{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:GX3546CYBKCJSEWRU6H42XGFNZ","short_pith_number":"pith:GX3546CY","canonical_record":{"source":{"id":"1807.09705","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-07-25T16:31:05Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"23f2e78a4ce9127b1d699a2a1f82cf5260fdc5f027d32a2dcdfd3ab27818e905","abstract_canon_sha256":"d2a40805323ec8490818823f8d50464a94e38d80a7057c58a444b0f4b3e64139"},"schema_version":"1.0"},"canonical_sha256":"35f7de78580a849912d1a78fcd5cc56e46ba85e9adf6afedd9c74cf2d8ba8b2c","source":{"kind":"arxiv","id":"1807.09705","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1807.09705","created_at":"2026-05-18T00:09:48Z"},{"alias_kind":"arxiv_version","alias_value":"1807.09705v1","created_at":"2026-05-18T00:09:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1807.09705","created_at":"2026-05-18T00:09:48Z"},{"alias_kind":"pith_short_12","alias_value":"GX3546CYBKCJ","created_at":"2026-05-18T12:32:25Z"},{"alias_kind":"pith_short_16","alias_value":"GX3546CYBKCJSEWR","created_at":"2026-05-18T12:32:25Z"},{"alias_kind":"pith_short_8","alias_value":"GX3546CY","created_at":"2026-05-18T12:32:25Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:GX3546CYBKCJSEWRU6H42XGFNZ","target":"record","payload":{"canonical_record":{"source":{"id":"1807.09705","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-07-25T16:31:05Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"23f2e78a4ce9127b1d699a2a1f82cf5260fdc5f027d32a2dcdfd3ab27818e905","abstract_canon_sha256":"d2a40805323ec8490818823f8d50464a94e38d80a7057c58a444b0f4b3e64139"},"schema_version":"1.0"},"canonical_sha256":"35f7de78580a849912d1a78fcd5cc56e46ba85e9adf6afedd9c74cf2d8ba8b2c","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:09:48.459434Z","signature_b64":"TShklJB9TYwPxJWukHwnvBb51Ym1g53jh4ro17bI7118ilC8+9jH/4cH7IEpbt6LXtJG687LuhL6MCGP6/+SDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"35f7de78580a849912d1a78fcd5cc56e46ba85e9adf6afedd9c74cf2d8ba8b2c","last_reissued_at":"2026-05-18T00:09:48.458915Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:09:48.458915Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1807.09705","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:09:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"nue51oXy/ym7NfFhgiKf6+bNqcSvPQ6SKTIg/15jalVIG6vtFBZvpqZrlXYv6cUbfHCs1hfawIUD2bQRfgQ8CA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-28T11:48:34.691749Z"},"content_sha256":"7c4a5109f35bb622ef1b6d41737361041304a03d98c875c25ea29230e25e60e5","schema_version":"1.0","event_id":"sha256:7c4a5109f35bb622ef1b6d41737361041304a03d98c875c25ea29230e25e60e5"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:GX3546CYBKCJSEWRU6H42XGFNZ","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Limitations of the Lipschitz constant as a defense against adversarial examples","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Cho-Yu Jason Chiang, Ritu Chadha, Todd Huster","submitted_at":"2018-07-25T16:31:05Z","abstract_excerpt":"Several recent papers have discussed utilizing Lipschitz constants to limit the susceptibility of neural networks to adversarial examples. We analyze recently proposed methods for computing the Lipschitz constant. We show that the Lipschitz constant may indeed enable adversarially robust neural networks. However, the methods currently employed for computing it suffer from theoretical and practical limitations. We argue that addressing this shortcoming is a promising direction for future research into certified adversarial defenses."},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1807.09705","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:09:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"9gaJXFMzBociVarLFeUyobqd5HIvQqplEAnDqmdnPUEdpr+oe7v22S6E7Q/xfSkmPhFmRYUhZNrf5Kt100dkBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-28T11:48:34.692089Z"},"content_sha256":"c66274782b0fb27d62b7aed73d2711babe5604b95c7d558f91dec4bedf62d23a","schema_version":"1.0","event_id":"sha256:c66274782b0fb27d62b7aed73d2711babe5604b95c7d558f91dec4bedf62d23a"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/GX3546CYBKCJSEWRU6H42XGFNZ/bundle.json","state_url":"https://pith.science/pith/GX3546CYBKCJSEWRU6H42XGFNZ/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/GX3546CYBKCJSEWRU6H42XGFNZ/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-28T11:48:34Z","links":{"resolver":"https://pith.science/pith/GX3546CYBKCJSEWRU6H42XGFNZ","bundle":"https://pith.science/pith/GX3546CYBKCJSEWRU6H42XGFNZ/bundle.json","state":"https://pith.science/pith/GX3546CYBKCJSEWRU6H42XGFNZ/state.json","well_known_bundle":"https://pith.science/.well-known/pith/GX3546CYBKCJSEWRU6H42XGFNZ/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:GX3546CYBKCJSEWRU6H42XGFNZ","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"d2a40805323ec8490818823f8d50464a94e38d80a7057c58a444b0f4b3e64139","cross_cats_sorted":["stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-07-25T16:31:05Z","title_canon_sha256":"23f2e78a4ce9127b1d699a2a1f82cf5260fdc5f027d32a2dcdfd3ab27818e905"},"schema_version":"1.0","source":{"id":"1807.09705","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1807.09705","created_at":"2026-05-18T00:09:48Z"},{"alias_kind":"arxiv_version","alias_value":"1807.09705v1","created_at":"2026-05-18T00:09:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1807.09705","created_at":"2026-05-18T00:09:48Z"},{"alias_kind":"pith_short_12","alias_value":"GX3546CYBKCJ","created_at":"2026-05-18T12:32:25Z"},{"alias_kind":"pith_short_16","alias_value":"GX3546CYBKCJSEWR","created_at":"2026-05-18T12:32:25Z"},{"alias_kind":"pith_short_8","alias_value":"GX3546CY","created_at":"2026-05-18T12:32:25Z"}],"graph_snapshots":[{"event_id":"sha256:c66274782b0fb27d62b7aed73d2711babe5604b95c7d558f91dec4bedf62d23a","target":"graph","created_at":"2026-05-18T00:09:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Several recent papers have discussed utilizing Lipschitz constants to limit the susceptibility of neural networks to adversarial examples. We analyze recently proposed methods for computing the Lipschitz constant. We show that the Lipschitz constant may indeed enable adversarially robust neural networks. However, the methods currently employed for computing it suffer from theoretical and practical limitations. We argue that addressing this shortcoming is a promising direction for future research into certified adversarial defenses.","authors_text":"Cho-Yu Jason Chiang, Ritu Chadha, Todd Huster","cross_cats":["stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-07-25T16:31:05Z","title":"Limitations of the Lipschitz constant as a defense against adversarial examples"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1807.09705","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:7c4a5109f35bb622ef1b6d41737361041304a03d98c875c25ea29230e25e60e5","target":"record","created_at":"2026-05-18T00:09:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"d2a40805323ec8490818823f8d50464a94e38d80a7057c58a444b0f4b3e64139","cross_cats_sorted":["stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-07-25T16:31:05Z","title_canon_sha256":"23f2e78a4ce9127b1d699a2a1f82cf5260fdc5f027d32a2dcdfd3ab27818e905"},"schema_version":"1.0","source":{"id":"1807.09705","kind":"arxiv","version":1}},"canonical_sha256":"35f7de78580a849912d1a78fcd5cc56e46ba85e9adf6afedd9c74cf2d8ba8b2c","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"35f7de78580a849912d1a78fcd5cc56e46ba85e9adf6afedd9c74cf2d8ba8b2c","first_computed_at":"2026-05-18T00:09:48.458915Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:09:48.458915Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"TShklJB9TYwPxJWukHwnvBb51Ym1g53jh4ro17bI7118ilC8+9jH/4cH7IEpbt6LXtJG687LuhL6MCGP6/+SDA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:09:48.459434Z","signed_message":"canonical_sha256_bytes"},"source_id":"1807.09705","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:7c4a5109f35bb622ef1b6d41737361041304a03d98c875c25ea29230e25e60e5","sha256:c66274782b0fb27d62b7aed73d2711babe5604b95c7d558f91dec4bedf62d23a"],"state_sha256":"dd5a364f95945463480f451260f448b8f88e7f50851a9c6ac86bf4b49afe1ff2"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"R0N5d65F997J/1X1NN/E8tDnQvloTsQwpDEQOmMdrjsintFvox0zBP4o8UHUXZAXy0bOZafPc0JblUCiuHzjDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-28T11:48:34.693973Z","bundle_sha256":"8b862e2c114ebf41886a263066b99fecdba11e272364950816ff91dbe3bd7dc2"}}