{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:XZ5LWDNKZDYCECXIBSZI5G424P","short_pith_number":"pith:XZ5LWDNK","schema_version":"1.0","canonical_sha256":"be7abb0daac8f0220ae80cb28e9b9ae3dc128d4af542ba0c7f00dfc250837f85","source":{"kind":"arxiv","id":"2503.17173","version":2},"attestation_state":"computed","paper":{"title":"Robustness of deep learning classification to adversarial input on GPUs: asynchronous parallel accumulation is a source of vulnerability","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.DC"],"primary_cat":"cs.LG","authors_text":"Ada Sedova, Christopher Culver, Mathieu Taillefumier, Oscar Hernandez, Sanjif Shanmugavelu, Vijay Ganesh","submitted_at":"2025-03-21T14:19:45Z","abstract_excerpt":"The ability of machine learning (ML) classification models to resist small, targeted input perturbations -- known as adversarial attacks -- is a key measure of their safety and reliability. We show that floating-point non-associativity (FPNA) coupled with asynchronous parallel programming on GPUs is sufficient to result in misclassification, without any perturbation to the input. Additionally, we show that standard adversarial robustness results may be overestimated up to 4.6 when not considering machine-level details. We develop a novel black-box attack using Bayesian optimization to discover"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2503.17173","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2025-03-21T14:19:45Z","cross_cats_sorted":["cs.DC"],"title_canon_sha256":"1c2e022b04e2eaa6fdeaece9ea93398e51d4176f104c54643b45a59e363b162e","abstract_canon_sha256":"c3ca60354cc4589fb3b1433ec8963d7bfe8605beefd646477ca84fdf869aa37a"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:57:35.297506Z","signature_b64":"vB6jmhVWOYdcYQ6BXES1r5k9pLgl/Yzs5tG9g6VBoRPPpQuPDBgWe1MYr6uQXZcF/0PBEP06zwqkGTJGtGYbDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"be7abb0daac8f0220ae80cb28e9b9ae3dc128d4af542ba0c7f00dfc250837f85","last_reissued_at":"2026-07-05T11:57:35.297015Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:57:35.297015Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Robustness of deep learning classification to adversarial input on GPUs: asynchronous parallel accumulation is a source of vulnerability","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.DC"],"primary_cat":"cs.LG","authors_text":"Ada Sedova, Christopher Culver, Mathieu Taillefumier, Oscar Hernandez, Sanjif Shanmugavelu, Vijay Ganesh","submitted_at":"2025-03-21T14:19:45Z","abstract_excerpt":"The ability of machine learning (ML) classification models to resist small, targeted input perturbations -- known as adversarial attacks -- is a key measure of their safety and reliability. We show that floating-point non-associativity (FPNA) coupled with asynchronous parallel programming on GPUs is sufficient to result in misclassification, without any perturbation to the input. Additionally, we show that standard adversarial robustness results may be overestimated up to 4.6 when not considering machine-level details. We develop a novel black-box attack using Bayesian optimization to discover"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2503.17173","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2503.17173/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2503.17173","created_at":"2026-07-05T11:57:35.297074+00:00"},{"alias_kind":"arxiv_version","alias_value":"2503.17173v2","created_at":"2026-07-05T11:57:35.297074+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2503.17173","created_at":"2026-07-05T11:57:35.297074+00:00"},{"alias_kind":"pith_short_12","alias_value":"XZ5LWDNKZDYC","created_at":"2026-07-05T11:57:35.297074+00:00"},{"alias_kind":"pith_short_16","alias_value":"XZ5LWDNKZDYCECXI","created_at":"2026-07-05T11:57:35.297074+00:00"},{"alias_kind":"pith_short_8","alias_value":"XZ5LWDNK","created_at":"2026-07-05T11:57:35.297074+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/XZ5LWDNKZDYCECXIBSZI5G424P","json":"https://pith.science/pith/XZ5LWDNKZDYCECXIBSZI5G424P.json","graph_json":"https://pith.science/api/pith-number/XZ5LWDNKZDYCECXIBSZI5G424P/graph.json","events_json":"https://pith.science/api/pith-number/XZ5LWDNKZDYCECXIBSZI5G424P/events.json","paper":"https://pith.science/paper/XZ5LWDNK"},"agent_actions":{"view_html":"https://pith.science/pith/XZ5LWDNKZDYCECXIBSZI5G424P","download_json":"https://pith.science/pith/XZ5LWDNKZDYCECXIBSZI5G424P.json","view_paper":"https://pith.science/paper/XZ5LWDNK","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2503.17173&json=true","fetch_graph":"https://pith.science/api/pith-number/XZ5LWDNKZDYCECXIBSZI5G424P/graph.json","fetch_events":"https://pith.science/api/pith-number/XZ5LWDNKZDYCECXIBSZI5G424P/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/XZ5LWDNKZDYCECXIBSZI5G424P/action/timestamp_anchor","attest_storage":"https://pith.science/pith/XZ5LWDNKZDYCECXIBSZI5G424P/action/storage_attestation","attest_author":"https://pith.science/pith/XZ5LWDNKZDYCECXIBSZI5G424P/action/author_attestation","sign_citation":"https://pith.science/pith/XZ5LWDNKZDYCECXIBSZI5G424P/action/citation_signature","submit_replication":"https://pith.science/pith/XZ5LWDNKZDYCECXIBSZI5G424P/action/replication_record"}},"created_at":"2026-07-05T11:57:35.297074+00:00","updated_at":"2026-07-05T11:57:35.297074+00:00"}