{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:XV3IR52QLRJ2V7LE23UMPXPJTH","short_pith_number":"pith:XV3IR52Q","canonical_record":{"source":{"id":"1906.06765","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-06-16T20:46:44Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"be645ff2658fdd6762edc08bdb8da0f0e4a10d0189e464eb811325659dfc9a19","abstract_canon_sha256":"0d5d278c5ffe5da98bd82b7abd01e84db54e5e69100afddd1fb316482f728ab1"},"schema_version":"1.0"},"canonical_sha256":"bd7688f7505c53aafd64d6e8c7dde999e4e7db511c6661ffbc3f0b3cec2bb80e","source":{"kind":"arxiv","id":"1906.06765","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1906.06765","created_at":"2026-05-17T23:43:12Z"},{"alias_kind":"arxiv_version","alias_value":"1906.06765v1","created_at":"2026-05-17T23:43:12Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1906.06765","created_at":"2026-05-17T23:43:12Z"},{"alias_kind":"pith_short_12","alias_value":"XV3IR52QLRJ2","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_16","alias_value":"XV3IR52QLRJ2V7LE","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_8","alias_value":"XV3IR52Q","created_at":"2026-05-18T12:33:33Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:XV3IR52QLRJ2V7LE23UMPXPJTH","target":"record","payload":{"canonical_record":{"source":{"id":"1906.06765","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-06-16T20:46:44Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"be645ff2658fdd6762edc08bdb8da0f0e4a10d0189e464eb811325659dfc9a19","abstract_canon_sha256":"0d5d278c5ffe5da98bd82b7abd01e84db54e5e69100afddd1fb316482f728ab1"},"schema_version":"1.0"},"canonical_sha256":"bd7688f7505c53aafd64d6e8c7dde999e4e7db511c6661ffbc3f0b3cec2bb80e","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:43:12.687923Z","signature_b64":"3xA4JJYAstlgCr5oAUm77XTgdu5XuS76+JXr0ws/Cq3h0lkk7COq57U37NlIWeWQSOPXYE8YNJXvrhKLZ8HFAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"bd7688f7505c53aafd64d6e8c7dde999e4e7db511c6661ffbc3f0b3cec2bb80e","last_reissued_at":"2026-05-17T23:43:12.687506Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:43:12.687506Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1906.06765","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:43:12Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"lXBXc65HU4c/dqc7zvt27/sEC3PTELmspUC4+XTbRhIipVz5F7H/7CJee7w9+BJxGiAtzJPmMXaaE/IMMM2ICQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T19:45:38.302223Z"},"content_sha256":"259279bba832b57b90d2af4661c46326f5cc88c2d36a5cb4f56a549691fdd2db","schema_version":"1.0","event_id":"sha256:259279bba832b57b90d2af4661c46326f5cc88c2d36a5cb4f56a549691fdd2db"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:XV3IR52QLRJ2V7LE23UMPXPJTH","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Defending Against Adversarial Attacks Using Random Forests","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.CV","authors_text":"Boqing Gong, Deliang Fan, Huan Zhang, Jinfeng Yi, Liqiang Wang, Yifan Ding","submitted_at":"2019-06-16T20:46:44Z","abstract_excerpt":"As deep neural networks (DNNs) have become increasingly important and popular, the robustness of DNNs is the key to the safety of both the Internet and the physical world. Unfortunately, some recent studies show that adversarial examples, which are hard to be distinguished from real examples, can easily fool DNNs and manipulate their predictions. Upon observing that adversarial examples are mostly generated by gradient-based methods, in this paper, we first propose to use a simple yet very effective non-differentiable hybrid model that combines DNNs and random forests, rather than hide gradien"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1906.06765","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:43:12Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ZOpDdJx7sSWE5uaq+FFyIP3GBHmapB9eO8gXINlK2dljPWOd1la2oKHwr5ILBqmPok+ZTXTjsh3Vu1Wgq0/SDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T19:45:38.302766Z"},"content_sha256":"e1345f6167cd2ec8e43e1de30a23501f5111caf04548caa04d223c8387ac7fb5","schema_version":"1.0","event_id":"sha256:e1345f6167cd2ec8e43e1de30a23501f5111caf04548caa04d223c8387ac7fb5"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/XV3IR52QLRJ2V7LE23UMPXPJTH/bundle.json","state_url":"https://pith.science/pith/XV3IR52QLRJ2V7LE23UMPXPJTH/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/XV3IR52QLRJ2V7LE23UMPXPJTH/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-30T19:45:38Z","links":{"resolver":"https://pith.science/pith/XV3IR52QLRJ2V7LE23UMPXPJTH","bundle":"https://pith.science/pith/XV3IR52QLRJ2V7LE23UMPXPJTH/bundle.json","state":"https://pith.science/pith/XV3IR52QLRJ2V7LE23UMPXPJTH/state.json","well_known_bundle":"https://pith.science/.well-known/pith/XV3IR52QLRJ2V7LE23UMPXPJTH/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:XV3IR52QLRJ2V7LE23UMPXPJTH","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"0d5d278c5ffe5da98bd82b7abd01e84db54e5e69100afddd1fb316482f728ab1","cross_cats_sorted":["cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-06-16T20:46:44Z","title_canon_sha256":"be645ff2658fdd6762edc08bdb8da0f0e4a10d0189e464eb811325659dfc9a19"},"schema_version":"1.0","source":{"id":"1906.06765","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1906.06765","created_at":"2026-05-17T23:43:12Z"},{"alias_kind":"arxiv_version","alias_value":"1906.06765v1","created_at":"2026-05-17T23:43:12Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1906.06765","created_at":"2026-05-17T23:43:12Z"},{"alias_kind":"pith_short_12","alias_value":"XV3IR52QLRJ2","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_16","alias_value":"XV3IR52QLRJ2V7LE","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_8","alias_value":"XV3IR52Q","created_at":"2026-05-18T12:33:33Z"}],"graph_snapshots":[{"event_id":"sha256:e1345f6167cd2ec8e43e1de30a23501f5111caf04548caa04d223c8387ac7fb5","target":"graph","created_at":"2026-05-17T23:43:12Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"As deep neural networks (DNNs) have become increasingly important and popular, the robustness of DNNs is the key to the safety of both the Internet and the physical world. Unfortunately, some recent studies show that adversarial examples, which are hard to be distinguished from real examples, can easily fool DNNs and manipulate their predictions. Upon observing that adversarial examples are mostly generated by gradient-based methods, in this paper, we first propose to use a simple yet very effective non-differentiable hybrid model that combines DNNs and random forests, rather than hide gradien","authors_text":"Boqing Gong, Deliang Fan, Huan Zhang, Jinfeng Yi, Liqiang Wang, Yifan Ding","cross_cats":["cs.CR"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-06-16T20:46:44Z","title":"Defending Against Adversarial Attacks Using Random Forests"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1906.06765","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:259279bba832b57b90d2af4661c46326f5cc88c2d36a5cb4f56a549691fdd2db","target":"record","created_at":"2026-05-17T23:43:12Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"0d5d278c5ffe5da98bd82b7abd01e84db54e5e69100afddd1fb316482f728ab1","cross_cats_sorted":["cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-06-16T20:46:44Z","title_canon_sha256":"be645ff2658fdd6762edc08bdb8da0f0e4a10d0189e464eb811325659dfc9a19"},"schema_version":"1.0","source":{"id":"1906.06765","kind":"arxiv","version":1}},"canonical_sha256":"bd7688f7505c53aafd64d6e8c7dde999e4e7db511c6661ffbc3f0b3cec2bb80e","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"bd7688f7505c53aafd64d6e8c7dde999e4e7db511c6661ffbc3f0b3cec2bb80e","first_computed_at":"2026-05-17T23:43:12.687506Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:43:12.687506Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"3xA4JJYAstlgCr5oAUm77XTgdu5XuS76+JXr0ws/Cq3h0lkk7COq57U37NlIWeWQSOPXYE8YNJXvrhKLZ8HFAg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:43:12.687923Z","signed_message":"canonical_sha256_bytes"},"source_id":"1906.06765","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:259279bba832b57b90d2af4661c46326f5cc88c2d36a5cb4f56a549691fdd2db","sha256:e1345f6167cd2ec8e43e1de30a23501f5111caf04548caa04d223c8387ac7fb5"],"state_sha256":"d0b84deaf22a47e338a7f534d48345b1096ba4ffe4716dd79091a5c5c5643dc1"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"rYSxAr9sKcUpsQ7LZ1nPLbbH3ljqql10RR7K7O2vU9Ba8GzNPF4tuw5jYGDPogn+zV5oGXnO0nhuE7MXQ410Cg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-30T19:45:38.305119Z","bundle_sha256":"0ce76ee47630fe2fbdba6ce340036717c9c143da24f2919d61e2f33e90adb5da"}}