{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2024:XHDSCA5UC3FKJ3L4WX5PBHV5YU","short_pith_number":"pith:XHDSCA5U","canonical_record":{"source":{"id":"2402.17509","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2024-02-27T13:49:12Z","cross_cats_sorted":[],"title_canon_sha256":"ab840216a81c1741fc2f4c59042b1d93f4b1b6a0ff02de184755e85bd41c1704","abstract_canon_sha256":"fa21ffbabb8ab3274a29e5b2b41a9cc734acfbac57b9601b8c142608cc3ecfa5"},"schema_version":"1.0"},"canonical_sha256":"b9c72103b416caa4ed7cb5faf09ebdc53ce82486231917165cc80695f0c62896","source":{"kind":"arxiv","id":"2402.17509","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2402.17509","created_at":"2026-07-05T09:19:54Z"},{"alias_kind":"arxiv_version","alias_value":"2402.17509v3","created_at":"2026-07-05T09:19:54Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.17509","created_at":"2026-07-05T09:19:54Z"},{"alias_kind":"pith_short_12","alias_value":"XHDSCA5UC3FK","created_at":"2026-07-05T09:19:54Z"},{"alias_kind":"pith_short_16","alias_value":"XHDSCA5UC3FKJ3L4","created_at":"2026-07-05T09:19:54Z"},{"alias_kind":"pith_short_8","alias_value":"XHDSCA5U","created_at":"2026-07-05T09:19:54Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2024:XHDSCA5UC3FKJ3L4WX5PBHV5YU","target":"record","payload":{"canonical_record":{"source":{"id":"2402.17509","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2024-02-27T13:49:12Z","cross_cats_sorted":[],"title_canon_sha256":"ab840216a81c1741fc2f4c59042b1d93f4b1b6a0ff02de184755e85bd41c1704","abstract_canon_sha256":"fa21ffbabb8ab3274a29e5b2b41a9cc734acfbac57b9601b8c142608cc3ecfa5"},"schema_version":"1.0"},"canonical_sha256":"b9c72103b416caa4ed7cb5faf09ebdc53ce82486231917165cc80695f0c62896","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:19:54.408973Z","signature_b64":"YjqCXYZXFg32OrEmjDKCZ6/OTMB31Xs5HOmz9y5ZeE+la2qIM6QZW2lqUDnQMei+UhCAcXrreyoO/YjQq6A8Aw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b9c72103b416caa4ed7cb5faf09ebdc53ce82486231917165cc80695f0c62896","last_reissued_at":"2026-07-05T09:19:54.408508Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:19:54.408508Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2402.17509","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T09:19:54Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"/cC2nbvGwS+60c2VvKL+aN+w7lW0ndfMZyIiRgFSYidxDY5RquGPb0YancOWbBDFfx/Wy1W2Ft69fr4NE0YKAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-16T20:15:18.019929Z"},"content_sha256":"aa8256a42cffebb29024d6aa0699e726c0b31486df600de2f9e109c78bf7e38f","schema_version":"1.0","event_id":"sha256:aa8256a42cffebb29024d6aa0699e726c0b31486df600de2f9e109c78bf7e38f"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2024:XHDSCA5UC3FKJ3L4WX5PBHV5YU","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Extreme Miscalibration and the Illusion of Adversarial Robustness","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Aditya Rawal, George Karypis, Samson Tan, Sheng Zha, Volkan Cevher, Vyas Raina","submitted_at":"2024-02-27T13:49:12Z","abstract_excerpt":"Deep learning-based Natural Language Processing (NLP) models are vulnerable to adversarial attacks, where small perturbations can cause a model to misclassify. Adversarial Training (AT) is often used to increase model robustness. However, we have discovered an intriguing phenomenon: deliberately or accidentally miscalibrating models masks gradients in a way that interferes with adversarial attack search methods, giving rise to an apparent increase in robustness. We show that this observed gain in robustness is an illusion of robustness (IOR), and demonstrate how an adversary can perform variou"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2402.17509","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2402.17509/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T09:19:54Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"tRKJtpZTluCk6VIShX225GY7K/ELQVpCqc02+RfuE+ljsM2yTC3BKbhte8XTa5dznztBVz+ip84tx5xtH11eAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-16T20:15:18.020496Z"},"content_sha256":"ad1c869971ad2dbc39428290d057e982fbab6808286b37fdc02f97c843a99eec","schema_version":"1.0","event_id":"sha256:ad1c869971ad2dbc39428290d057e982fbab6808286b37fdc02f97c843a99eec"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/XHDSCA5UC3FKJ3L4WX5PBHV5YU/bundle.json","state_url":"https://pith.science/pith/XHDSCA5UC3FKJ3L4WX5PBHV5YU/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/XHDSCA5UC3FKJ3L4WX5PBHV5YU/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-16T20:15:18Z","links":{"resolver":"https://pith.science/pith/XHDSCA5UC3FKJ3L4WX5PBHV5YU","bundle":"https://pith.science/pith/XHDSCA5UC3FKJ3L4WX5PBHV5YU/bundle.json","state":"https://pith.science/pith/XHDSCA5UC3FKJ3L4WX5PBHV5YU/state.json","well_known_bundle":"https://pith.science/.well-known/pith/XHDSCA5UC3FKJ3L4WX5PBHV5YU/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2024:XHDSCA5UC3FKJ3L4WX5PBHV5YU","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"fa21ffbabb8ab3274a29e5b2b41a9cc734acfbac57b9601b8c142608cc3ecfa5","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2024-02-27T13:49:12Z","title_canon_sha256":"ab840216a81c1741fc2f4c59042b1d93f4b1b6a0ff02de184755e85bd41c1704"},"schema_version":"1.0","source":{"id":"2402.17509","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2402.17509","created_at":"2026-07-05T09:19:54Z"},{"alias_kind":"arxiv_version","alias_value":"2402.17509v3","created_at":"2026-07-05T09:19:54Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.17509","created_at":"2026-07-05T09:19:54Z"},{"alias_kind":"pith_short_12","alias_value":"XHDSCA5UC3FK","created_at":"2026-07-05T09:19:54Z"},{"alias_kind":"pith_short_16","alias_value":"XHDSCA5UC3FKJ3L4","created_at":"2026-07-05T09:19:54Z"},{"alias_kind":"pith_short_8","alias_value":"XHDSCA5U","created_at":"2026-07-05T09:19:54Z"}],"graph_snapshots":[{"event_id":"sha256:ad1c869971ad2dbc39428290d057e982fbab6808286b37fdc02f97c843a99eec","target":"graph","created_at":"2026-07-05T09:19:54Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2402.17509/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Deep learning-based Natural Language Processing (NLP) models are vulnerable to adversarial attacks, where small perturbations can cause a model to misclassify. Adversarial Training (AT) is often used to increase model robustness. However, we have discovered an intriguing phenomenon: deliberately or accidentally miscalibrating models masks gradients in a way that interferes with adversarial attack search methods, giving rise to an apparent increase in robustness. We show that this observed gain in robustness is an illusion of robustness (IOR), and demonstrate how an adversary can perform variou","authors_text":"Aditya Rawal, George Karypis, Samson Tan, Sheng Zha, Volkan Cevher, Vyas Raina","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2024-02-27T13:49:12Z","title":"Extreme Miscalibration and the Illusion of Adversarial Robustness"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2402.17509","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:aa8256a42cffebb29024d6aa0699e726c0b31486df600de2f9e109c78bf7e38f","target":"record","created_at":"2026-07-05T09:19:54Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"fa21ffbabb8ab3274a29e5b2b41a9cc734acfbac57b9601b8c142608cc3ecfa5","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2024-02-27T13:49:12Z","title_canon_sha256":"ab840216a81c1741fc2f4c59042b1d93f4b1b6a0ff02de184755e85bd41c1704"},"schema_version":"1.0","source":{"id":"2402.17509","kind":"arxiv","version":3}},"canonical_sha256":"b9c72103b416caa4ed7cb5faf09ebdc53ce82486231917165cc80695f0c62896","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b9c72103b416caa4ed7cb5faf09ebdc53ce82486231917165cc80695f0c62896","first_computed_at":"2026-07-05T09:19:54.408508Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T09:19:54.408508Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"YjqCXYZXFg32OrEmjDKCZ6/OTMB31Xs5HOmz9y5ZeE+la2qIM6QZW2lqUDnQMei+UhCAcXrreyoO/YjQq6A8Aw==","signature_status":"signed_v1","signed_at":"2026-07-05T09:19:54.408973Z","signed_message":"canonical_sha256_bytes"},"source_id":"2402.17509","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:aa8256a42cffebb29024d6aa0699e726c0b31486df600de2f9e109c78bf7e38f","sha256:ad1c869971ad2dbc39428290d057e982fbab6808286b37fdc02f97c843a99eec"],"state_sha256":"01ed84f06c127b6da37026738f5b55630550ef7b69a7a9c1a279e8530484d215"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Y3gGaTlHnioL+I437kEMmcjhFtcTOFTzsqSfuRMdlVJLM7lPgnGdFP1tOOBJ7xRnwJCpJhescmrgKn6oLXY7BA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-16T20:15:18.025863Z","bundle_sha256":"4df8a86d91bfef2ddc14f3844db7c9df9587c9af08cc62ce1ab7312d90b0124c"}}