{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:YVJD3YJK4X3VVEP7N4OS37PGWF","short_pith_number":"pith:YVJD3YJK","schema_version":"1.0","canonical_sha256":"c5523de12ae5f75a91ff6f1d2dfde6b142a9c27d12554d9551c64ab13f144fb4","source":{"kind":"arxiv","id":"1911.09272","version":1},"attestation_state":"computed","paper":{"title":"Robustness Certificates for Sparse Adversarial Attacks by Randomized Ablation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Alexander Levine, Soheil Feizi","submitted_at":"2019-11-21T03:52:32Z","abstract_excerpt":"Recently, techniques have been developed to provably guarantee the robustness of a classifier to adversarial perturbations of bounded L_1 and L_2 magnitudes by using randomized smoothing: the robust classification is a consensus of base classifications on randomly noised samples where the noise is additive. In this paper, we extend this technique to the L_0 threat model. We propose an efficient and certifiably robust defense against sparse adversarial attacks by randomly ablating input features, rather than using additive noise. Experimentally, on MNIST, we can certify the classifications of o"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1911.09272","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-11-21T03:52:32Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"3fb4faa201dcbc9ce616a8b3354273c57e9b68bb69e3a704e04e2db901b73a4c","abstract_canon_sha256":"7d454cf232f0efe39e687566f5c028b8d4a4f7fba740250055ce15044b92f9f0"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:20:58.171204Z","signature_b64":"0Fgm2aXDvkH1A/YM2IK6gyiT0mEH6HjdNXbPkoJLV3gG9bKhhxOBwmwhVkPm9+mfAnGIFwpjLs/SuSUWsJ4vDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c5523de12ae5f75a91ff6f1d2dfde6b142a9c27d12554d9551c64ab13f144fb4","last_reissued_at":"2026-07-05T00:20:58.170743Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:20:58.170743Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Robustness Certificates for Sparse Adversarial Attacks by Randomized Ablation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Alexander Levine, Soheil Feizi","submitted_at":"2019-11-21T03:52:32Z","abstract_excerpt":"Recently, techniques have been developed to provably guarantee the robustness of a classifier to adversarial perturbations of bounded L_1 and L_2 magnitudes by using randomized smoothing: the robust classification is a consensus of base classifications on randomly noised samples where the noise is additive. In this paper, we extend this technique to the L_0 threat model. We propose an efficient and certifiably robust defense against sparse adversarial attacks by randomly ablating input features, rather than using additive noise. Experimentally, on MNIST, we can certify the classifications of o"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1911.09272","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1911.09272/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1911.09272","created_at":"2026-07-05T00:20:58.170798+00:00"},{"alias_kind":"arxiv_version","alias_value":"1911.09272v1","created_at":"2026-07-05T00:20:58.170798+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1911.09272","created_at":"2026-07-05T00:20:58.170798+00:00"},{"alias_kind":"pith_short_12","alias_value":"YVJD3YJK4X3V","created_at":"2026-07-05T00:20:58.170798+00:00"},{"alias_kind":"pith_short_16","alias_value":"YVJD3YJK4X3VVEP7","created_at":"2026-07-05T00:20:58.170798+00:00"},{"alias_kind":"pith_short_8","alias_value":"YVJD3YJK","created_at":"2026-07-05T00:20:58.170798+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.12703","citing_title":"SMSR: Certified Defence Against Runtime Memory Poisoning in Persistent LLM Agent Systems","ref_index":17,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/YVJD3YJK4X3VVEP7N4OS37PGWF","json":"https://pith.science/pith/YVJD3YJK4X3VVEP7N4OS37PGWF.json","graph_json":"https://pith.science/api/pith-number/YVJD3YJK4X3VVEP7N4OS37PGWF/graph.json","events_json":"https://pith.science/api/pith-number/YVJD3YJK4X3VVEP7N4OS37PGWF/events.json","paper":"https://pith.science/paper/YVJD3YJK"},"agent_actions":{"view_html":"https://pith.science/pith/YVJD3YJK4X3VVEP7N4OS37PGWF","download_json":"https://pith.science/pith/YVJD3YJK4X3VVEP7N4OS37PGWF.json","view_paper":"https://pith.science/paper/YVJD3YJK","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1911.09272&json=true","fetch_graph":"https://pith.science/api/pith-number/YVJD3YJK4X3VVEP7N4OS37PGWF/graph.json","fetch_events":"https://pith.science/api/pith-number/YVJD3YJK4X3VVEP7N4OS37PGWF/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/YVJD3YJK4X3VVEP7N4OS37PGWF/action/timestamp_anchor","attest_storage":"https://pith.science/pith/YVJD3YJK4X3VVEP7N4OS37PGWF/action/storage_attestation","attest_author":"https://pith.science/pith/YVJD3YJK4X3VVEP7N4OS37PGWF/action/author_attestation","sign_citation":"https://pith.science/pith/YVJD3YJK4X3VVEP7N4OS37PGWF/action/citation_signature","submit_replication":"https://pith.science/pith/YVJD3YJK4X3VVEP7N4OS37PGWF/action/replication_record"}},"created_at":"2026-07-05T00:20:58.170798+00:00","updated_at":"2026-07-05T00:20:58.170798+00:00"}