{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:YBZ4NSEQU7FEB22PZFUHD7JPLH","short_pith_number":"pith:YBZ4NSEQ","canonical_record":{"source":{"id":"1809.03063","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-09-09T23:57:29Z","cross_cats_sorted":["cs.CC","cs.CR","stat.ML"],"title_canon_sha256":"2b820103a171ec6be0d6ae7919cf25c33e92956da1f03e19aa369e8ee6debfcb","abstract_canon_sha256":"ec78bf9088f887aa56c450f12e2359b41769079f7377a831a296662f5dce3347"},"schema_version":"1.0"},"canonical_sha256":"c073c6c890a7ca40eb4fc96871fd2f59c21bbeacbdc2e8baccccdb9c36a3c098","source":{"kind":"arxiv","id":"1809.03063","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1809.03063","created_at":"2026-05-18T00:01:28Z"},{"alias_kind":"arxiv_version","alias_value":"1809.03063v2","created_at":"2026-05-18T00:01:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1809.03063","created_at":"2026-05-18T00:01:28Z"},{"alias_kind":"pith_short_12","alias_value":"YBZ4NSEQU7FE","created_at":"2026-05-18T12:33:04Z"},{"alias_kind":"pith_short_16","alias_value":"YBZ4NSEQU7FEB22P","created_at":"2026-05-18T12:33:04Z"},{"alias_kind":"pith_short_8","alias_value":"YBZ4NSEQ","created_at":"2026-05-18T12:33:04Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:YBZ4NSEQU7FEB22PZFUHD7JPLH","target":"record","payload":{"canonical_record":{"source":{"id":"1809.03063","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-09-09T23:57:29Z","cross_cats_sorted":["cs.CC","cs.CR","stat.ML"],"title_canon_sha256":"2b820103a171ec6be0d6ae7919cf25c33e92956da1f03e19aa369e8ee6debfcb","abstract_canon_sha256":"ec78bf9088f887aa56c450f12e2359b41769079f7377a831a296662f5dce3347"},"schema_version":"1.0"},"canonical_sha256":"c073c6c890a7ca40eb4fc96871fd2f59c21bbeacbdc2e8baccccdb9c36a3c098","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:01:28.394106Z","signature_b64":"7SndXSTi8Wa3Hxn/ezHlyzFkzqUnIgC8HRlX/3OkEZcRgNi+OLAl09ZMpmvrud5ta1Zc3V3761ksyYr0ujqSDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c073c6c890a7ca40eb4fc96871fd2f59c21bbeacbdc2e8baccccdb9c36a3c098","last_reissued_at":"2026-05-18T00:01:28.393468Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:01:28.393468Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1809.03063","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:01:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"nUMVubEdV+2uESkp4fjbKooMwFJZNuGBzrko7x0hEJPo2z9whwMQxY9WB683aMB04IhuOxc5a8l24kVRNMoQDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-31T02:31:57.780620Z"},"content_sha256":"01e0d03fa668fde2c2736d250a79885f37ae831fde24849b23ffacc0301c0102","schema_version":"1.0","event_id":"sha256:01e0d03fa668fde2c2736d250a79885f37ae831fde24849b23ffacc0301c0102"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:YBZ4NSEQU7FEB22PZFUHD7JPLH","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"The Curse of Concentration in Robust Learning: Evasion and Poisoning Attacks from Concentration of Measure","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CC","cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Dimitrios I. Diochnos, Mohammad Mahmoody, Saeed Mahloujifar","submitted_at":"2018-09-09T23:57:29Z","abstract_excerpt":"Many modern machine learning classifiers are shown to be vulnerable to adversarial perturbations of the instances. Despite a massive amount of work focusing on making classifiers robust, the task seems quite challenging. In this work, through a theoretical study, we investigate the adversarial risk and robustness of classifiers and draw a connection to the well-known phenomenon of concentration of measure in metric measure spaces. We show that if the metric probability space of the test instance is concentrated, any classifier with some initial constant error is inherently vulnerable to advers"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1809.03063","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:01:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"uhN7WSXT4ylq3SDzmllkgH0MYp7RadoMt3NtMTHLGel1IhraLGp3aUTJCfweMfaIdzh/uecSnGIDvu+7kNKBDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-31T02:31:57.781339Z"},"content_sha256":"0e06ff3bc1f8931fd1e32db0a36507d2d0e7b34a21ad4b91a0f21f04f0b18aa7","schema_version":"1.0","event_id":"sha256:0e06ff3bc1f8931fd1e32db0a36507d2d0e7b34a21ad4b91a0f21f04f0b18aa7"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/YBZ4NSEQU7FEB22PZFUHD7JPLH/bundle.json","state_url":"https://pith.science/pith/YBZ4NSEQU7FEB22PZFUHD7JPLH/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/YBZ4NSEQU7FEB22PZFUHD7JPLH/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-31T02:31:57Z","links":{"resolver":"https://pith.science/pith/YBZ4NSEQU7FEB22PZFUHD7JPLH","bundle":"https://pith.science/pith/YBZ4NSEQU7FEB22PZFUHD7JPLH/bundle.json","state":"https://pith.science/pith/YBZ4NSEQU7FEB22PZFUHD7JPLH/state.json","well_known_bundle":"https://pith.science/.well-known/pith/YBZ4NSEQU7FEB22PZFUHD7JPLH/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:YBZ4NSEQU7FEB22PZFUHD7JPLH","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"ec78bf9088f887aa56c450f12e2359b41769079f7377a831a296662f5dce3347","cross_cats_sorted":["cs.CC","cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-09-09T23:57:29Z","title_canon_sha256":"2b820103a171ec6be0d6ae7919cf25c33e92956da1f03e19aa369e8ee6debfcb"},"schema_version":"1.0","source":{"id":"1809.03063","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1809.03063","created_at":"2026-05-18T00:01:28Z"},{"alias_kind":"arxiv_version","alias_value":"1809.03063v2","created_at":"2026-05-18T00:01:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1809.03063","created_at":"2026-05-18T00:01:28Z"},{"alias_kind":"pith_short_12","alias_value":"YBZ4NSEQU7FE","created_at":"2026-05-18T12:33:04Z"},{"alias_kind":"pith_short_16","alias_value":"YBZ4NSEQU7FEB22P","created_at":"2026-05-18T12:33:04Z"},{"alias_kind":"pith_short_8","alias_value":"YBZ4NSEQ","created_at":"2026-05-18T12:33:04Z"}],"graph_snapshots":[{"event_id":"sha256:0e06ff3bc1f8931fd1e32db0a36507d2d0e7b34a21ad4b91a0f21f04f0b18aa7","target":"graph","created_at":"2026-05-18T00:01:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Many modern machine learning classifiers are shown to be vulnerable to adversarial perturbations of the instances. Despite a massive amount of work focusing on making classifiers robust, the task seems quite challenging. In this work, through a theoretical study, we investigate the adversarial risk and robustness of classifiers and draw a connection to the well-known phenomenon of concentration of measure in metric measure spaces. We show that if the metric probability space of the test instance is concentrated, any classifier with some initial constant error is inherently vulnerable to advers","authors_text":"Dimitrios I. Diochnos, Mohammad Mahmoody, Saeed Mahloujifar","cross_cats":["cs.CC","cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-09-09T23:57:29Z","title":"The Curse of Concentration in Robust Learning: Evasion and Poisoning Attacks from Concentration of Measure"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1809.03063","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:01e0d03fa668fde2c2736d250a79885f37ae831fde24849b23ffacc0301c0102","target":"record","created_at":"2026-05-18T00:01:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"ec78bf9088f887aa56c450f12e2359b41769079f7377a831a296662f5dce3347","cross_cats_sorted":["cs.CC","cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-09-09T23:57:29Z","title_canon_sha256":"2b820103a171ec6be0d6ae7919cf25c33e92956da1f03e19aa369e8ee6debfcb"},"schema_version":"1.0","source":{"id":"1809.03063","kind":"arxiv","version":2}},"canonical_sha256":"c073c6c890a7ca40eb4fc96871fd2f59c21bbeacbdc2e8baccccdb9c36a3c098","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"c073c6c890a7ca40eb4fc96871fd2f59c21bbeacbdc2e8baccccdb9c36a3c098","first_computed_at":"2026-05-18T00:01:28.393468Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:01:28.393468Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"7SndXSTi8Wa3Hxn/ezHlyzFkzqUnIgC8HRlX/3OkEZcRgNi+OLAl09ZMpmvrud5ta1Zc3V3761ksyYr0ujqSDA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:01:28.394106Z","signed_message":"canonical_sha256_bytes"},"source_id":"1809.03063","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:01e0d03fa668fde2c2736d250a79885f37ae831fde24849b23ffacc0301c0102","sha256:0e06ff3bc1f8931fd1e32db0a36507d2d0e7b34a21ad4b91a0f21f04f0b18aa7"],"state_sha256":"c7b0540637a4a24e8cfd86cc927b637041f933085a076bd4b3c5ced3931c9aff"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"jsPzB20cCjlhDsPje5lVnlQMi9h5mqtCTb+TVd+rrrSwNWF6dWATHQoJNJGwEeLZHV3AO3E5saAgWkuc0S5DCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-31T02:31:57.785448Z","bundle_sha256":"5d129e9e8d31084fc1cdc573705b9d8faf6a725064ed763a69ef2ac14f8dad01"}}