{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2022:XBBHUPYUWUVJ5DL434KXF7YIR7","short_pith_number":"pith:XBBHUPYU","canonical_record":{"source":{"id":"2209.03358","kind":"arxiv","version":5},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.NE","submitted_at":"2022-09-07T17:05:48Z","cross_cats_sorted":["cs.AI","cs.CR","cs.CV","cs.LG"],"title_canon_sha256":"21ac28c104c001e550a7bf01c270cd9848c135a0d406d33ff125026cd4669e1b","abstract_canon_sha256":"a10a61530d42e80dc5b80de9bfde0748355085e1339dee168d6814a192c844ba"},"schema_version":"1.0"},"canonical_sha256":"b8427a3f14b52a9e8d7cdf1572ff088fd0926ed09033554c8aaf3d3566b4bbe0","source":{"kind":"arxiv","id":"2209.03358","version":5},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2209.03358","created_at":"2026-05-22T01:03:38Z"},{"alias_kind":"arxiv_version","alias_value":"2209.03358v5","created_at":"2026-05-22T01:03:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2209.03358","created_at":"2026-05-22T01:03:38Z"},{"alias_kind":"pith_short_12","alias_value":"XBBHUPYUWUVJ","created_at":"2026-05-22T01:03:38Z"},{"alias_kind":"pith_short_16","alias_value":"XBBHUPYUWUVJ5DL4","created_at":"2026-05-22T01:03:38Z"},{"alias_kind":"pith_short_8","alias_value":"XBBHUPYU","created_at":"2026-05-22T01:03:38Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2022:XBBHUPYUWUVJ5DL434KXF7YIR7","target":"record","payload":{"canonical_record":{"source":{"id":"2209.03358","kind":"arxiv","version":5},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.NE","submitted_at":"2022-09-07T17:05:48Z","cross_cats_sorted":["cs.AI","cs.CR","cs.CV","cs.LG"],"title_canon_sha256":"21ac28c104c001e550a7bf01c270cd9848c135a0d406d33ff125026cd4669e1b","abstract_canon_sha256":"a10a61530d42e80dc5b80de9bfde0748355085e1339dee168d6814a192c844ba"},"schema_version":"1.0"},"canonical_sha256":"b8427a3f14b52a9e8d7cdf1572ff088fd0926ed09033554c8aaf3d3566b4bbe0","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-22T01:03:38.640224Z","signature_b64":"6SGZa8OopbY0spDBXUFuzT8IkqU5iFDpXzJuV7433aDvu5fgWybK7e/h7DxbkbUyM+o+a4vO/Jbe5Qeuhx5dCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b8427a3f14b52a9e8d7cdf1572ff088fd0926ed09033554c8aaf3d3566b4bbe0","last_reissued_at":"2026-05-22T01:03:38.639553Z","signature_status":"signed_v1","first_computed_at":"2026-05-22T01:03:38.639553Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2209.03358","source_version":5,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-22T01:03:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"c8yYSir7qibu0GMM6BJP0KwQqmJtQRGI+3IOlUpIq2urteysiKOeT/a4ZkbyeCp7aXvZl6kVSr8cF8ju0ks3CA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T19:20:44.062058Z"},"content_sha256":"3049817c04cd65ddf84a99515308b80c9d38eb017000f355607d9bb45f386fab","schema_version":"1.0","event_id":"sha256:3049817c04cd65ddf84a99515308b80c9d38eb017000f355607d9bb45f386fab"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2022:XBBHUPYUWUVJ5DL434KXF7YIR7","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Attacking the Spike: On the Transferability and Security of Spiking Neural Networks to Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CR","cs.CV","cs.LG"],"primary_cat":"cs.NE","authors_text":"Caiwen Ding, Ethan Rathbun, Haowen Fang, Kaleel Mahmood, Nuo Xu, Wujie Wen","submitted_at":"2022-09-07T17:05:48Z","abstract_excerpt":"Spiking neural networks (SNNs) have attracted much attention for their high energy efficiency and recent advances in classification performance. However, unlike traditional deep learning approaches, the study of SNN robustness to adversarial examples remains relatively underdeveloped. In this work, we advance the adversarial attack side of SNNs through three contributions. First, we show that successful white-box adversarial attacks on SNNs are highly dependent on the underlying surrogate gradient estimator, even for adversarially trained SNNs. Second, using the best single surrogate gradient "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2209.03358","kind":"arxiv","version":5},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2209.03358/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-22T01:03:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"K04XrW2nT9DIo35mZHhbDcC6cyWk3pvkaF9mdod8gbmcxuj9j/VQxTjLfiDxh7FIuBxvolD/uKPDl7Jc5oieDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T19:20:44.062794Z"},"content_sha256":"594e5428ee227489dc52e616191efaa6189a09bc184504398889677e807ea895","schema_version":"1.0","event_id":"sha256:594e5428ee227489dc52e616191efaa6189a09bc184504398889677e807ea895"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/XBBHUPYUWUVJ5DL434KXF7YIR7/bundle.json","state_url":"https://pith.science/pith/XBBHUPYUWUVJ5DL434KXF7YIR7/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/XBBHUPYUWUVJ5DL434KXF7YIR7/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T19:20:44Z","links":{"resolver":"https://pith.science/pith/XBBHUPYUWUVJ5DL434KXF7YIR7","bundle":"https://pith.science/pith/XBBHUPYUWUVJ5DL434KXF7YIR7/bundle.json","state":"https://pith.science/pith/XBBHUPYUWUVJ5DL434KXF7YIR7/state.json","well_known_bundle":"https://pith.science/.well-known/pith/XBBHUPYUWUVJ5DL434KXF7YIR7/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2022:XBBHUPYUWUVJ5DL434KXF7YIR7","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"a10a61530d42e80dc5b80de9bfde0748355085e1339dee168d6814a192c844ba","cross_cats_sorted":["cs.AI","cs.CR","cs.CV","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.NE","submitted_at":"2022-09-07T17:05:48Z","title_canon_sha256":"21ac28c104c001e550a7bf01c270cd9848c135a0d406d33ff125026cd4669e1b"},"schema_version":"1.0","source":{"id":"2209.03358","kind":"arxiv","version":5}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2209.03358","created_at":"2026-05-22T01:03:38Z"},{"alias_kind":"arxiv_version","alias_value":"2209.03358v5","created_at":"2026-05-22T01:03:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2209.03358","created_at":"2026-05-22T01:03:38Z"},{"alias_kind":"pith_short_12","alias_value":"XBBHUPYUWUVJ","created_at":"2026-05-22T01:03:38Z"},{"alias_kind":"pith_short_16","alias_value":"XBBHUPYUWUVJ5DL4","created_at":"2026-05-22T01:03:38Z"},{"alias_kind":"pith_short_8","alias_value":"XBBHUPYU","created_at":"2026-05-22T01:03:38Z"}],"graph_snapshots":[{"event_id":"sha256:594e5428ee227489dc52e616191efaa6189a09bc184504398889677e807ea895","target":"graph","created_at":"2026-05-22T01:03:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2209.03358/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Spiking neural networks (SNNs) have attracted much attention for their high energy efficiency and recent advances in classification performance. However, unlike traditional deep learning approaches, the study of SNN robustness to adversarial examples remains relatively underdeveloped. In this work, we advance the adversarial attack side of SNNs through three contributions. First, we show that successful white-box adversarial attacks on SNNs are highly dependent on the underlying surrogate gradient estimator, even for adversarially trained SNNs. Second, using the best single surrogate gradient ","authors_text":"Caiwen Ding, Ethan Rathbun, Haowen Fang, Kaleel Mahmood, Nuo Xu, Wujie Wen","cross_cats":["cs.AI","cs.CR","cs.CV","cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.NE","submitted_at":"2022-09-07T17:05:48Z","title":"Attacking the Spike: On the Transferability and Security of Spiking Neural Networks to Adversarial Examples"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2209.03358","kind":"arxiv","version":5},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:3049817c04cd65ddf84a99515308b80c9d38eb017000f355607d9bb45f386fab","target":"record","created_at":"2026-05-22T01:03:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"a10a61530d42e80dc5b80de9bfde0748355085e1339dee168d6814a192c844ba","cross_cats_sorted":["cs.AI","cs.CR","cs.CV","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.NE","submitted_at":"2022-09-07T17:05:48Z","title_canon_sha256":"21ac28c104c001e550a7bf01c270cd9848c135a0d406d33ff125026cd4669e1b"},"schema_version":"1.0","source":{"id":"2209.03358","kind":"arxiv","version":5}},"canonical_sha256":"b8427a3f14b52a9e8d7cdf1572ff088fd0926ed09033554c8aaf3d3566b4bbe0","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b8427a3f14b52a9e8d7cdf1572ff088fd0926ed09033554c8aaf3d3566b4bbe0","first_computed_at":"2026-05-22T01:03:38.639553Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-22T01:03:38.639553Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"6SGZa8OopbY0spDBXUFuzT8IkqU5iFDpXzJuV7433aDvu5fgWybK7e/h7DxbkbUyM+o+a4vO/Jbe5Qeuhx5dCw==","signature_status":"signed_v1","signed_at":"2026-05-22T01:03:38.640224Z","signed_message":"canonical_sha256_bytes"},"source_id":"2209.03358","source_kind":"arxiv","source_version":5}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:3049817c04cd65ddf84a99515308b80c9d38eb017000f355607d9bb45f386fab","sha256:594e5428ee227489dc52e616191efaa6189a09bc184504398889677e807ea895"],"state_sha256":"8a499d4b96e05aa87b782fed03b9c7ca9d93f6e483761f805cb96f44853f4203"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"qvT+X8MzrCHBzdO4ZRkRUmcxuqjz3LNn7Vx/4FGcevLAdAcyc43TryoWqk9Ag9D2TCD3qQ2rLte2uULUd6sPDg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T19:20:44.065869Z","bundle_sha256":"2d72bd58c10b6c5c5c6e195416ad690c893d0b58109376fea45746fc30ac54c7"}}