{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:ZTJCSMSLO4VLPVWC2OUZ3SQRG7","short_pith_number":"pith:ZTJCSMSL","canonical_record":{"source":{"id":"1907.05718","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-07-11T06:28:25Z","cross_cats_sorted":["cs.AI","stat.ML"],"title_canon_sha256":"1cc4608ff3c282f142bcea06518bf04c32a3591bca54a68dcbdd96f860907d4c","abstract_canon_sha256":"37b115825541388b0e7c958498b9ed1f135b5750643b083b18615b94cbb07c25"},"schema_version":"1.0"},"canonical_sha256":"ccd229324b772ab7d6c2d3a99dca1137de62d78a958f5bad5548c71dfef607a9","source":{"kind":"arxiv","id":"1907.05718","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1907.05718","created_at":"2026-05-17T23:40:44Z"},{"alias_kind":"arxiv_version","alias_value":"1907.05718v1","created_at":"2026-05-17T23:40:44Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1907.05718","created_at":"2026-05-17T23:40:44Z"},{"alias_kind":"pith_short_12","alias_value":"ZTJCSMSLO4VL","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_16","alias_value":"ZTJCSMSLO4VLPVWC","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_8","alias_value":"ZTJCSMSL","created_at":"2026-05-18T12:33:33Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:ZTJCSMSLO4VLPVWC2OUZ3SQRG7","target":"record","payload":{"canonical_record":{"source":{"id":"1907.05718","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-07-11T06:28:25Z","cross_cats_sorted":["cs.AI","stat.ML"],"title_canon_sha256":"1cc4608ff3c282f142bcea06518bf04c32a3591bca54a68dcbdd96f860907d4c","abstract_canon_sha256":"37b115825541388b0e7c958498b9ed1f135b5750643b083b18615b94cbb07c25"},"schema_version":"1.0"},"canonical_sha256":"ccd229324b772ab7d6c2d3a99dca1137de62d78a958f5bad5548c71dfef607a9","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:40:44.677854Z","signature_b64":"yR5uf1bgK2qYxoEjKKDAUjnaDoccB8jjZQO+OBDRg09WWSb7ZP2kxO3VDLy4hkYkjBSTLo9Z3Tb0xB6NqZ6dAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ccd229324b772ab7d6c2d3a99dca1137de62d78a958f5bad5548c71dfef607a9","last_reissued_at":"2026-05-17T23:40:44.677207Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:40:44.677207Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1907.05718","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:40:44Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"PDJpCt6Yg2W9R8HUnZsPYzpyVq/Tcmzgl0oqs/k79bgorLA4C9Uf5lXFq6OvTJnOaRMmkodtw4JuCHhx1svXDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T17:08:08.070692Z"},"content_sha256":"37be277b6384765072480c901e503d2984f226c519f0ba82b77b40908198a122","schema_version":"1.0","event_id":"sha256:37be277b6384765072480c901e503d2984f226c519f0ba82b77b40908198a122"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:ZTJCSMSLO4VLPVWC2OUZ3SQRG7","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Why Blocking Targeted Adversarial Perturbations Impairs the Ability to Learn","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","stat.ML"],"primary_cat":"cs.LG","authors_text":"Yuval Elovici, Ziv Katzir","submitted_at":"2019-07-11T06:28:25Z","abstract_excerpt":"Despite their accuracy, neural network-based classifiers are still prone to manipulation through adversarial perturbations. Those perturbations are designed to be misclassified by the neural network, while being perceptually identical to some valid input. The vast majority of attack methods rely on white-box conditions, where the attacker has full knowledge of the attacked network's parameters. This allows the attacker to calculate the network's loss gradient with respect to some valid input and use this gradient in order to create an adversarial example. The task of blocking white-box attacks"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1907.05718","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:40:44Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"DzQY9ox9FsfoJkDlnww0rv1RSiJnkJcdvUeKeCw6es+ebxc8zEwIR437GOT/6x16lvrubdVRG05Vy5JJDHmQBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T17:08:08.071381Z"},"content_sha256":"9677bb56025b1a54ca8c5cb208b2f06966bd3ab147a047f4a6db1838889afed2","schema_version":"1.0","event_id":"sha256:9677bb56025b1a54ca8c5cb208b2f06966bd3ab147a047f4a6db1838889afed2"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/ZTJCSMSLO4VLPVWC2OUZ3SQRG7/bundle.json","state_url":"https://pith.science/pith/ZTJCSMSLO4VLPVWC2OUZ3SQRG7/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/ZTJCSMSLO4VLPVWC2OUZ3SQRG7/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T17:08:08Z","links":{"resolver":"https://pith.science/pith/ZTJCSMSLO4VLPVWC2OUZ3SQRG7","bundle":"https://pith.science/pith/ZTJCSMSLO4VLPVWC2OUZ3SQRG7/bundle.json","state":"https://pith.science/pith/ZTJCSMSLO4VLPVWC2OUZ3SQRG7/state.json","well_known_bundle":"https://pith.science/.well-known/pith/ZTJCSMSLO4VLPVWC2OUZ3SQRG7/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:ZTJCSMSLO4VLPVWC2OUZ3SQRG7","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"37b115825541388b0e7c958498b9ed1f135b5750643b083b18615b94cbb07c25","cross_cats_sorted":["cs.AI","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-07-11T06:28:25Z","title_canon_sha256":"1cc4608ff3c282f142bcea06518bf04c32a3591bca54a68dcbdd96f860907d4c"},"schema_version":"1.0","source":{"id":"1907.05718","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1907.05718","created_at":"2026-05-17T23:40:44Z"},{"alias_kind":"arxiv_version","alias_value":"1907.05718v1","created_at":"2026-05-17T23:40:44Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1907.05718","created_at":"2026-05-17T23:40:44Z"},{"alias_kind":"pith_short_12","alias_value":"ZTJCSMSLO4VL","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_16","alias_value":"ZTJCSMSLO4VLPVWC","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_8","alias_value":"ZTJCSMSL","created_at":"2026-05-18T12:33:33Z"}],"graph_snapshots":[{"event_id":"sha256:9677bb56025b1a54ca8c5cb208b2f06966bd3ab147a047f4a6db1838889afed2","target":"graph","created_at":"2026-05-17T23:40:44Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Despite their accuracy, neural network-based classifiers are still prone to manipulation through adversarial perturbations. Those perturbations are designed to be misclassified by the neural network, while being perceptually identical to some valid input. The vast majority of attack methods rely on white-box conditions, where the attacker has full knowledge of the attacked network's parameters. This allows the attacker to calculate the network's loss gradient with respect to some valid input and use this gradient in order to create an adversarial example. The task of blocking white-box attacks","authors_text":"Yuval Elovici, Ziv Katzir","cross_cats":["cs.AI","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-07-11T06:28:25Z","title":"Why Blocking Targeted Adversarial Perturbations Impairs the Ability to Learn"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1907.05718","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:37be277b6384765072480c901e503d2984f226c519f0ba82b77b40908198a122","target":"record","created_at":"2026-05-17T23:40:44Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"37b115825541388b0e7c958498b9ed1f135b5750643b083b18615b94cbb07c25","cross_cats_sorted":["cs.AI","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-07-11T06:28:25Z","title_canon_sha256":"1cc4608ff3c282f142bcea06518bf04c32a3591bca54a68dcbdd96f860907d4c"},"schema_version":"1.0","source":{"id":"1907.05718","kind":"arxiv","version":1}},"canonical_sha256":"ccd229324b772ab7d6c2d3a99dca1137de62d78a958f5bad5548c71dfef607a9","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"ccd229324b772ab7d6c2d3a99dca1137de62d78a958f5bad5548c71dfef607a9","first_computed_at":"2026-05-17T23:40:44.677207Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:40:44.677207Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"yR5uf1bgK2qYxoEjKKDAUjnaDoccB8jjZQO+OBDRg09WWSb7ZP2kxO3VDLy4hkYkjBSTLo9Z3Tb0xB6NqZ6dAA==","signature_status":"signed_v1","signed_at":"2026-05-17T23:40:44.677854Z","signed_message":"canonical_sha256_bytes"},"source_id":"1907.05718","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:37be277b6384765072480c901e503d2984f226c519f0ba82b77b40908198a122","sha256:9677bb56025b1a54ca8c5cb208b2f06966bd3ab147a047f4a6db1838889afed2"],"state_sha256":"d0b8213ad02bba90645cb494a9f8fcbf4f4664bf73cd739190bb9f1f851538ba"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"16nB4ifXobAP7zdoKPjyopRJRuDIYG8nqvH6bCM8XDWhY4QAxmojRbVZpZOEu6oROD/j/RKfxsQykefkqzUlCA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T17:08:08.074819Z","bundle_sha256":"c7f2befcdae16c92e8673b8b0b626134460d23cf3588ef6ee121974d8fe4f729"}}