{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:VHBKJ2FLEMD7JTJLN3FZXLA2PU","short_pith_number":"pith:VHBKJ2FL","canonical_record":{"source":{"id":"1712.08713","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-12-23T04:40:47Z","cross_cats_sorted":["cs.LG","stat.ML"],"title_canon_sha256":"bb7143936d44882dd0e5593661f6c0aedeb6727410f6f790ec21937ae6c3e676","abstract_canon_sha256":"7ebd83aaeb0658ec0ae55e8d59db88f91559bea8d2fd9a95e559393ce9f509a4"},"schema_version":"1.0"},"canonical_sha256":"a9c2a4e8ab2307f4cd2b6ecb9bac1a7d21a6162b4625d3bd67e55d92fdef2498","source":{"kind":"arxiv","id":"1712.08713","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1712.08713","created_at":"2026-05-18T00:27:17Z"},{"alias_kind":"arxiv_version","alias_value":"1712.08713v1","created_at":"2026-05-18T00:27:17Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1712.08713","created_at":"2026-05-18T00:27:17Z"},{"alias_kind":"pith_short_12","alias_value":"VHBKJ2FLEMD7","created_at":"2026-05-18T12:31:49Z"},{"alias_kind":"pith_short_16","alias_value":"VHBKJ2FLEMD7JTJL","created_at":"2026-05-18T12:31:49Z"},{"alias_kind":"pith_short_8","alias_value":"VHBKJ2FL","created_at":"2026-05-18T12:31:49Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:VHBKJ2FLEMD7JTJLN3FZXLA2PU","target":"record","payload":{"canonical_record":{"source":{"id":"1712.08713","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-12-23T04:40:47Z","cross_cats_sorted":["cs.LG","stat.ML"],"title_canon_sha256":"bb7143936d44882dd0e5593661f6c0aedeb6727410f6f790ec21937ae6c3e676","abstract_canon_sha256":"7ebd83aaeb0658ec0ae55e8d59db88f91559bea8d2fd9a95e559393ce9f509a4"},"schema_version":"1.0"},"canonical_sha256":"a9c2a4e8ab2307f4cd2b6ecb9bac1a7d21a6162b4625d3bd67e55d92fdef2498","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:27:17.007252Z","signature_b64":"QG5qW9OIY78FcvUQ9T/PftKR2+zozTAftd6npY6QV8gOH3YO1LnMKo14oiy1wZJxEz70V13ongJNa8ybQxnnBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a9c2a4e8ab2307f4cd2b6ecb9bac1a7d21a6162b4625d3bd67e55d92fdef2498","last_reissued_at":"2026-05-18T00:27:17.006814Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:27:17.006814Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1712.08713","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:27:17Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"qDxtsSqrKMSJKZFNYUBaQnMCBYFpcSFZpVHuJT6x7wWowI55QGXyh1kxxaSPz1WfJbsV2XBNWR5+Zj3q7f+XCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-12T07:53:50.621294Z"},"content_sha256":"c45f0c7a97e4733cce57714aa1b393f80bcdc9525fd827ca77513e704a2098af","schema_version":"1.0","event_id":"sha256:c45f0c7a97e4733cce57714aa1b393f80bcdc9525fd827ca77513e704a2098af"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:VHBKJ2FLEMD7JTJLN3FZXLA2PU","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Query-limited Black-box Attacks to Classifiers","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG","stat.ML"],"primary_cat":"cs.CR","authors_text":"David Evans, Fnu Suya, Paolo Papotti, Yuan Tian","submitted_at":"2017-12-23T04:40:47Z","abstract_excerpt":"We study black-box attacks on machine learning classifiers where each query to the model incurs some cost or risk of detection to the adversary. We focus explicitly on minimizing the number of queries as a major objective. Specifically, we consider the problem of attacking machine learning classifiers subject to a budget of feature modification cost while minimizing the number of queries, where each query returns only a class and confidence score. We describe an approach that uses Bayesian optimization to minimize the number of queries, and find that the number of queries can be reduced to app"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1712.08713","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:27:17Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"AXQ9GK6VLLuercJzsl4ZIBxpvifpAM/Ghlv2/Hsq0Rp3GFrkLNZP6/ApdRNBk4FZbLx4IHqpAOrKF6zJwc2/BQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-12T07:53:50.621670Z"},"content_sha256":"0751bed61b1f6fb31bc24d1215e0f922ba6a94662f18a9c91c642c48fdc91e84","schema_version":"1.0","event_id":"sha256:0751bed61b1f6fb31bc24d1215e0f922ba6a94662f18a9c91c642c48fdc91e84"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/VHBKJ2FLEMD7JTJLN3FZXLA2PU/bundle.json","state_url":"https://pith.science/pith/VHBKJ2FLEMD7JTJLN3FZXLA2PU/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/VHBKJ2FLEMD7JTJLN3FZXLA2PU/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-12T07:53:50Z","links":{"resolver":"https://pith.science/pith/VHBKJ2FLEMD7JTJLN3FZXLA2PU","bundle":"https://pith.science/pith/VHBKJ2FLEMD7JTJLN3FZXLA2PU/bundle.json","state":"https://pith.science/pith/VHBKJ2FLEMD7JTJLN3FZXLA2PU/state.json","well_known_bundle":"https://pith.science/.well-known/pith/VHBKJ2FLEMD7JTJLN3FZXLA2PU/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:VHBKJ2FLEMD7JTJLN3FZXLA2PU","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"7ebd83aaeb0658ec0ae55e8d59db88f91559bea8d2fd9a95e559393ce9f509a4","cross_cats_sorted":["cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-12-23T04:40:47Z","title_canon_sha256":"bb7143936d44882dd0e5593661f6c0aedeb6727410f6f790ec21937ae6c3e676"},"schema_version":"1.0","source":{"id":"1712.08713","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1712.08713","created_at":"2026-05-18T00:27:17Z"},{"alias_kind":"arxiv_version","alias_value":"1712.08713v1","created_at":"2026-05-18T00:27:17Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1712.08713","created_at":"2026-05-18T00:27:17Z"},{"alias_kind":"pith_short_12","alias_value":"VHBKJ2FLEMD7","created_at":"2026-05-18T12:31:49Z"},{"alias_kind":"pith_short_16","alias_value":"VHBKJ2FLEMD7JTJL","created_at":"2026-05-18T12:31:49Z"},{"alias_kind":"pith_short_8","alias_value":"VHBKJ2FL","created_at":"2026-05-18T12:31:49Z"}],"graph_snapshots":[{"event_id":"sha256:0751bed61b1f6fb31bc24d1215e0f922ba6a94662f18a9c91c642c48fdc91e84","target":"graph","created_at":"2026-05-18T00:27:17Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We study black-box attacks on machine learning classifiers where each query to the model incurs some cost or risk of detection to the adversary. We focus explicitly on minimizing the number of queries as a major objective. Specifically, we consider the problem of attacking machine learning classifiers subject to a budget of feature modification cost while minimizing the number of queries, where each query returns only a class and confidence score. We describe an approach that uses Bayesian optimization to minimize the number of queries, and find that the number of queries can be reduced to app","authors_text":"David Evans, Fnu Suya, Paolo Papotti, Yuan Tian","cross_cats":["cs.LG","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-12-23T04:40:47Z","title":"Query-limited Black-box Attacks to Classifiers"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1712.08713","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:c45f0c7a97e4733cce57714aa1b393f80bcdc9525fd827ca77513e704a2098af","target":"record","created_at":"2026-05-18T00:27:17Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"7ebd83aaeb0658ec0ae55e8d59db88f91559bea8d2fd9a95e559393ce9f509a4","cross_cats_sorted":["cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-12-23T04:40:47Z","title_canon_sha256":"bb7143936d44882dd0e5593661f6c0aedeb6727410f6f790ec21937ae6c3e676"},"schema_version":"1.0","source":{"id":"1712.08713","kind":"arxiv","version":1}},"canonical_sha256":"a9c2a4e8ab2307f4cd2b6ecb9bac1a7d21a6162b4625d3bd67e55d92fdef2498","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a9c2a4e8ab2307f4cd2b6ecb9bac1a7d21a6162b4625d3bd67e55d92fdef2498","first_computed_at":"2026-05-18T00:27:17.006814Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:27:17.006814Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"QG5qW9OIY78FcvUQ9T/PftKR2+zozTAftd6npY6QV8gOH3YO1LnMKo14oiy1wZJxEz70V13ongJNa8ybQxnnBw==","signature_status":"signed_v1","signed_at":"2026-05-18T00:27:17.007252Z","signed_message":"canonical_sha256_bytes"},"source_id":"1712.08713","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:c45f0c7a97e4733cce57714aa1b393f80bcdc9525fd827ca77513e704a2098af","sha256:0751bed61b1f6fb31bc24d1215e0f922ba6a94662f18a9c91c642c48fdc91e84"],"state_sha256":"8b160747db190bd0ddce1f819f60aacc83d3bd0f489491e5c4da3898fa420d87"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"B1iIAJMVrHhiJGayv5A7bF/7Gxyai0kz5cRAlaa3s1uoUirB4MTupsRuxCNZjwc2Xgsm8oj6xca5sIpuzFXvDg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-12T07:53:50.623921Z","bundle_sha256":"6514eda94bac324732dda4d3f5b1c17032052de876329e1d6a4dd9313bd0faea"}}