{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:YTWR2CDPOC633KJZQORS7UILVK","short_pith_number":"pith:YTWR2CDP","canonical_record":{"source":{"id":"1905.09871","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-23T18:58:39Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"953b0a87207592540f6f5f5b7f0bb3f3f69632e07f089670e3893358a8955033","abstract_canon_sha256":"423d4c8dd93ee15ab9e29c48a65eb4ddec821cde32d47667f1192b8833a8956f"},"schema_version":"1.0"},"canonical_sha256":"c4ed1d086f70bdbda93983a32fd10baa83193350c3a27ec7f2520834a4e831ff","source":{"kind":"arxiv","id":"1905.09871","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.09871","created_at":"2026-05-17T23:45:14Z"},{"alias_kind":"arxiv_version","alias_value":"1905.09871v1","created_at":"2026-05-17T23:45:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.09871","created_at":"2026-05-17T23:45:14Z"},{"alias_kind":"pith_short_12","alias_value":"YTWR2CDPOC63","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_16","alias_value":"YTWR2CDPOC633KJZ","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_8","alias_value":"YTWR2CDP","created_at":"2026-05-18T12:33:33Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:YTWR2CDPOC633KJZQORS7UILVK","target":"record","payload":{"canonical_record":{"source":{"id":"1905.09871","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-23T18:58:39Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"953b0a87207592540f6f5f5b7f0bb3f3f69632e07f089670e3893358a8955033","abstract_canon_sha256":"423d4c8dd93ee15ab9e29c48a65eb4ddec821cde32d47667f1192b8833a8956f"},"schema_version":"1.0"},"canonical_sha256":"c4ed1d086f70bdbda93983a32fd10baa83193350c3a27ec7f2520834a4e831ff","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:45:14.242202Z","signature_b64":"hTYV8xsU8p81ZWATejsfPnkWiyLhLlq36DjAokohbar6tkCSsrntxxCpB4gpJqxhx3GHhXlBVER4eLBmD/tfAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c4ed1d086f70bdbda93983a32fd10baa83193350c3a27ec7f2520834a4e831ff","last_reissued_at":"2026-05-17T23:45:14.241794Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:45:14.241794Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1905.09871","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:45:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"RxZVOor1GrRfCzglcAL34Z87EJujvD/bVIv2Mxv2gf5Sf5Lwl+wW/nl30M19kmwhyUu+mhenFZ6NWLEura1tDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T14:31:42.531474Z"},"content_sha256":"e4c7ffa7a4971c1f25b05df64baafd4569ad875563f0a4b65daf56a709827867","schema_version":"1.0","event_id":"sha256:e4c7ffa7a4971c1f25b05df64baafd4569ad875563f0a4b65daf56a709827867"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:YTWR2CDPOC633KJZQORS7UILVK","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Thwarting finite difference adversarial attacks with output randomization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Azer Khan, B\\\"ulent Yener, Daniel Park, Haidar Khan","submitted_at":"2019-05-23T18:58:39Z","abstract_excerpt":"Adversarial examples pose a threat to deep neural network models in a variety of scenarios, from settings where the adversary has complete knowledge of the model and to the opposite \"black box\" setting. Black box attacks are particularly threatening as the adversary only needs access to the input and output of the model. Defending against black box adversarial example generation attacks is paramount as currently proposed defenses are not effective. Since these types of attacks rely on repeated queries to the model to estimate gradients over input dimensions, we investigate the use of randomiza"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.09871","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:45:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"6SjhmemJwlnrnbBnJnQazlY5DwCZ6H6c60N2o+8683bPTeq39y4Ym43GiFuTCLuKRl8OC4DmfZrXVT9qGZ4LBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T14:31:42.531822Z"},"content_sha256":"8a0499c040e2fb0439c81b2a52c955a51039ba10f58da5c501126d516b0dcb99","schema_version":"1.0","event_id":"sha256:8a0499c040e2fb0439c81b2a52c955a51039ba10f58da5c501126d516b0dcb99"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/YTWR2CDPOC633KJZQORS7UILVK/bundle.json","state_url":"https://pith.science/pith/YTWR2CDPOC633KJZQORS7UILVK/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/YTWR2CDPOC633KJZQORS7UILVK/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-03T14:31:42Z","links":{"resolver":"https://pith.science/pith/YTWR2CDPOC633KJZQORS7UILVK","bundle":"https://pith.science/pith/YTWR2CDPOC633KJZQORS7UILVK/bundle.json","state":"https://pith.science/pith/YTWR2CDPOC633KJZQORS7UILVK/state.json","well_known_bundle":"https://pith.science/.well-known/pith/YTWR2CDPOC633KJZQORS7UILVK/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:YTWR2CDPOC633KJZQORS7UILVK","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"423d4c8dd93ee15ab9e29c48a65eb4ddec821cde32d47667f1192b8833a8956f","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-23T18:58:39Z","title_canon_sha256":"953b0a87207592540f6f5f5b7f0bb3f3f69632e07f089670e3893358a8955033"},"schema_version":"1.0","source":{"id":"1905.09871","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.09871","created_at":"2026-05-17T23:45:14Z"},{"alias_kind":"arxiv_version","alias_value":"1905.09871v1","created_at":"2026-05-17T23:45:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.09871","created_at":"2026-05-17T23:45:14Z"},{"alias_kind":"pith_short_12","alias_value":"YTWR2CDPOC63","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_16","alias_value":"YTWR2CDPOC633KJZ","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_8","alias_value":"YTWR2CDP","created_at":"2026-05-18T12:33:33Z"}],"graph_snapshots":[{"event_id":"sha256:8a0499c040e2fb0439c81b2a52c955a51039ba10f58da5c501126d516b0dcb99","target":"graph","created_at":"2026-05-17T23:45:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Adversarial examples pose a threat to deep neural network models in a variety of scenarios, from settings where the adversary has complete knowledge of the model and to the opposite \"black box\" setting. Black box attacks are particularly threatening as the adversary only needs access to the input and output of the model. Defending against black box adversarial example generation attacks is paramount as currently proposed defenses are not effective. Since these types of attacks rely on repeated queries to the model to estimate gradients over input dimensions, we investigate the use of randomiza","authors_text":"Azer Khan, B\\\"ulent Yener, Daniel Park, Haidar Khan","cross_cats":["cs.CR","cs.CV","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-23T18:58:39Z","title":"Thwarting finite difference adversarial attacks with output randomization"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.09871","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:e4c7ffa7a4971c1f25b05df64baafd4569ad875563f0a4b65daf56a709827867","target":"record","created_at":"2026-05-17T23:45:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"423d4c8dd93ee15ab9e29c48a65eb4ddec821cde32d47667f1192b8833a8956f","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-23T18:58:39Z","title_canon_sha256":"953b0a87207592540f6f5f5b7f0bb3f3f69632e07f089670e3893358a8955033"},"schema_version":"1.0","source":{"id":"1905.09871","kind":"arxiv","version":1}},"canonical_sha256":"c4ed1d086f70bdbda93983a32fd10baa83193350c3a27ec7f2520834a4e831ff","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"c4ed1d086f70bdbda93983a32fd10baa83193350c3a27ec7f2520834a4e831ff","first_computed_at":"2026-05-17T23:45:14.241794Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:45:14.241794Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"hTYV8xsU8p81ZWATejsfPnkWiyLhLlq36DjAokohbar6tkCSsrntxxCpB4gpJqxhx3GHhXlBVER4eLBmD/tfAQ==","signature_status":"signed_v1","signed_at":"2026-05-17T23:45:14.242202Z","signed_message":"canonical_sha256_bytes"},"source_id":"1905.09871","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:e4c7ffa7a4971c1f25b05df64baafd4569ad875563f0a4b65daf56a709827867","sha256:8a0499c040e2fb0439c81b2a52c955a51039ba10f58da5c501126d516b0dcb99"],"state_sha256":"67538750496af29eaa043bb126a43451363db300fea9945e53159ab9e4a8d086"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"y9TY13emCnpBQ3d4NTDbzHdgtqoca0B0fhbZ3aYtaxqdaPC5W38QuQYM22ZwVu+BgfoZ31KsvqiUgvyjiqX/AQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-03T14:31:42.533794Z","bundle_sha256":"c58bd8a67221e788cd756508ee365552935581a25fddb00adecfd80f18e32016"}}