{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:VH2PPIKD6LHQEFGPQSLLVBTTLO","short_pith_number":"pith:VH2PPIKD","canonical_record":{"source":{"id":"1902.03151","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-02-08T15:38:24Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"72971688bdc1bd17e0fd716e25b0226b94d2733769eca7f191e0bed8f8cb2a86","abstract_canon_sha256":"89c42a869fa578082801fe032d081a36921fb10718ea57a255ff80f20483563e"},"schema_version":"1.0"},"canonical_sha256":"a9f4f7a143f2cf0214cf8496ba86735badf6550d264264da5b5ce269fac09a9f","source":{"kind":"arxiv","id":"1902.03151","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1902.03151","created_at":"2026-05-17T23:44:29Z"},{"alias_kind":"arxiv_version","alias_value":"1902.03151v2","created_at":"2026-05-17T23:44:29Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1902.03151","created_at":"2026-05-17T23:44:29Z"},{"alias_kind":"pith_short_12","alias_value":"VH2PPIKD6LHQ","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_16","alias_value":"VH2PPIKD6LHQEFGP","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_8","alias_value":"VH2PPIKD","created_at":"2026-05-18T12:33:30Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:VH2PPIKD6LHQEFGPQSLLVBTTLO","target":"record","payload":{"canonical_record":{"source":{"id":"1902.03151","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-02-08T15:38:24Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"72971688bdc1bd17e0fd716e25b0226b94d2733769eca7f191e0bed8f8cb2a86","abstract_canon_sha256":"89c42a869fa578082801fe032d081a36921fb10718ea57a255ff80f20483563e"},"schema_version":"1.0"},"canonical_sha256":"a9f4f7a143f2cf0214cf8496ba86735badf6550d264264da5b5ce269fac09a9f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:44:29.412438Z","signature_b64":"fn7ZQiPqTtP0ISBF6e6/1/DGvUTvAE/9vAAh/I4jcH17lsK4ZygGUfPYk4/hLUXs4mR2ZC1mPBM1jxHEZUHCBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a9f4f7a143f2cf0214cf8496ba86735badf6550d264264da5b5ce269fac09a9f","last_reissued_at":"2026-05-17T23:44:29.411740Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:44:29.411740Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1902.03151","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:44:29Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8MAagWVFi4syNZnOw4h8xJTUR/Tg+LLCd+qBenI4h3M+suvV/yhv5JGJ0OyTuNByyIkGwo8szvckwBebeOltDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T19:10:41.007503Z"},"content_sha256":"c0a7263f6f3a3b61b4a19f87805d00bf1cf8f136549641928d8ade1824ea3c4e","schema_version":"1.0","event_id":"sha256:c0a7263f6f3a3b61b4a19f87805d00bf1cf8f136549641928d8ade1824ea3c4e"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:VH2PPIKD6LHQEFGPQSLLVBTTLO","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Discretization based Solutions for Secure Machine Learning against Adversarial Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Indranil Chakraborty, Kaushik Roy, Priyadarshini Panda","submitted_at":"2019-02-08T15:38:24Z","abstract_excerpt":"Adversarial examples are perturbed inputs that are designed (from a deep learning network's (DLN) parameter gradients) to mislead the DLN during test time. Intuitively, constraining the dimensionality of inputs or parameters of a network reduces the 'space' in which adversarial examples exist. Guided by this intuition, we demonstrate that discretization greatly improves the robustness of DLNs against adversarial attacks. Specifically, discretizing the input space (or allowed pixel levels from 256 values or 8-bit to 4 values or 2-bit) extensively improves the adversarial robustness of DLNs for "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1902.03151","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:44:29Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"sBP7aWYpRZKchkKQxWshhKt73CamojYfRADCI03n5rHvEpAYBOVA8W2F6S5tTkEEiuUMQTlxW/qz9ajDWox1Aw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T19:10:41.007895Z"},"content_sha256":"6ad213679aa9f55bdaace1a97ae991533693aa0ab562b0ef17f2fdd438b6d419","schema_version":"1.0","event_id":"sha256:6ad213679aa9f55bdaace1a97ae991533693aa0ab562b0ef17f2fdd438b6d419"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/VH2PPIKD6LHQEFGPQSLLVBTTLO/bundle.json","state_url":"https://pith.science/pith/VH2PPIKD6LHQEFGPQSLLVBTTLO/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/VH2PPIKD6LHQEFGPQSLLVBTTLO/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T19:10:41Z","links":{"resolver":"https://pith.science/pith/VH2PPIKD6LHQEFGPQSLLVBTTLO","bundle":"https://pith.science/pith/VH2PPIKD6LHQEFGPQSLLVBTTLO/bundle.json","state":"https://pith.science/pith/VH2PPIKD6LHQEFGPQSLLVBTTLO/state.json","well_known_bundle":"https://pith.science/.well-known/pith/VH2PPIKD6LHQEFGPQSLLVBTTLO/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:VH2PPIKD6LHQEFGPQSLLVBTTLO","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"89c42a869fa578082801fe032d081a36921fb10718ea57a255ff80f20483563e","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-02-08T15:38:24Z","title_canon_sha256":"72971688bdc1bd17e0fd716e25b0226b94d2733769eca7f191e0bed8f8cb2a86"},"schema_version":"1.0","source":{"id":"1902.03151","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1902.03151","created_at":"2026-05-17T23:44:29Z"},{"alias_kind":"arxiv_version","alias_value":"1902.03151v2","created_at":"2026-05-17T23:44:29Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1902.03151","created_at":"2026-05-17T23:44:29Z"},{"alias_kind":"pith_short_12","alias_value":"VH2PPIKD6LHQ","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_16","alias_value":"VH2PPIKD6LHQEFGP","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_8","alias_value":"VH2PPIKD","created_at":"2026-05-18T12:33:30Z"}],"graph_snapshots":[{"event_id":"sha256:6ad213679aa9f55bdaace1a97ae991533693aa0ab562b0ef17f2fdd438b6d419","target":"graph","created_at":"2026-05-17T23:44:29Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Adversarial examples are perturbed inputs that are designed (from a deep learning network's (DLN) parameter gradients) to mislead the DLN during test time. Intuitively, constraining the dimensionality of inputs or parameters of a network reduces the 'space' in which adversarial examples exist. Guided by this intuition, we demonstrate that discretization greatly improves the robustness of DLNs against adversarial attacks. Specifically, discretizing the input space (or allowed pixel levels from 256 values or 8-bit to 4 values or 2-bit) extensively improves the adversarial robustness of DLNs for ","authors_text":"Indranil Chakraborty, Kaushik Roy, Priyadarshini Panda","cross_cats":["cs.CR","cs.CV","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-02-08T15:38:24Z","title":"Discretization based Solutions for Secure Machine Learning against Adversarial Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1902.03151","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:c0a7263f6f3a3b61b4a19f87805d00bf1cf8f136549641928d8ade1824ea3c4e","target":"record","created_at":"2026-05-17T23:44:29Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"89c42a869fa578082801fe032d081a36921fb10718ea57a255ff80f20483563e","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-02-08T15:38:24Z","title_canon_sha256":"72971688bdc1bd17e0fd716e25b0226b94d2733769eca7f191e0bed8f8cb2a86"},"schema_version":"1.0","source":{"id":"1902.03151","kind":"arxiv","version":2}},"canonical_sha256":"a9f4f7a143f2cf0214cf8496ba86735badf6550d264264da5b5ce269fac09a9f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a9f4f7a143f2cf0214cf8496ba86735badf6550d264264da5b5ce269fac09a9f","first_computed_at":"2026-05-17T23:44:29.411740Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:44:29.411740Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"fn7ZQiPqTtP0ISBF6e6/1/DGvUTvAE/9vAAh/I4jcH17lsK4ZygGUfPYk4/hLUXs4mR2ZC1mPBM1jxHEZUHCBg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:44:29.412438Z","signed_message":"canonical_sha256_bytes"},"source_id":"1902.03151","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:c0a7263f6f3a3b61b4a19f87805d00bf1cf8f136549641928d8ade1824ea3c4e","sha256:6ad213679aa9f55bdaace1a97ae991533693aa0ab562b0ef17f2fdd438b6d419"],"state_sha256":"05cfd45dbc1331fa66797f42435c3482ab582788a29b5c3fe4ef379a655feaeb"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"34KwLqh6ZcV3oAq3aMx81DdoQuJm1R6yg5/5VqqSiO0n1blOSkTwPaDM4jOUfRih1JZdmnXyAwHjgROsfWxnAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T19:10:41.011119Z","bundle_sha256":"689d82da202c85bf3544296d7ab1544a46f055cc3bcd4efecbd9fca13ede190b"}}