{"as_of":"2026-08-09T21:43:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:fb02d69f968db72ac9cf066a229b3b7ae26b4901a951c8bc48e30896ae5cf188","coverage":[{"denominator":56,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":56,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-07T10:34:52.370923Z","state":"measured"},{"denominator":56,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":56,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-09T06:31:02.800959+00:00","state":"measured"},{"denominator":0,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"cited_works","source_observed_at":null,"state":"measured"}],"external_citation_measurements":[],"inbound":[],"links":{"evidence":"/evidence","html":"/paper/2506.05032/citation-record","integrity":"/paper/2506.05032/integrity","json":"/paper/2506.05032/citation-record.json","paper":"/paper/2506.05032"},"outbound":[{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:48.113234Z","title":"write newline","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":1,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:48.113234Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:5990acff33083f73e543a86f525e3d2ca7efb61e3915d39289f993ca09c37ad9","observation_id":"9c3b8ac7-00e6-4b05-8e11-a2ac00e47022","resolution":{"observed_at":"2026-08-07T10:34:48.113234Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.980200Z","title":"and Flammarion, N","venue":null,"work_id":"1f21c98b-4e57-4b8d-a668-74e1775ce12f","year":2020},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":2,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:48.167416Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:5b9f520e634061317fb447e69b1481dac29f3979351d22acac92a99be0a5f4cb","observation_id":"2f457378-a363-4f3b-9ebc-ee9111b3f389","resolution":{"observed_at":"2026-08-07T10:34:57.986361Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.953011Z","title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","venue":null,"work_id":"d1c13154-3a1f-4a14-9e59-2301a28cef48","year":2018},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":3,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:48.267870Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:55086d7fef6d665b6860d1f7dc1b7d6306d8a724c2aab10f59b400787b08ef80","observation_id":"9245bc7f-c5ae-4d34-87be-570a08455b7f","resolution":{"observed_at":"2026-08-07T10:34:57.960046Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.928940Z","title":"Clustering effect of adversarial robust models","venue":null,"work_id":"f615b926-a21a-4165-8789-b15751901116","year":2021},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":4,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:48.321401Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:7e2a7f0a55e34188e39623af6d9df894653776359567508677516b691197a932","observation_id":"2b3115b3-e486-4b5e-949b-dbcb0e9b1b47","resolution":{"observed_at":"2026-08-07T10:34:57.935619Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.905638Z","title":"Improving adversarial robustness via channel-wise activation suppressing","venue":null,"work_id":"ffe91fac-a888-4a1b-8068-f63b572e4b57","year":2021},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":5,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:48.366765Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:f78ff93cb23ad25bf6669e783634627b64f3ba7f4009db10bd4011c77175dfe4","observation_id":"0adfbe5f-8ade-4508-814e-a076576efd23","resolution":{"observed_at":"2026-08-07T10:34:57.912823Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.884243Z","title":"Robust classification via a single diffusion model","venue":null,"work_id":"284cb19a-a3ba-46c9-af3d-c4b5a7149faf","year":2024},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":6,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:48.430198Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:38711691879e09cb0b2c94288b149116cf762bc8ad47ac8e97db52034c145aff","observation_id":"ed9b4fdd-5ec7-4132-9e92-664186cbd735","resolution":{"observed_at":"2026-08-07T10:34:57.889808Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.861946Z","title":"Robust overfitting may be mitigated by properly learned smoothening","venue":null,"work_id":"f4d2818b-7439-41d0-9fd0-626276644735","year":2021},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":7,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:48.496972Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:490ef2bf92753b0ef3802c5cf999220ae5e24456aa1aee83753288ea5b97c02c","observation_id":"b82cde2d-a096-49dd-b8e7-3fc336f9646b","resolution":{"observed_at":"2026-08-07T10:34:57.868571Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.840647Z","title":"Cat: Customized adversarial training for improved robustness","venue":null,"work_id":"ee013a1e-3f21-4bd2-9948-8b505f51d5d4","year":2022},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":8,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:48.555318Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:937eab3a264250831ade24b288f6f6d74183a157fd500f42bdbae5d9f6c64062","observation_id":"ab786668-7600-493d-99ac-d7b5a0e20d19","resolution":{"observed_at":"2026-08-07T10:34:57.846751Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.813566Z","title":"M., Rosenfeld, E., and Kolter, J","venue":null,"work_id":"e189b4f4-9c93-4929-b5e6-90642c3c716f","year":2019},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":9,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:48.640160Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:4481017a74af632728f1bbcf08e55a5e837f64f54660c651ae21ff4be7a08dbd","observation_id":"9cb0ae4a-ede4-479a-86d6-ab16538968ce","resolution":{"observed_at":"2026-08-07T10:34:57.821831Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.788918Z","title":"Label noise in adversarial training: A novel perspective to study robust overfitting","venue":null,"work_id":"07276d41-597e-4c21-9de1-554367d02bbc","year":2022},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":10,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:48.692504Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:fef06e3302c47179aff01295ab666cf83cf6d5aea35ce22aefd4276271c968c7","observation_id":"d44772a5-5aa8-4bb2-9217-d5d5983e08bd","resolution":{"observed_at":"2026-08-07T10:34:57.795766Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.761909Z","title":"Exploring memorization in adversarial training","venue":null,"work_id":"706ccdfc-8d83-47e5-99dd-14e94ecab943","year":2022},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":11,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:48.754026Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:8d5e443a134264c49ab88b2c6939c201a428a4e561888f0cca5e0b5387e9e2ce","observation_id":"7db92a89-bd1b-430e-9ddf-15e50612950a","resolution":{"observed_at":"2026-08-07T10:34:57.769572Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2407.09087","last_updated":"2024-07-12T08:25:31Z","snapshot_observed_at":"2026-07-06T18:45:13.949715Z","submitted_at":"2024-07-12T08:25:31Z","title":"On the Role of Discrete Tokenization in Visual Representation Learning","version":1},"cited_work":{"arxiv_id":"2407.09087","doi":null,"metadata_source":"pith","pith_arxiv_id":"2407.09087","snapshot_observed_at":"2026-08-07T10:34:52.785456Z","title":"On the Role of Discrete Tokenization in Visual Representation Learning","venue":"cs.LG","work_id":"9950f873-bb9e-4e1b-9184-db41d0457b7a","year":2024},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":12,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:48.839735Z"},"links":{"cited_paper":"/paper/2407.09087","citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:83a007693c7059b8ecadfb47655217e380769722095a4e5040f920d08c13dca4","observation_id":"9a2db324-d3e6-4d29-bf90-e04e98e591b3","resolution":{"observed_at":"2026-08-07T10:34:52.817077Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.720956Z","title":"A., and Mann, T","venue":null,"work_id":"35acc599-3fc5-4f67-8771-b84fb2544f1b","year":2021},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":14,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:48.991226Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:cfa4b6288b848c1557a5f0b89c4b00767a86ae844b3d8b8cf54adca4399559c6","observation_id":"c33c4f02-976c-4c12-8fc6-7f5550ec1136","resolution":{"observed_at":"2026-08-07T10:34:57.731777Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2303.06562","last_updated":"2023-05-02T13:38:34Z","snapshot_observed_at":"2026-07-06T15:01:49.803305Z","submitted_at":"2023-03-12T04:04:51Z","title":"ContraNorm: A Contrastive Learning Perspective on Oversmoothing and Beyond","version":2},"cited_work":{"arxiv_id":"2303.06562","doi":null,"metadata_source":"pith","pith_arxiv_id":"2303.06562","snapshot_observed_at":"2026-08-07T10:34:52.566291Z","title":"ContraNorm: A Contrastive Learning Perspective on Oversmoothing and Beyond","venue":"cs.LG","work_id":"f6b18c3c-ac1d-47f1-8a69-f9094207f287","year":2023},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":15,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:49.077030Z"},"links":{"cited_paper":"/paper/2303.06562","citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:d206a06032719fe03314eedfd737819b8f2dc13843ae1988fe75d3421351d6c4","observation_id":"11d51226-2229-4f70-b015-597970ad66fb","resolution":{"observed_at":"2026-08-07T10:34:52.636023Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.700299Z","title":"Identity mappings in deep residual networks","venue":null,"work_id":"0ba3d0bb-7380-48b3-8af5-5037488ed5bd","year":2016},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":16,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:49.130636Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:48d794206f92cd12a3a1275f2bf403627856d29f2489a478daa66b69f79af8fb","observation_id":"26b3cc54-8868-43b6-9071-e090e02ff4f9","resolution":{"observed_at":"2026-08-07T10:34:57.707403Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1503.02531","last_updated":"2015-03-09T15:44:49Z","snapshot_observed_at":"2026-07-06T04:11:24.157003Z","submitted_at":"2015-03-09T15:44:49Z","title":"Distilling the Knowledge in a Neural Network","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1503.02531","snapshot_observed_at":"2026-08-07T10:34:49.196262Z","title":"Distilling the knowledge in a neural network","venue":null,"work_id":null,"year":2015},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":17,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:49.196262Z"},"links":{"cited_paper":"/paper/1503.02531","citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:2e410ba3700f997806c37bc0fc278dcdfdf387daf7d70760c97b08ea047b99ce","observation_id":"0fb2187b-cc70-4a7b-8e38-c3aeb626952a","resolution":{"observed_at":"2026-08-07T10:34:49.196262Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.677521Z","title":"Boosting accuracy and robustness of student models via adaptive adversarial distillation","venue":null,"work_id":"48f10e0f-7259-4f29-9fc7-c50f1c4fa1c7","year":2023},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":18,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:49.268858Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:2aff9f9ca4d244a1d37d77ba557e3498ac7ef2885ec366c4cf49ebadc8f245d0","observation_id":"ffd9b3d3-d5e1-48f5-b618-2c9f38a465c3","resolution":{"observed_at":"2026-08-07T10:34:57.686091Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.650275Z","title":"M., Gu, Q., Bailey, J., and Ma, X","venue":null,"work_id":"6d1ff7cd-9980-407b-ba86-fdf77d2c45cb","year":2021},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":19,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:49.353250Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:cd516bc59636b27a891595caddca4912d014e3cf1fa727a35a96658c0fd29e30","observation_id":"06f5ee13-070e-4f1d-a37f-cf63ef02ab0c","resolution":{"observed_at":"2026-08-07T10:34:57.658969Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.624820Z","title":"Adversarial examples are not bugs, they are features","venue":null,"work_id":"c0c48918-d63c-468c-b5a6-16f799b2a8ea","year":2019},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":20,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:49.437534Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:a5ba60d72aab417de29b22ca68f256c4fbb0c67432df87a51685cdfea95ad9b9","observation_id":"f1b30812-5b25-423b-9df2-90dcb64c9d0e","resolution":{"observed_at":"2026-08-07T10:34:57.633332Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:49.500159Z","title":"Fantastic generalization measures and where to find them","venue":null,"work_id":null,"year":2020},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":21,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:49.500159Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:d203eaa7d48097708e15ff3e614faeaa96a4a885278995da71e610052ba9f5a0","observation_id":"f242b1f5-e4c5-4336-9697-0f396410a004","resolution":{"observed_at":"2026-08-07T10:34:49.500159Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.588982Z","title":"Understanding catastrophic overfitting in single-step adversarial training","venue":null,"work_id":"2e181990-e991-4f83-aa75-101a1e22f556","year":2021},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":22,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:49.575883Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:c775fdaeeea7faef1de7b9e8389661b005c738b25936466cd7c3a1d396f00475","observation_id":"b00896b5-eb1c-4bde-88f9-f846285e25e6","resolution":{"observed_at":"2026-08-07T10:34:57.593796Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:49.639355Z","title":"Learning multiple layers of features from tiny images","venue":null,"work_id":null,"year":2009},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":23,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:49.639355Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:579ef075c2a7bba4f9c54c63bf12c09c1c6e65c76193c30bd7a17d44d1f48bb2","observation_id":"ba14a905-cda6-4b88-8d4d-9a8a3129ed23","resolution":{"observed_at":"2026-08-07T10:34:49.639355Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.554229Z","title":"and Aila, T","venue":null,"work_id":"c2c95a11-8b9f-4ac6-82c4-f33c43985341","year":2017},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":24,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:49.690531Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:5de219f2d3b6cd86c164a3f43fe411f943cef429e8b2a81a8255fdb7efaafbe4","observation_id":"401cb63e-4012-4a0e-b7cd-fb60b91d8aa1","resolution":{"observed_at":"2026-08-07T10:34:57.560997Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.536883Z","title":"Adversarial examples are not real features","venue":null,"work_id":"24bc9985-92cd-4c78-9168-962b278afd07","year":2023},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":25,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:49.767228Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:a171ae65d08e38bb58e6e939330573de303bcdd9e6d4070c5e9c353333d27320","observation_id":"315c830a-5fe0-4a49-a38d-b2ecabf74d53","resolution":{"observed_at":"2026-08-07T10:34:57.542165Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:57.237678Z","title":"and Li, Y","venue":null,"work_id":"494d9845-4be2-4094-8003-e1a3ee349b2c","year":2024},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":26,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:49.820646Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:70ce4feebb8283cbddc6909e0622d3a97e2ecd7026f29553b81ed6ac31cdd09d","observation_id":"f818867f-11b3-4207-bcf2-f1b0819e02e1","resolution":{"observed_at":"2026-08-07T10:34:57.394460Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:56.849047Z","title":"and Spratling, M","venue":null,"work_id":"dafde4c8-2cf3-47f9-8ffb-04f0dcc4b33a","year":2023},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":27,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:49.880240Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:093b7214f82b6c5f50c25df53bcdc625be3a1ce364d348199aef20e38653aaa0","observation_id":"c430700c-c7af-43d8-8d8e-0f91c8df88ef","resolution":{"observed_at":"2026-08-07T10:34:57.008979Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:56.686796Z","title":"Towards deep learning models resistant to adversarial attacks","venue":null,"work_id":"3f13659c-816d-4813-80fe-0c85bfd9fbff","year":2018},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":28,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:49.955054Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:6468898b8298bcdcba85a191c9cb1cfad47809f30821396fcea9c3b87c1027c1","observation_id":"900ca3ec-a33a-434f-97b7-618b3765410e","resolution":{"observed_at":"2026-08-07T10:34:56.768252Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:56.603911Z","title":null,"venue":null,"work_id":"42c3c74c-d906-4d46-b92e-e64a779c2157","year":2017},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":29,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:50.032717Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:5464e20742a9f54cbe41b76efca3bd2c0bb1b45775e8f88ecb9be9ba8be98929","observation_id":"91a3e40c-65d6-4520-ba8d-bde5eeea21fb","resolution":{"observed_at":"2026-08-07T10:34:56.647767Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:56.478651Z","title":"When adversarial training meets vision transformers: Recipes from training to architecture","venue":null,"work_id":"31924d61-f590-4fce-a2ed-5bc2babfa654","year":2022},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":30,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:50.144343Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:2979790e11bd223678e7a176fc8444eb8a57b089990bbb1e78c5cb9cb78fe09d","observation_id":"5dc79aae-68b9-4032-ac29-f347c2c95d48","resolution":{"observed_at":"2026-08-07T10:34:56.520004Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:56.350641Z","title":"Bag of tricks for adversarial training","venue":null,"work_id":"920a0981-4202-4c38-80a2-9ac0eaf4381c","year":2021},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":31,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:50.221607Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:f2e0af10698b29be1a96607723d744fd2660113ff9650385c2aed73296a12f11","observation_id":"720b3061-4e18-4657-b9da-21fb8c029db6","resolution":{"observed_at":"2026-08-07T10:34:56.417223Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:56.195159Z","title":"Distillation as a defense to adversarial perturbations against deep neural networks","venue":null,"work_id":"41da6bfb-4e16-4746-b217-6d0c4069ba68","year":2016},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":32,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:50.332259Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:1679b6fd19e2ef0d070ff2b49bd126e5988cf417319d365345bcaea1172c843f","observation_id":"1cb6dbed-51ec-4f9a-93b0-c55544e1741b","resolution":{"observed_at":"2026-08-07T10:34:56.221125Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:56.080306Z","title":"A., Stimberg, F., Wiles, O., and Mann, T","venue":null,"work_id":"fee54e73-4bda-444b-8154-25a462d9d020","year":2021},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":33,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:50.395661Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:39ad0768e6a043327689878678ab3bf61144887d6fe617d12569271972346682","observation_id":"bb80cd42-4f6c-4e6a-9105-3bc884e76520","resolution":{"observed_at":"2026-08-07T10:34:56.114297Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:55.977234Z","title":"Overfitting in adversarially robust deep learning","venue":null,"work_id":"cee5dc0a-1e21-4bd0-87d5-d9a67ade0b4e","year":2020},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":34,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:50.446876Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:e2b17bbc7989143c50ddf2ccdf12a2669459fb965c8918bc6f6fb3695643a9b4","observation_id":"ac7fa0eb-e9c9-4179-9813-268e529a994d","resolution":{"observed_at":"2026-08-07T10:34:56.017803Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:55.838943Z","title":"R., Cogswell, M., Das, A., Vedantam, R., Parikh, D., and Batra, D","venue":null,"work_id":"beeb01ee-7133-4ef8-a14f-182ac97d3538","year":2017},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":35,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:50.515427Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:f78a2026253ec2dc7cf1dacec25f38c9bcb42507d8bd3b72b803ae2a1219aa3a","observation_id":"7b2e986f-4ae2-4539-90a4-5583c67975b4","resolution":{"observed_at":"2026-08-07T10:34:55.897508Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:55.709462Z","title":"A., Xu, Z., Dickerson, J., Studer, C., Davis, L","venue":null,"work_id":"f44e08b8-4da7-4f77-bf86-a7f50190e922","year":2019},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":36,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:50.583872Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:8198d8f170ad772981a2e85f5fef3092d9bc578d373c4177d0d641587af5517d","observation_id":"7ede34dc-8b2c-4009-b078-49b8321d4fb8","resolution":{"observed_at":"2026-08-07T10:34:55.759379Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:55.596129Z","title":"Training data-efficient image transformers & distillation through attention","venue":null,"work_id":"7e9c92b8-f9ff-4c99-bb91-8d9f23038cf7","year":2021},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":37,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:50.694943Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:f955d84443e9d896f01cf19483103b6733b7a72dc1719649c7261de608eb3852","observation_id":"9f77166b-7b89-4eb9-9a33-20955e112189","resolution":{"observed_at":"2026-08-07T10:34:55.648743Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:55.489471Z","title":"Robustness may be at odds with accuracy","venue":null,"work_id":"aaff185e-64fb-46c4-b123-7aaded1a1d70","year":2019},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":38,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:50.745065Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:3414d59bb282ad01785a3b1e1d451001ac24e8657544bf197aa8ad6a4348d6e5","observation_id":"386be28d-eb1b-4198-ac13-71f656ef106a","resolution":{"observed_at":"2026-08-07T10:34:55.544880Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:55.329548Z","title":"and Wang, Y","venue":null,"work_id":"7a4769ec-c0fb-4d93-b9a2-f5b42d8def0e","year":2022},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":39,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:50.848319Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:d096ea5ee9d6fa834cdf714e63d496cd6a5ada9e5a18bbfd1b164e8692917333","observation_id":"3a65b41b-4d99-4e0e-8b12-db38368a2381","resolution":{"observed_at":"2026-08-07T10:34:55.375828Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:55.153877Z","title":"On the convergence and robustness of adversarial training","venue":null,"work_id":"f450ab93-4db6-4d4a-aeee-e2d7aeb36e12","year":2019},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":40,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:50.909329Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:ec7d2e3257f4f700a47713ae8c286eec7aba23fdfef43adea18479bb8206d00a","observation_id":"94ec5d26-7c56-45cc-bcc9-980cf740647d","resolution":{"observed_at":"2026-08-07T10:34:55.225294Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:55.057982Z","title":"Improving adversarial robustness requires revisiting misclassified examples","venue":null,"work_id":"5bae692a-e869-42a6-b144-77494a9bd750","year":2020},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":41,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:50.950321Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:34407cf515b18d7cd62204498809b106e06f5fdf2abea48023c75d2f27319457","observation_id":"bf0da95f-fa68-4067-877e-a3e91aed7927","resolution":{"observed_at":"2026-08-07T10:34:55.098904Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:54.914146Z","title":"Balance, imbalance, and rebalance: Understanding robust overfitting from a minimax game perspective","venue":null,"work_id":"980bacba-5966-4327-ace3-a4e5dde44450","year":2024},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":42,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:51.037655Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:b23717183551b1e3833ea2e44f43209aefca6eaeb46fe455aad1ce8a9c042710","observation_id":"bfb6aaf9-fa8c-4993-8ae2-af273649cebe","resolution":{"observed_at":"2026-08-07T10:34:54.961071Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:54.740525Z","title":"Better diffusion models further improve adversarial training","venue":null,"work_id":"d6394749-b604-49c6-80e9-88658587fe01","year":2023},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":43,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:51.101345Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:51ae26cd442add34a96b94176eb82c1eccbbc6aed72fffc580a71081f899a9d9","observation_id":"3f129fb1-96d6-4bb5-aa1e-4ac46936e0be","resolution":{"observed_at":"2026-08-07T10:34:54.837050Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:54.611097Z","title":"Cfa: Class-wise calibrated fair adversarial training","venue":null,"work_id":"eed2a561-3e7f-48d3-bc99-f695d54a1cf7","year":2023},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":44,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:51.196678Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:629740d8af584dcf7bd9cfe00ce04986b9555cfa4345e8d2c56fb7595ecb0c1f","observation_id":"65959015-de72-496d-8b11-cc83a0f7909c","resolution":{"observed_at":"2026-08-07T10:34:54.670006Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:54.481006Z","title":null,"venue":null,"work_id":"31d70747-640c-4803-8364-89ef345acbae","year":2020},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":45,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:51.268047Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:797b093639cecb57fb17f4d22103f6944e13fe0ab7af18b26455275ca5ea0500","observation_id":"b61adc8f-f40b-46c0-a144-d623a317af46","resolution":{"observed_at":"2026-08-07T10:34:54.541635Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:54.294751Z","title":"Adversarial weight perturbation helps robust generalization","venue":null,"work_id":"be251567-3f36-4f98-bc5a-1bb82ea8da53","year":2020},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":46,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:51.384382Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:fd6a3f91cca5e71df1be294990518a9dea8a54d7379c87bae25dcaf5134b7963","observation_id":"8c054155-ccf2-420e-a4f2-2a0ec2d34b8d","resolution":{"observed_at":"2026-08-07T10:34:54.396147Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:54.115178Z","title":"Annealing self-distillation rectification improves adversarial training","venue":null,"work_id":"1e0432ff-675b-46fa-b6b4-1527a7273447","year":2024},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":47,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:51.462883Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:ca8ca78058db942f9793c815d5a85bc0868bc170c2aab50b5be533dc0bc0f596","observation_id":"9c53b880-b162-4acf-bbd3-ebb61791df5b","resolution":{"observed_at":"2026-08-07T10:34:54.179841Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:53.949143Z","title":"Robust weight perturbation for adversarial training","venue":null,"work_id":"7171b3dd-b5f8-4d6b-9c3e-72fc559d7267","year":2022},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":48,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:51.583013Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:ad69f9e997e05b1a95909562d62da850808ee563a175d72649b2576ddd9faf9b","observation_id":"1ff460b9-52b7-40ee-ab57-789655cddf8f","resolution":{"observed_at":"2026-08-07T10:34:54.027548Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:53.792405Z","title":"Understanding robust overfitting of adversarial training and beyond","venue":null,"work_id":"358fd713-d854-4f05-8968-5119f2b939b3","year":2022},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":49,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:51.703953Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:ccebb2c1a9f2dc3fe51ace2fb2fc56672a4d8f7a623111419fa55674826470c4","observation_id":"621bbda7-24bf-407f-82b7-142891bda1c4","resolution":{"observed_at":"2026-08-07T10:34:53.875197Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:53.652851Z","title":"Revisiting adversarial robustness distillation from the perspective of robust fairness","venue":null,"work_id":"2e17646a-24e6-4999-9470-188c97309801","year":2023},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":50,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:51.807829Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:09789d90950611c935bd66b52a0ecbf755a2ef75e04c69ebe2ab0e537b0cb2f3","observation_id":"d695adce-f4b8-425f-ae70-b5684fd03e40","resolution":{"observed_at":"2026-08-07T10:34:53.727117Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:53.520409Z","title":"Theoretically principled trade-off between robustness and accuracy","venue":null,"work_id":"4e8f0f62-49b4-46d2-ace7-1de58e76bc46","year":2019},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":51,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:51.870482Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:87cfd1191d1518567ac519411bcd5b0307b651d718a1f23c1057c6509cf595f7","observation_id":"c985fbaf-edf0-4ffb-a919-e22f2d538b81","resolution":{"observed_at":"2026-08-07T10:34:53.578133Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:53.318727Z","title":"On the duality between sharpness-aware minimization and adversarial training","venue":null,"work_id":"9a8fc529-ed00-4b74-b642-f2cf14833cc1","year":2024},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":52,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:51.939809Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:c25c0e444e8a414a93fd370f5453a85af36b9c7bcb744ee4527e2f0a7ffe49c9","observation_id":"958e5b6c-2e6a-4ecb-8221-9a586e40b6fe","resolution":{"observed_at":"2026-08-07T10:34:53.413142Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:53.137175Z","title":"Reliable adversarial distillation with unreliable teachers","venue":null,"work_id":"c8f5251f-37a9-4e2f-ba1f-ca2757e65f94","year":2022},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":53,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:52.047504Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:c15996fc6ba3fa0c510bb55a9e2829cf85753c76180bf2a7e7e2eb4f8b9f0e9c","observation_id":"54108b5a-5427-4400-acde-37cbef870e4c","resolution":{"observed_at":"2026-08-07T10:34:53.238327Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:52.955121Z","title":"Revisiting adversarial robustness distillation: Robust soft labels make student better","venue":null,"work_id":"92be4425-cee7-43d3-b384-b8f189e5746b","year":2021},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":54,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:52.125716Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:f1e40087aae08a4284ded36c123f74317f867e5e41acc323f48857d814afb811","observation_id":"84924bda-b719-425b-85dc-a7d19fa3a8c5","resolution":{"observed_at":"2026-08-07T10:34:53.021954Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:52.209720Z","title":"@esa (Ref","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":55,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:52.209720Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:36a83b32eb7fcd0bcbf272bfce3a373d5f80c5ba27c29fcb6470bf309e98b2b9","observation_id":"b5510bb6-dc40-4b35-aa16-2392e3aa4424","resolution":{"observed_at":"2026-08-07T10:34:52.209720Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T10:34:52.290541Z","title":null,"venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":56,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:52.290541Z"},"links":{"citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:dce0d0d17dd6734bf8d588c4ea7cf433104744c6066232f8f6138df16780ebc9","observation_id":"dc0ea3bf-b1f2-43ec-abf3-67c273fcab90","resolution":{"observed_at":"2026-08-07T10:34:52.290541Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1412.6572","last_updated":"2015-03-20T20:19:16Z","snapshot_observed_at":"2026-07-06T04:04:16.777653Z","submitted_at":"2014-12-20T01:17:12Z","title":"Explaining and Harnessing Adversarial Examples","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1412.6572","snapshot_observed_at":"2026-08-07T10:34:52.370923Z","title":"Notations Let N( , ) be the normal distribution with mean and variance ^2","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training","version":1},"reference_index":57,"source":"arxiv_source","source_observed_at":"2026-08-07T10:34:52.370923Z"},"links":{"cited_paper":"/paper/1412.6572","citing_paper":"/paper/2506.05032"},"observation_digest":"sha256:6627a3df35fa4c2889e757c66e04f7c2d01b0e08a99779471aebcdba6a4f9d8c","observation_id":"728c4eee-45db-4577-bbfc-d83313426467","resolution":{"observed_at":"2026-08-07T10:34:52.370923Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"paper":{"arxiv_id":"2506.05032","last_updated":"2025-06-05T13:40:11Z","latest_version":1,"primary_category":"cs.LG","snapshot_observed_at":"2026-08-07T10:24:47.899090Z","submitted_at":"2025-06-05T13:40:11Z","title":"Identifying and Understanding Cross-Class Features in Adversarial Training"},"reference_resolution":{"displayed":56,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":9,"verified_exact":2,"verified_fuzzy":45},"total_outbound_references":56},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"thesis":"As of 9 August 2026, this Paper Citation Record lists 56 of 56 outbound references and 0 inbound Pith citation observations for arXiv:2506.05032."}