{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2020:PABHHKFUYRF6XW35CACZMU2MT4","short_pith_number":"pith:PABHHKFU","schema_version":"1.0","canonical_sha256":"780273a8b4c44bebdb7d100596534c9f23e49a0e7d684abd3fa515cb300e0995","source":{"kind":"arxiv","id":"2006.12655","version":4},"attestation_state":"computed","paper":{"title":"Perceptual Adversarial Robustness: Defense Against Unseen Threat Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Cassidy Laidlaw, Sahil Singla, Soheil Feizi","submitted_at":"2020-06-22T22:40:46Z","abstract_excerpt":"A key challenge in adversarial robustness is the lack of a precise mathematical characterization of human perception, used in the very definition of adversarial attacks that are imperceptible to human eyes. Most current attacks and defenses try to avoid this issue by considering restrictive adversarial threat models such as those bounded by $L_2$ or $L_\\infty$ distance, spatial perturbations, etc. However, models that are robust against any of these restrictive threat models are still fragile against other threat models. To resolve this issue, we propose adversarial training against the set of"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2006.12655","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2020-06-22T22:40:46Z","cross_cats_sorted":["cs.CV","stat.ML"],"title_canon_sha256":"f48c934c69129b196abb410fe5edb52e8fae333fca12c71d015688dbb254f1f6","abstract_canon_sha256":"3e270aa767a0afa08afd3d9811b9c9f5f81eab99d6b131af1bdd88ca3bfeef59"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T02:54:50.496044Z","signature_b64":"8UtaDq4zyrwP/kkyh3oODg5FDVOrlzNI9Xok70GAfa/ETw9e7F6+0SeNcUvmPaymfPl7dcD4tBIWUvaj5LiaBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"780273a8b4c44bebdb7d100596534c9f23e49a0e7d684abd3fa515cb300e0995","last_reissued_at":"2026-07-05T02:54:50.495543Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T02:54:50.495543Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Perceptual Adversarial Robustness: Defense Against Unseen Threat Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Cassidy Laidlaw, Sahil Singla, Soheil Feizi","submitted_at":"2020-06-22T22:40:46Z","abstract_excerpt":"A key challenge in adversarial robustness is the lack of a precise mathematical characterization of human perception, used in the very definition of adversarial attacks that are imperceptible to human eyes. Most current attacks and defenses try to avoid this issue by considering restrictive adversarial threat models such as those bounded by $L_2$ or $L_\\infty$ distance, spatial perturbations, etc. However, models that are robust against any of these restrictive threat models are still fragile against other threat models. To resolve this issue, we propose adversarial training against the set of"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2006.12655","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2006.12655/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2006.12655","created_at":"2026-07-05T02:54:50.495608+00:00"},{"alias_kind":"arxiv_version","alias_value":"2006.12655v4","created_at":"2026-07-05T02:54:50.495608+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2006.12655","created_at":"2026-07-05T02:54:50.495608+00:00"},{"alias_kind":"pith_short_12","alias_value":"PABHHKFUYRF6","created_at":"2026-07-05T02:54:50.495608+00:00"},{"alias_kind":"pith_short_16","alias_value":"PABHHKFUYRF6XW35","created_at":"2026-07-05T02:54:50.495608+00:00"},{"alias_kind":"pith_short_8","alias_value":"PABHHKFU","created_at":"2026-07-05T02:54:50.495608+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":5,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.16720","citing_title":"Compositional Adversarial Training for Robust Visual Watermarking","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2605.12813","citing_title":"REALISTA: Realistic Latent Adversarial Attacks that Elicit LLM Hallucinations","ref_index":172,"is_internal_anchor":false},{"citing_arxiv_id":"2310.03684","citing_title":"SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks","ref_index":57,"is_internal_anchor":false},{"citing_arxiv_id":"2605.07690","citing_title":"Fortifying Time Series: DTW-Certified Robust Anomaly Detection","ref_index":32,"is_internal_anchor":false},{"citing_arxiv_id":"2604.16532","citing_title":"Beyond Attack Success Rate: A Multi-Metric Evaluation of Adversarial Transferability in Medical Imaging Models","ref_index":37,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/PABHHKFUYRF6XW35CACZMU2MT4","json":"https://pith.science/pith/PABHHKFUYRF6XW35CACZMU2MT4.json","graph_json":"https://pith.science/api/pith-number/PABHHKFUYRF6XW35CACZMU2MT4/graph.json","events_json":"https://pith.science/api/pith-number/PABHHKFUYRF6XW35CACZMU2MT4/events.json","paper":"https://pith.science/paper/PABHHKFU"},"agent_actions":{"view_html":"https://pith.science/pith/PABHHKFUYRF6XW35CACZMU2MT4","download_json":"https://pith.science/pith/PABHHKFUYRF6XW35CACZMU2MT4.json","view_paper":"https://pith.science/paper/PABHHKFU","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2006.12655&json=true","fetch_graph":"https://pith.science/api/pith-number/PABHHKFUYRF6XW35CACZMU2MT4/graph.json","fetch_events":"https://pith.science/api/pith-number/PABHHKFUYRF6XW35CACZMU2MT4/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/PABHHKFUYRF6XW35CACZMU2MT4/action/timestamp_anchor","attest_storage":"https://pith.science/pith/PABHHKFUYRF6XW35CACZMU2MT4/action/storage_attestation","attest_author":"https://pith.science/pith/PABHHKFUYRF6XW35CACZMU2MT4/action/author_attestation","sign_citation":"https://pith.science/pith/PABHHKFUYRF6XW35CACZMU2MT4/action/citation_signature","submit_replication":"https://pith.science/pith/PABHHKFUYRF6XW35CACZMU2MT4/action/replication_record"}},"created_at":"2026-07-05T02:54:50.495608+00:00","updated_at":"2026-07-05T02:54:50.495608+00:00"}