{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2020:OAEHB3YQHGNAQ7ZH76HURTHT2Y","short_pith_number":"pith:OAEHB3YQ","schema_version":"1.0","canonical_sha256":"700870ef10399a087f27ff8f48ccf3d616d278a32e276347d63ff81a868e2e32","source":{"kind":"arxiv","id":"2001.03994","version":1},"attestation_state":"computed","paper":{"title":"Fast is better than free: Revisiting adversarial training","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Eric Wong, J. Zico Kolter, Leslie Rice","submitted_at":"2020-01-12T20:30:22Z","abstract_excerpt":"Adversarial training, a method for learning robust deep networks, is typically assumed to be more expensive than traditional training due to the necessity of constructing adversarial examples via a first-order method like projected gradient decent (PGD). In this paper, we make the surprising discovery that it is possible to train empirically robust models using a much weaker and cheaper adversary, an approach that was previously believed to be ineffective, rendering the method no more costly than standard training in practice. Specifically, we show that adversarial training with the fast gradi"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2001.03994","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2020-01-12T20:30:22Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"9d2b771385c7276e88884dfaaf46e976facff38600e0875aaddbf60f97938a6b","abstract_canon_sha256":"8de881a31a1cc56dd5b3e4f9104f461fef0fa2512e0a91afd4765aea783c0d65"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:32:57.726510Z","signature_b64":"GjOWO4l2jKPFis2awfvOtWb1H5qQG877oQafPSIK6m9QfXRvqVeSono8YZNuZOYkoyX+bHtbvKTvueLRUDWrCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"700870ef10399a087f27ff8f48ccf3d616d278a32e276347d63ff81a868e2e32","last_reissued_at":"2026-07-05T00:32:57.726102Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:32:57.726102Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Fast is better than free: Revisiting adversarial training","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Eric Wong, J. Zico Kolter, Leslie Rice","submitted_at":"2020-01-12T20:30:22Z","abstract_excerpt":"Adversarial training, a method for learning robust deep networks, is typically assumed to be more expensive than traditional training due to the necessity of constructing adversarial examples via a first-order method like projected gradient decent (PGD). In this paper, we make the surprising discovery that it is possible to train empirically robust models using a much weaker and cheaper adversary, an approach that was previously believed to be ineffective, rendering the method no more costly than standard training in practice. Specifically, we show that adversarial training with the fast gradi"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2001.03994","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2001.03994/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2001.03994","created_at":"2026-07-05T00:32:57.726156+00:00"},{"alias_kind":"arxiv_version","alias_value":"2001.03994v1","created_at":"2026-07-05T00:32:57.726156+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2001.03994","created_at":"2026-07-05T00:32:57.726156+00:00"},{"alias_kind":"pith_short_12","alias_value":"OAEHB3YQHGNA","created_at":"2026-07-05T00:32:57.726156+00:00"},{"alias_kind":"pith_short_16","alias_value":"OAEHB3YQHGNAQ7ZH","created_at":"2026-07-05T00:32:57.726156+00:00"},{"alias_kind":"pith_short_8","alias_value":"OAEHB3YQ","created_at":"2026-07-05T00:32:57.726156+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":11,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.20666","citing_title":"Robust Auto-associative Memory via Convolutional Restricted Hopfield Networks","ref_index":43,"is_internal_anchor":false},{"citing_arxiv_id":"2606.02267","citing_title":"A combination of noise and bilateral filters achieve supralinear and scalable adversarial robustness in CNNs","ref_index":54,"is_internal_anchor":false},{"citing_arxiv_id":"2505.02360","citing_title":"Catastrophic Overfitting, Entropy Gap and Participation Ratio: A Noiseless $l^p$ Norm Solution for Fast Adversarial Training","ref_index":25,"is_internal_anchor":false},{"citing_arxiv_id":"2601.14505","citing_title":"Uncovering and Understanding FPR Manipulation Attack in Industrial IoT Networks","ref_index":71,"is_internal_anchor":false},{"citing_arxiv_id":"2310.03684","citing_title":"SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks","ref_index":45,"is_internal_anchor":false},{"citing_arxiv_id":"2604.11590","citing_title":"Learning Robustness at Test-Time from a Non-Robust Teacher","ref_index":34,"is_internal_anchor":false},{"citing_arxiv_id":"2604.12757","citing_title":"GF-Score: Certified Class-Conditional Robustness Evaluation with Fairness Guarantees","ref_index":3,"is_internal_anchor":false},{"citing_arxiv_id":"2604.08827","citing_title":"Quantum Patches: Enhancing Robustness of Quantum Machine Learning Models","ref_index":30,"is_internal_anchor":false},{"citing_arxiv_id":"2604.06954","citing_title":"Compression as an Adversarial Amplifier Through Decision Space Reduction","ref_index":47,"is_internal_anchor":false},{"citing_arxiv_id":"2604.17396","citing_title":"Representation-Guided Parameter-Efficient LLM Unlearning","ref_index":67,"is_internal_anchor":false},{"citing_arxiv_id":"2604.22853","citing_title":"FastAT Benchmark: A Comprehensive Framework for Fair Evaluation of Fast Adversarial Training Methods","ref_index":2,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/OAEHB3YQHGNAQ7ZH76HURTHT2Y","json":"https://pith.science/pith/OAEHB3YQHGNAQ7ZH76HURTHT2Y.json","graph_json":"https://pith.science/api/pith-number/OAEHB3YQHGNAQ7ZH76HURTHT2Y/graph.json","events_json":"https://pith.science/api/pith-number/OAEHB3YQHGNAQ7ZH76HURTHT2Y/events.json","paper":"https://pith.science/paper/OAEHB3YQ"},"agent_actions":{"view_html":"https://pith.science/pith/OAEHB3YQHGNAQ7ZH76HURTHT2Y","download_json":"https://pith.science/pith/OAEHB3YQHGNAQ7ZH76HURTHT2Y.json","view_paper":"https://pith.science/paper/OAEHB3YQ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2001.03994&json=true","fetch_graph":"https://pith.science/api/pith-number/OAEHB3YQHGNAQ7ZH76HURTHT2Y/graph.json","fetch_events":"https://pith.science/api/pith-number/OAEHB3YQHGNAQ7ZH76HURTHT2Y/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/OAEHB3YQHGNAQ7ZH76HURTHT2Y/action/timestamp_anchor","attest_storage":"https://pith.science/pith/OAEHB3YQHGNAQ7ZH76HURTHT2Y/action/storage_attestation","attest_author":"https://pith.science/pith/OAEHB3YQHGNAQ7ZH76HURTHT2Y/action/author_attestation","sign_citation":"https://pith.science/pith/OAEHB3YQHGNAQ7ZH76HURTHT2Y/action/citation_signature","submit_replication":"https://pith.science/pith/OAEHB3YQHGNAQ7ZH76HURTHT2Y/action/replication_record"}},"created_at":"2026-07-05T00:32:57.726156+00:00","updated_at":"2026-07-05T00:32:57.726156+00:00"}