{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:YTWR2CDPOC633KJZQORS7UILVK","short_pith_number":"pith:YTWR2CDP","schema_version":"1.0","canonical_sha256":"c4ed1d086f70bdbda93983a32fd10baa83193350c3a27ec7f2520834a4e831ff","source":{"kind":"arxiv","id":"1905.09871","version":1},"attestation_state":"computed","paper":{"title":"Thwarting finite difference adversarial attacks with output randomization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Azer Khan, B\\\"ulent Yener, Daniel Park, Haidar Khan","submitted_at":"2019-05-23T18:58:39Z","abstract_excerpt":"Adversarial examples pose a threat to deep neural network models in a variety of scenarios, from settings where the adversary has complete knowledge of the model and to the opposite \"black box\" setting. Black box attacks are particularly threatening as the adversary only needs access to the input and output of the model. Defending against black box adversarial example generation attacks is paramount as currently proposed defenses are not effective. Since these types of attacks rely on repeated queries to the model to estimate gradients over input dimensions, we investigate the use of randomiza"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1905.09871","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-23T18:58:39Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"953b0a87207592540f6f5f5b7f0bb3f3f69632e07f089670e3893358a8955033","abstract_canon_sha256":"423d4c8dd93ee15ab9e29c48a65eb4ddec821cde32d47667f1192b8833a8956f"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:45:14.242202Z","signature_b64":"hTYV8xsU8p81ZWATejsfPnkWiyLhLlq36DjAokohbar6tkCSsrntxxCpB4gpJqxhx3GHhXlBVER4eLBmD/tfAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c4ed1d086f70bdbda93983a32fd10baa83193350c3a27ec7f2520834a4e831ff","last_reissued_at":"2026-05-17T23:45:14.241794Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:45:14.241794Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Thwarting finite difference adversarial attacks with output randomization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Azer Khan, B\\\"ulent Yener, Daniel Park, Haidar Khan","submitted_at":"2019-05-23T18:58:39Z","abstract_excerpt":"Adversarial examples pose a threat to deep neural network models in a variety of scenarios, from settings where the adversary has complete knowledge of the model and to the opposite \"black box\" setting. Black box attacks are particularly threatening as the adversary only needs access to the input and output of the model. Defending against black box adversarial example generation attacks is paramount as currently proposed defenses are not effective. Since these types of attacks rely on repeated queries to the model to estimate gradients over input dimensions, we investigate the use of randomiza"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.09871","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1905.09871","created_at":"2026-05-17T23:45:14.241852+00:00"},{"alias_kind":"arxiv_version","alias_value":"1905.09871v1","created_at":"2026-05-17T23:45:14.241852+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.09871","created_at":"2026-05-17T23:45:14.241852+00:00"},{"alias_kind":"pith_short_12","alias_value":"YTWR2CDPOC63","created_at":"2026-05-18T12:33:33.725879+00:00"},{"alias_kind":"pith_short_16","alias_value":"YTWR2CDPOC633KJZ","created_at":"2026-05-18T12:33:33.725879+00:00"},{"alias_kind":"pith_short_8","alias_value":"YTWR2CDP","created_at":"2026-05-18T12:33:33.725879+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/YTWR2CDPOC633KJZQORS7UILVK","json":"https://pith.science/pith/YTWR2CDPOC633KJZQORS7UILVK.json","graph_json":"https://pith.science/api/pith-number/YTWR2CDPOC633KJZQORS7UILVK/graph.json","events_json":"https://pith.science/api/pith-number/YTWR2CDPOC633KJZQORS7UILVK/events.json","paper":"https://pith.science/paper/YTWR2CDP"},"agent_actions":{"view_html":"https://pith.science/pith/YTWR2CDPOC633KJZQORS7UILVK","download_json":"https://pith.science/pith/YTWR2CDPOC633KJZQORS7UILVK.json","view_paper":"https://pith.science/paper/YTWR2CDP","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1905.09871&json=true","fetch_graph":"https://pith.science/api/pith-number/YTWR2CDPOC633KJZQORS7UILVK/graph.json","fetch_events":"https://pith.science/api/pith-number/YTWR2CDPOC633KJZQORS7UILVK/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/YTWR2CDPOC633KJZQORS7UILVK/action/timestamp_anchor","attest_storage":"https://pith.science/pith/YTWR2CDPOC633KJZQORS7UILVK/action/storage_attestation","attest_author":"https://pith.science/pith/YTWR2CDPOC633KJZQORS7UILVK/action/author_attestation","sign_citation":"https://pith.science/pith/YTWR2CDPOC633KJZQORS7UILVK/action/citation_signature","submit_replication":"https://pith.science/pith/YTWR2CDPOC633KJZQORS7UILVK/action/replication_record"}},"created_at":"2026-05-17T23:45:14.241852+00:00","updated_at":"2026-05-17T23:45:14.241852+00:00"}