{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:VERUG3JJ5VMQYMOMGHJHRRDQIU","short_pith_number":"pith:VERUG3JJ","canonical_record":{"source":{"id":"1907.11780","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-07-26T20:05:19Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"8fcd5374b93740cda01cab9ded3db91f35f42261f6b3d4a0bfb6591b5838f3db","abstract_canon_sha256":"9a3b5b0b5bee1b00e91e443785ca4f7273e66b61eadd30f8476e31b4acb27384"},"schema_version":"1.0"},"canonical_sha256":"a923436d29ed590c31cc31d278c470452da830c40372d8963c52560809e33e52","source":{"kind":"arxiv","id":"1907.11780","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1907.11780","created_at":"2026-05-17T23:39:23Z"},{"alias_kind":"arxiv_version","alias_value":"1907.11780v1","created_at":"2026-05-17T23:39:23Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1907.11780","created_at":"2026-05-17T23:39:23Z"},{"alias_kind":"pith_short_12","alias_value":"VERUG3JJ5VMQ","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_16","alias_value":"VERUG3JJ5VMQYMOM","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_8","alias_value":"VERUG3JJ","created_at":"2026-05-18T12:33:30Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:VERUG3JJ5VMQYMOMGHJHRRDQIU","target":"record","payload":{"canonical_record":{"source":{"id":"1907.11780","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-07-26T20:05:19Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"8fcd5374b93740cda01cab9ded3db91f35f42261f6b3d4a0bfb6591b5838f3db","abstract_canon_sha256":"9a3b5b0b5bee1b00e91e443785ca4f7273e66b61eadd30f8476e31b4acb27384"},"schema_version":"1.0"},"canonical_sha256":"a923436d29ed590c31cc31d278c470452da830c40372d8963c52560809e33e52","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:39:23.085511Z","signature_b64":"ycFqQuQ26jJXDcrKt8dLOHd17iyW81TnJ7sjHz2k8s413y31IDD9o4+ZlRHoI7+RBSVIfOSXFqjtyaDNvpFdCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a923436d29ed590c31cc31d278c470452da830c40372d8963c52560809e33e52","last_reissued_at":"2026-05-17T23:39:23.084812Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:39:23.084812Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1907.11780","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:39:23Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"WyeNXdxqLwAk2C3fRTWc8sYRqdfqGTnqyvf2CSvmu++zEoVae14o7ZadH+D0h71GyrGeJuwaFSSniCyz73NQCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-05T09:48:38.502852Z"},"content_sha256":"2d295c50417d64741f0a1379301500a960eafde73d4c13f5817aed196bf8af52","schema_version":"1.0","event_id":"sha256:2d295c50417d64741f0a1379301500a960eafde73d4c13f5817aed196bf8af52"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:VERUG3JJ5VMQYMOMGHJHRRDQIU","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Understanding Adversarial Robustness: The Trade-off between Minimum and Average Margin","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Kaiwen Wu, Yaoliang Yu","submitted_at":"2019-07-26T20:05:19Z","abstract_excerpt":"Deep models, while being extremely versatile and accurate, are vulnerable to adversarial attacks: slight perturbations that are imperceptible to humans can completely flip the prediction of deep models. Many attack and defense mechanisms have been proposed, although a satisfying solution still largely remains elusive. In this work, we give strong evidence that during training, deep models maximize the minimum margin in order to achieve high accuracy, but at the same time decrease the \\emph{average} margin hence hurting robustness. Our empirical results highlight an intrinsic trade-off between "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1907.11780","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:39:23Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"MaKWhCdrVVJmuraXqTRDtQk4Dedd1JNaiJxaCg9rAKDB29z/h2l0Lt9AAfUYO/df7cBZtoTP12Bat1w2iFC5Dw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-05T09:48:38.503206Z"},"content_sha256":"b22148be2c5e43de201875f8f814ada944a246eb95e5a1e03352b2ce83b6edba","schema_version":"1.0","event_id":"sha256:b22148be2c5e43de201875f8f814ada944a246eb95e5a1e03352b2ce83b6edba"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/VERUG3JJ5VMQYMOMGHJHRRDQIU/bundle.json","state_url":"https://pith.science/pith/VERUG3JJ5VMQYMOMGHJHRRDQIU/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/VERUG3JJ5VMQYMOMGHJHRRDQIU/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-05T09:48:38Z","links":{"resolver":"https://pith.science/pith/VERUG3JJ5VMQYMOMGHJHRRDQIU","bundle":"https://pith.science/pith/VERUG3JJ5VMQYMOMGHJHRRDQIU/bundle.json","state":"https://pith.science/pith/VERUG3JJ5VMQYMOMGHJHRRDQIU/state.json","well_known_bundle":"https://pith.science/.well-known/pith/VERUG3JJ5VMQYMOMGHJHRRDQIU/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:VERUG3JJ5VMQYMOMGHJHRRDQIU","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"9a3b5b0b5bee1b00e91e443785ca4f7273e66b61eadd30f8476e31b4acb27384","cross_cats_sorted":["stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-07-26T20:05:19Z","title_canon_sha256":"8fcd5374b93740cda01cab9ded3db91f35f42261f6b3d4a0bfb6591b5838f3db"},"schema_version":"1.0","source":{"id":"1907.11780","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1907.11780","created_at":"2026-05-17T23:39:23Z"},{"alias_kind":"arxiv_version","alias_value":"1907.11780v1","created_at":"2026-05-17T23:39:23Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1907.11780","created_at":"2026-05-17T23:39:23Z"},{"alias_kind":"pith_short_12","alias_value":"VERUG3JJ5VMQ","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_16","alias_value":"VERUG3JJ5VMQYMOM","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_8","alias_value":"VERUG3JJ","created_at":"2026-05-18T12:33:30Z"}],"graph_snapshots":[{"event_id":"sha256:b22148be2c5e43de201875f8f814ada944a246eb95e5a1e03352b2ce83b6edba","target":"graph","created_at":"2026-05-17T23:39:23Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep models, while being extremely versatile and accurate, are vulnerable to adversarial attacks: slight perturbations that are imperceptible to humans can completely flip the prediction of deep models. Many attack and defense mechanisms have been proposed, although a satisfying solution still largely remains elusive. In this work, we give strong evidence that during training, deep models maximize the minimum margin in order to achieve high accuracy, but at the same time decrease the \\emph{average} margin hence hurting robustness. Our empirical results highlight an intrinsic trade-off between ","authors_text":"Kaiwen Wu, Yaoliang Yu","cross_cats":["stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-07-26T20:05:19Z","title":"Understanding Adversarial Robustness: The Trade-off between Minimum and Average Margin"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1907.11780","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:2d295c50417d64741f0a1379301500a960eafde73d4c13f5817aed196bf8af52","target":"record","created_at":"2026-05-17T23:39:23Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"9a3b5b0b5bee1b00e91e443785ca4f7273e66b61eadd30f8476e31b4acb27384","cross_cats_sorted":["stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-07-26T20:05:19Z","title_canon_sha256":"8fcd5374b93740cda01cab9ded3db91f35f42261f6b3d4a0bfb6591b5838f3db"},"schema_version":"1.0","source":{"id":"1907.11780","kind":"arxiv","version":1}},"canonical_sha256":"a923436d29ed590c31cc31d278c470452da830c40372d8963c52560809e33e52","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a923436d29ed590c31cc31d278c470452da830c40372d8963c52560809e33e52","first_computed_at":"2026-05-17T23:39:23.084812Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:39:23.084812Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"ycFqQuQ26jJXDcrKt8dLOHd17iyW81TnJ7sjHz2k8s413y31IDD9o4+ZlRHoI7+RBSVIfOSXFqjtyaDNvpFdCg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:39:23.085511Z","signed_message":"canonical_sha256_bytes"},"source_id":"1907.11780","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:2d295c50417d64741f0a1379301500a960eafde73d4c13f5817aed196bf8af52","sha256:b22148be2c5e43de201875f8f814ada944a246eb95e5a1e03352b2ce83b6edba"],"state_sha256":"3e39622acd6df3193214296327ead4c25f8d872fddbd7a0a8d7484e77697bdf0"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"U1LpAT49Qv5Ue8f4Fg7UEx6ckmWGUnOnlkFIQqYTYlsgtDb5/PLJtv8iAWYAeOZKVkOaaSPFk8dUfZV20lRJCA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-05T09:48:38.505616Z","bundle_sha256":"f516d9e215fe00486276a10bdf422dc22e5a13291f2166de2e25416c8e30e4a0"}}