{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:MMYVTSB7G6WWPF6S4DRAHB7R2X","short_pith_number":"pith:MMYVTSB7","canonical_record":{"source":{"id":"1805.11090","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-05-28T06:40:55Z","cross_cats_sorted":["cs.AI","cs.CR","cs.CV"],"title_canon_sha256":"5bc1b67a87ff36f6f9acc90826d34025e1984c99c33b1b0eadf4bb75cc651cd6","abstract_canon_sha256":"ed5a39b84b6a8f9a409900f68efde49007406440b730751e6c9eb2316b156336"},"schema_version":"1.0"},"canonical_sha256":"633159c83f37ad6797d2e0e20387f1d5da15ccbda3b5c6415c8f3ec16209ee93","source":{"kind":"arxiv","id":"1805.11090","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1805.11090","created_at":"2026-05-17T23:41:54Z"},{"alias_kind":"arxiv_version","alias_value":"1805.11090v3","created_at":"2026-05-17T23:41:54Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1805.11090","created_at":"2026-05-17T23:41:54Z"},{"alias_kind":"pith_short_12","alias_value":"MMYVTSB7G6WW","created_at":"2026-05-18T12:32:37Z"},{"alias_kind":"pith_short_16","alias_value":"MMYVTSB7G6WWPF6S","created_at":"2026-05-18T12:32:37Z"},{"alias_kind":"pith_short_8","alias_value":"MMYVTSB7","created_at":"2026-05-18T12:32:37Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:MMYVTSB7G6WWPF6S4DRAHB7R2X","target":"record","payload":{"canonical_record":{"source":{"id":"1805.11090","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-05-28T06:40:55Z","cross_cats_sorted":["cs.AI","cs.CR","cs.CV"],"title_canon_sha256":"5bc1b67a87ff36f6f9acc90826d34025e1984c99c33b1b0eadf4bb75cc651cd6","abstract_canon_sha256":"ed5a39b84b6a8f9a409900f68efde49007406440b730751e6c9eb2316b156336"},"schema_version":"1.0"},"canonical_sha256":"633159c83f37ad6797d2e0e20387f1d5da15ccbda3b5c6415c8f3ec16209ee93","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:41:54.056034Z","signature_b64":"O+GDGfc4CToRS3r3Pu2Pz7ds7xyTvupnKe40O+2e/y5Xf7IeWtK2uyb0QEXAG2n+a3MNPhX/L67GjeaRuApADg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"633159c83f37ad6797d2e0e20387f1d5da15ccbda3b5c6415c8f3ec16209ee93","last_reissued_at":"2026-05-17T23:41:54.055574Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:41:54.055574Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1805.11090","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:41:54Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Mm40AQmhnXrhtzQxDMyauPL/p+RSzJBw5MOwiOCB11eLcxPqRw67RhRXRjphPMDwnF5ZGvldPUNAUoGCwxZLAw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T23:15:51.839230Z"},"content_sha256":"dba0a77eae45490708fa6ffcd9c4aef134b499f18529ff636e18892c3a53fec1","schema_version":"1.0","event_id":"sha256:dba0a77eae45490708fa6ffcd9c4aef134b499f18529ff636e18892c3a53fec1"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:MMYVTSB7G6WWPF6S4DRAHB7R2X","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"GenAttack: Practical Black-box Attacks with Gradient-Free Optimization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CR","cs.CV"],"primary_cat":"cs.LG","authors_text":"Cho-Jui Hsieh, Huan Zhang, Mani Srivastava, Moustafa Alzantot, Supriyo Chakraborty, Yash Sharma","submitted_at":"2018-05-28T06:40:55Z","abstract_excerpt":"Deep neural networks are vulnerable to adversarial examples, even in the black-box setting, where the attacker is restricted solely to query access. Existing black-box approaches to generating adversarial examples typically require a significant number of queries, either for training a substitute network or performing gradient estimation. We introduce GenAttack, a gradient-free optimization technique that uses genetic algorithms for synthesizing adversarial examples in the black-box setting. Our experiments on different datasets (MNIST, CIFAR-10, and ImageNet) show that GenAttack can successfu"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1805.11090","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:41:54Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"0x9Obzjr534A7aE7nm+sI9riyqdiN2yp7hlGhq3wm4Ozz0XhwlV3dMKtb5S50oPZ1lY1cX1CEqxwrSk7gr8eBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T23:15:51.839884Z"},"content_sha256":"97e8a3a921e5ff3ffd1e3a8ed42ade7891bc00628eeb7e6699e1bdfdb3d32c8f","schema_version":"1.0","event_id":"sha256:97e8a3a921e5ff3ffd1e3a8ed42ade7891bc00628eeb7e6699e1bdfdb3d32c8f"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/MMYVTSB7G6WWPF6S4DRAHB7R2X/bundle.json","state_url":"https://pith.science/pith/MMYVTSB7G6WWPF6S4DRAHB7R2X/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/MMYVTSB7G6WWPF6S4DRAHB7R2X/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-28T23:15:51Z","links":{"resolver":"https://pith.science/pith/MMYVTSB7G6WWPF6S4DRAHB7R2X","bundle":"https://pith.science/pith/MMYVTSB7G6WWPF6S4DRAHB7R2X/bundle.json","state":"https://pith.science/pith/MMYVTSB7G6WWPF6S4DRAHB7R2X/state.json","well_known_bundle":"https://pith.science/.well-known/pith/MMYVTSB7G6WWPF6S4DRAHB7R2X/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:MMYVTSB7G6WWPF6S4DRAHB7R2X","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"ed5a39b84b6a8f9a409900f68efde49007406440b730751e6c9eb2316b156336","cross_cats_sorted":["cs.AI","cs.CR","cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-05-28T06:40:55Z","title_canon_sha256":"5bc1b67a87ff36f6f9acc90826d34025e1984c99c33b1b0eadf4bb75cc651cd6"},"schema_version":"1.0","source":{"id":"1805.11090","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1805.11090","created_at":"2026-05-17T23:41:54Z"},{"alias_kind":"arxiv_version","alias_value":"1805.11090v3","created_at":"2026-05-17T23:41:54Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1805.11090","created_at":"2026-05-17T23:41:54Z"},{"alias_kind":"pith_short_12","alias_value":"MMYVTSB7G6WW","created_at":"2026-05-18T12:32:37Z"},{"alias_kind":"pith_short_16","alias_value":"MMYVTSB7G6WWPF6S","created_at":"2026-05-18T12:32:37Z"},{"alias_kind":"pith_short_8","alias_value":"MMYVTSB7","created_at":"2026-05-18T12:32:37Z"}],"graph_snapshots":[{"event_id":"sha256:97e8a3a921e5ff3ffd1e3a8ed42ade7891bc00628eeb7e6699e1bdfdb3d32c8f","target":"graph","created_at":"2026-05-17T23:41:54Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep neural networks are vulnerable to adversarial examples, even in the black-box setting, where the attacker is restricted solely to query access. Existing black-box approaches to generating adversarial examples typically require a significant number of queries, either for training a substitute network or performing gradient estimation. We introduce GenAttack, a gradient-free optimization technique that uses genetic algorithms for synthesizing adversarial examples in the black-box setting. Our experiments on different datasets (MNIST, CIFAR-10, and ImageNet) show that GenAttack can successfu","authors_text":"Cho-Jui Hsieh, Huan Zhang, Mani Srivastava, Moustafa Alzantot, Supriyo Chakraborty, Yash Sharma","cross_cats":["cs.AI","cs.CR","cs.CV"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-05-28T06:40:55Z","title":"GenAttack: Practical Black-box Attacks with Gradient-Free Optimization"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1805.11090","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:dba0a77eae45490708fa6ffcd9c4aef134b499f18529ff636e18892c3a53fec1","target":"record","created_at":"2026-05-17T23:41:54Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"ed5a39b84b6a8f9a409900f68efde49007406440b730751e6c9eb2316b156336","cross_cats_sorted":["cs.AI","cs.CR","cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-05-28T06:40:55Z","title_canon_sha256":"5bc1b67a87ff36f6f9acc90826d34025e1984c99c33b1b0eadf4bb75cc651cd6"},"schema_version":"1.0","source":{"id":"1805.11090","kind":"arxiv","version":3}},"canonical_sha256":"633159c83f37ad6797d2e0e20387f1d5da15ccbda3b5c6415c8f3ec16209ee93","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"633159c83f37ad6797d2e0e20387f1d5da15ccbda3b5c6415c8f3ec16209ee93","first_computed_at":"2026-05-17T23:41:54.055574Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:41:54.055574Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"O+GDGfc4CToRS3r3Pu2Pz7ds7xyTvupnKe40O+2e/y5Xf7IeWtK2uyb0QEXAG2n+a3MNPhX/L67GjeaRuApADg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:41:54.056034Z","signed_message":"canonical_sha256_bytes"},"source_id":"1805.11090","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:dba0a77eae45490708fa6ffcd9c4aef134b499f18529ff636e18892c3a53fec1","sha256:97e8a3a921e5ff3ffd1e3a8ed42ade7891bc00628eeb7e6699e1bdfdb3d32c8f"],"state_sha256":"3bab89fd5541848e782d31a1a6b7291fd85d92cfe66e935e2833eb8beaafd0d6"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8Q0+EfO71035JNfV5L6d5yn4psPK9Ue/DvgbuaM/W198/zNlAIUXEFly7QH2TFhY2EqiaQvIDi+qvuA4gCETBg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-28T23:15:51.842870Z","bundle_sha256":"71a6a4bda043e73d303b72f8ba5be047384b941388dc42c739fd13c237202469"}}