{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:XZKY7PKP75XEZBWOSRHDKEUKHG","short_pith_number":"pith:XZKY7PKP","canonical_record":{"source":{"id":"1812.03087","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-07T16:21:24Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"36ce5dc6f77eaf9062cdf1135f1939740339b5992a37049b61e999e22106bce9","abstract_canon_sha256":"756faf7a6a7acb7035e6efa1501534ec1ca7a0d4e4f42bdb9bcf09e931d29fcc"},"schema_version":"1.0"},"canonical_sha256":"be558fbd4fff6e4c86ce944e35128a399e87410dcc48716bc97a1b3954da149f","source":{"kind":"arxiv","id":"1812.03087","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1812.03087","created_at":"2026-05-17T23:58:50Z"},{"alias_kind":"arxiv_version","alias_value":"1812.03087v1","created_at":"2026-05-17T23:58:50Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1812.03087","created_at":"2026-05-17T23:58:50Z"},{"alias_kind":"pith_short_12","alias_value":"XZKY7PKP75XE","created_at":"2026-05-18T12:33:04Z"},{"alias_kind":"pith_short_16","alias_value":"XZKY7PKP75XEZBWO","created_at":"2026-05-18T12:33:04Z"},{"alias_kind":"pith_short_8","alias_value":"XZKY7PKP","created_at":"2026-05-18T12:33:04Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:XZKY7PKP75XEZBWOSRHDKEUKHG","target":"record","payload":{"canonical_record":{"source":{"id":"1812.03087","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-07T16:21:24Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"36ce5dc6f77eaf9062cdf1135f1939740339b5992a37049b61e999e22106bce9","abstract_canon_sha256":"756faf7a6a7acb7035e6efa1501534ec1ca7a0d4e4f42bdb9bcf09e931d29fcc"},"schema_version":"1.0"},"canonical_sha256":"be558fbd4fff6e4c86ce944e35128a399e87410dcc48716bc97a1b3954da149f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:58:50.995404Z","signature_b64":"FchBQ4xk62LxkzDyenEJyT6zKLJN23b4Kaoahh5BIRggauEvRvPE2P5pZsP+6oVjPX6Vr6r69jQaZ1MEKljZDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"be558fbd4fff6e4c86ce944e35128a399e87410dcc48716bc97a1b3954da149f","last_reissued_at":"2026-05-17T23:58:50.994923Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:58:50.994923Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1812.03087","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:58:50Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"52MjWiRIIgumCmu/3old8KrHwapGZdM/WtZvjDM8cPCulfHNJ/lWbACO0anV4L/R8hZOVucCZjlgDkaPYbYJAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-05T05:15:50.452785Z"},"content_sha256":"cf7abd5859dd87e0e1bac41c2a490f1ad7a3689294e5969ae7a47dee1ed2c156","schema_version":"1.0","event_id":"sha256:cf7abd5859dd87e0e1bac41c2a490f1ad7a3689294e5969ae7a47dee1ed2c156"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:XZKY7PKP75XEZBWOSRHDKEUKHG","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Combatting Adversarial Attacks through Denoising and Dimensionality Reduction: A Cascaded Autoencoder Approach","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Aly El Gamal, Rajeev Sahay, Rehana Mahfuz","submitted_at":"2018-12-07T16:21:24Z","abstract_excerpt":"Machine Learning models are vulnerable to adversarial attacks that rely on perturbing the input data. This work proposes a novel strategy using Autoencoder Deep Neural Networks to defend a machine learning model against two gradient-based attacks: The Fast Gradient Sign attack and Fast Gradient attack. First we use an autoencoder to denoise the test data, which is trained with both clean and corrupted data. Then, we reduce the dimension of the denoised data using the hidden layer representation of another autoencoder. We perform this experiment for multiple values of the bound of adversarial p"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1812.03087","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:58:50Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"fCKMo9S3FMGia4O8fOJCggjj8hy635qddcVK1LaDTu6gr733mD6e2Kc3/CmgsrogS1DuiedLQG+8sKV4CGocCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-05T05:15:50.453434Z"},"content_sha256":"01fa67caefb984f4245d03f384fb0211c9244a5fd79e03387d7679bc19aa342f","schema_version":"1.0","event_id":"sha256:01fa67caefb984f4245d03f384fb0211c9244a5fd79e03387d7679bc19aa342f"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/XZKY7PKP75XEZBWOSRHDKEUKHG/bundle.json","state_url":"https://pith.science/pith/XZKY7PKP75XEZBWOSRHDKEUKHG/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/XZKY7PKP75XEZBWOSRHDKEUKHG/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-05T05:15:50Z","links":{"resolver":"https://pith.science/pith/XZKY7PKP75XEZBWOSRHDKEUKHG","bundle":"https://pith.science/pith/XZKY7PKP75XEZBWOSRHDKEUKHG/bundle.json","state":"https://pith.science/pith/XZKY7PKP75XEZBWOSRHDKEUKHG/state.json","well_known_bundle":"https://pith.science/.well-known/pith/XZKY7PKP75XEZBWOSRHDKEUKHG/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:XZKY7PKP75XEZBWOSRHDKEUKHG","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"756faf7a6a7acb7035e6efa1501534ec1ca7a0d4e4f42bdb9bcf09e931d29fcc","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-07T16:21:24Z","title_canon_sha256":"36ce5dc6f77eaf9062cdf1135f1939740339b5992a37049b61e999e22106bce9"},"schema_version":"1.0","source":{"id":"1812.03087","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1812.03087","created_at":"2026-05-17T23:58:50Z"},{"alias_kind":"arxiv_version","alias_value":"1812.03087v1","created_at":"2026-05-17T23:58:50Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1812.03087","created_at":"2026-05-17T23:58:50Z"},{"alias_kind":"pith_short_12","alias_value":"XZKY7PKP75XE","created_at":"2026-05-18T12:33:04Z"},{"alias_kind":"pith_short_16","alias_value":"XZKY7PKP75XEZBWO","created_at":"2026-05-18T12:33:04Z"},{"alias_kind":"pith_short_8","alias_value":"XZKY7PKP","created_at":"2026-05-18T12:33:04Z"}],"graph_snapshots":[{"event_id":"sha256:01fa67caefb984f4245d03f384fb0211c9244a5fd79e03387d7679bc19aa342f","target":"graph","created_at":"2026-05-17T23:58:50Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Machine Learning models are vulnerable to adversarial attacks that rely on perturbing the input data. This work proposes a novel strategy using Autoencoder Deep Neural Networks to defend a machine learning model against two gradient-based attacks: The Fast Gradient Sign attack and Fast Gradient attack. First we use an autoencoder to denoise the test data, which is trained with both clean and corrupted data. Then, we reduce the dimension of the denoised data using the hidden layer representation of another autoencoder. We perform this experiment for multiple values of the bound of adversarial p","authors_text":"Aly El Gamal, Rajeev Sahay, Rehana Mahfuz","cross_cats":["cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-07T16:21:24Z","title":"Combatting Adversarial Attacks through Denoising and Dimensionality Reduction: A Cascaded Autoencoder Approach"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1812.03087","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:cf7abd5859dd87e0e1bac41c2a490f1ad7a3689294e5969ae7a47dee1ed2c156","target":"record","created_at":"2026-05-17T23:58:50Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"756faf7a6a7acb7035e6efa1501534ec1ca7a0d4e4f42bdb9bcf09e931d29fcc","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-07T16:21:24Z","title_canon_sha256":"36ce5dc6f77eaf9062cdf1135f1939740339b5992a37049b61e999e22106bce9"},"schema_version":"1.0","source":{"id":"1812.03087","kind":"arxiv","version":1}},"canonical_sha256":"be558fbd4fff6e4c86ce944e35128a399e87410dcc48716bc97a1b3954da149f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"be558fbd4fff6e4c86ce944e35128a399e87410dcc48716bc97a1b3954da149f","first_computed_at":"2026-05-17T23:58:50.994923Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:58:50.994923Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"FchBQ4xk62LxkzDyenEJyT6zKLJN23b4Kaoahh5BIRggauEvRvPE2P5pZsP+6oVjPX6Vr6r69jQaZ1MEKljZDA==","signature_status":"signed_v1","signed_at":"2026-05-17T23:58:50.995404Z","signed_message":"canonical_sha256_bytes"},"source_id":"1812.03087","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:cf7abd5859dd87e0e1bac41c2a490f1ad7a3689294e5969ae7a47dee1ed2c156","sha256:01fa67caefb984f4245d03f384fb0211c9244a5fd79e03387d7679bc19aa342f"],"state_sha256":"a5498ef2ea65ffbd021aa4bae113a72a1abc6e01e3bf2b9536e1ba98439d4f6f"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"dZ7gffeMrcqNL4HtP+VaVlvWpDFdf+nwWEjERsxtV9QPfVc2O8wbHYozN5g6b0jEpYrJph2HQOiRPllm+BQZBw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-05T05:15:50.456883Z","bundle_sha256":"b9788100d44dafed8efdaca8b259f479f52cd6e8ae8769cea53916ace4197caf"}}