{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:WTD7POKOORTG5SM5NOF7JYRMSU","short_pith_number":"pith:WTD7POKO","canonical_record":{"source":{"id":"1708.02582","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-08-08T17:58:40Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"60a681446e4747fffda70ced9c4879783ff33c464ee21f7f36272be8caae6555","abstract_canon_sha256":"8f4e12e2faa95bcd8f1cbabb6db1c94781315c20689fa71ffc6d1a7ea9b3367b"},"schema_version":"1.0"},"canonical_sha256":"b4c7f7b94e74666ec99d6b8bf4e22c951f15b4ae7a8a17b8413478ca71635511","source":{"kind":"arxiv","id":"1708.02582","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1708.02582","created_at":"2026-05-18T00:20:46Z"},{"alias_kind":"arxiv_version","alias_value":"1708.02582v3","created_at":"2026-05-18T00:20:46Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1708.02582","created_at":"2026-05-18T00:20:46Z"},{"alias_kind":"pith_short_12","alias_value":"WTD7POKOORTG","created_at":"2026-05-18T12:31:53Z"},{"alias_kind":"pith_short_16","alias_value":"WTD7POKOORTG5SM5","created_at":"2026-05-18T12:31:53Z"},{"alias_kind":"pith_short_8","alias_value":"WTD7POKO","created_at":"2026-05-18T12:31:53Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:WTD7POKOORTG5SM5NOF7JYRMSU","target":"record","payload":{"canonical_record":{"source":{"id":"1708.02582","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-08-08T17:58:40Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"60a681446e4747fffda70ced9c4879783ff33c464ee21f7f36272be8caae6555","abstract_canon_sha256":"8f4e12e2faa95bcd8f1cbabb6db1c94781315c20689fa71ffc6d1a7ea9b3367b"},"schema_version":"1.0"},"canonical_sha256":"b4c7f7b94e74666ec99d6b8bf4e22c951f15b4ae7a8a17b8413478ca71635511","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:20:46.849272Z","signature_b64":"QBnc0lfJb9T93i4CMc1PzfF4vC9wyUet8pvX9f5JAqMlMsVN9+nNBz8konuqiVzvRsnJpZpFkaP4f0PQ/D1jBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b4c7f7b94e74666ec99d6b8bf4e22c951f15b4ae7a8a17b8413478ca71635511","last_reissued_at":"2026-05-18T00:20:46.848779Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:20:46.848779Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1708.02582","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:20:46Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"pcJpddVyDsMNhby4kJuQyzQE0CGxOhzPq/goJWPbmdPjFAvelZZLzFw6S7xp4lnobo8Zo9oOvap8zDooVyRVDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T10:46:20.443265Z"},"content_sha256":"4e78e4beda0ee4bb81d22b25770ec614cc3d2419574591575c71f469d8526420","schema_version":"1.0","event_id":"sha256:4e78e4beda0ee4bb81d22b25770ec614cc3d2419574591575c71f469d8526420"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:WTD7POKOORTG5SM5NOF7JYRMSU","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Cascade Adversarial Machine Learning Regularized with a Unified Embedding","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"stat.ML","authors_text":"Jong Hwan Ko, Saibal Mukhopadhyay, Taesik Na","submitted_at":"2017-08-08T17:58:40Z","abstract_excerpt":"Injecting adversarial examples during training, known as adversarial training, can improve robustness against one-step attacks, but not for unknown iterative attacks. To address this challenge, we first show iteratively generated adversarial images easily transfer between networks trained with the same strategy. Inspired by this observation, we propose cascade adversarial training, which transfers the knowledge of the end results of adversarial training. We train a network from scratch by injecting iteratively generated adversarial images crafted from already defended networks in addition to o"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1708.02582","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:20:46Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"39TzVNr2tdCaagdzbv5/MVlKdcxAzknHMzX/O3hrKbBv5zGAIAA4Eauj9M41SIGrXDCEVrvauI5HeCJ0lvSWDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T10:46:20.443636Z"},"content_sha256":"818b2cf2b8b9b4ca2d924096d6eb6ec4924d928f0e9c4f55f72e32a4cade6ef8","schema_version":"1.0","event_id":"sha256:818b2cf2b8b9b4ca2d924096d6eb6ec4924d928f0e9c4f55f72e32a4cade6ef8"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/WTD7POKOORTG5SM5NOF7JYRMSU/bundle.json","state_url":"https://pith.science/pith/WTD7POKOORTG5SM5NOF7JYRMSU/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/WTD7POKOORTG5SM5NOF7JYRMSU/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-30T10:46:20Z","links":{"resolver":"https://pith.science/pith/WTD7POKOORTG5SM5NOF7JYRMSU","bundle":"https://pith.science/pith/WTD7POKOORTG5SM5NOF7JYRMSU/bundle.json","state":"https://pith.science/pith/WTD7POKOORTG5SM5NOF7JYRMSU/state.json","well_known_bundle":"https://pith.science/.well-known/pith/WTD7POKOORTG5SM5NOF7JYRMSU/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:WTD7POKOORTG5SM5NOF7JYRMSU","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"8f4e12e2faa95bcd8f1cbabb6db1c94781315c20689fa71ffc6d1a7ea9b3367b","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-08-08T17:58:40Z","title_canon_sha256":"60a681446e4747fffda70ced9c4879783ff33c464ee21f7f36272be8caae6555"},"schema_version":"1.0","source":{"id":"1708.02582","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1708.02582","created_at":"2026-05-18T00:20:46Z"},{"alias_kind":"arxiv_version","alias_value":"1708.02582v3","created_at":"2026-05-18T00:20:46Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1708.02582","created_at":"2026-05-18T00:20:46Z"},{"alias_kind":"pith_short_12","alias_value":"WTD7POKOORTG","created_at":"2026-05-18T12:31:53Z"},{"alias_kind":"pith_short_16","alias_value":"WTD7POKOORTG5SM5","created_at":"2026-05-18T12:31:53Z"},{"alias_kind":"pith_short_8","alias_value":"WTD7POKO","created_at":"2026-05-18T12:31:53Z"}],"graph_snapshots":[{"event_id":"sha256:818b2cf2b8b9b4ca2d924096d6eb6ec4924d928f0e9c4f55f72e32a4cade6ef8","target":"graph","created_at":"2026-05-18T00:20:46Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Injecting adversarial examples during training, known as adversarial training, can improve robustness against one-step attacks, but not for unknown iterative attacks. To address this challenge, we first show iteratively generated adversarial images easily transfer between networks trained with the same strategy. Inspired by this observation, we propose cascade adversarial training, which transfers the knowledge of the end results of adversarial training. We train a network from scratch by injecting iteratively generated adversarial images crafted from already defended networks in addition to o","authors_text":"Jong Hwan Ko, Saibal Mukhopadhyay, Taesik Na","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-08-08T17:58:40Z","title":"Cascade Adversarial Machine Learning Regularized with a Unified Embedding"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1708.02582","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:4e78e4beda0ee4bb81d22b25770ec614cc3d2419574591575c71f469d8526420","target":"record","created_at":"2026-05-18T00:20:46Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"8f4e12e2faa95bcd8f1cbabb6db1c94781315c20689fa71ffc6d1a7ea9b3367b","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2017-08-08T17:58:40Z","title_canon_sha256":"60a681446e4747fffda70ced9c4879783ff33c464ee21f7f36272be8caae6555"},"schema_version":"1.0","source":{"id":"1708.02582","kind":"arxiv","version":3}},"canonical_sha256":"b4c7f7b94e74666ec99d6b8bf4e22c951f15b4ae7a8a17b8413478ca71635511","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b4c7f7b94e74666ec99d6b8bf4e22c951f15b4ae7a8a17b8413478ca71635511","first_computed_at":"2026-05-18T00:20:46.848779Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:20:46.848779Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"QBnc0lfJb9T93i4CMc1PzfF4vC9wyUet8pvX9f5JAqMlMsVN9+nNBz8konuqiVzvRsnJpZpFkaP4f0PQ/D1jBg==","signature_status":"signed_v1","signed_at":"2026-05-18T00:20:46.849272Z","signed_message":"canonical_sha256_bytes"},"source_id":"1708.02582","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:4e78e4beda0ee4bb81d22b25770ec614cc3d2419574591575c71f469d8526420","sha256:818b2cf2b8b9b4ca2d924096d6eb6ec4924d928f0e9c4f55f72e32a4cade6ef8"],"state_sha256":"1b23e1e69c7327ed01c591f1adeb7a1388490931ff4bcf6bba1b57e225119013"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"IIH/PkAaLEMsIaY8njmkXxEfdoREqPZdB5uDCBBKv4ENZ4rQbPkHSYu0AtKfCU9yADicLwzyNDwGtMhkbcneAw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-30T10:46:20.445712Z","bundle_sha256":"64cbbbf9029e54bf4453a746aa0d82c51266ff0cd849ede2d63f45ab20a8a9e5"}}