{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:BXCYOCZKP7LK5JI546DE36AHHY","short_pith_number":"pith:BXCYOCZK","canonical_record":{"source":{"id":"1909.12272","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-09-26T17:30:16Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"71b3b5321996237dfd4491a7e27bbc530e5f79db90deb6eda8d4def438dfe9d4","abstract_canon_sha256":"03fe07de39046039c17294613aafe3dc828f2b60b1d48728eadc324dc94c1277"},"schema_version":"1.0"},"canonical_sha256":"0dc5870b2a7fd6aea51de7864df8073e280ea376e1cb83813ab5211f255bc424","source":{"kind":"arxiv","id":"1909.12272","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1909.12272","created_at":"2026-07-05T00:16:06Z"},{"alias_kind":"arxiv_version","alias_value":"1909.12272v2","created_at":"2026-07-05T00:16:06Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1909.12272","created_at":"2026-07-05T00:16:06Z"},{"alias_kind":"pith_short_12","alias_value":"BXCYOCZKP7LK","created_at":"2026-07-05T00:16:06Z"},{"alias_kind":"pith_short_16","alias_value":"BXCYOCZKP7LK5JI5","created_at":"2026-07-05T00:16:06Z"},{"alias_kind":"pith_short_8","alias_value":"BXCYOCZK","created_at":"2026-07-05T00:16:06Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:BXCYOCZKP7LK5JI546DE36AHHY","target":"record","payload":{"canonical_record":{"source":{"id":"1909.12272","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-09-26T17:30:16Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"71b3b5321996237dfd4491a7e27bbc530e5f79db90deb6eda8d4def438dfe9d4","abstract_canon_sha256":"03fe07de39046039c17294613aafe3dc828f2b60b1d48728eadc324dc94c1277"},"schema_version":"1.0"},"canonical_sha256":"0dc5870b2a7fd6aea51de7864df8073e280ea376e1cb83813ab5211f255bc424","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:16:06.100889Z","signature_b64":"FSC4HF/WtNWvHlrBw3/Ez5Hy30zVlwUYE7RNFshk5k4drUfLxw5dqX/rAjWt+jbZaMMtk2rUJ9UL+R39kvLCCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"0dc5870b2a7fd6aea51de7864df8073e280ea376e1cb83813ab5211f255bc424","last_reissued_at":"2026-07-05T00:16:06.100434Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:16:06.100434Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1909.12272","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T00:16:06Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"UiFHu1gJYJYsmu8n8WoFP5JxmhzkZhUoQGtFuzHedWfGs03QSFmvagvawjg+SsuGjT3QrTxNqvFnA3YLILeeDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-05T04:25:16.571383Z"},"content_sha256":"5cca1cde9094a198f9e52156a39e6c260f22572ab55dec70134108af8cd93f4c","schema_version":"1.0","event_id":"sha256:5cca1cde9094a198f9e52156a39e6c260f22572ab55dec70134108af8cd93f4c"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:BXCYOCZKP7LK5JI546DE36AHHY","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Lower Bounds on Adversarial Robustness from Optimal Transport","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Arjun Nitin Bhagoji, Daniel Cullina, Prateek Mittal","submitted_at":"2019-09-26T17:30:16Z","abstract_excerpt":"While progress has been made in understanding the robustness of machine learning classifiers to test-time adversaries (evasion attacks), fundamental questions remain unresolved. In this paper, we use optimal transport to characterize the minimum possible loss in an adversarial classification scenario. In this setting, an adversary receives a random labeled example from one of two classes, perturbs the example subject to a neighborhood constraint, and presents the modified example to the classifier. We define an appropriate cost function such that the minimum transportation cost between the dis"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1909.12272","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1909.12272/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T00:16:06Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"+LziFOi50bRQS3iyBAQoTmb6JETaQTUX8louFSC5o2oUhpiu87qRGCvEOpoF2RrcO5Z5C9phFYHUYm1edRniCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-05T04:25:16.571752Z"},"content_sha256":"70283a4e40dfe8328d2b8cbf9b41c37e144abfffc1e14f9920be89128972d9c3","schema_version":"1.0","event_id":"sha256:70283a4e40dfe8328d2b8cbf9b41c37e144abfffc1e14f9920be89128972d9c3"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/BXCYOCZKP7LK5JI546DE36AHHY/bundle.json","state_url":"https://pith.science/pith/BXCYOCZKP7LK5JI546DE36AHHY/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/BXCYOCZKP7LK5JI546DE36AHHY/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-05T04:25:16Z","links":{"resolver":"https://pith.science/pith/BXCYOCZKP7LK5JI546DE36AHHY","bundle":"https://pith.science/pith/BXCYOCZKP7LK5JI546DE36AHHY/bundle.json","state":"https://pith.science/pith/BXCYOCZKP7LK5JI546DE36AHHY/state.json","well_known_bundle":"https://pith.science/.well-known/pith/BXCYOCZKP7LK5JI546DE36AHHY/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:BXCYOCZKP7LK5JI546DE36AHHY","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"03fe07de39046039c17294613aafe3dc828f2b60b1d48728eadc324dc94c1277","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-09-26T17:30:16Z","title_canon_sha256":"71b3b5321996237dfd4491a7e27bbc530e5f79db90deb6eda8d4def438dfe9d4"},"schema_version":"1.0","source":{"id":"1909.12272","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1909.12272","created_at":"2026-07-05T00:16:06Z"},{"alias_kind":"arxiv_version","alias_value":"1909.12272v2","created_at":"2026-07-05T00:16:06Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1909.12272","created_at":"2026-07-05T00:16:06Z"},{"alias_kind":"pith_short_12","alias_value":"BXCYOCZKP7LK","created_at":"2026-07-05T00:16:06Z"},{"alias_kind":"pith_short_16","alias_value":"BXCYOCZKP7LK5JI5","created_at":"2026-07-05T00:16:06Z"},{"alias_kind":"pith_short_8","alias_value":"BXCYOCZK","created_at":"2026-07-05T00:16:06Z"}],"graph_snapshots":[{"event_id":"sha256:70283a4e40dfe8328d2b8cbf9b41c37e144abfffc1e14f9920be89128972d9c3","target":"graph","created_at":"2026-07-05T00:16:06Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/1909.12272/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"While progress has been made in understanding the robustness of machine learning classifiers to test-time adversaries (evasion attacks), fundamental questions remain unresolved. In this paper, we use optimal transport to characterize the minimum possible loss in an adversarial classification scenario. In this setting, an adversary receives a random labeled example from one of two classes, perturbs the example subject to a neighborhood constraint, and presents the modified example to the classifier. We define an appropriate cost function such that the minimum transportation cost between the dis","authors_text":"Arjun Nitin Bhagoji, Daniel Cullina, Prateek Mittal","cross_cats":["cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-09-26T17:30:16Z","title":"Lower Bounds on Adversarial Robustness from Optimal Transport"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1909.12272","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:5cca1cde9094a198f9e52156a39e6c260f22572ab55dec70134108af8cd93f4c","target":"record","created_at":"2026-07-05T00:16:06Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"03fe07de39046039c17294613aafe3dc828f2b60b1d48728eadc324dc94c1277","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-09-26T17:30:16Z","title_canon_sha256":"71b3b5321996237dfd4491a7e27bbc530e5f79db90deb6eda8d4def438dfe9d4"},"schema_version":"1.0","source":{"id":"1909.12272","kind":"arxiv","version":2}},"canonical_sha256":"0dc5870b2a7fd6aea51de7864df8073e280ea376e1cb83813ab5211f255bc424","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"0dc5870b2a7fd6aea51de7864df8073e280ea376e1cb83813ab5211f255bc424","first_computed_at":"2026-07-05T00:16:06.100434Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T00:16:06.100434Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"FSC4HF/WtNWvHlrBw3/Ez5Hy30zVlwUYE7RNFshk5k4drUfLxw5dqX/rAjWt+jbZaMMtk2rUJ9UL+R39kvLCCA==","signature_status":"signed_v1","signed_at":"2026-07-05T00:16:06.100889Z","signed_message":"canonical_sha256_bytes"},"source_id":"1909.12272","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:5cca1cde9094a198f9e52156a39e6c260f22572ab55dec70134108af8cd93f4c","sha256:70283a4e40dfe8328d2b8cbf9b41c37e144abfffc1e14f9920be89128972d9c3"],"state_sha256":"bc9ed7f38709da481eafeab7f07d0d68a9f26c83b9b5be683d60e67015084123"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"PzoDwKqQKOTAgQmdWvh0Dy4cPqBgkZLQCmis8bs1/hvgLjABpSX5/F4t5nJi5Jh1PpX9Fx8A4OtvQS13rqFACA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-05T04:25:16.574059Z","bundle_sha256":"5d2082fd1fa04d6c293622e9a99059855e34b334796426aa14d8b9aef094b763"}}