{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:MOERPWBX7PDAYGC2E3XZY2C6CV","short_pith_number":"pith:MOERPWBX","canonical_record":{"source":{"id":"1812.01198","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-12-04T03:25:50Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"f20226644a18e49795cfb544f1f8190c1113c5f24d107b444aee13a2508e6343","abstract_canon_sha256":"db95828cd7af30442962fb38a35cd96af3fe39e41d1b9282b2ef448580007670"},"schema_version":"1.0"},"canonical_sha256":"638917d837fbc60c185a26ef9c685e1571e5998e464499a75dd82965e1d01b31","source":{"kind":"arxiv","id":"1812.01198","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1812.01198","created_at":"2026-05-17T23:42:48Z"},{"alias_kind":"arxiv_version","alias_value":"1812.01198v2","created_at":"2026-05-17T23:42:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1812.01198","created_at":"2026-05-17T23:42:48Z"},{"alias_kind":"pith_short_12","alias_value":"MOERPWBX7PDA","created_at":"2026-05-18T12:32:37Z"},{"alias_kind":"pith_short_16","alias_value":"MOERPWBX7PDAYGC2","created_at":"2026-05-18T12:32:37Z"},{"alias_kind":"pith_short_8","alias_value":"MOERPWBX","created_at":"2026-05-18T12:32:37Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:MOERPWBX7PDAYGC2E3XZY2C6CV","target":"record","payload":{"canonical_record":{"source":{"id":"1812.01198","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-12-04T03:25:50Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"f20226644a18e49795cfb544f1f8190c1113c5f24d107b444aee13a2508e6343","abstract_canon_sha256":"db95828cd7af30442962fb38a35cd96af3fe39e41d1b9282b2ef448580007670"},"schema_version":"1.0"},"canonical_sha256":"638917d837fbc60c185a26ef9c685e1571e5998e464499a75dd82965e1d01b31","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:42:48.695919Z","signature_b64":"8Y6oTNv6mJjMBlIm/+fYD0cZt5BNihpE7DhuImHF/cl7iyBcrx3Pjv+8jMdqGujlgij5+WLkoek+heB4qjdfCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"638917d837fbc60c185a26ef9c685e1571e5998e464499a75dd82965e1d01b31","last_reissued_at":"2026-05-17T23:42:48.695427Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:42:48.695427Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1812.01198","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:42:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"BrY8g1zw/873zbkCsHW8QNfsEgi4g7MEh13x69Kti/j767X3XITgxjyoA6UokQKd5w12gXVuUdphhyQ7oQX7AA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T20:47:06.696278Z"},"content_sha256":"ecdcc2df11645be285603fc78b6c497d43652755d374063fd5d7bf2772a27cb1","schema_version":"1.0","event_id":"sha256:ecdcc2df11645be285603fc78b6c497d43652755d374063fd5d7bf2772a27cb1"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:MOERPWBX7PDAYGC2E3XZY2C6CV","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Adversarial Example Decomposition","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"stat.ML","authors_text":"Aaron Lou, Horace He, Isay Katsman, Qingxuan Jiang, Serge Belongie, Ser-Nam Lim","submitted_at":"2018-12-04T03:25:50Z","abstract_excerpt":"Research has shown that widely used deep neural networks are vulnerable to carefully crafted adversarial perturbations. Moreover, these adversarial perturbations often transfer across models. We hypothesize that adversarial weakness is composed of three sources of bias: architecture, dataset, and random initialization. We show that one can decompose adversarial examples into an architecture-dependent component, data-dependent component, and noise-dependent component and that these components behave intuitively. For example, noise-dependent components transfer poorly to all other models, while "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1812.01198","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:42:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"2X3yCDPOmyb2xjn0tzrxci5XXULkMLvX3E+RaZbZ0zt0IuSOmmQ4C0qlarXDsTRvpX9+QC1XAo3GfnqVCNaUCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T20:47:06.696985Z"},"content_sha256":"e02dd300767552a581c3187e6e97ae00bedb9aca2aa7cb0e651ed98535c3e707","schema_version":"1.0","event_id":"sha256:e02dd300767552a581c3187e6e97ae00bedb9aca2aa7cb0e651ed98535c3e707"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/MOERPWBX7PDAYGC2E3XZY2C6CV/bundle.json","state_url":"https://pith.science/pith/MOERPWBX7PDAYGC2E3XZY2C6CV/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/MOERPWBX7PDAYGC2E3XZY2C6CV/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T20:47:06Z","links":{"resolver":"https://pith.science/pith/MOERPWBX7PDAYGC2E3XZY2C6CV","bundle":"https://pith.science/pith/MOERPWBX7PDAYGC2E3XZY2C6CV/bundle.json","state":"https://pith.science/pith/MOERPWBX7PDAYGC2E3XZY2C6CV/state.json","well_known_bundle":"https://pith.science/.well-known/pith/MOERPWBX7PDAYGC2E3XZY2C6CV/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:MOERPWBX7PDAYGC2E3XZY2C6CV","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"db95828cd7af30442962fb38a35cd96af3fe39e41d1b9282b2ef448580007670","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-12-04T03:25:50Z","title_canon_sha256":"f20226644a18e49795cfb544f1f8190c1113c5f24d107b444aee13a2508e6343"},"schema_version":"1.0","source":{"id":"1812.01198","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1812.01198","created_at":"2026-05-17T23:42:48Z"},{"alias_kind":"arxiv_version","alias_value":"1812.01198v2","created_at":"2026-05-17T23:42:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1812.01198","created_at":"2026-05-17T23:42:48Z"},{"alias_kind":"pith_short_12","alias_value":"MOERPWBX7PDA","created_at":"2026-05-18T12:32:37Z"},{"alias_kind":"pith_short_16","alias_value":"MOERPWBX7PDAYGC2","created_at":"2026-05-18T12:32:37Z"},{"alias_kind":"pith_short_8","alias_value":"MOERPWBX","created_at":"2026-05-18T12:32:37Z"}],"graph_snapshots":[{"event_id":"sha256:e02dd300767552a581c3187e6e97ae00bedb9aca2aa7cb0e651ed98535c3e707","target":"graph","created_at":"2026-05-17T23:42:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Research has shown that widely used deep neural networks are vulnerable to carefully crafted adversarial perturbations. Moreover, these adversarial perturbations often transfer across models. We hypothesize that adversarial weakness is composed of three sources of bias: architecture, dataset, and random initialization. We show that one can decompose adversarial examples into an architecture-dependent component, data-dependent component, and noise-dependent component and that these components behave intuitively. For example, noise-dependent components transfer poorly to all other models, while ","authors_text":"Aaron Lou, Horace He, Isay Katsman, Qingxuan Jiang, Serge Belongie, Ser-Nam Lim","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-12-04T03:25:50Z","title":"Adversarial Example Decomposition"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1812.01198","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:ecdcc2df11645be285603fc78b6c497d43652755d374063fd5d7bf2772a27cb1","target":"record","created_at":"2026-05-17T23:42:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"db95828cd7af30442962fb38a35cd96af3fe39e41d1b9282b2ef448580007670","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-12-04T03:25:50Z","title_canon_sha256":"f20226644a18e49795cfb544f1f8190c1113c5f24d107b444aee13a2508e6343"},"schema_version":"1.0","source":{"id":"1812.01198","kind":"arxiv","version":2}},"canonical_sha256":"638917d837fbc60c185a26ef9c685e1571e5998e464499a75dd82965e1d01b31","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"638917d837fbc60c185a26ef9c685e1571e5998e464499a75dd82965e1d01b31","first_computed_at":"2026-05-17T23:42:48.695427Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:42:48.695427Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"8Y6oTNv6mJjMBlIm/+fYD0cZt5BNihpE7DhuImHF/cl7iyBcrx3Pjv+8jMdqGujlgij5+WLkoek+heB4qjdfCg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:42:48.695919Z","signed_message":"canonical_sha256_bytes"},"source_id":"1812.01198","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:ecdcc2df11645be285603fc78b6c497d43652755d374063fd5d7bf2772a27cb1","sha256:e02dd300767552a581c3187e6e97ae00bedb9aca2aa7cb0e651ed98535c3e707"],"state_sha256":"4a81572e1fc6e11b7f26f82e34bd8d30dcb06ee0788873306e0a94c6610c3b8b"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"KyzHTse5e4rRZOXOMqCnXoNvLTXawWJoDjT2J/ati6xttmg5ud1jzdZjx3sVH7yJ/tHddxKxvAR77EcysBrkDg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T20:47:06.700762Z","bundle_sha256":"73f92d6b136255c837adf2406ee8876fe2e737f5f88013ebe482b830e46546e0"}}