{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:WHH7W3IMXUS6GLGWCULWXXFSIO","short_pith_number":"pith:WHH7W3IM","canonical_record":{"source":{"id":"1703.01340","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-03-03T21:13:48Z","cross_cats_sorted":["cs.LG","stat.ML"],"title_canon_sha256":"b0b24e7c28c5377b3171d16371804a232daba85842632675975ecbd450bff522","abstract_canon_sha256":"cff325914b0f646c8f7cff474cf7123d7a5052eac5b0ebb5a275992ac10e858e"},"schema_version":"1.0"},"canonical_sha256":"b1cffb6d0cbd25e32cd615176bdcb24383094b18b318877c35bf3fcee3d77e3b","source":{"kind":"arxiv","id":"1703.01340","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1703.01340","created_at":"2026-05-18T00:49:31Z"},{"alias_kind":"arxiv_version","alias_value":"1703.01340v1","created_at":"2026-05-18T00:49:31Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1703.01340","created_at":"2026-05-18T00:49:31Z"},{"alias_kind":"pith_short_12","alias_value":"WHH7W3IMXUS6","created_at":"2026-05-18T12:31:53Z"},{"alias_kind":"pith_short_16","alias_value":"WHH7W3IMXUS6GLGW","created_at":"2026-05-18T12:31:53Z"},{"alias_kind":"pith_short_8","alias_value":"WHH7W3IM","created_at":"2026-05-18T12:31:53Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:WHH7W3IMXUS6GLGWCULWXXFSIO","target":"record","payload":{"canonical_record":{"source":{"id":"1703.01340","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-03-03T21:13:48Z","cross_cats_sorted":["cs.LG","stat.ML"],"title_canon_sha256":"b0b24e7c28c5377b3171d16371804a232daba85842632675975ecbd450bff522","abstract_canon_sha256":"cff325914b0f646c8f7cff474cf7123d7a5052eac5b0ebb5a275992ac10e858e"},"schema_version":"1.0"},"canonical_sha256":"b1cffb6d0cbd25e32cd615176bdcb24383094b18b318877c35bf3fcee3d77e3b","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:49:31.053761Z","signature_b64":"hWiyMha2zZBJx5PYyIUBQfgTG2Yfu3RMpGCJnkx1si0KJd4h9+76GcRL3t/vbFmFIBx+X4HMRJpi9vEwX7uoDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b1cffb6d0cbd25e32cd615176bdcb24383094b18b318877c35bf3fcee3d77e3b","last_reissued_at":"2026-05-18T00:49:31.053081Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:49:31.053081Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1703.01340","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:49:31Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"wisER9FpRqftJXi6NFyfngm2tIoBRUGFFSxm08wXjJkSSvpaLlegmPlPh7qax84luqDWT7Ldyp47m7SbYhetDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-31T19:42:18.234986Z"},"content_sha256":"03b06d838dc70a912790f56230a1747fefa923839c790c9444d0e1faab681813","schema_version":"1.0","event_id":"sha256:03b06d838dc70a912790f56230a1747fefa923839c790c9444d0e1faab681813"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:WHH7W3IMXUS6GLGWCULWXXFSIO","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Generative Poisoning Attack Method Against Neural Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG","stat.ML"],"primary_cat":"cs.CR","authors_text":"Chaofei Yang, Hai Li, Qing Wu, Yiran Chen","submitted_at":"2017-03-03T21:13:48Z","abstract_excerpt":"Poisoning attack is identified as a severe security threat to machine learning algorithms. In many applications, for example, deep neural network (DNN) models collect public data as the inputs to perform re-training, where the input data can be poisoned. Although poisoning attack against support vector machines (SVM) has been extensively studied before, there is still very limited knowledge about how such attack can be implemented on neural networks (NN), especially DNNs. In this work, we first examine the possibility of applying traditional gradient-based method (named as the direct gradient "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1703.01340","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:49:31Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"aqwPMvFKtTeo3QBgvKWqcwaevGK+dML8Bbqh8DjoEEf49Lk1xUqGvVVPJ/14iBti7CbmCdryxXjkr2GsvpqNDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-31T19:42:18.235722Z"},"content_sha256":"87d053f8a9af6226bc3c01d5c6b1c53f636f2edd04e5e3afae6af35313209ae9","schema_version":"1.0","event_id":"sha256:87d053f8a9af6226bc3c01d5c6b1c53f636f2edd04e5e3afae6af35313209ae9"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/WHH7W3IMXUS6GLGWCULWXXFSIO/bundle.json","state_url":"https://pith.science/pith/WHH7W3IMXUS6GLGWCULWXXFSIO/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/WHH7W3IMXUS6GLGWCULWXXFSIO/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-31T19:42:18Z","links":{"resolver":"https://pith.science/pith/WHH7W3IMXUS6GLGWCULWXXFSIO","bundle":"https://pith.science/pith/WHH7W3IMXUS6GLGWCULWXXFSIO/bundle.json","state":"https://pith.science/pith/WHH7W3IMXUS6GLGWCULWXXFSIO/state.json","well_known_bundle":"https://pith.science/.well-known/pith/WHH7W3IMXUS6GLGWCULWXXFSIO/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:WHH7W3IMXUS6GLGWCULWXXFSIO","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"cff325914b0f646c8f7cff474cf7123d7a5052eac5b0ebb5a275992ac10e858e","cross_cats_sorted":["cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-03-03T21:13:48Z","title_canon_sha256":"b0b24e7c28c5377b3171d16371804a232daba85842632675975ecbd450bff522"},"schema_version":"1.0","source":{"id":"1703.01340","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1703.01340","created_at":"2026-05-18T00:49:31Z"},{"alias_kind":"arxiv_version","alias_value":"1703.01340v1","created_at":"2026-05-18T00:49:31Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1703.01340","created_at":"2026-05-18T00:49:31Z"},{"alias_kind":"pith_short_12","alias_value":"WHH7W3IMXUS6","created_at":"2026-05-18T12:31:53Z"},{"alias_kind":"pith_short_16","alias_value":"WHH7W3IMXUS6GLGW","created_at":"2026-05-18T12:31:53Z"},{"alias_kind":"pith_short_8","alias_value":"WHH7W3IM","created_at":"2026-05-18T12:31:53Z"}],"graph_snapshots":[{"event_id":"sha256:87d053f8a9af6226bc3c01d5c6b1c53f636f2edd04e5e3afae6af35313209ae9","target":"graph","created_at":"2026-05-18T00:49:31Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Poisoning attack is identified as a severe security threat to machine learning algorithms. In many applications, for example, deep neural network (DNN) models collect public data as the inputs to perform re-training, where the input data can be poisoned. Although poisoning attack against support vector machines (SVM) has been extensively studied before, there is still very limited knowledge about how such attack can be implemented on neural networks (NN), especially DNNs. In this work, we first examine the possibility of applying traditional gradient-based method (named as the direct gradient ","authors_text":"Chaofei Yang, Hai Li, Qing Wu, Yiran Chen","cross_cats":["cs.LG","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-03-03T21:13:48Z","title":"Generative Poisoning Attack Method Against Neural Networks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1703.01340","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:03b06d838dc70a912790f56230a1747fefa923839c790c9444d0e1faab681813","target":"record","created_at":"2026-05-18T00:49:31Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"cff325914b0f646c8f7cff474cf7123d7a5052eac5b0ebb5a275992ac10e858e","cross_cats_sorted":["cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-03-03T21:13:48Z","title_canon_sha256":"b0b24e7c28c5377b3171d16371804a232daba85842632675975ecbd450bff522"},"schema_version":"1.0","source":{"id":"1703.01340","kind":"arxiv","version":1}},"canonical_sha256":"b1cffb6d0cbd25e32cd615176bdcb24383094b18b318877c35bf3fcee3d77e3b","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b1cffb6d0cbd25e32cd615176bdcb24383094b18b318877c35bf3fcee3d77e3b","first_computed_at":"2026-05-18T00:49:31.053081Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:49:31.053081Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"hWiyMha2zZBJx5PYyIUBQfgTG2Yfu3RMpGCJnkx1si0KJd4h9+76GcRL3t/vbFmFIBx+X4HMRJpi9vEwX7uoDw==","signature_status":"signed_v1","signed_at":"2026-05-18T00:49:31.053761Z","signed_message":"canonical_sha256_bytes"},"source_id":"1703.01340","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:03b06d838dc70a912790f56230a1747fefa923839c790c9444d0e1faab681813","sha256:87d053f8a9af6226bc3c01d5c6b1c53f636f2edd04e5e3afae6af35313209ae9"],"state_sha256":"841a41ddfc18023b65324f8ea1785d8c0536421948e3dd5bbd2b2d1a5e5e55f0"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Y13DVCNvngQFEwvr1rJQ/ujsr1jQPgPC8jGUW/fOvE6SnXDkAevRiIoXGwf4XzdESaB4bYTzgLe2q6lLUx7vBg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-31T19:42:18.239553Z","bundle_sha256":"a337d459cf677a1da333f8444aa0f5fc7d53c3afdf27e7983c071a07f76605b0"}}