{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2016:F2FTGVKK6TRALMSXBXI35YSIRV","short_pith_number":"pith:F2FTGVKK","canonical_record":{"source":{"id":"1602.02697","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-02-08T19:12:25Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"0316bdd3d4e3898411aa99f0a617d081a578c078d4a1607790ec88d393c2271a","abstract_canon_sha256":"0ad4ee9f7b2d40fc64e428463838da4db5dda92ef65ff1047022fc60097e0c87"},"schema_version":"1.0"},"canonical_sha256":"2e8b33554af4e205b2570dd1bee2488d4e105dec9b1a481fe96863b58e58077e","source":{"kind":"arxiv","id":"1602.02697","version":4},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1602.02697","created_at":"2026-05-18T00:48:28Z"},{"alias_kind":"arxiv_version","alias_value":"1602.02697v4","created_at":"2026-05-18T00:48:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1602.02697","created_at":"2026-05-18T00:48:28Z"},{"alias_kind":"pith_short_12","alias_value":"F2FTGVKK6TRA","created_at":"2026-05-18T12:30:15Z"},{"alias_kind":"pith_short_16","alias_value":"F2FTGVKK6TRALMSX","created_at":"2026-05-18T12:30:15Z"},{"alias_kind":"pith_short_8","alias_value":"F2FTGVKK","created_at":"2026-05-18T12:30:15Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2016:F2FTGVKK6TRALMSXBXI35YSIRV","target":"record","payload":{"canonical_record":{"source":{"id":"1602.02697","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-02-08T19:12:25Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"0316bdd3d4e3898411aa99f0a617d081a578c078d4a1607790ec88d393c2271a","abstract_canon_sha256":"0ad4ee9f7b2d40fc64e428463838da4db5dda92ef65ff1047022fc60097e0c87"},"schema_version":"1.0"},"canonical_sha256":"2e8b33554af4e205b2570dd1bee2488d4e105dec9b1a481fe96863b58e58077e","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:48:28.501993Z","signature_b64":"Uxn43hjbTlDY41KoZBC7WliX73plLqT/B/fnMJVYPpA00Ukr9xI9r5LlECSaavEMi9lXIvWMZpZnxS/2tHoPAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"2e8b33554af4e205b2570dd1bee2488d4e105dec9b1a481fe96863b58e58077e","last_reissued_at":"2026-05-18T00:48:28.501432Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:48:28.501432Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1602.02697","source_version":4,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:48:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"CsYpWhTdKWpb7fAcTk3fa8soFZm/Lfk8VlRfMAzPdTgccBMcoz+LW7iqt+gcWqF4g551EgirNO8m7j0NPKFyDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-07T20:20:45.620427Z"},"content_sha256":"ecaee2ec8ea3d9b9cc4ab4bc34363e9327305dd20fdbeee74aecda77b03e1bba","schema_version":"1.0","event_id":"sha256:ecaee2ec8ea3d9b9cc4ab4bc34363e9327305dd20fdbeee74aecda77b03e1bba"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2016:F2FTGVKK6TRALMSXBXI35YSIRV","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Practical Black-Box Attacks against Machine Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Ananthram Swami, Ian Goodfellow, Nicolas Papernot, Patrick McDaniel, Somesh Jha, Z. Berkay Celik","submitted_at":"2016-02-08T19:12:25Z","abstract_excerpt":"Machine learning (ML) models, e.g., deep neural networks (DNNs), are vulnerable to adversarial examples: malicious inputs modified to yield erroneous model outputs, while appearing unmodified to human observers. Potential attacks include having malicious content like malware identified as legitimate or controlling vehicle behavior. Yet, all existing adversarial example attacks require knowledge of either the model internals or its training data. We introduce the first practical demonstration of an attacker controlling a remotely hosted DNN with no such knowledge. Indeed, the only capability of"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1602.02697","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:48:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"t6Jj5l7P3KqkwH34684BGayieb371DFLq6WaGvSURuse//Ij4MUjhimic0lLQ46BZXv0Wn/NguhoWGeueVpbAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-07T20:20:45.621125Z"},"content_sha256":"e53d952d5d15833bacc19167dc75f7be5f37fa9ee20bb57c73b9247d5ee033a2","schema_version":"1.0","event_id":"sha256:e53d952d5d15833bacc19167dc75f7be5f37fa9ee20bb57c73b9247d5ee033a2"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/F2FTGVKK6TRALMSXBXI35YSIRV/bundle.json","state_url":"https://pith.science/pith/F2FTGVKK6TRALMSXBXI35YSIRV/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/F2FTGVKK6TRALMSXBXI35YSIRV/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-07T20:20:45Z","links":{"resolver":"https://pith.science/pith/F2FTGVKK6TRALMSXBXI35YSIRV","bundle":"https://pith.science/pith/F2FTGVKK6TRALMSXBXI35YSIRV/bundle.json","state":"https://pith.science/pith/F2FTGVKK6TRALMSXBXI35YSIRV/state.json","well_known_bundle":"https://pith.science/.well-known/pith/F2FTGVKK6TRALMSXBXI35YSIRV/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2016:F2FTGVKK6TRALMSXBXI35YSIRV","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"0ad4ee9f7b2d40fc64e428463838da4db5dda92ef65ff1047022fc60097e0c87","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-02-08T19:12:25Z","title_canon_sha256":"0316bdd3d4e3898411aa99f0a617d081a578c078d4a1607790ec88d393c2271a"},"schema_version":"1.0","source":{"id":"1602.02697","kind":"arxiv","version":4}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1602.02697","created_at":"2026-05-18T00:48:28Z"},{"alias_kind":"arxiv_version","alias_value":"1602.02697v4","created_at":"2026-05-18T00:48:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1602.02697","created_at":"2026-05-18T00:48:28Z"},{"alias_kind":"pith_short_12","alias_value":"F2FTGVKK6TRA","created_at":"2026-05-18T12:30:15Z"},{"alias_kind":"pith_short_16","alias_value":"F2FTGVKK6TRALMSX","created_at":"2026-05-18T12:30:15Z"},{"alias_kind":"pith_short_8","alias_value":"F2FTGVKK","created_at":"2026-05-18T12:30:15Z"}],"graph_snapshots":[{"event_id":"sha256:e53d952d5d15833bacc19167dc75f7be5f37fa9ee20bb57c73b9247d5ee033a2","target":"graph","created_at":"2026-05-18T00:48:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Machine learning (ML) models, e.g., deep neural networks (DNNs), are vulnerable to adversarial examples: malicious inputs modified to yield erroneous model outputs, while appearing unmodified to human observers. Potential attacks include having malicious content like malware identified as legitimate or controlling vehicle behavior. Yet, all existing adversarial example attacks require knowledge of either the model internals or its training data. We introduce the first practical demonstration of an attacker controlling a remotely hosted DNN with no such knowledge. Indeed, the only capability of","authors_text":"Ananthram Swami, Ian Goodfellow, Nicolas Papernot, Patrick McDaniel, Somesh Jha, Z. Berkay Celik","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-02-08T19:12:25Z","title":"Practical Black-Box Attacks against Machine Learning"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1602.02697","kind":"arxiv","version":4},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:ecaee2ec8ea3d9b9cc4ab4bc34363e9327305dd20fdbeee74aecda77b03e1bba","target":"record","created_at":"2026-05-18T00:48:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"0ad4ee9f7b2d40fc64e428463838da4db5dda92ef65ff1047022fc60097e0c87","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-02-08T19:12:25Z","title_canon_sha256":"0316bdd3d4e3898411aa99f0a617d081a578c078d4a1607790ec88d393c2271a"},"schema_version":"1.0","source":{"id":"1602.02697","kind":"arxiv","version":4}},"canonical_sha256":"2e8b33554af4e205b2570dd1bee2488d4e105dec9b1a481fe96863b58e58077e","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"2e8b33554af4e205b2570dd1bee2488d4e105dec9b1a481fe96863b58e58077e","first_computed_at":"2026-05-18T00:48:28.501432Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:48:28.501432Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Uxn43hjbTlDY41KoZBC7WliX73plLqT/B/fnMJVYPpA00Ukr9xI9r5LlECSaavEMi9lXIvWMZpZnxS/2tHoPAQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:48:28.501993Z","signed_message":"canonical_sha256_bytes"},"source_id":"1602.02697","source_kind":"arxiv","source_version":4}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:ecaee2ec8ea3d9b9cc4ab4bc34363e9327305dd20fdbeee74aecda77b03e1bba","sha256:e53d952d5d15833bacc19167dc75f7be5f37fa9ee20bb57c73b9247d5ee033a2"],"state_sha256":"86845977d9a07ff0cd49a5e40a73df99008179b5063d6a957b1958566f3e3d1d"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"NxFzHQmtJ9p42wSV/aSfM9/AAvTt6KnKN7ci6WIsvZj1OxFONHSLLc8fqiP39RtWvnXjy2quG7PzRSoHMGWmAw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-07T20:20:45.625137Z","bundle_sha256":"3e180c9890fb86cdf19d81d209042b61d50a34dbab9da279fa07d33a5dbbce7a"}}