{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:VNOYZ7EJ4DP2XNJ44T6ODRC632","short_pith_number":"pith:VNOYZ7EJ","canonical_record":{"source":{"id":"1809.04913","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-09-13T12:35:18Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"6114df5830d2c677d9ece472cbeb310479481c1abde69b9f221a03fd4e65f3a2","abstract_canon_sha256":"f1d514234495338648f637348046967d82ae628e11bccff052d7f8da2874661a"},"schema_version":"1.0"},"canonical_sha256":"ab5d8cfc89e0dfabb53ce4fce1c45ede86a10f020797bcdf3be72d4ad9abf83c","source":{"kind":"arxiv","id":"1809.04913","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1809.04913","created_at":"2026-05-18T00:05:47Z"},{"alias_kind":"arxiv_version","alias_value":"1809.04913v1","created_at":"2026-05-18T00:05:47Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1809.04913","created_at":"2026-05-18T00:05:47Z"},{"alias_kind":"pith_short_12","alias_value":"VNOYZ7EJ4DP2","created_at":"2026-05-18T12:32:59Z"},{"alias_kind":"pith_short_16","alias_value":"VNOYZ7EJ4DP2XNJ4","created_at":"2026-05-18T12:32:59Z"},{"alias_kind":"pith_short_8","alias_value":"VNOYZ7EJ","created_at":"2026-05-18T12:32:59Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:VNOYZ7EJ4DP2XNJ44T6ODRC632","target":"record","payload":{"canonical_record":{"source":{"id":"1809.04913","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-09-13T12:35:18Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"6114df5830d2c677d9ece472cbeb310479481c1abde69b9f221a03fd4e65f3a2","abstract_canon_sha256":"f1d514234495338648f637348046967d82ae628e11bccff052d7f8da2874661a"},"schema_version":"1.0"},"canonical_sha256":"ab5d8cfc89e0dfabb53ce4fce1c45ede86a10f020797bcdf3be72d4ad9abf83c","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:05:47.125273Z","signature_b64":"xvMlCfGPyPISTrGoYTMRmyD1iAgdnZpCYkcrYEJRXi457FNfS3V0SR5mcjooFI6y5/50KFwGCVz3+O9OREHDCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ab5d8cfc89e0dfabb53ce4fce1c45ede86a10f020797bcdf3be72d4ad9abf83c","last_reissued_at":"2026-05-18T00:05:47.124624Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:05:47.124624Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1809.04913","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:05:47Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"yBm3yaQbdoGGiAAZpOhRHpIPlY8c4B/YtYfPwfC5ZESzoD3wuL0yxGgsyms4Gb2Sc8Xtto5YbnIoq5Mc0ryeDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T19:16:44.244608Z"},"content_sha256":"ebe5dffe7f57a1d4bc2650d992a25a22a1d23ef7a5b55e6580f0a5cca743e152","schema_version":"1.0","event_id":"sha256:ebe5dffe7f57a1d4bc2650d992a25a22a1d23ef7a5b55e6580f0a5cca743e152"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:VNOYZ7EJ4DP2XNJ44T6ODRC632","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Query-Efficient Black-Box Attack by Active Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Jinfeng Yi, Lijun Zhang, Pengcheng Li","submitted_at":"2018-09-13T12:35:18Z","abstract_excerpt":"Deep neural network (DNN) as a popular machine learning model is found to be vulnerable to adversarial attack. This attack constructs adversarial examples by adding small perturbations to the raw input, while appearing unmodified to human eyes but will be misclassified by a well-trained classifier. In this paper, we focus on the black-box attack setting where attackers have almost no access to the underlying models. To conduct black-box attack, a popular approach aims to train a substitute model based on the information queried from the target DNN. The substitute model can then be attacked usi"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1809.04913","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:05:47Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"mJrgObWHuMlznr5/8drmUFB1wVrlEVvsFdEexcW4bihddOJoHEpg8n3b69egemqAO9o3Y1/BUPmg+rAbGrLUCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T19:16:44.245222Z"},"content_sha256":"72587bc9fb0c469bfdbb84d2a199f99c2fb4c56c44da56838fe62cb111027a09","schema_version":"1.0","event_id":"sha256:72587bc9fb0c469bfdbb84d2a199f99c2fb4c56c44da56838fe62cb111027a09"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/VNOYZ7EJ4DP2XNJ44T6ODRC632/bundle.json","state_url":"https://pith.science/pith/VNOYZ7EJ4DP2XNJ44T6ODRC632/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/VNOYZ7EJ4DP2XNJ44T6ODRC632/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T19:16:44Z","links":{"resolver":"https://pith.science/pith/VNOYZ7EJ4DP2XNJ44T6ODRC632","bundle":"https://pith.science/pith/VNOYZ7EJ4DP2XNJ44T6ODRC632/bundle.json","state":"https://pith.science/pith/VNOYZ7EJ4DP2XNJ44T6ODRC632/state.json","well_known_bundle":"https://pith.science/.well-known/pith/VNOYZ7EJ4DP2XNJ44T6ODRC632/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:VNOYZ7EJ4DP2XNJ44T6ODRC632","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"f1d514234495338648f637348046967d82ae628e11bccff052d7f8da2874661a","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-09-13T12:35:18Z","title_canon_sha256":"6114df5830d2c677d9ece472cbeb310479481c1abde69b9f221a03fd4e65f3a2"},"schema_version":"1.0","source":{"id":"1809.04913","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1809.04913","created_at":"2026-05-18T00:05:47Z"},{"alias_kind":"arxiv_version","alias_value":"1809.04913v1","created_at":"2026-05-18T00:05:47Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1809.04913","created_at":"2026-05-18T00:05:47Z"},{"alias_kind":"pith_short_12","alias_value":"VNOYZ7EJ4DP2","created_at":"2026-05-18T12:32:59Z"},{"alias_kind":"pith_short_16","alias_value":"VNOYZ7EJ4DP2XNJ4","created_at":"2026-05-18T12:32:59Z"},{"alias_kind":"pith_short_8","alias_value":"VNOYZ7EJ","created_at":"2026-05-18T12:32:59Z"}],"graph_snapshots":[{"event_id":"sha256:72587bc9fb0c469bfdbb84d2a199f99c2fb4c56c44da56838fe62cb111027a09","target":"graph","created_at":"2026-05-18T00:05:47Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep neural network (DNN) as a popular machine learning model is found to be vulnerable to adversarial attack. This attack constructs adversarial examples by adding small perturbations to the raw input, while appearing unmodified to human eyes but will be misclassified by a well-trained classifier. In this paper, we focus on the black-box attack setting where attackers have almost no access to the underlying models. To conduct black-box attack, a popular approach aims to train a substitute model based on the information queried from the target DNN. The substitute model can then be attacked usi","authors_text":"Jinfeng Yi, Lijun Zhang, Pengcheng Li","cross_cats":["cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-09-13T12:35:18Z","title":"Query-Efficient Black-Box Attack by Active Learning"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1809.04913","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:ebe5dffe7f57a1d4bc2650d992a25a22a1d23ef7a5b55e6580f0a5cca743e152","target":"record","created_at":"2026-05-18T00:05:47Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"f1d514234495338648f637348046967d82ae628e11bccff052d7f8da2874661a","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-09-13T12:35:18Z","title_canon_sha256":"6114df5830d2c677d9ece472cbeb310479481c1abde69b9f221a03fd4e65f3a2"},"schema_version":"1.0","source":{"id":"1809.04913","kind":"arxiv","version":1}},"canonical_sha256":"ab5d8cfc89e0dfabb53ce4fce1c45ede86a10f020797bcdf3be72d4ad9abf83c","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"ab5d8cfc89e0dfabb53ce4fce1c45ede86a10f020797bcdf3be72d4ad9abf83c","first_computed_at":"2026-05-18T00:05:47.124624Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:05:47.124624Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"xvMlCfGPyPISTrGoYTMRmyD1iAgdnZpCYkcrYEJRXi457FNfS3V0SR5mcjooFI6y5/50KFwGCVz3+O9OREHDCQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:05:47.125273Z","signed_message":"canonical_sha256_bytes"},"source_id":"1809.04913","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:ebe5dffe7f57a1d4bc2650d992a25a22a1d23ef7a5b55e6580f0a5cca743e152","sha256:72587bc9fb0c469bfdbb84d2a199f99c2fb4c56c44da56838fe62cb111027a09"],"state_sha256":"03e27cf3bff6b390ac05382689086b68bc0858ed4c77d1cc62c38bbc5586c561"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"YAyMOKqiTddSjxY/nA1ZdnENxzNi3wH+FO8yPDRBfx4bumErXAM65C1bO2tk5qy1gR/B3esVs4RdgIZcsypeAA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T19:16:44.248484Z","bundle_sha256":"592bc99cd04d79711b491fb70bb51deeb39b40905bf1e819d7a8d4c94fda3746"}}