{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:XGVLHQV6P6OEOIKWWVMXSKEANB","short_pith_number":"pith:XGVLHQV6","canonical_record":{"source":{"id":"1810.10939","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-10-25T15:53:19Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"79ebc28e42a918dc2b76bf8e6082b069b246834de0ed40c83c7a3d5d84b0d6f7","abstract_canon_sha256":"43f1974b7499300447939f9f9295fc363d1a4056911f99dbfed43d7148b2e4ea"},"schema_version":"1.0"},"canonical_sha256":"b9aab3c2be7f9c472156b55979288068601b7982af21292b40d92a7de5f0a44e","source":{"kind":"arxiv","id":"1810.10939","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1810.10939","created_at":"2026-05-17T23:41:53Z"},{"alias_kind":"arxiv_version","alias_value":"1810.10939v3","created_at":"2026-05-17T23:41:53Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1810.10939","created_at":"2026-05-17T23:41:53Z"},{"alias_kind":"pith_short_12","alias_value":"XGVLHQV6P6OE","created_at":"2026-05-18T12:33:01Z"},{"alias_kind":"pith_short_16","alias_value":"XGVLHQV6P6OEOIKW","created_at":"2026-05-18T12:33:01Z"},{"alias_kind":"pith_short_8","alias_value":"XGVLHQV6","created_at":"2026-05-18T12:33:01Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:XGVLHQV6P6OEOIKWWVMXSKEANB","target":"record","payload":{"canonical_record":{"source":{"id":"1810.10939","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-10-25T15:53:19Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"79ebc28e42a918dc2b76bf8e6082b069b246834de0ed40c83c7a3d5d84b0d6f7","abstract_canon_sha256":"43f1974b7499300447939f9f9295fc363d1a4056911f99dbfed43d7148b2e4ea"},"schema_version":"1.0"},"canonical_sha256":"b9aab3c2be7f9c472156b55979288068601b7982af21292b40d92a7de5f0a44e","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:41:53.787457Z","signature_b64":"99A2qBZ3Zde4AykL3om6zjHqsPaOoDoBVPh+ofVSChFjQ1mON2kM4BtW36cDQsfjeIOsZF/YbCPiZmXqCIihAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b9aab3c2be7f9c472156b55979288068601b7982af21292b40d92a7de5f0a44e","last_reissued_at":"2026-05-17T23:41:53.786913Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:41:53.786913Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1810.10939","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:41:53Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"qYgK1OA1zw+9nSs4tPxfKUTn7o4uMnI1VF6zBRp5gG1uSl5ffSfPn9EvE3nXJxfSENeFbax572oo4BPG6/veBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T10:03:18.552921Z"},"content_sha256":"6c7659822cf2136c5079d4393160a39fca1f13436106f88e2f841f59ad82909d","schema_version":"1.0","event_id":"sha256:6c7659822cf2136c5079d4393160a39fca1f13436106f88e2f841f59ad82909d"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:XGVLHQV6P6OEOIKWWVMXSKEANB","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Evading classifiers in discrete domains with provable optimality guarantees","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Bogdan Kulynych, Carmela Troncoso, Jamie Hayes, Nikita Samarin","submitted_at":"2018-10-25T15:53:19Z","abstract_excerpt":"Machine-learning models for security-critical applications such as bot, malware, or spam detection, operate in constrained discrete domains. These applications would benefit from having provable guarantees against adversarial examples. The existing literature on provable adversarial robustness of models, however, exclusively focuses on robustness to gradient-based attacks in domains such as images. These attacks model the adversarial cost, e.g., amount of distortion applied to an image, as a $p$-norm. We argue that this approach is not well-suited to model adversarial costs in constrained doma"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1810.10939","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:41:53Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"9sbv4LVKzLI7mTIXIoBAutl7tV+Rwm/CYJXqCKfsXJr5TFe96g9heEImc+hGaEl1zueXkOFjRFMufIU/+9bRDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T10:03:18.553586Z"},"content_sha256":"354ccd427c896f511b7f6b5cf991fcd5116629a19c3e411eeccfb66cbd178508","schema_version":"1.0","event_id":"sha256:354ccd427c896f511b7f6b5cf991fcd5116629a19c3e411eeccfb66cbd178508"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/XGVLHQV6P6OEOIKWWVMXSKEANB/bundle.json","state_url":"https://pith.science/pith/XGVLHQV6P6OEOIKWWVMXSKEANB/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/XGVLHQV6P6OEOIKWWVMXSKEANB/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-27T10:03:18Z","links":{"resolver":"https://pith.science/pith/XGVLHQV6P6OEOIKWWVMXSKEANB","bundle":"https://pith.science/pith/XGVLHQV6P6OEOIKWWVMXSKEANB/bundle.json","state":"https://pith.science/pith/XGVLHQV6P6OEOIKWWVMXSKEANB/state.json","well_known_bundle":"https://pith.science/.well-known/pith/XGVLHQV6P6OEOIKWWVMXSKEANB/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:XGVLHQV6P6OEOIKWWVMXSKEANB","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"43f1974b7499300447939f9f9295fc363d1a4056911f99dbfed43d7148b2e4ea","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-10-25T15:53:19Z","title_canon_sha256":"79ebc28e42a918dc2b76bf8e6082b069b246834de0ed40c83c7a3d5d84b0d6f7"},"schema_version":"1.0","source":{"id":"1810.10939","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1810.10939","created_at":"2026-05-17T23:41:53Z"},{"alias_kind":"arxiv_version","alias_value":"1810.10939v3","created_at":"2026-05-17T23:41:53Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1810.10939","created_at":"2026-05-17T23:41:53Z"},{"alias_kind":"pith_short_12","alias_value":"XGVLHQV6P6OE","created_at":"2026-05-18T12:33:01Z"},{"alias_kind":"pith_short_16","alias_value":"XGVLHQV6P6OEOIKW","created_at":"2026-05-18T12:33:01Z"},{"alias_kind":"pith_short_8","alias_value":"XGVLHQV6","created_at":"2026-05-18T12:33:01Z"}],"graph_snapshots":[{"event_id":"sha256:354ccd427c896f511b7f6b5cf991fcd5116629a19c3e411eeccfb66cbd178508","target":"graph","created_at":"2026-05-17T23:41:53Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Machine-learning models for security-critical applications such as bot, malware, or spam detection, operate in constrained discrete domains. These applications would benefit from having provable guarantees against adversarial examples. The existing literature on provable adversarial robustness of models, however, exclusively focuses on robustness to gradient-based attacks in domains such as images. These attacks model the adversarial cost, e.g., amount of distortion applied to an image, as a $p$-norm. We argue that this approach is not well-suited to model adversarial costs in constrained doma","authors_text":"Bogdan Kulynych, Carmela Troncoso, Jamie Hayes, Nikita Samarin","cross_cats":["cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-10-25T15:53:19Z","title":"Evading classifiers in discrete domains with provable optimality guarantees"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1810.10939","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:6c7659822cf2136c5079d4393160a39fca1f13436106f88e2f841f59ad82909d","target":"record","created_at":"2026-05-17T23:41:53Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"43f1974b7499300447939f9f9295fc363d1a4056911f99dbfed43d7148b2e4ea","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-10-25T15:53:19Z","title_canon_sha256":"79ebc28e42a918dc2b76bf8e6082b069b246834de0ed40c83c7a3d5d84b0d6f7"},"schema_version":"1.0","source":{"id":"1810.10939","kind":"arxiv","version":3}},"canonical_sha256":"b9aab3c2be7f9c472156b55979288068601b7982af21292b40d92a7de5f0a44e","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b9aab3c2be7f9c472156b55979288068601b7982af21292b40d92a7de5f0a44e","first_computed_at":"2026-05-17T23:41:53.786913Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:41:53.786913Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"99A2qBZ3Zde4AykL3om6zjHqsPaOoDoBVPh+ofVSChFjQ1mON2kM4BtW36cDQsfjeIOsZF/YbCPiZmXqCIihAg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:41:53.787457Z","signed_message":"canonical_sha256_bytes"},"source_id":"1810.10939","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:6c7659822cf2136c5079d4393160a39fca1f13436106f88e2f841f59ad82909d","sha256:354ccd427c896f511b7f6b5cf991fcd5116629a19c3e411eeccfb66cbd178508"],"state_sha256":"da3ace9c335be787978763d5d6c2a44b4194b792baaa192fd7fbf22300e20d0d"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"IaQtiUVetipwl+c6jNgUXQsT4ppMjY3TUmXQpFZzH2guJoB+vQN0xbEd/tpHEqW02V+/DgNn+PDFCrvEXXdfCA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-27T10:03:18.557545Z","bundle_sha256":"f3f4f1b943e41466331d4688303cad6ff73ce863d57cef3a7d78513a3cae71cf"}}