{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:Z2B7OPQF7NB77ANE656MA2GDPP","short_pith_number":"pith:Z2B7OPQF","canonical_record":{"source":{"id":"1907.04774","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-07-10T15:04:18Z","cross_cats_sorted":["cs.LG","eess.IV"],"title_canon_sha256":"223f5470ec81899f65a33cd543bd0263c6572b1d9dd0939b3162e223e86c1d7f","abstract_canon_sha256":"c80336aaa0032ccb81400e2416ba74dde77f5109e899a711fe7aa45b75f7fb89"},"schema_version":"1.0"},"canonical_sha256":"ce83f73e05fb43ff81a4f77cc068c37bc0871d294bde6e10c71eadb03e8efb53","source":{"kind":"arxiv","id":"1907.04774","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1907.04774","created_at":"2026-05-17T23:40:56Z"},{"alias_kind":"arxiv_version","alias_value":"1907.04774v1","created_at":"2026-05-17T23:40:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1907.04774","created_at":"2026-05-17T23:40:56Z"},{"alias_kind":"pith_short_12","alias_value":"Z2B7OPQF7NB7","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_16","alias_value":"Z2B7OPQF7NB77ANE","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_8","alias_value":"Z2B7OPQF","created_at":"2026-05-18T12:33:33Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:Z2B7OPQF7NB77ANE656MA2GDPP","target":"record","payload":{"canonical_record":{"source":{"id":"1907.04774","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-07-10T15:04:18Z","cross_cats_sorted":["cs.LG","eess.IV"],"title_canon_sha256":"223f5470ec81899f65a33cd543bd0263c6572b1d9dd0939b3162e223e86c1d7f","abstract_canon_sha256":"c80336aaa0032ccb81400e2416ba74dde77f5109e899a711fe7aa45b75f7fb89"},"schema_version":"1.0"},"canonical_sha256":"ce83f73e05fb43ff81a4f77cc068c37bc0871d294bde6e10c71eadb03e8efb53","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:40:56.778416Z","signature_b64":"V6bJz9GbaAEguG8PuSPqcrWFTfyUc+yXMTUfRR0FL06rlNM+ej+tN2IdTdmMDRtAfl2e821TYrSPk0014Nd+DA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ce83f73e05fb43ff81a4f77cc068c37bc0871d294bde6e10c71eadb03e8efb53","last_reissued_at":"2026-05-17T23:40:56.777671Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:40:56.777671Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1907.04774","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:40:56Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"efnocWvX13io1ibJXWGkDPurLbIoHM6womaelCttx6K2A5ELrqFl6MinJZs1cuZAZdP6EQ4XLyCsxpFwgs51Bg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T10:00:45.865578Z"},"content_sha256":"ae8cdaf8b47765b3d32241772bd239b69a560b9aeffedef83c111b588eab5be9","schema_version":"1.0","event_id":"sha256:ae8cdaf8b47765b3d32241772bd239b69a560b9aeffedef83c111b588eab5be9"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:Z2B7OPQF7NB77ANE656MA2GDPP","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Metamorphic Detection of Adversarial Examples in Deep Learning Models With Affine Transformations","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG","eess.IV"],"primary_cat":"cs.CV","authors_text":"Adam Porter, Gudjon Einar Magnusson, Madeline Diep, Mikael Lindvall, Rohan Reddy Mekala","submitted_at":"2019-07-10T15:04:18Z","abstract_excerpt":"Adversarial attacks are small, carefully crafted perturbations, imperceptible to the naked eye; that when added to an image cause deep learning models to misclassify the image with potentially detrimental outcomes. With the rise of artificial intelligence models in consumer safety and security intensive industries such as self-driving cars, camera surveillance and face recognition, there is a growing need for guarding against adversarial attacks. In this paper, we present an approach that uses metamorphic testing principles to automatically detect such adversarial attacks. The approach can det"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1907.04774","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:40:56Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"vu1K8yCycSbyOGYuRpgZwCaWKS9VVKP24WGEWcpBESO4ORw0jCRiX92dUBsHVfyCv/sdwZveade5Cta4ETekDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T10:00:45.866142Z"},"content_sha256":"7923ce4aa7d94c11286c50b0537349fa4364c0cc713c8cf066dbae46a4d0c08f","schema_version":"1.0","event_id":"sha256:7923ce4aa7d94c11286c50b0537349fa4364c0cc713c8cf066dbae46a4d0c08f"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/Z2B7OPQF7NB77ANE656MA2GDPP/bundle.json","state_url":"https://pith.science/pith/Z2B7OPQF7NB77ANE656MA2GDPP/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/Z2B7OPQF7NB77ANE656MA2GDPP/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T10:00:45Z","links":{"resolver":"https://pith.science/pith/Z2B7OPQF7NB77ANE656MA2GDPP","bundle":"https://pith.science/pith/Z2B7OPQF7NB77ANE656MA2GDPP/bundle.json","state":"https://pith.science/pith/Z2B7OPQF7NB77ANE656MA2GDPP/state.json","well_known_bundle":"https://pith.science/.well-known/pith/Z2B7OPQF7NB77ANE656MA2GDPP/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:Z2B7OPQF7NB77ANE656MA2GDPP","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"c80336aaa0032ccb81400e2416ba74dde77f5109e899a711fe7aa45b75f7fb89","cross_cats_sorted":["cs.LG","eess.IV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-07-10T15:04:18Z","title_canon_sha256":"223f5470ec81899f65a33cd543bd0263c6572b1d9dd0939b3162e223e86c1d7f"},"schema_version":"1.0","source":{"id":"1907.04774","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1907.04774","created_at":"2026-05-17T23:40:56Z"},{"alias_kind":"arxiv_version","alias_value":"1907.04774v1","created_at":"2026-05-17T23:40:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1907.04774","created_at":"2026-05-17T23:40:56Z"},{"alias_kind":"pith_short_12","alias_value":"Z2B7OPQF7NB7","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_16","alias_value":"Z2B7OPQF7NB77ANE","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_8","alias_value":"Z2B7OPQF","created_at":"2026-05-18T12:33:33Z"}],"graph_snapshots":[{"event_id":"sha256:7923ce4aa7d94c11286c50b0537349fa4364c0cc713c8cf066dbae46a4d0c08f","target":"graph","created_at":"2026-05-17T23:40:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Adversarial attacks are small, carefully crafted perturbations, imperceptible to the naked eye; that when added to an image cause deep learning models to misclassify the image with potentially detrimental outcomes. With the rise of artificial intelligence models in consumer safety and security intensive industries such as self-driving cars, camera surveillance and face recognition, there is a growing need for guarding against adversarial attacks. In this paper, we present an approach that uses metamorphic testing principles to automatically detect such adversarial attacks. The approach can det","authors_text":"Adam Porter, Gudjon Einar Magnusson, Madeline Diep, Mikael Lindvall, Rohan Reddy Mekala","cross_cats":["cs.LG","eess.IV"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-07-10T15:04:18Z","title":"Metamorphic Detection of Adversarial Examples in Deep Learning Models With Affine Transformations"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1907.04774","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:ae8cdaf8b47765b3d32241772bd239b69a560b9aeffedef83c111b588eab5be9","target":"record","created_at":"2026-05-17T23:40:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"c80336aaa0032ccb81400e2416ba74dde77f5109e899a711fe7aa45b75f7fb89","cross_cats_sorted":["cs.LG","eess.IV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2019-07-10T15:04:18Z","title_canon_sha256":"223f5470ec81899f65a33cd543bd0263c6572b1d9dd0939b3162e223e86c1d7f"},"schema_version":"1.0","source":{"id":"1907.04774","kind":"arxiv","version":1}},"canonical_sha256":"ce83f73e05fb43ff81a4f77cc068c37bc0871d294bde6e10c71eadb03e8efb53","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"ce83f73e05fb43ff81a4f77cc068c37bc0871d294bde6e10c71eadb03e8efb53","first_computed_at":"2026-05-17T23:40:56.777671Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:40:56.777671Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"V6bJz9GbaAEguG8PuSPqcrWFTfyUc+yXMTUfRR0FL06rlNM+ej+tN2IdTdmMDRtAfl2e821TYrSPk0014Nd+DA==","signature_status":"signed_v1","signed_at":"2026-05-17T23:40:56.778416Z","signed_message":"canonical_sha256_bytes"},"source_id":"1907.04774","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:ae8cdaf8b47765b3d32241772bd239b69a560b9aeffedef83c111b588eab5be9","sha256:7923ce4aa7d94c11286c50b0537349fa4364c0cc713c8cf066dbae46a4d0c08f"],"state_sha256":"9bdc2d9e1dd276ca9f17e900b1a674551105b836390139ec6d02878ab613565e"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"I4FboCBCu29XwIdHLAz8lgHhUyzr41GR427fOZCzGJs/95HPzyq7NeGEWLcZeLhjle7oXkug3snxo+M3obwpBQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T10:00:45.870839Z","bundle_sha256":"25771fcd1cb515ff530407d9b8f7c53c1bff8212d3689688cd86fb0f525eb0f5"}}