847b40c6486661f65"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8GhKsJkfEJXUTV4cbkDybeyX4J+lRvoWo75ag/oRLQdSiP2G+JBrRYiJoB7amPvOXfPl/TrWyqE/wkH2b7aJDw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-01T17:41:20.353105Z","bundle_sha256":"df08218f828e6c5c4ebf1660353c0d00445cb8c3e2ba3b3433bb6d064dc97594"}}