{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:VTRWE2QZMLL2NHU2K2GMVVM37C","short_pith_number":"pith:VTRWE2QZ","schema_version":"1.0","canonical_sha256":"ace3626a1962d7a69e9a568ccad59bf89be4edb3bc25bcdb46df0f6ca8231cbd","source":{"kind":"arxiv","id":"2404.19460","version":3},"attestation_state":"computed","paper":{"title":"AttackBench: Evaluating Gradient-based Attacks for Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV"],"primary_cat":"cs.LG","authors_text":"Ambra Demontis, Antonio Emanuele Cin\\`a, Battista Biggio, Fabio Roli, Ismail Ben Ayed, J\\'er\\^ome Rony, Luca Demetrio, Maura Pintor","submitted_at":"2024-04-30T11:19:05Z","abstract_excerpt":"Adversarial examples are typically optimized with gradient-based attacks. While novel attacks are continuously proposed, each is shown to outperform its predecessors using different experimental setups, hyperparameter settings, and number of forward and backward calls to the target models. This provides overly-optimistic and even biased evaluations that may unfairly favor one particular attack over the others. In this work, we aim to overcome these limitations by proposing AttackBench, i.e., the first evaluation framework that enables a fair comparison among different attacks. To this end, we "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2404.19460","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2024-04-30T11:19:05Z","cross_cats_sorted":["cs.CR","cs.CV"],"title_canon_sha256":"1f8f26e98706a6c7b2bc72ea8614fd4c9117e7437fa4b875347d012eaf7f6eeb","abstract_canon_sha256":"527db813a89e749a87e1788bb5a61d9551b97b53a22fd9f26cf8ce6ab0c0f6b8"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:01:24.350203Z","signature_b64":"3Ag+GqzPL3ZTY9arJpcXCfPiiymu1X9mod+IEAHJKs+J2HuzhhUdoGvfJUm9cEKeNFLhtd1L4NosLuFDUSVdBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ace3626a1962d7a69e9a568ccad59bf89be4edb3bc25bcdb46df0f6ca8231cbd","last_reissued_at":"2026-07-05T11:01:24.349779Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:01:24.349779Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"AttackBench: Evaluating Gradient-based Attacks for Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV"],"primary_cat":"cs.LG","authors_text":"Ambra Demontis, Antonio Emanuele Cin\\`a, Battista Biggio, Fabio Roli, Ismail Ben Ayed, J\\'er\\^ome Rony, Luca Demetrio, Maura Pintor","submitted_at":"2024-04-30T11:19:05Z","abstract_excerpt":"Adversarial examples are typically optimized with gradient-based attacks. While novel attacks are continuously proposed, each is shown to outperform its predecessors using different experimental setups, hyperparameter settings, and number of forward and backward calls to the target models. This provides overly-optimistic and even biased evaluations that may unfairly favor one particular attack over the others. In this work, we aim to overcome these limitations by proposing AttackBench, i.e., the first evaluation framework that enables a fair comparison among different attacks. To this end, we "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2404.19460","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2404.19460/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2404.19460","created_at":"2026-07-05T11:01:24.349835+00:00"},{"alias_kind":"arxiv_version","alias_value":"2404.19460v3","created_at":"2026-07-05T11:01:24.349835+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2404.19460","created_at":"2026-07-05T11:01:24.349835+00:00"},{"alias_kind":"pith_short_12","alias_value":"VTRWE2QZMLL2","created_at":"2026-07-05T11:01:24.349835+00:00"},{"alias_kind":"pith_short_16","alias_value":"VTRWE2QZMLL2NHU2","created_at":"2026-07-05T11:01:24.349835+00:00"},{"alias_kind":"pith_short_8","alias_value":"VTRWE2QZ","created_at":"2026-07-05T11:01:24.349835+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/VTRWE2QZMLL2NHU2K2GMVVM37C","json":"https://pith.science/pith/VTRWE2QZMLL2NHU2K2GMVVM37C.json","graph_json":"https://pith.science/api/pith-number/VTRWE2QZMLL2NHU2K2GMVVM37C/graph.json","events_json":"https://pith.science/api/pith-number/VTRWE2QZMLL2NHU2K2GMVVM37C/events.json","paper":"https://pith.science/paper/VTRWE2QZ"},"agent_actions":{"view_html":"https://pith.science/pith/VTRWE2QZMLL2NHU2K2GMVVM37C","download_json":"https://pith.science/pith/VTRWE2QZMLL2NHU2K2GMVVM37C.json","view_paper":"https://pith.science/paper/VTRWE2QZ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2404.19460&json=true","fetch_graph":"https://pith.science/api/pith-number/VTRWE2QZMLL2NHU2K2GMVVM37C/graph.json","fetch_events":"https://pith.science/api/pith-number/VTRWE2QZMLL2NHU2K2GMVVM37C/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/VTRWE2QZMLL2NHU2K2GMVVM37C/action/timestamp_anchor","attest_storage":"https://pith.science/pith/VTRWE2QZMLL2NHU2K2GMVVM37C/action/storage_attestation","attest_author":"https://pith.science/pith/VTRWE2QZMLL2NHU2K2GMVVM37C/action/author_attestation","sign_citation":"https://pith.science/pith/VTRWE2QZMLL2NHU2K2GMVVM37C/action/citation_signature","submit_replication":"https://pith.science/pith/VTRWE2QZMLL2NHU2K2GMVVM37C/action/replication_record"}},"created_at":"2026-07-05T11:01:24.349835+00:00","updated_at":"2026-07-05T11:01:24.349835+00:00"}