{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:XJHDRESAUWMVQU3XBBFDRA23UC","short_pith_number":"pith:XJHDRESA","canonical_record":{"source":{"id":"1903.02926","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-03-07T14:13:59Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"a05d0cbe3ee7f0e612f641b505813cabdc080c99f64bb6cf7a1a4c381f12d069","abstract_canon_sha256":"93e5235a61424eb69c02e51372b258ce60d74fcdb338b7f91b56e54b2b9528b3"},"schema_version":"1.0"},"canonical_sha256":"ba4e389240a599585377084a38835ba08edc77871fe434568d44b762b94f76e9","source":{"kind":"arxiv","id":"1903.02926","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1903.02926","created_at":"2026-05-17T23:46:18Z"},{"alias_kind":"arxiv_version","alias_value":"1903.02926v2","created_at":"2026-05-17T23:46:18Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1903.02926","created_at":"2026-05-17T23:46:18Z"},{"alias_kind":"pith_short_12","alias_value":"XJHDRESAUWMV","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_16","alias_value":"XJHDRESAUWMVQU3X","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_8","alias_value":"XJHDRESA","created_at":"2026-05-18T12:33:33Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:XJHDRESAUWMVQU3XBBFDRA23UC","target":"record","payload":{"canonical_record":{"source":{"id":"1903.02926","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-03-07T14:13:59Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"a05d0cbe3ee7f0e612f641b505813cabdc080c99f64bb6cf7a1a4c381f12d069","abstract_canon_sha256":"93e5235a61424eb69c02e51372b258ce60d74fcdb338b7f91b56e54b2b9528b3"},"schema_version":"1.0"},"canonical_sha256":"ba4e389240a599585377084a38835ba08edc77871fe434568d44b762b94f76e9","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:46:18.334549Z","signature_b64":"31DZqkddjw8qVloiXDKiXGYQCmBfe7ZwmKaA0GHxkP2iYpPN04/3zN6HnLxyRFZsGqfmgQfNJTxWInkOkWpOCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ba4e389240a599585377084a38835ba08edc77871fe434568d44b762b94f76e9","last_reissued_at":"2026-05-17T23:46:18.333883Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:46:18.333883Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1903.02926","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:46:18Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"7wIK98Z/Q9fHgY4ToSwKMTW4GQlv5owznzmYFDy34OariTSe8/eC5HDrOtx+DvhiGZ3ZdHVsaq1lVU9S/EdeAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T07:43:04.837718Z"},"content_sha256":"af1d5697744434f06eb685c4c47b7517e5c92ceb386be98ff50962927ad23717","schema_version":"1.0","event_id":"sha256:af1d5697744434f06eb685c4c47b7517e5c92ceb386be98ff50962927ad23717"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:XJHDRESAUWMVQU3XBBFDRA23UC","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Adversarial Out-domain Examples for Generative Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Dario Pasquini, Marco Mingione, Massimo Bernaschi","submitted_at":"2019-03-07T14:13:59Z","abstract_excerpt":"Deep generative models are rapidly becoming a common tool for researchers and developers. However, as exhaustively shown for the family of discriminative models, the test-time inference of deep neural networks cannot be fully controlled and erroneous behaviors can be induced by an attacker. In the present work, we show how a malicious user can force a pre-trained generator to reproduce arbitrary data instances by feeding it suitable adversarial inputs. Moreover, we show that these adversarial latent vectors can be shaped so as to be statistically indistinguishable from the set of genuine input"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1903.02926","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:46:18Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"5rqpZZhGof/DYMRcPtXTTbdmUaFrldOtwlphf8sh25cCfe/lldLVb3RheW69R7UuBhhJUlNJUE3PYD0EjglUCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T07:43:04.838059Z"},"content_sha256":"160b162b196b301c24bc3dc537aed0b74cc5d855545f4576eaaa00ea71507f07","schema_version":"1.0","event_id":"sha256:160b162b196b301c24bc3dc537aed0b74cc5d855545f4576eaaa00ea71507f07"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/XJHDRESAUWMVQU3XBBFDRA23UC/bundle.json","state_url":"https://pith.science/pith/XJHDRESAUWMVQU3XBBFDRA23UC/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/XJHDRESAUWMVQU3XBBFDRA23UC/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-02T07:43:04Z","links":{"resolver":"https://pith.science/pith/XJHDRESAUWMVQU3XBBFDRA23UC","bundle":"https://pith.science/pith/XJHDRESAUWMVQU3XBBFDRA23UC/bundle.json","state":"https://pith.science/pith/XJHDRESAUWMVQU3XBBFDRA23UC/state.json","well_known_bundle":"https://pith.science/.well-known/pith/XJHDRESAUWMVQU3XBBFDRA23UC/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:XJHDRESAUWMVQU3XBBFDRA23UC","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"93e5235a61424eb69c02e51372b258ce60d74fcdb338b7f91b56e54b2b9528b3","cross_cats_sorted":["stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-03-07T14:13:59Z","title_canon_sha256":"a05d0cbe3ee7f0e612f641b505813cabdc080c99f64bb6cf7a1a4c381f12d069"},"schema_version":"1.0","source":{"id":"1903.02926","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1903.02926","created_at":"2026-05-17T23:46:18Z"},{"alias_kind":"arxiv_version","alias_value":"1903.02926v2","created_at":"2026-05-17T23:46:18Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1903.02926","created_at":"2026-05-17T23:46:18Z"},{"alias_kind":"pith_short_12","alias_value":"XJHDRESAUWMV","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_16","alias_value":"XJHDRESAUWMVQU3X","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_8","alias_value":"XJHDRESA","created_at":"2026-05-18T12:33:33Z"}],"graph_snapshots":[{"event_id":"sha256:160b162b196b301c24bc3dc537aed0b74cc5d855545f4576eaaa00ea71507f07","target":"graph","created_at":"2026-05-17T23:46:18Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep generative models are rapidly becoming a common tool for researchers and developers. However, as exhaustively shown for the family of discriminative models, the test-time inference of deep neural networks cannot be fully controlled and erroneous behaviors can be induced by an attacker. In the present work, we show how a malicious user can force a pre-trained generator to reproduce arbitrary data instances by feeding it suitable adversarial inputs. Moreover, we show that these adversarial latent vectors can be shaped so as to be statistically indistinguishable from the set of genuine input","authors_text":"Dario Pasquini, Marco Mingione, Massimo Bernaschi","cross_cats":["stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-03-07T14:13:59Z","title":"Adversarial Out-domain Examples for Generative Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1903.02926","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:af1d5697744434f06eb685c4c47b7517e5c92ceb386be98ff50962927ad23717","target":"record","created_at":"2026-05-17T23:46:18Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"93e5235a61424eb69c02e51372b258ce60d74fcdb338b7f91b56e54b2b9528b3","cross_cats_sorted":["stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-03-07T14:13:59Z","title_canon_sha256":"a05d0cbe3ee7f0e612f641b505813cabdc080c99f64bb6cf7a1a4c381f12d069"},"schema_version":"1.0","source":{"id":"1903.02926","kind":"arxiv","version":2}},"canonical_sha256":"ba4e389240a599585377084a38835ba08edc77871fe434568d44b762b94f76e9","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"ba4e389240a599585377084a38835ba08edc77871fe434568d44b762b94f76e9","first_computed_at":"2026-05-17T23:46:18.333883Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:46:18.333883Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"31DZqkddjw8qVloiXDKiXGYQCmBfe7ZwmKaA0GHxkP2iYpPN04/3zN6HnLxyRFZsGqfmgQfNJTxWInkOkWpOCQ==","signature_status":"signed_v1","signed_at":"2026-05-17T23:46:18.334549Z","signed_message":"canonical_sha256_bytes"},"source_id":"1903.02926","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:af1d5697744434f06eb685c4c47b7517e5c92ceb386be98ff50962927ad23717","sha256:160b162b196b301c24bc3dc537aed0b74cc5d855545f4576eaaa00ea71507f07"],"state_sha256":"f43bb4f08d0b25c6acc963b69269b237b9dfbe64cb91073645d829c9efc54a3d"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"yLtH/iUT+R5c0SYSSB6Su6r+EkwLn0zru5rMSTZeV1GhR/97HvvW9ZC2GvR21PEqQAgmQDglMSMKAj1WjtcZCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-02T07:43:04.839994Z","bundle_sha256":"97fd40125a42826e1b8c5f370027ce7859ab613639040e6fc6e57586ab43c907"}}