{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2016:VP6D7NNNKDDZRUQEGA6UDPY2MA","short_pith_number":"pith:VP6D7NNN","canonical_record":{"source":{"id":"1606.04435","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-06-14T16:01:52Z","cross_cats_sorted":["cs.LG","cs.NE"],"title_canon_sha256":"91059ea02704b4e2ef1ec09fa8c9c54eb4c06158e54bfab680d5f08d734d742f","abstract_canon_sha256":"815f169994a1be763cb2aadbfbbe551149b717d3245bef2cfb3e89b3281d96ba"},"schema_version":"1.0"},"canonical_sha256":"abfc3fb5ad50c798d204303d41bf1a60241bcc7a193eaee2898b9d6b03b3bba8","source":{"kind":"arxiv","id":"1606.04435","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1606.04435","created_at":"2026-05-18T01:12:22Z"},{"alias_kind":"arxiv_version","alias_value":"1606.04435v2","created_at":"2026-05-18T01:12:22Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1606.04435","created_at":"2026-05-18T01:12:22Z"},{"alias_kind":"pith_short_12","alias_value":"VP6D7NNNKDDZ","created_at":"2026-05-18T12:30:48Z"},{"alias_kind":"pith_short_16","alias_value":"VP6D7NNNKDDZRUQE","created_at":"2026-05-18T12:30:48Z"},{"alias_kind":"pith_short_8","alias_value":"VP6D7NNN","created_at":"2026-05-18T12:30:48Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2016:VP6D7NNNKDDZRUQEGA6UDPY2MA","target":"record","payload":{"canonical_record":{"source":{"id":"1606.04435","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-06-14T16:01:52Z","cross_cats_sorted":["cs.LG","cs.NE"],"title_canon_sha256":"91059ea02704b4e2ef1ec09fa8c9c54eb4c06158e54bfab680d5f08d734d742f","abstract_canon_sha256":"815f169994a1be763cb2aadbfbbe551149b717d3245bef2cfb3e89b3281d96ba"},"schema_version":"1.0"},"canonical_sha256":"abfc3fb5ad50c798d204303d41bf1a60241bcc7a193eaee2898b9d6b03b3bba8","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T01:12:22.344424Z","signature_b64":"JS/r4PvP/R3hx6SUHqI3vj5aYMMTUyxYjoM9i4ImvEa4YhL5W71cubvLQ7dsQPZ4N2Zk4gz0uXUlC1vtcLSxDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"abfc3fb5ad50c798d204303d41bf1a60241bcc7a193eaee2898b9d6b03b3bba8","last_reissued_at":"2026-05-18T01:12:22.344086Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T01:12:22.344086Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1606.04435","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T01:12:22Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"3oCvWZ8CVLaj2Bn+eWrJ+HZkzB0oxOvAIf2EmhNXc/H4bqPR4UWoOxtY/vWZcpgC5oas++sTAftXcfAOMySOAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T21:46:13.447956Z"},"content_sha256":"f592b85098bbc14c95366853b050cb4535a21a68a046ee785f55755399db176c","schema_version":"1.0","event_id":"sha256:f592b85098bbc14c95366853b050cb4535a21a68a046ee785f55755399db176c"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2016:VP6D7NNNKDDZRUQEGA6UDPY2MA","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Adversarial Perturbations Against Deep Neural Networks for Malware Classification","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG","cs.NE"],"primary_cat":"cs.CR","authors_text":"Kathrin Grosse, Michael Backes, Nicolas Papernot, Patrick McDaniel, Praveen Manoharan","submitted_at":"2016-06-14T16:01:52Z","abstract_excerpt":"Deep neural networks, like many other machine learning models, have recently been shown to lack robustness against adversarially crafted inputs. These inputs are derived from regular inputs by minor yet carefully selected perturbations that deceive machine learning models into desired misclassifications. Existing work in this emerging field was largely specific to the domain of image classification, since the high-entropy of images can be conveniently manipulated without changing the images' overall visual appearance. Yet, it remains unclear how such attacks translate to more security-sensitiv"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1606.04435","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T01:12:22Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"9f1UnW92F6EPLY72oVpYQ6h9bUAonQHGhcAN0wum7jL+tSWgfT+j/NEQEHgtM6M/xvCWEfTfnt52hYqwGoqeDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T21:46:13.448630Z"},"content_sha256":"e811d0262425fd4d827736cb60ea5adae0bc6ff4f5e116dc6454ca91510f4eb0","schema_version":"1.0","event_id":"sha256:e811d0262425fd4d827736cb60ea5adae0bc6ff4f5e116dc6454ca91510f4eb0"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/VP6D7NNNKDDZRUQEGA6UDPY2MA/bundle.json","state_url":"https://pith.science/pith/VP6D7NNNKDDZRUQEGA6UDPY2MA/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/VP6D7NNNKDDZRUQEGA6UDPY2MA/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-28T21:46:13Z","links":{"resolver":"https://pith.science/pith/VP6D7NNNKDDZRUQEGA6UDPY2MA","bundle":"https://pith.science/pith/VP6D7NNNKDDZRUQEGA6UDPY2MA/bundle.json","state":"https://pith.science/pith/VP6D7NNNKDDZRUQEGA6UDPY2MA/state.json","well_known_bundle":"https://pith.science/.well-known/pith/VP6D7NNNKDDZRUQEGA6UDPY2MA/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2016:VP6D7NNNKDDZRUQEGA6UDPY2MA","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"815f169994a1be763cb2aadbfbbe551149b717d3245bef2cfb3e89b3281d96ba","cross_cats_sorted":["cs.LG","cs.NE"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-06-14T16:01:52Z","title_canon_sha256":"91059ea02704b4e2ef1ec09fa8c9c54eb4c06158e54bfab680d5f08d734d742f"},"schema_version":"1.0","source":{"id":"1606.04435","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1606.04435","created_at":"2026-05-18T01:12:22Z"},{"alias_kind":"arxiv_version","alias_value":"1606.04435v2","created_at":"2026-05-18T01:12:22Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1606.04435","created_at":"2026-05-18T01:12:22Z"},{"alias_kind":"pith_short_12","alias_value":"VP6D7NNNKDDZ","created_at":"2026-05-18T12:30:48Z"},{"alias_kind":"pith_short_16","alias_value":"VP6D7NNNKDDZRUQE","created_at":"2026-05-18T12:30:48Z"},{"alias_kind":"pith_short_8","alias_value":"VP6D7NNN","created_at":"2026-05-18T12:30:48Z"}],"graph_snapshots":[{"event_id":"sha256:e811d0262425fd4d827736cb60ea5adae0bc6ff4f5e116dc6454ca91510f4eb0","target":"graph","created_at":"2026-05-18T01:12:22Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep neural networks, like many other machine learning models, have recently been shown to lack robustness against adversarially crafted inputs. These inputs are derived from regular inputs by minor yet carefully selected perturbations that deceive machine learning models into desired misclassifications. Existing work in this emerging field was largely specific to the domain of image classification, since the high-entropy of images can be conveniently manipulated without changing the images' overall visual appearance. Yet, it remains unclear how such attacks translate to more security-sensitiv","authors_text":"Kathrin Grosse, Michael Backes, Nicolas Papernot, Patrick McDaniel, Praveen Manoharan","cross_cats":["cs.LG","cs.NE"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-06-14T16:01:52Z","title":"Adversarial Perturbations Against Deep Neural Networks for Malware Classification"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1606.04435","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:f592b85098bbc14c95366853b050cb4535a21a68a046ee785f55755399db176c","target":"record","created_at":"2026-05-18T01:12:22Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"815f169994a1be763cb2aadbfbbe551149b717d3245bef2cfb3e89b3281d96ba","cross_cats_sorted":["cs.LG","cs.NE"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-06-14T16:01:52Z","title_canon_sha256":"91059ea02704b4e2ef1ec09fa8c9c54eb4c06158e54bfab680d5f08d734d742f"},"schema_version":"1.0","source":{"id":"1606.04435","kind":"arxiv","version":2}},"canonical_sha256":"abfc3fb5ad50c798d204303d41bf1a60241bcc7a193eaee2898b9d6b03b3bba8","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"abfc3fb5ad50c798d204303d41bf1a60241bcc7a193eaee2898b9d6b03b3bba8","first_computed_at":"2026-05-18T01:12:22.344086Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T01:12:22.344086Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"JS/r4PvP/R3hx6SUHqI3vj5aYMMTUyxYjoM9i4ImvEa4YhL5W71cubvLQ7dsQPZ4N2Zk4gz0uXUlC1vtcLSxDA==","signature_status":"signed_v1","signed_at":"2026-05-18T01:12:22.344424Z","signed_message":"canonical_sha256_bytes"},"source_id":"1606.04435","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:f592b85098bbc14c95366853b050cb4535a21a68a046ee785f55755399db176c","sha256:e811d0262425fd4d827736cb60ea5adae0bc6ff4f5e116dc6454ca91510f4eb0"],"state_sha256":"da6cd8f75b0f9181a2c33d76f7de1a3b9b5c3fd7ac8d138df5ced9f501c72e72"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"sViTP8mpc+VqpJ4bazVIGeTfDvZ0AN8kpAeMDke7M1EMhbaiQcrPs1AZDTRfzWhN07W1HL3701TbBHu+kY86CQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-28T21:46:13.451257Z","bundle_sha256":"944ab8184f0d3a3bb7cec7b06e5cb039201cdc0dd22b23c1418b696e2171f860"}}