{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:XVCO6C56KU6Q7AH7KFHRZO7ZMI","short_pith_number":"pith:XVCO6C56","canonical_record":{"source":{"id":"1802.00420","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-02-01T18:20:05Z","cross_cats_sorted":["cs.AI","cs.CR"],"title_canon_sha256":"9335a571e41234839b23d2281c310451d1834e637687258cefd10bf6c2872b93","abstract_canon_sha256":"5fe612cac022bce55403a3b2fa9954e31ad6fec3f08214655472a009dd55b1d5"},"schema_version":"1.0"},"canonical_sha256":"bd44ef0bbe553d0f80ff514f1cbbf9622f752906a38f23a3db5b82d132f6cb56","source":{"kind":"arxiv","id":"1802.00420","version":4},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1802.00420","created_at":"2026-05-18T00:09:27Z"},{"alias_kind":"arxiv_version","alias_value":"1802.00420v4","created_at":"2026-05-18T00:09:27Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1802.00420","created_at":"2026-05-18T00:09:27Z"},{"alias_kind":"pith_short_12","alias_value":"XVCO6C56KU6Q","created_at":"2026-05-18T12:33:01Z"},{"alias_kind":"pith_short_16","alias_value":"XVCO6C56KU6Q7AH7","created_at":"2026-05-18T12:33:01Z"},{"alias_kind":"pith_short_8","alias_value":"XVCO6C56","created_at":"2026-05-18T12:33:01Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:XVCO6C56KU6Q7AH7KFHRZO7ZMI","target":"record","payload":{"canonical_record":{"source":{"id":"1802.00420","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-02-01T18:20:05Z","cross_cats_sorted":["cs.AI","cs.CR"],"title_canon_sha256":"9335a571e41234839b23d2281c310451d1834e637687258cefd10bf6c2872b93","abstract_canon_sha256":"5fe612cac022bce55403a3b2fa9954e31ad6fec3f08214655472a009dd55b1d5"},"schema_version":"1.0"},"canonical_sha256":"bd44ef0bbe553d0f80ff514f1cbbf9622f752906a38f23a3db5b82d132f6cb56","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:09:27.311643Z","signature_b64":"g/lXsU+FPWljfHr2t7PbPsCRAPX8lvX4ylDgWx3Lk3mVRtOHBujsXh2ne7okMmbG9Aa0OjOfg/VZUmAD7CKiBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"bd44ef0bbe553d0f80ff514f1cbbf9622f752906a38f23a3db5b82d132f6cb56","last_reissued_at":"2026-05-18T00:09:27.310944Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:09:27.310944Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1802.00420","source_version":4,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:09:27Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"MTLB2PBk16gzek5JCwZOMuJ/im88+N1P39DVobQWViGJe7Z6e5X66p/Zh1MWSbqI504P5U6KqJpebP/aBSR3Dg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T08:47:22.090526Z"},"content_sha256":"ef53e7f5497cc1f545bee045f2e11f30c6e29d07b9a43bf2b6e04be34bb11870","schema_version":"1.0","event_id":"sha256:ef53e7f5497cc1f545bee045f2e11f30c6e29d07b9a43bf2b6e04be34bb11870"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:XVCO6C56KU6Q7AH7KFHRZO7ZMI","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CR"],"primary_cat":"cs.LG","authors_text":"Anish Athalye, David Wagner, Nicholas Carlini","submitted_at":"2018-02-01T18:20:05Z","abstract_excerpt":"We identify obfuscated gradients, a kind of gradient masking, as a phenomenon that leads to a false sense of security in defenses against adversarial examples. While defenses that cause obfuscated gradients appear to defeat iterative optimization-based attacks, we find defenses relying on this effect can be circumvented. We describe characteristic behaviors of defenses exhibiting the effect, and for each of the three types of obfuscated gradients we discover, we develop attack techniques to overcome it. In a case study, examining non-certified white-box-secure defenses at ICLR 2018, we find ob"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1802.00420","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:09:27Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8/Fn4nezebPk6oiOvnfQhZI3oaJmNFt0ydung794vxZsnCzw6TrxSuke4TfSnQafghz1exhbymi9pDUHLG5GBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T08:47:22.090874Z"},"content_sha256":"17c31545c69db2c090e229c3ff6f49b0e85a9c69701f45e29fa62e16d1b541b8","schema_version":"1.0","event_id":"sha256:17c31545c69db2c090e229c3ff6f49b0e85a9c69701f45e29fa62e16d1b541b8"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/XVCO6C56KU6Q7AH7KFHRZO7ZMI/bundle.json","state_url":"https://pith.science/pith/XVCO6C56KU6Q7AH7KFHRZO7ZMI/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/XVCO6C56KU6Q7AH7KFHRZO7ZMI/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-01T08:47:22Z","links":{"resolver":"https://pith.science/pith/XVCO6C56KU6Q7AH7KFHRZO7ZMI","bundle":"https://pith.science/pith/XVCO6C56KU6Q7AH7KFHRZO7ZMI/bundle.json","state":"https://pith.science/pith/XVCO6C56KU6Q7AH7KFHRZO7ZMI/state.json","well_known_bundle":"https://pith.science/.well-known/pith/XVCO6C56KU6Q7AH7KFHRZO7ZMI/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:XVCO6C56KU6Q7AH7KFHRZO7ZMI","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"5fe612cac022bce55403a3b2fa9954e31ad6fec3f08214655472a009dd55b1d5","cross_cats_sorted":["cs.AI","cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-02-01T18:20:05Z","title_canon_sha256":"9335a571e41234839b23d2281c310451d1834e637687258cefd10bf6c2872b93"},"schema_version":"1.0","source":{"id":"1802.00420","kind":"arxiv","version":4}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1802.00420","created_at":"2026-05-18T00:09:27Z"},{"alias_kind":"arxiv_version","alias_value":"1802.00420v4","created_at":"2026-05-18T00:09:27Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1802.00420","created_at":"2026-05-18T00:09:27Z"},{"alias_kind":"pith_short_12","alias_value":"XVCO6C56KU6Q","created_at":"2026-05-18T12:33:01Z"},{"alias_kind":"pith_short_16","alias_value":"XVCO6C56KU6Q7AH7","created_at":"2026-05-18T12:33:01Z"},{"alias_kind":"pith_short_8","alias_value":"XVCO6C56","created_at":"2026-05-18T12:33:01Z"}],"graph_snapshots":[{"event_id":"sha256:17c31545c69db2c090e229c3ff6f49b0e85a9c69701f45e29fa62e16d1b541b8","target":"graph","created_at":"2026-05-18T00:09:27Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We identify obfuscated gradients, a kind of gradient masking, as a phenomenon that leads to a false sense of security in defenses against adversarial examples. While defenses that cause obfuscated gradients appear to defeat iterative optimization-based attacks, we find defenses relying on this effect can be circumvented. We describe characteristic behaviors of defenses exhibiting the effect, and for each of the three types of obfuscated gradients we discover, we develop attack techniques to overcome it. In a case study, examining non-certified white-box-secure defenses at ICLR 2018, we find ob","authors_text":"Anish Athalye, David Wagner, Nicholas Carlini","cross_cats":["cs.AI","cs.CR"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-02-01T18:20:05Z","title":"Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1802.00420","kind":"arxiv","version":4},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:ef53e7f5497cc1f545bee045f2e11f30c6e29d07b9a43bf2b6e04be34bb11870","target":"record","created_at":"2026-05-18T00:09:27Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"5fe612cac022bce55403a3b2fa9954e31ad6fec3f08214655472a009dd55b1d5","cross_cats_sorted":["cs.AI","cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-02-01T18:20:05Z","title_canon_sha256":"9335a571e41234839b23d2281c310451d1834e637687258cefd10bf6c2872b93"},"schema_version":"1.0","source":{"id":"1802.00420","kind":"arxiv","version":4}},"canonical_sha256":"bd44ef0bbe553d0f80ff514f1cbbf9622f752906a38f23a3db5b82d132f6cb56","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"bd44ef0bbe553d0f80ff514f1cbbf9622f752906a38f23a3db5b82d132f6cb56","first_computed_at":"2026-05-18T00:09:27.310944Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:09:27.310944Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"g/lXsU+FPWljfHr2t7PbPsCRAPX8lvX4ylDgWx3Lk3mVRtOHBujsXh2ne7okMmbG9Aa0OjOfg/VZUmAD7CKiBQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:09:27.311643Z","signed_message":"canonical_sha256_bytes"},"source_id":"1802.00420","source_kind":"arxiv","source_version":4}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:ef53e7f5497cc1f545bee045f2e11f30c6e29d07b9a43bf2b6e04be34bb11870","sha256:17c31545c69db2c090e229c3ff6f49b0e85a9c69701f45e29fa62e16d1b541b8"],"state_sha256":"948ae03338385225a1ef2e8e73d54ba58c2a27bb2c9c24a493ebe96d8e9d95ed"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"z66d5lTvP25WIT5QOtg64nQ3OOSaDRm1saUCcmikFQizFx9eG7Yjvh87LPPUvvxT0li5ZER/0eNhASA25g8SBQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-01T08:47:22.093003Z","bundle_sha256":"bb6ddcf2ef2b40557603023d86307706dde13a40e610036eabab5b7393c94a56"}}