{"as_of":"2026-08-15T12:38:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:17c9b31adb986592609e010d2436185abcb16f7bd6dea567cb0291f14e43e2d9","coverage":[{"denominator":36,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":36,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-12T14:53:50.037447Z","state":"measured"},{"denominator":39,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":39,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-15T06:32:42.880941+00:00","state":"measured"},{"denominator":3,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":3,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-11T16:59:11.782620Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"pith","source_observed_at":"2026-08-06T23:13:23.111381Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2411.14834","snapshot_observed_at":"2026-08-11T16:59:11.782620Z","title":"Gradient Masking All-at-Once: Ensemble Everything Everywhere Is Not Robust","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2412.09565","last_updated":"2025-02-08T23:58:36Z","snapshot_observed_at":"2026-08-12T22:00:21.320460Z","submitted_at":"2024-12-12T18:49:53Z","title":"Obfuscated Activations Bypass LLM Latent-Space Defenses","version":2},"reference_index":108,"source":"arxiv_source","source_observed_at":"2026-08-11T16:59:11.782620Z"},"links":{"cited_paper":"/paper/2411.14834","citing_paper":"/paper/2412.09565"},"observation_digest":"sha256:21d9de0dac842c7bfade408b2f6c3a3c3eaa21b53ff12c06c46aa6c3dc430c11","observation_id":"717f7e6f-9a0e-45e0-9b1f-dbe646eb59c1","resolution":{"observed_at":"2026-08-11T16:59:11.782620Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2411.14834","snapshot_observed_at":"2026-08-10T15:07:57.603843Z","title":"Gradient masking all-at-once: Ensemble everything everywhere is not robust, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.14496","last_updated":"2025-01-24T13:52:37Z","snapshot_observed_at":"2026-08-13T03:27:17.834592Z","submitted_at":"2025-01-24T13:52:37Z","title":"A Note on Implementation Errors in Recent Adaptive Attacks Against Multi-Resolution Self-Ensembles","version":1},"reference_index":1,"source":"arxiv_source","source_observed_at":"2026-08-10T15:07:57.603843Z"},"links":{"cited_paper":"/paper/2411.14834","citing_paper":"/paper/2501.14496"},"observation_digest":"sha256:74e02770f939d6238e6bfc7255feaf0795ac6a93366e14352ccbc5b91c54d6c1","observation_id":"c2e8f636-5555-402c-93d0-d36e5ea8c869","resolution":{"observed_at":"2026-08-10T15:07:57.603843Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"cited_work":{"arxiv_id":"2411.14834","doi":null,"metadata_source":"pith","pith_arxiv_id":"2411.14834","snapshot_observed_at":"2026-08-06T23:13:23.111381Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","venue":"cs.LG","work_id":"654570cb-aadd-441a-8312-f68a7747d304","year":2024},"citing_paper":{"arxiv_id":"2506.19882","last_updated":"2025-07-07T02:00:46Z","snapshot_observed_at":"2026-08-14T09:27:38.836085Z","submitted_at":"2025-06-24T02:19:30Z","title":"Position: Machine Learning Conferences Should Establish a \"Refutations and Critiques\" Track","version":3},"reference_index":97,"source":"arxiv_source","source_observed_at":"2026-08-06T23:13:21.907911Z"},"links":{"cited_paper":"/paper/2411.14834","citing_paper":"/paper/2506.19882"},"observation_digest":"sha256:5412ff16044762e47759f8ffbe6f953021ea7bec8254cffbe8036033f1ce4fd2","observation_id":"ff203279-d3e1-42e9-b737-42f90cc9a2e6","resolution":{"observed_at":"2026-08-06T23:13:23.189698Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2411.14834/citation-record","integrity":"/paper/2411.14834/integrity","json":"/paper/2411.14834/citation-record.json","paper":"/paper/2411.14834"},"outbound":[{"citation":{"cited_paper":{"arxiv_id":"1702.06856","last_updated":"2017-03-10T04:10:18Z","snapshot_observed_at":"2026-08-14T21:15:17.962137Z","submitted_at":"2017-02-22T15:37:50Z","title":"Robustness to Adversarial Examples through an Ensemble of Specialists","version":3},"cited_work":{"arxiv_id":"1702.06856","doi":null,"metadata_source":"pith","pith_arxiv_id":"1702.06856","snapshot_observed_at":"2026-08-12T14:53:51.181401Z","title":"Robustness to Adversarial Examples through an Ensemble of Specialists","venue":"cs.NE","work_id":"8c01aa3f-1701-4b4f-8e32-513966696b18","year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.475213Z"},"links":{"cited_paper":"/paper/1702.06856","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:bae653799f2512067ead4eed5b5932a90724f74fa30c50a252481adfda374394","observation_id":"e700af40-ed39-40a5-8453-da724994a0a5","resolution":{"observed_at":"2026-08-12T14:53:51.193595Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:49.494441Z","title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.494441Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:2e12e3c6f544c77e0ee53ddc912f4c2182e0511ee5a422bd28da02291d26ff75","observation_id":"6d267bd0-f9d3-4006-8124-01b0f2accdc8","resolution":{"observed_at":"2026-08-12T14:53:49.494441Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.904585Z","title":"Evasion attacks against machine learning at test time","venue":null,"work_id":"32120f81-fbc6-4c31-af60-9c0dc93ee377","year":2013},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.531196Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:525f7fb7804dfc579f416fdb0c4a90c351fd8e0e73b2a9a6c3ce6b6ff10bb670","observation_id":"128d5d5d-ffc5-4cf1-affd-34fbbe6607b6","resolution":{"observed_at":"2026-08-12T14:53:51.914360Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1704.01547","last_updated":"2017-04-05T17:47:25Z","snapshot_observed_at":"2026-08-14T21:08:07.271314Z","submitted_at":"2017-04-05T17:47:25Z","title":"Comment on \"Biologically inspired protection of deep networks from adversarial attacks\"","version":1},"cited_work":{"arxiv_id":"1704.01547","doi":null,"metadata_source":"pith","pith_arxiv_id":"1704.01547","snapshot_observed_at":"2026-08-12T14:53:51.121905Z","title":"Comment on \"Biologically inspired protection of deep networks from adversarial attacks\"","venue":"stat.ML","work_id":"3bfcc7b1-ae2f-46ba-9c56-5cdc4e814257","year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.549429Z"},"links":{"cited_paper":"/paper/1704.01547","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:032bca5f1017310023bf701a037734b6b7a2f4190832a362818d93fa49eabdc6","observation_id":"de0ff193-5166-4b4d-8b08-7651b52ba56b","resolution":{"observed_at":"2026-08-12T14:53:51.136225Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1607.04311","last_updated":"2016-07-14T20:44:27Z","snapshot_observed_at":"2026-08-14T21:48:19.250759Z","submitted_at":"2016-07-14T20:44:27Z","title":"Defensive Distillation is Not Robust to Adversarial Examples","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1607.04311","snapshot_observed_at":"2026-08-12T14:53:49.556161Z","title":"Defensive distillation is not robust to adversarial examples","venue":null,"work_id":null,"year":2016},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.556161Z"},"links":{"cited_paper":"/paper/1607.04311","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:6e73345862b68d267a0a919c716b5c0d53c47f8c076405a8ec23cf8b2845e214","observation_id":"de1b09f3-ac13-423d-9476-cc5cfdd83ec7","resolution":{"observed_at":"2026-08-12T14:53:49.556161Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:49.564786Z","title":"Towards evaluating the robustness of neural networks","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.564786Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:8ea9e7f6752cd70ab3493bc8796e03668039d3f9f440c43c8d3fca917ab20ecd","observation_id":"a3594dd7-b938-4b83-add6-301e7a66d2e3","resolution":{"observed_at":"2026-08-12T14:53:49.564786Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.822879Z","title":"Certified adversarial robustness via randomized smoothing","venue":null,"work_id":"3e130176-32fe-49e8-8539-aefe3c545c0f","year":2019},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.577258Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:67f2d6ce133f0bea7a3a279eff2adbf0328bfab3474c3d115f76a6dd1a02b658","observation_id":"7c1219a4-8011-4cb7-bf1f-f8a8fbfb0605","resolution":{"observed_at":"2026-08-12T14:53:51.832178Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.794931Z","title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","venue":null,"work_id":"7bc4fd3e-800c-4327-9378-53e70b1838d6","year":2020},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.589749Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:26aee99da032f2dd14fc37d24a6715213f62ba9a7fd5bbc977023455fd29da98","observation_id":"7063d669-64a8-4270-afda-8d2566bdd889","resolution":{"observed_at":"2026-08-12T14:53:51.802270Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.766445Z","title":"Mind the box: l 1-apgd for sparse adversarial attacks on image classifiers","venue":null,"work_id":"6f429ecc-ef90-47ca-9080-67eb31bcfd68","year":2021},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.603087Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:238772bd881ba6e74f504b115dee7145569e4f156fc0f35d39c1eea8c37a923c","observation_id":"90a6de1e-18ce-45ba-98a9-e02cf990be24","resolution":{"observed_at":"2026-08-12T14:53:51.772450Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.726171Z","title":"A note on implementation errors in recent adaptive attacks against multi-resolution self-ensembles, 2025","venue":null,"work_id":"eb67381b-922e-4de6-a503-cddaa801b9bb","year":2025},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.616821Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:4ecb4f77cdd3dc0e957dd051f4be50c9509b5c6e33bd758f55d2389353b01abe","observation_id":"718fd03b-459e-49b9-94dc-4274e04416b8","resolution":{"observed_at":"2026-08-12T14:53:51.732837Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.693201Z","title":"Ensemble everything everywhere: Multi-scale aggregation for adversarial robustness, 2024","venue":null,"work_id":"1cec0476-171e-499e-9a7e-8c238666077f","year":2024},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.628359Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:f9b2f0cb07a109730122a6704e5de347b5890c0d69551887fec8facc71ca4877","observation_id":"21282a69-2370-4218-b347-dd4590b01900","resolution":{"observed_at":"2026-08-12T14:53:51.707237Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2207.11378","last_updated":"2023-08-09T17:06:52Z","snapshot_observed_at":"2026-08-13T14:58:34.118967Z","submitted_at":"2022-07-22T23:48:26Z","title":"Do Perceptually Aligned Gradients Imply Adversarial Robustness?","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2207.11378","snapshot_observed_at":"2026-08-12T14:53:49.636427Z","title":"Do perceptually aligned gradients imply adversarial robustness? arXiv preprint arXiv:2207.11378 , 2022","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.636427Z"},"links":{"cited_paper":"/paper/2207.11378","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:3221b372669bb27f7e00f5d5a3cffac9f0b03eb588076184db4315611f9b2461","observation_id":"287e0bf2-e22c-4e8b-97b3-0a7c889dc73a","resolution":{"observed_at":"2026-08-12T14:53:49.636427Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.643352Z","title":"Ai2: Safety and robustness certification of neural networks with abstract interpretation","venue":null,"work_id":"133d6439-23a6-4c5a-82f2-3b74dd37178c","year":2018},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.650681Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:7d96e78d9b846ba48fe07deeffe09da8dba41d93742234e38853a74fde30ea8c","observation_id":"19664959-5658-4e6d-9b18-94517d64e1a8","resolution":{"observed_at":"2026-08-12T14:53:51.648974Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1711.00117","last_updated":"2018-01-25T19:04:48Z","snapshot_observed_at":"2026-08-14T20:18:12.840327Z","submitted_at":"2017-10-31T21:22:16Z","title":"Countering Adversarial Images using Input Transformations","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1711.00117","snapshot_observed_at":"2026-08-12T14:53:49.660015Z","title":"Countering adversarial images using input transformations","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.660015Z"},"links":{"cited_paper":"/paper/1711.00117","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:5d01c779d164c48b0333d6a63a4074444c4a62a88eb1e0d7fae861fcd809b910","observation_id":"a26a68f9-dd56-41d3-87e9-34d545b08f6d","resolution":{"observed_at":"2026-08-12T14:53:49.660015Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.613295Z","title":"Certified robustness to adversarial examples with differential privacy","venue":null,"work_id":"52b88b4f-3c24-41cd-b4f2-fac69d6f4d02","year":2019},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.670366Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:bd254f44e31df5e3733afc15d135f8d40b8a12885055e2b21212ab47ff5b5ac6","observation_id":"d539ec5f-2cec-406e-bbfb-12664d330255","resolution":{"observed_at":"2026-08-12T14:53:51.620719Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2404.14309","last_updated":"2025-04-05T02:30:06Z","snapshot_observed_at":"2026-08-13T00:24:32.670986Z","submitted_at":"2024-04-22T16:10:38Z","title":"Towards Understanding the Robustness of Diffusion-Based Purification: A Stochastic Perspective","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2404.14309","snapshot_observed_at":"2026-08-12T14:53:49.683838Z","title":"Towards better adversarial purification via adversarial denoising diffusion training","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.683838Z"},"links":{"cited_paper":"/paper/2404.14309","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:13474061a16c4d2a90315625ca63a4337c8703c64c78e8f9df69b03026c7dc95","observation_id":"273752d5-9c32-4cd4-919a-de7a25591e17","resolution":{"observed_at":"2026-08-12T14:53:49.683838Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1511.06292","last_updated":"2016-01-19T18:15:28Z","snapshot_observed_at":"2026-08-14T22:22:11.522970Z","submitted_at":"2015-11-19T18:35:07Z","title":"Foveation-based Mechanisms Alleviate Adversarial Examples","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1511.06292","snapshot_observed_at":"2026-08-12T14:53:49.695032Z","title":"Foveation-based mechanisms alleviate adversarial examples","venue":null,"work_id":null,"year":2015},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.695032Z"},"links":{"cited_paper":"/paper/1511.06292","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:9ac719c20179b1f3adc50d58989648bcd2449637988af2b203ff9434191cf366","observation_id":"fd852625-9c08-46ef-abb3-833e168f1111","resolution":{"observed_at":"2026-08-12T14:53:49.695032Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:49.712438Z","title":"Towards deep learning models resistant to adversarial attacks","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.712438Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:09629850686d7b201f229a92a9b67956fc140c6f4082dab6d42480100fe0d433","observation_id":"5cddd7ea-12f3-4fcc-a0c5-7f994486b273","resolution":{"observed_at":"2026-08-12T14:53:49.712438Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1702.04267","last_updated":"2017-02-21T06:53:38Z","snapshot_observed_at":"2026-08-14T21:16:31.936442Z","submitted_at":"2017-02-14T15:44:26Z","title":"On Detecting Adversarial Perturbations","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1702.04267","snapshot_observed_at":"2026-08-12T14:53:49.745827Z","title":"On detecting adversarial perturbations","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.745827Z"},"links":{"cited_paper":"/paper/1702.04267","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:37d7a3c86ba887bd4c637e643d10df66e3abd2a5723026be075221a0df23755f","observation_id":"03ba3dba-afd0-4dd6-b3d2-9695316903e1","resolution":{"observed_at":"2026-08-12T14:53:49.745827Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1703.09202","last_updated":"2017-03-27T17:45:07Z","snapshot_observed_at":"2026-08-14T21:09:48.455312Z","submitted_at":"2017-03-27T17:45:07Z","title":"Biologically inspired protection of deep networks from adversarial attacks","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1703.09202","snapshot_observed_at":"2026-08-12T14:53:49.767307Z","title":"Biologically inspired protection of deep networks from adversarial attacks","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.767307Z"},"links":{"cited_paper":"/paper/1703.09202","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:ff20d73f8d58d7622d71eb8767005a4d022d8bd20d7cfb665214267ced0828b6","observation_id":"a0bc53ba-7838-4ec5-afa0-2298a0f46c79","resolution":{"observed_at":"2026-08-12T14:53:49.767307Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:49.792683Z","title":"Improving adversarial robustness via promoting ensemble diversity","venue":null,"work_id":null,"year":2019},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.792683Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:1c45a8d1f2de638bd80af2a40f7248f5e8c6fc51df49c273d7727ebe658bfdfa","observation_id":"d7074886-5d57-462b-86de-6bd3397eaf29","resolution":{"observed_at":"2026-08-12T14:53:49.792683Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.519417Z","title":"Practical black-box attacks against machine learning","venue":null,"work_id":"48d26c08-3bd3-4f65-86c7-ea6a9d554be8","year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.802539Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:fd58aaac13d615635511a4ab63e787d16ce76ec38b2c808f710096baa0c1ba2f","observation_id":"bab62494-06c6-4ff3-8652-69fdb9d33746","resolution":{"observed_at":"2026-08-12T14:53:51.525501Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.484919Z","title":"Barrage of random transforms for adversarially robust defense","venue":null,"work_id":"2cda837b-ef43-48e0-8752-7ed54815901d","year":2019},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.810977Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:875f7001a2697f2e01863c95d327471f35df8321dc3d7e033d45f3e259dc35e2","observation_id":"2e03977d-314c-4f75-8240-f81472f9a95c","resolution":{"observed_at":"2026-08-12T14:53:51.491245Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.434106Z","title":"Certified defenses against adversarial examples","venue":null,"work_id":"1ca875b1-efff-4015-814e-f8d78b0d88e1","year":2018},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.816710Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:9da4855a3c0f14d55fc0873276a044716068e8756628c41478684c13dbb155f8","observation_id":"9aa09eef-21df-489a-b3d5-5bd56ddd86e8","resolution":{"observed_at":"2026-08-12T14:53:51.444316Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1511.05122","last_updated":"2016-03-04T20:21:24Z","snapshot_observed_at":"2026-08-14T22:22:43.670149Z","submitted_at":"2015-11-16T20:48:20Z","title":"Adversarial Manipulation of Deep Representations","version":9},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1511.05122","snapshot_observed_at":"2026-08-12T14:53:49.829281Z","title":"Adversarial manipulation of deep representations","venue":null,"work_id":null,"year":2015},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.829281Z"},"links":{"cited_paper":"/paper/1511.05122","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:c5695a0eb6883a41c9ce778f618944d63d3dd26559ce462387b67c0eaa1e4377","observation_id":"8f9a4fe8-443b-4040-b0b0-77db521a6432","resolution":{"observed_at":"2026-08-12T14:53:49.829281Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.406879Z","title":"Public comment: Robustness eval- uation seems invalid","venue":null,"work_id":"bd59a9ce-72d9-4abf-98d6-601a69e46685","year":2024},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.837748Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:2b7c7c800cde79a037cf84fbaa40865df0f93c85e0cc6583998e17fd07843530","observation_id":"e8e66328-887f-43ca-9ed4-8f94eac8163c","resolution":{"observed_at":"2026-08-12T14:53:51.415034Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.382851Z","title":"Intriguing properties of neural networks","venue":null,"work_id":"7164df83-4857-4e82-8635-2eb634434a58","year":2014},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.850161Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:0d8807fad33c3f5734991fbf6f3cd257e466a65eb4d717a2228f7135d18468ff","observation_id":"d3d9b41d-766b-4200-9248-86cefbad637b","resolution":{"observed_at":"2026-08-12T14:53:51.388474Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.347405Z","title":"On adaptive attacks to adversarial example defenses","venue":null,"work_id":"151b1b3d-e63f-4c62-9845-d858807b50a5","year":2020},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.856498Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:0f9f9e9b9624e75c786599591d2a3fa498281267722d46851feeb19c1cf7f18d","observation_id":"eaa4b932-70e0-4115-907d-e0965d3d56e5","resolution":{"observed_at":"2026-08-12T14:53:51.357585Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.311989Z","title":"Ensemble adversarial training: Attacks and defenses","venue":null,"work_id":"1bc9e89a-3436-4c41-a8db-b602060bec7c","year":2018},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.869390Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:f171d0a4aec2a82d74312bfb4c18d2a4d498a0bdfbd4a1e7e8ae637bae99ce4f","observation_id":"f6382127-2423-4069-8539-63d6dc8b49e1","resolution":{"observed_at":"2026-08-12T14:53:51.323175Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1805.12152","last_updated":"2019-09-09T08:09:25Z","snapshot_observed_at":"2026-08-14T19:09:20.967940Z","submitted_at":"2018-05-30T18:00:32Z","title":"Robustness May Be at Odds with Accuracy","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1805.12152","snapshot_observed_at":"2026-08-12T14:53:49.890355Z","title":"Robustness may be at odds with accuracy","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.890355Z"},"links":{"cited_paper":"/paper/1805.12152","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:20c981aa5e25766ed00673ec9b261734b535953cbd7ef88f97ed2decd5a412c3","observation_id":"db086f34-d2c6-4674-8e8f-a9891a3594fc","resolution":{"observed_at":"2026-08-12T14:53:49.890355Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.278237Z","title":"Provable defenses against adversarial examples via the convex outer adversarial polytope","venue":null,"work_id":"8390cd2e-dc4f-4ca2-a7b7-ee2beeaaf532","year":2018},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.920072Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:a10f578d594addb3d49153c959da533a883956647ac57ca947e5db17303f7d4d","observation_id":"46a9d7fe-f7a1-4db8-9775-814805734c3c","resolution":{"observed_at":"2026-08-12T14:53:51.296416Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2001.03994","last_updated":"2020-01-12T20:30:22Z","snapshot_observed_at":"2026-08-10T02:39:16.757240Z","submitted_at":"2020-01-12T20:30:22Z","title":"Fast is better than free: Revisiting adversarial training","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2001.03994","snapshot_observed_at":"2026-08-12T14:53:49.935262Z","title":"Fast is better than free: Revisiting adversarial training","venue":null,"work_id":null,"year":2001},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.935262Z"},"links":{"cited_paper":"/paper/2001.03994","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:34df0bad2938efc000b89b6a25e647f1e5697b2f8843b15c9b3d3507dcad3a2e","observation_id":"a3659500-9e2a-4bf2-bdc1-45a26bfb4934","resolution":{"observed_at":"2026-08-12T14:53:49.935262Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1711.01991","last_updated":"2018-02-28T22:39:15Z","snapshot_observed_at":"2026-08-14T20:16:33.101754Z","submitted_at":"2017-11-06T16:22:54Z","title":"Mitigating Adversarial Effects Through Randomization","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1711.01991","snapshot_observed_at":"2026-08-12T14:53:49.943965Z","title":"Mitigating adversarial effects through randomization","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.943965Z"},"links":{"cited_paper":"/paper/1711.01991","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:12db39f519dffb260560497dc9eb63b52e73c60acf99504f776f7f0fdf59eccb","observation_id":"17055f19-c58c-4746-97d6-4cbf3ffd4973","resolution":{"observed_at":"2026-08-12T14:53:49.943965Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1704.01155","last_updated":"2017-12-05T23:45:08Z","snapshot_observed_at":"2026-08-14T21:08:18.764548Z","submitted_at":"2017-04-04T18:56:53Z","title":"Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1704.01155","snapshot_observed_at":"2026-08-12T14:53:49.956062Z","title":"Feature squeezing: Detecting adversarial examples in deep neural networks","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.956062Z"},"links":{"cited_paper":"/paper/1704.01155","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:2e594692a6ea19e682e058e3519b1f0ea78d4047e30e5560442527cbdb486213","observation_id":"c9f64418-68c4-4247-a308-f041475ebbc5","resolution":{"observed_at":"2026-08-12T14:53:49.956062Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1905.11971","last_updated":"2019-05-28T17:47:33Z","snapshot_observed_at":"2026-08-14T16:25:01.638693Z","submitted_at":"2019-05-28T17:47:33Z","title":"ME-Net: Towards Effective Adversarial Robustness with Matrix Estimation","version":1},"cited_work":{"arxiv_id":"1905.11971","doi":null,"metadata_source":"pith","pith_arxiv_id":"1905.11971","snapshot_observed_at":"2026-08-12T14:53:50.160419Z","title":"ME-Net: Towards Effective Adversarial Robustness with Matrix Estimation","venue":"cs.LG","work_id":"c18b8d88-92aa-4fc4-afd4-0ac23198b39e","year":2019},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:49.983850Z"},"links":{"cited_paper":"/paper/1905.11971","citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:e2488d06fb1593e5cc8d7eb3af44da2049ce6d29cd7e35e700bfb2d424bbcbef","observation_id":"5912b5f7-bb59-4425-b7c9-82380fddcf21","resolution":{"observed_at":"2026-08-12T14:53:50.185618Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T14:53:51.227371Z","title":"Increasing confidence in adversarial robustness evaluations","venue":null,"work_id":"6e9586d1-af6f-4980-8192-2c08ad6ba3c4","year":2022},"citing_paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense","version":2},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-08-12T14:53:50.037447Z"},"links":{"citing_paper":"/paper/2411.14834"},"observation_digest":"sha256:233a436f00d05484c7c5e7077c12745e2b9fcc7c5155b06fbcaf4eaa7022e26a","observation_id":"a9337580-12b0-4298-b0fb-c33ba03fce1a","resolution":{"observed_at":"2026-08-12T14:53:51.243245Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-15T06:32:42.880941+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"state":"measured"}}],"paper":{"arxiv_id":"2411.14834","last_updated":"2025-02-04T01:30:13Z","latest_version":2,"primary_category":"cs.LG","snapshot_observed_at":"2026-08-12T17:40:35.722397Z","submitted_at":"2024-11-22T10:17:32Z","title":"Evaluating the Robustness of the \"Ensemble Everything Everywhere\" Defense"},"reference_resolution":{"displayed":36,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":16,"verified_exact":3,"verified_fuzzy":17},"total_outbound_references":36},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-15T06:32:42.880941+00:00","source":"crossref"},{"observed_at":"2026-08-15T06:32:39.529945+00:00","source":"retraction_watch"}],"thesis":"As of 15 August 2026, this Paper Citation Record lists 36 of 36 outbound references and 3 inbound Pith citation observations for arXiv:2411.14834."}