{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:X5NS5QAVLJYNR4EWJOBQAHO3KF","short_pith_number":"pith:X5NS5QAV","canonical_record":{"source":{"id":"1708.06939","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-08-23T10:01:35Z","cross_cats_sorted":["cs.RO","stat.ML"],"title_canon_sha256":"354139112464efd985a60eb51c69516e21b7457ab6c1a45d40c7183b675e0c98","abstract_canon_sha256":"400a10303c4a05b3083e1aeab1bbf309863c6bd52a794e63896bdb3a164eb53d"},"schema_version":"1.0"},"canonical_sha256":"bf5b2ec0155a70d8f0964b83001ddb517d1e8433c4d914a3ec932cae6d7b58a0","source":{"kind":"arxiv","id":"1708.06939","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1708.06939","created_at":"2026-05-18T00:36:48Z"},{"alias_kind":"arxiv_version","alias_value":"1708.06939v1","created_at":"2026-05-18T00:36:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1708.06939","created_at":"2026-05-18T00:36:48Z"},{"alias_kind":"pith_short_12","alias_value":"X5NS5QAVLJYN","created_at":"2026-05-18T12:31:53Z"},{"alias_kind":"pith_short_16","alias_value":"X5NS5QAVLJYNR4EW","created_at":"2026-05-18T12:31:53Z"},{"alias_kind":"pith_short_8","alias_value":"X5NS5QAV","created_at":"2026-05-18T12:31:53Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:X5NS5QAVLJYNR4EWJOBQAHO3KF","target":"record","payload":{"canonical_record":{"source":{"id":"1708.06939","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-08-23T10:01:35Z","cross_cats_sorted":["cs.RO","stat.ML"],"title_canon_sha256":"354139112464efd985a60eb51c69516e21b7457ab6c1a45d40c7183b675e0c98","abstract_canon_sha256":"400a10303c4a05b3083e1aeab1bbf309863c6bd52a794e63896bdb3a164eb53d"},"schema_version":"1.0"},"canonical_sha256":"bf5b2ec0155a70d8f0964b83001ddb517d1e8433c4d914a3ec932cae6d7b58a0","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:36:48.847716Z","signature_b64":"ZHoNBQ9q3yIj/K+H+SAXW8bu5dhb+tn1Tcn6vS+rh8ioYjEufEy7in8OTebMGzuO4tPhicVvOE7IOuuifDgQCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"bf5b2ec0155a70d8f0964b83001ddb517d1e8433c4d914a3ec932cae6d7b58a0","last_reissued_at":"2026-05-18T00:36:48.846965Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:36:48.846965Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1708.06939","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:36:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"whPxQKLUEmxk5gF57GLtZ6rGqfBlcCKyqld3/FX3uQb1CZsvwwUvqmeiRUW4eRUQfzjAVPzQjFDmmnlgkmRaBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T02:42:37.685842Z"},"content_sha256":"accac09fb1a4fedc47d6fd900f29a98f4255e61517719120ee208ec28a94e2da","schema_version":"1.0","event_id":"sha256:accac09fb1a4fedc47d6fd900f29a98f4255e61517719120ee208ec28a94e2da"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:X5NS5QAVLJYNR4EWJOBQAHO3KF","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Is Deep Learning Safe for Robot Vision? Adversarial Examples against the iCub Humanoid","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.RO","stat.ML"],"primary_cat":"cs.LG","authors_text":"Ambra Demontis, Battista Biggio, Fabio Roli, Gavin Brown, Giorgio Fumera, Marco Melis","submitted_at":"2017-08-23T10:01:35Z","abstract_excerpt":"Deep neural networks have been widely adopted in recent years, exhibiting impressive performances in several application domains. It has however been shown that they can be fooled by adversarial examples, i.e., images altered by a barely-perceivable adversarial noise, carefully crafted to mislead classification. In this work, we aim to evaluate the extent to which robot-vision systems embodying deep-learning algorithms are vulnerable to adversarial examples, and propose a computationally efficient countermeasure to mitigate this threat, based on rejecting classification of anomalous inputs. We"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1708.06939","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:36:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"BhjYmH2M8G2gwCqSFGFZRngwfrtaCcR5plApc73Z0mgDbwCIe7ZFLvvIaFNohfjkOuvKusyqutjZ8jfVUqXYDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T02:42:37.686483Z"},"content_sha256":"d0f518029eba3c9aa0552ffc739fcd28e832ea105cf63cd8d3892f3721b9f4f4","schema_version":"1.0","event_id":"sha256:d0f518029eba3c9aa0552ffc739fcd28e832ea105cf63cd8d3892f3721b9f4f4"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/X5NS5QAVLJYNR4EWJOBQAHO3KF/bundle.json","state_url":"https://pith.science/pith/X5NS5QAVLJYNR4EWJOBQAHO3KF/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/X5NS5QAVLJYNR4EWJOBQAHO3KF/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-09T02:42:37Z","links":{"resolver":"https://pith.science/pith/X5NS5QAVLJYNR4EWJOBQAHO3KF","bundle":"https://pith.science/pith/X5NS5QAVLJYNR4EWJOBQAHO3KF/bundle.json","state":"https://pith.science/pith/X5NS5QAVLJYNR4EWJOBQAHO3KF/state.json","well_known_bundle":"https://pith.science/.well-known/pith/X5NS5QAVLJYNR4EWJOBQAHO3KF/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:X5NS5QAVLJYNR4EWJOBQAHO3KF","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"400a10303c4a05b3083e1aeab1bbf309863c6bd52a794e63896bdb3a164eb53d","cross_cats_sorted":["cs.RO","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-08-23T10:01:35Z","title_canon_sha256":"354139112464efd985a60eb51c69516e21b7457ab6c1a45d40c7183b675e0c98"},"schema_version":"1.0","source":{"id":"1708.06939","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1708.06939","created_at":"2026-05-18T00:36:48Z"},{"alias_kind":"arxiv_version","alias_value":"1708.06939v1","created_at":"2026-05-18T00:36:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1708.06939","created_at":"2026-05-18T00:36:48Z"},{"alias_kind":"pith_short_12","alias_value":"X5NS5QAVLJYN","created_at":"2026-05-18T12:31:53Z"},{"alias_kind":"pith_short_16","alias_value":"X5NS5QAVLJYNR4EW","created_at":"2026-05-18T12:31:53Z"},{"alias_kind":"pith_short_8","alias_value":"X5NS5QAV","created_at":"2026-05-18T12:31:53Z"}],"graph_snapshots":[{"event_id":"sha256:d0f518029eba3c9aa0552ffc739fcd28e832ea105cf63cd8d3892f3721b9f4f4","target":"graph","created_at":"2026-05-18T00:36:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep neural networks have been widely adopted in recent years, exhibiting impressive performances in several application domains. It has however been shown that they can be fooled by adversarial examples, i.e., images altered by a barely-perceivable adversarial noise, carefully crafted to mislead classification. In this work, we aim to evaluate the extent to which robot-vision systems embodying deep-learning algorithms are vulnerable to adversarial examples, and propose a computationally efficient countermeasure to mitigate this threat, based on rejecting classification of anomalous inputs. We","authors_text":"Ambra Demontis, Battista Biggio, Fabio Roli, Gavin Brown, Giorgio Fumera, Marco Melis","cross_cats":["cs.RO","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-08-23T10:01:35Z","title":"Is Deep Learning Safe for Robot Vision? Adversarial Examples against the iCub Humanoid"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1708.06939","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:accac09fb1a4fedc47d6fd900f29a98f4255e61517719120ee208ec28a94e2da","target":"record","created_at":"2026-05-18T00:36:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"400a10303c4a05b3083e1aeab1bbf309863c6bd52a794e63896bdb3a164eb53d","cross_cats_sorted":["cs.RO","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-08-23T10:01:35Z","title_canon_sha256":"354139112464efd985a60eb51c69516e21b7457ab6c1a45d40c7183b675e0c98"},"schema_version":"1.0","source":{"id":"1708.06939","kind":"arxiv","version":1}},"canonical_sha256":"bf5b2ec0155a70d8f0964b83001ddb517d1e8433c4d914a3ec932cae6d7b58a0","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"bf5b2ec0155a70d8f0964b83001ddb517d1e8433c4d914a3ec932cae6d7b58a0","first_computed_at":"2026-05-18T00:36:48.846965Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:36:48.846965Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"ZHoNBQ9q3yIj/K+H+SAXW8bu5dhb+tn1Tcn6vS+rh8ioYjEufEy7in8OTebMGzuO4tPhicVvOE7IOuuifDgQCA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:36:48.847716Z","signed_message":"canonical_sha256_bytes"},"source_id":"1708.06939","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:accac09fb1a4fedc47d6fd900f29a98f4255e61517719120ee208ec28a94e2da","sha256:d0f518029eba3c9aa0552ffc739fcd28e832ea105cf63cd8d3892f3721b9f4f4"],"state_sha256":"51688a5d5d0233fbca603baa573f02d80ac0c62987ae73eb4d5f094d7d932c08"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"oY5BNtkS7Hr0+esYHoJlLOg7dPQ8kGGbxlMXu2hg7mOLiyTjSXhEsmuHeWpDtgGIOPkdKpfHgl5yClLSkvyuCA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-09T02:42:37.690278Z","bundle_sha256":"c31f9ef9436d82dab6c0af1aed735c582e46e83e3b15a7aef0af5d7700c09637"}}