{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:7Y5JYMCPKX7U4ZWC7YHNDGKR25","short_pith_number":"pith:7Y5JYMCP","canonical_record":{"source":{"id":"1811.02625","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-06T20:47:28Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"dc718a5979d6134b7f69cbd3f9313968e6a12e5fd5f66f09dbeba05c9ba936c1","abstract_canon_sha256":"2dc420c8c20de8069fc973d404690a66512b89ac682236e72d4de25e08072fc4"},"schema_version":"1.0"},"canonical_sha256":"fe3a9c304f55ff4e66c2fe0ed19951d77bb15a5529a063c846a366914ac5c261","source":{"kind":"arxiv","id":"1811.02625","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1811.02625","created_at":"2026-05-17T23:59:22Z"},{"alias_kind":"arxiv_version","alias_value":"1811.02625v2","created_at":"2026-05-17T23:59:22Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.02625","created_at":"2026-05-17T23:59:22Z"},{"alias_kind":"pith_short_12","alias_value":"7Y5JYMCPKX7U","created_at":"2026-05-18T12:32:13Z"},{"alias_kind":"pith_short_16","alias_value":"7Y5JYMCPKX7U4ZWC","created_at":"2026-05-18T12:32:13Z"},{"alias_kind":"pith_short_8","alias_value":"7Y5JYMCP","created_at":"2026-05-18T12:32:13Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:7Y5JYMCPKX7U4ZWC7YHNDGKR25","target":"record","payload":{"canonical_record":{"source":{"id":"1811.02625","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-06T20:47:28Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"dc718a5979d6134b7f69cbd3f9313968e6a12e5fd5f66f09dbeba05c9ba936c1","abstract_canon_sha256":"2dc420c8c20de8069fc973d404690a66512b89ac682236e72d4de25e08072fc4"},"schema_version":"1.0"},"canonical_sha256":"fe3a9c304f55ff4e66c2fe0ed19951d77bb15a5529a063c846a366914ac5c261","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:59:22.089544Z","signature_b64":"Q4hAjKUK8TPYVqHObucZfYA6leR363nRsnXGS2VcJvJ0jQfzpsBb12SnricTX38Tw77qJ8TsPDb4CADGoZyrCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"fe3a9c304f55ff4e66c2fe0ed19951d77bb15a5529a063c846a366914ac5c261","last_reissued_at":"2026-05-17T23:59:22.089203Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:59:22.089203Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1811.02625","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:59:22Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"p2mlfnEElmN883KN2hoy0oKKruVqu4C/CQOqSVSsN4ahzYUfSWpnqAKQjOoz7xZXmsghmPQWAsQpk0ACJo/UBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-29T00:41:45.532256Z"},"content_sha256":"f816b053bbf8ae44780d13e1dd7047a0f0bda6f918d04aabc3bf2706f7aadb3f","schema_version":"1.0","event_id":"sha256:f816b053bbf8ae44780d13e1dd7047a0f0bda6f918d04aabc3bf2706f7aadb3f"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:7Y5JYMCPKX7U4ZWC7YHNDGKR25","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"MixTrain: Scalable Training of Verifiably Robust Neural Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Ahmed Abdou, Shiqi Wang, Suman Jana, Yizheng Chen","submitted_at":"2018-11-06T20:47:28Z","abstract_excerpt":"Making neural networks robust against adversarial inputs has resulted in an arms race between new defenses and attacks. The most promising defenses, adversarially robust training and verifiably robust training, have limitations that restrict their practical applications. The adversarially robust training only makes the networks robust against a subclass of attackers and we reveal such weaknesses by developing a new attack based on interval gradients. By contrast, verifiably robust training provides protection against any L-p norm-bounded attacker but incurs orders of magnitude more computation"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.02625","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:59:22Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ynIIF+ttlWKq0KEZpDK5iqr0jgFTsAHlgA6EGXhCtI/KPMsISl6vUjhfDnTGQS2qMXZOmYBxAq36h5CPmMmyBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-29T00:41:45.532607Z"},"content_sha256":"be8939014f796d1ee4dfa5249d46e77c3d18408ddb888a79b61583908e6dfc7e","schema_version":"1.0","event_id":"sha256:be8939014f796d1ee4dfa5249d46e77c3d18408ddb888a79b61583908e6dfc7e"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/7Y5JYMCPKX7U4ZWC7YHNDGKR25/bundle.json","state_url":"https://pith.science/pith/7Y5JYMCPKX7U4ZWC7YHNDGKR25/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/7Y5JYMCPKX7U4ZWC7YHNDGKR25/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-29T00:41:45Z","links":{"resolver":"https://pith.science/pith/7Y5JYMCPKX7U4ZWC7YHNDGKR25","bundle":"https://pith.science/pith/7Y5JYMCPKX7U4ZWC7YHNDGKR25/bundle.json","state":"https://pith.science/pith/7Y5JYMCPKX7U4ZWC7YHNDGKR25/state.json","well_known_bundle":"https://pith.science/.well-known/pith/7Y5JYMCPKX7U4ZWC7YHNDGKR25/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:7Y5JYMCPKX7U4ZWC7YHNDGKR25","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"2dc420c8c20de8069fc973d404690a66512b89ac682236e72d4de25e08072fc4","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-06T20:47:28Z","title_canon_sha256":"dc718a5979d6134b7f69cbd3f9313968e6a12e5fd5f66f09dbeba05c9ba936c1"},"schema_version":"1.0","source":{"id":"1811.02625","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1811.02625","created_at":"2026-05-17T23:59:22Z"},{"alias_kind":"arxiv_version","alias_value":"1811.02625v2","created_at":"2026-05-17T23:59:22Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.02625","created_at":"2026-05-17T23:59:22Z"},{"alias_kind":"pith_short_12","alias_value":"7Y5JYMCPKX7U","created_at":"2026-05-18T12:32:13Z"},{"alias_kind":"pith_short_16","alias_value":"7Y5JYMCPKX7U4ZWC","created_at":"2026-05-18T12:32:13Z"},{"alias_kind":"pith_short_8","alias_value":"7Y5JYMCP","created_at":"2026-05-18T12:32:13Z"}],"graph_snapshots":[{"event_id":"sha256:be8939014f796d1ee4dfa5249d46e77c3d18408ddb888a79b61583908e6dfc7e","target":"graph","created_at":"2026-05-17T23:59:22Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Making neural networks robust against adversarial inputs has resulted in an arms race between new defenses and attacks. The most promising defenses, adversarially robust training and verifiably robust training, have limitations that restrict their practical applications. The adversarially robust training only makes the networks robust against a subclass of attackers and we reveal such weaknesses by developing a new attack based on interval gradients. By contrast, verifiably robust training provides protection against any L-p norm-bounded attacker but incurs orders of magnitude more computation","authors_text":"Ahmed Abdou, Shiqi Wang, Suman Jana, Yizheng Chen","cross_cats":["cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-06T20:47:28Z","title":"MixTrain: Scalable Training of Verifiably Robust Neural Networks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.02625","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:f816b053bbf8ae44780d13e1dd7047a0f0bda6f918d04aabc3bf2706f7aadb3f","target":"record","created_at":"2026-05-17T23:59:22Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"2dc420c8c20de8069fc973d404690a66512b89ac682236e72d4de25e08072fc4","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-11-06T20:47:28Z","title_canon_sha256":"dc718a5979d6134b7f69cbd3f9313968e6a12e5fd5f66f09dbeba05c9ba936c1"},"schema_version":"1.0","source":{"id":"1811.02625","kind":"arxiv","version":2}},"canonical_sha256":"fe3a9c304f55ff4e66c2fe0ed19951d77bb15a5529a063c846a366914ac5c261","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"fe3a9c304f55ff4e66c2fe0ed19951d77bb15a5529a063c846a366914ac5c261","first_computed_at":"2026-05-17T23:59:22.089203Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:59:22.089203Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Q4hAjKUK8TPYVqHObucZfYA6leR363nRsnXGS2VcJvJ0jQfzpsBb12SnricTX38Tw77qJ8TsPDb4CADGoZyrCA==","signature_status":"signed_v1","signed_at":"2026-05-17T23:59:22.089544Z","signed_message":"canonical_sha256_bytes"},"source_id":"1811.02625","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:f816b053bbf8ae44780d13e1dd7047a0f0bda6f918d04aabc3bf2706f7aadb3f","sha256:be8939014f796d1ee4dfa5249d46e77c3d18408ddb888a79b61583908e6dfc7e"],"state_sha256":"9245e7399995e039582eb35c2c0fe28c985a352a2ac21392c634788a66dfca18"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"iLeNUEMeyPV7ysbl1Oc2O8Hon1xDQO0A930OlipLkKy2Q/+yNsHkHheQAS38p65xRAQUSgWHQUFvqMIxu2MoCA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-29T00:41:45.534487Z","bundle_sha256":"1b406e2dfd3e55a0af8b5bc1f4ed4e5b7e4469b330d736625b1ad1a76aa0e6ec"}}