{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2016:WRVULBNJDCUHGPYID2E6MIQGZV","short_pith_number":"pith:WRVULBNJ","canonical_record":{"source":{"id":"1608.07690","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2016-08-27T10:44:54Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"7ec4e2cf04e3705a2421e02098f8d40e2b42ef2d728d9856ab82795b4d0cb9b3","abstract_canon_sha256":"cb61b12b7c7176fd792679b732d44594b436e558b07ad09b9f744b0322641296"},"schema_version":"1.0"},"canonical_sha256":"b46b4585a918a8733f081e89e62206cd6660bc79fa416cc09089106f490ae80c","source":{"kind":"arxiv","id":"1608.07690","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1608.07690","created_at":"2026-05-18T01:07:48Z"},{"alias_kind":"arxiv_version","alias_value":"1608.07690v1","created_at":"2026-05-18T01:07:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1608.07690","created_at":"2026-05-18T01:07:48Z"},{"alias_kind":"pith_short_12","alias_value":"WRVULBNJDCUH","created_at":"2026-05-18T12:30:51Z"},{"alias_kind":"pith_short_16","alias_value":"WRVULBNJDCUHGPYI","created_at":"2026-05-18T12:30:51Z"},{"alias_kind":"pith_short_8","alias_value":"WRVULBNJ","created_at":"2026-05-18T12:30:51Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2016:WRVULBNJDCUHGPYID2E6MIQGZV","target":"record","payload":{"canonical_record":{"source":{"id":"1608.07690","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2016-08-27T10:44:54Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"7ec4e2cf04e3705a2421e02098f8d40e2b42ef2d728d9856ab82795b4d0cb9b3","abstract_canon_sha256":"cb61b12b7c7176fd792679b732d44594b436e558b07ad09b9f744b0322641296"},"schema_version":"1.0"},"canonical_sha256":"b46b4585a918a8733f081e89e62206cd6660bc79fa416cc09089106f490ae80c","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T01:07:48.851791Z","signature_b64":"DuB5kRzrC0XSyOQ1JvNbMu98hw+/5S25w2MVjjadYfVJJlI7cF0j3Jr/sCtBaXF+zO8ZUe4FIHbr4Z3NHHUcCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b46b4585a918a8733f081e89e62206cd6660bc79fa416cc09089106f490ae80c","last_reissued_at":"2026-05-18T01:07:48.851266Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T01:07:48.851266Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1608.07690","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T01:07:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"xt+AgPkYxm3RQZrsvcJn2KK9RP0Wiv4ydxcDadxINqPwJHpH9+ln16H4EwQXA9lkCLDdevo8KGhf64vtIle1Bw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T00:07:26.413046Z"},"content_sha256":"e8760bf0be4573026da0bfd98d9c77b34055ec1c7e606f27f07d269f29694b95","schema_version":"1.0","event_id":"sha256:e8760bf0be4573026da0bfd98d9c77b34055ec1c7e606f27f07d269f29694b95"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2016:WRVULBNJDCUHGPYID2E6MIQGZV","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"A Boundary Tilting Persepective on the Phenomenon of Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Lewis Griffin, Thomas Tanay","submitted_at":"2016-08-27T10:44:54Z","abstract_excerpt":"Deep neural networks have been shown to suffer from a surprising weakness: their classification outputs can be changed by small, non-random perturbations of their inputs. This adversarial example phenomenon has been explained as originating from deep networks being \"too linear\" (Goodfellow et al., 2014). We show here that the linear explanation of adversarial examples presents a number of limitations: the formal argument is not convincing, linear classifiers do not always suffer from the phenomenon, and when they do their adversarial examples are different from the ones affecting deep networks"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1608.07690","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T01:07:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ts+qKVesDPBHOBrMPH0qLW+ZMs+XPLYrycD1BxgbfBFNUJsMB5jwX2jtoWoNmHCb4SvMEGQflHj82T8oVpXjCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T00:07:26.413757Z"},"content_sha256":"55e5b4bc0ff78f99e77bf7e1cb6fcef74d67ce6d6008bb4394a7e1d858261b46","schema_version":"1.0","event_id":"sha256:55e5b4bc0ff78f99e77bf7e1cb6fcef74d67ce6d6008bb4394a7e1d858261b46"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/WRVULBNJDCUHGPYID2E6MIQGZV/bundle.json","state_url":"https://pith.science/pith/WRVULBNJDCUHGPYID2E6MIQGZV/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/WRVULBNJDCUHGPYID2E6MIQGZV/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T00:07:26Z","links":{"resolver":"https://pith.science/pith/WRVULBNJDCUHGPYID2E6MIQGZV","bundle":"https://pith.science/pith/WRVULBNJDCUHGPYID2E6MIQGZV/bundle.json","state":"https://pith.science/pith/WRVULBNJDCUHGPYID2E6MIQGZV/state.json","well_known_bundle":"https://pith.science/.well-known/pith/WRVULBNJDCUHGPYID2E6MIQGZV/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2016:WRVULBNJDCUHGPYID2E6MIQGZV","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"cb61b12b7c7176fd792679b732d44594b436e558b07ad09b9f744b0322641296","cross_cats_sorted":["stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2016-08-27T10:44:54Z","title_canon_sha256":"7ec4e2cf04e3705a2421e02098f8d40e2b42ef2d728d9856ab82795b4d0cb9b3"},"schema_version":"1.0","source":{"id":"1608.07690","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1608.07690","created_at":"2026-05-18T01:07:48Z"},{"alias_kind":"arxiv_version","alias_value":"1608.07690v1","created_at":"2026-05-18T01:07:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1608.07690","created_at":"2026-05-18T01:07:48Z"},{"alias_kind":"pith_short_12","alias_value":"WRVULBNJDCUH","created_at":"2026-05-18T12:30:51Z"},{"alias_kind":"pith_short_16","alias_value":"WRVULBNJDCUHGPYI","created_at":"2026-05-18T12:30:51Z"},{"alias_kind":"pith_short_8","alias_value":"WRVULBNJ","created_at":"2026-05-18T12:30:51Z"}],"graph_snapshots":[{"event_id":"sha256:55e5b4bc0ff78f99e77bf7e1cb6fcef74d67ce6d6008bb4394a7e1d858261b46","target":"graph","created_at":"2026-05-18T01:07:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep neural networks have been shown to suffer from a surprising weakness: their classification outputs can be changed by small, non-random perturbations of their inputs. This adversarial example phenomenon has been explained as originating from deep networks being \"too linear\" (Goodfellow et al., 2014). We show here that the linear explanation of adversarial examples presents a number of limitations: the formal argument is not convincing, linear classifiers do not always suffer from the phenomenon, and when they do their adversarial examples are different from the ones affecting deep networks","authors_text":"Lewis Griffin, Thomas Tanay","cross_cats":["stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2016-08-27T10:44:54Z","title":"A Boundary Tilting Persepective on the Phenomenon of Adversarial Examples"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1608.07690","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:e8760bf0be4573026da0bfd98d9c77b34055ec1c7e606f27f07d269f29694b95","target":"record","created_at":"2026-05-18T01:07:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"cb61b12b7c7176fd792679b732d44594b436e558b07ad09b9f744b0322641296","cross_cats_sorted":["stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2016-08-27T10:44:54Z","title_canon_sha256":"7ec4e2cf04e3705a2421e02098f8d40e2b42ef2d728d9856ab82795b4d0cb9b3"},"schema_version":"1.0","source":{"id":"1608.07690","kind":"arxiv","version":1}},"canonical_sha256":"b46b4585a918a8733f081e89e62206cd6660bc79fa416cc09089106f490ae80c","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b46b4585a918a8733f081e89e62206cd6660bc79fa416cc09089106f490ae80c","first_computed_at":"2026-05-18T01:07:48.851266Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T01:07:48.851266Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"DuB5kRzrC0XSyOQ1JvNbMu98hw+/5S25w2MVjjadYfVJJlI7cF0j3Jr/sCtBaXF+zO8ZUe4FIHbr4Z3NHHUcCg==","signature_status":"signed_v1","signed_at":"2026-05-18T01:07:48.851791Z","signed_message":"canonical_sha256_bytes"},"source_id":"1608.07690","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:e8760bf0be4573026da0bfd98d9c77b34055ec1c7e606f27f07d269f29694b95","sha256:55e5b4bc0ff78f99e77bf7e1cb6fcef74d67ce6d6008bb4394a7e1d858261b46"],"state_sha256":"9eeae4a36333cc9e7abdca799ef0cb2ee3d4a3716efe46b0eb45473dbf34d19a"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"OjijimEppBo4BpkABkJtBx7Tj2Yxn0IvXX+zDVF/KLmVtCMS7Z0pmhthwDcgh/UKtSOMUwDbAxXrsjjfivdhAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T00:07:26.417170Z","bundle_sha256":"e8bef16afb13428a2a7fb67e475aa483bab617884c818e8f6979e85677e79e27"}}