{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:WFSLHSY66FDE4UQS7NHRAFY7AY","short_pith_number":"pith:WFSLHSY6","canonical_record":{"source":{"id":"1802.06430","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-02-18T19:39:28Z","cross_cats_sorted":["cs.CV"],"title_canon_sha256":"33a64dbe96c00ae5d5f1aa1d80d726b20d967c5a6d0b5ad99b640b12cc4061a5","abstract_canon_sha256":"f69d7410e12e2c92991a6636840ad59b024e9c47386513234ef7e718b54f8855"},"schema_version":"1.0"},"canonical_sha256":"b164b3cb1ef1464e5212fb4f10171f061ec320e64a58d90255f08da71aa07de3","source":{"kind":"arxiv","id":"1802.06430","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1802.06430","created_at":"2026-05-18T00:14:28Z"},{"alias_kind":"arxiv_version","alias_value":"1802.06430v3","created_at":"2026-05-18T00:14:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1802.06430","created_at":"2026-05-18T00:14:28Z"},{"alias_kind":"pith_short_12","alias_value":"WFSLHSY66FDE","created_at":"2026-05-18T12:32:59Z"},{"alias_kind":"pith_short_16","alias_value":"WFSLHSY66FDE4UQS","created_at":"2026-05-18T12:32:59Z"},{"alias_kind":"pith_short_8","alias_value":"WFSLHSY6","created_at":"2026-05-18T12:32:59Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:WFSLHSY66FDE4UQS7NHRAFY7AY","target":"record","payload":{"canonical_record":{"source":{"id":"1802.06430","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-02-18T19:39:28Z","cross_cats_sorted":["cs.CV"],"title_canon_sha256":"33a64dbe96c00ae5d5f1aa1d80d726b20d967c5a6d0b5ad99b640b12cc4061a5","abstract_canon_sha256":"f69d7410e12e2c92991a6636840ad59b024e9c47386513234ef7e718b54f8855"},"schema_version":"1.0"},"canonical_sha256":"b164b3cb1ef1464e5212fb4f10171f061ec320e64a58d90255f08da71aa07de3","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:14:28.365253Z","signature_b64":"Dj1xiB/sdKuEOar9ByI//ARl1J9eIvgcAbib6mqkZ5kO2xn/lEuSWC/zT/VaV1h1lAONIlcSOOzus/TcFcwyBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b164b3cb1ef1464e5212fb4f10171f061ec320e64a58d90255f08da71aa07de3","last_reissued_at":"2026-05-18T00:14:28.364577Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:14:28.364577Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1802.06430","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:14:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"iUkt5qWxGuIiHAj9jhK0HX3zNn2LBVioJNUu7qrTX/BBrlz9hFSbN3lLn0JKB3GTapXHDUhdNGbTEeGx6f42BA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T03:53:59.887768Z"},"content_sha256":"509a4c6aea3500e348edc7b09dcd52ed8b03a50264ae1f7bdc24ccec9e62e77f","schema_version":"1.0","event_id":"sha256:509a4c6aea3500e348edc7b09dcd52ed8b03a50264ae1f7bdc24ccec9e62e77f"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:WFSLHSY66FDE4UQS7NHRAFY7AY","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"DARTS: Deceiving Autonomous Cars with Toxic Signs","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV"],"primary_cat":"cs.CR","authors_text":"Arjun Nitin Bhagoji, Arsalan Mosenia, Chawin Sitawarin, Mung Chiang, Prateek Mittal","submitted_at":"2018-02-18T19:39:28Z","abstract_excerpt":"Sign recognition is an integral part of autonomous cars. Any misclassification of traffic signs can potentially lead to a multitude of disastrous consequences, ranging from a life-threatening accident to even a large-scale interruption of transportation services relying on autonomous cars. In this paper, we propose and examine security attacks against sign recognition systems for Deceiving Autonomous caRs with Toxic Signs (we call the proposed attacks DARTS). In particular, we introduce two novel methods to create these toxic signs. First, we propose Out-of-Distribution attacks, which expand t"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1802.06430","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:14:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"tfXKLyqTTOnupsr2q9eUeWN1DI3OYyxVPICyoFu9HvhvFh/O7FuBZ9mKWqOV3WH65Z9gp9JTWyIt5oqUkg/yBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T03:53:59.888376Z"},"content_sha256":"f1f3d77fccd8c640f869e4ab289a03e16ef9914af3fa586695e5f72fa91123e3","schema_version":"1.0","event_id":"sha256:f1f3d77fccd8c640f869e4ab289a03e16ef9914af3fa586695e5f72fa91123e3"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/WFSLHSY66FDE4UQS7NHRAFY7AY/bundle.json","state_url":"https://pith.science/pith/WFSLHSY66FDE4UQS7NHRAFY7AY/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/WFSLHSY66FDE4UQS7NHRAFY7AY/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T03:53:59Z","links":{"resolver":"https://pith.science/pith/WFSLHSY66FDE4UQS7NHRAFY7AY","bundle":"https://pith.science/pith/WFSLHSY66FDE4UQS7NHRAFY7AY/bundle.json","state":"https://pith.science/pith/WFSLHSY66FDE4UQS7NHRAFY7AY/state.json","well_known_bundle":"https://pith.science/.well-known/pith/WFSLHSY66FDE4UQS7NHRAFY7AY/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:WFSLHSY66FDE4UQS7NHRAFY7AY","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"f69d7410e12e2c92991a6636840ad59b024e9c47386513234ef7e718b54f8855","cross_cats_sorted":["cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-02-18T19:39:28Z","title_canon_sha256":"33a64dbe96c00ae5d5f1aa1d80d726b20d967c5a6d0b5ad99b640b12cc4061a5"},"schema_version":"1.0","source":{"id":"1802.06430","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1802.06430","created_at":"2026-05-18T00:14:28Z"},{"alias_kind":"arxiv_version","alias_value":"1802.06430v3","created_at":"2026-05-18T00:14:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1802.06430","created_at":"2026-05-18T00:14:28Z"},{"alias_kind":"pith_short_12","alias_value":"WFSLHSY66FDE","created_at":"2026-05-18T12:32:59Z"},{"alias_kind":"pith_short_16","alias_value":"WFSLHSY66FDE4UQS","created_at":"2026-05-18T12:32:59Z"},{"alias_kind":"pith_short_8","alias_value":"WFSLHSY6","created_at":"2026-05-18T12:32:59Z"}],"graph_snapshots":[{"event_id":"sha256:f1f3d77fccd8c640f869e4ab289a03e16ef9914af3fa586695e5f72fa91123e3","target":"graph","created_at":"2026-05-18T00:14:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Sign recognition is an integral part of autonomous cars. Any misclassification of traffic signs can potentially lead to a multitude of disastrous consequences, ranging from a life-threatening accident to even a large-scale interruption of transportation services relying on autonomous cars. In this paper, we propose and examine security attacks against sign recognition systems for Deceiving Autonomous caRs with Toxic Signs (we call the proposed attacks DARTS). In particular, we introduce two novel methods to create these toxic signs. First, we propose Out-of-Distribution attacks, which expand t","authors_text":"Arjun Nitin Bhagoji, Arsalan Mosenia, Chawin Sitawarin, Mung Chiang, Prateek Mittal","cross_cats":["cs.CV"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-02-18T19:39:28Z","title":"DARTS: Deceiving Autonomous Cars with Toxic Signs"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1802.06430","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:509a4c6aea3500e348edc7b09dcd52ed8b03a50264ae1f7bdc24ccec9e62e77f","target":"record","created_at":"2026-05-18T00:14:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"f69d7410e12e2c92991a6636840ad59b024e9c47386513234ef7e718b54f8855","cross_cats_sorted":["cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-02-18T19:39:28Z","title_canon_sha256":"33a64dbe96c00ae5d5f1aa1d80d726b20d967c5a6d0b5ad99b640b12cc4061a5"},"schema_version":"1.0","source":{"id":"1802.06430","kind":"arxiv","version":3}},"canonical_sha256":"b164b3cb1ef1464e5212fb4f10171f061ec320e64a58d90255f08da71aa07de3","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b164b3cb1ef1464e5212fb4f10171f061ec320e64a58d90255f08da71aa07de3","first_computed_at":"2026-05-18T00:14:28.364577Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:14:28.364577Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Dj1xiB/sdKuEOar9ByI//ARl1J9eIvgcAbib6mqkZ5kO2xn/lEuSWC/zT/VaV1h1lAONIlcSOOzus/TcFcwyBA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:14:28.365253Z","signed_message":"canonical_sha256_bytes"},"source_id":"1802.06430","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:509a4c6aea3500e348edc7b09dcd52ed8b03a50264ae1f7bdc24ccec9e62e77f","sha256:f1f3d77fccd8c640f869e4ab289a03e16ef9914af3fa586695e5f72fa91123e3"],"state_sha256":"833965ae0457888f091a48038b306168d17445676dd3ebb38bff46aae6dfcbb1"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"X8OjOmFgPp4Pj+Db6gEh/hcPwuKN8KQnfkrAuFUVFKfW3e5/uC9+UPZYSZkQFS75PSTlJLK0DTjbafl137y4Bg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T03:53:59.891620Z","bundle_sha256":"b1f5bee1dae4aebcd8f08acae44186175db84517be7a284262937ce42e78ce2e"}}