{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:T3IVZMKK6OEHYAWZ7WSKE7DYA7","short_pith_number":"pith:T3IVZMKK","canonical_record":{"source":{"id":"1901.03583","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-01-11T14:02:51Z","cross_cats_sorted":[],"title_canon_sha256":"193bf6b4f5bce675ad5301415e89ac35f376b8d8886172322235a7e8d994b98a","abstract_canon_sha256":"6d83b7969f19ee1faed0ac4b87a11fa6ca62375817a098269b0c1c6265fd80bd"},"schema_version":"1.0"},"canonical_sha256":"9ed15cb14af3887c02d9fda4a27c7807ee071ef4b7ca27c89b22bf119f5dab36","source":{"kind":"arxiv","id":"1901.03583","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1901.03583","created_at":"2026-05-17T23:55:38Z"},{"alias_kind":"arxiv_version","alias_value":"1901.03583v2","created_at":"2026-05-17T23:55:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1901.03583","created_at":"2026-05-17T23:55:38Z"},{"alias_kind":"pith_short_12","alias_value":"T3IVZMKK6OEH","created_at":"2026-05-18T12:33:27Z"},{"alias_kind":"pith_short_16","alias_value":"T3IVZMKK6OEHYAWZ","created_at":"2026-05-18T12:33:27Z"},{"alias_kind":"pith_short_8","alias_value":"T3IVZMKK","created_at":"2026-05-18T12:33:27Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:T3IVZMKK6OEHYAWZ7WSKE7DYA7","target":"record","payload":{"canonical_record":{"source":{"id":"1901.03583","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-01-11T14:02:51Z","cross_cats_sorted":[],"title_canon_sha256":"193bf6b4f5bce675ad5301415e89ac35f376b8d8886172322235a7e8d994b98a","abstract_canon_sha256":"6d83b7969f19ee1faed0ac4b87a11fa6ca62375817a098269b0c1c6265fd80bd"},"schema_version":"1.0"},"canonical_sha256":"9ed15cb14af3887c02d9fda4a27c7807ee071ef4b7ca27c89b22bf119f5dab36","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:55:38.112093Z","signature_b64":"Kw8nO3mLXj22IQMwbSPCGj9kFZOwZi32F4aWo1YV4Z8hEvFxRMJoNMoPsosjpwPRsTYW5bJpodfQrfVsyYkCCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9ed15cb14af3887c02d9fda4a27c7807ee071ef4b7ca27c89b22bf119f5dab36","last_reissued_at":"2026-05-17T23:55:38.111711Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:55:38.111711Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1901.03583","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:55:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ZNKOvDcncYFs0niI3huYQsfJFkHkJYMpdYg9dW/U705/4YonpCzPV6dp4D05CqmZINk13fEMOJPOLADdf8C5Cw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-22T00:50:47.376690Z"},"content_sha256":"2e4ceebb8d981e2674f564cbdc4c450ab8148ecfde785e39686ddb36e625941f","schema_version":"1.0","event_id":"sha256:2e4ceebb8d981e2674f564cbdc4c450ab8148ecfde785e39686ddb36e625941f"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:T3IVZMKK6OEHYAWZ7WSKE7DYA7","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Explaining Vulnerabilities of Deep Learning to Adversarial Malware Binaries","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Alessandro Armando, Battista Biggio, Fabio Roli, Giovanni Lagorio, Luca Demetrio","submitted_at":"2019-01-11T14:02:51Z","abstract_excerpt":"Recent work has shown that deep-learning algorithms for malware detection are also susceptible to adversarial examples, i.e., carefully-crafted perturbations to input malware that enable misleading classification. Although this has questioned their suitability for this task, it is not yet clear why such algorithms are easily fooled also in this particular application domain. In this work, we take a first step to tackle this issue by leveraging explainable machine-learning algorithms developed to interpret the black-box decisions of deep neural networks. In particular, we use an explainable tec"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1901.03583","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:55:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"oQ+KU1I+6qUewEn8R8J8YWkycaPn+DdEGT6NYiSD+OFuwkXLEfrcEEyCQ6MBKI1nlyigNqW/VWTHXvnoNcH0CQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-22T00:50:47.377028Z"},"content_sha256":"d9c6089e376d988a38631042842598f783617afd998716079b10828ef80d579f","schema_version":"1.0","event_id":"sha256:d9c6089e376d988a38631042842598f783617afd998716079b10828ef80d579f"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/T3IVZMKK6OEHYAWZ7WSKE7DYA7/bundle.json","state_url":"https://pith.science/pith/T3IVZMKK6OEHYAWZ7WSKE7DYA7/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/T3IVZMKK6OEHYAWZ7WSKE7DYA7/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-22T00:50:47Z","links":{"resolver":"https://pith.science/pith/T3IVZMKK6OEHYAWZ7WSKE7DYA7","bundle":"https://pith.science/pith/T3IVZMKK6OEHYAWZ7WSKE7DYA7/bundle.json","state":"https://pith.science/pith/T3IVZMKK6OEHYAWZ7WSKE7DYA7/state.json","well_known_bundle":"https://pith.science/.well-known/pith/T3IVZMKK6OEHYAWZ7WSKE7DYA7/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:T3IVZMKK6OEHYAWZ7WSKE7DYA7","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"6d83b7969f19ee1faed0ac4b87a11fa6ca62375817a098269b0c1c6265fd80bd","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-01-11T14:02:51Z","title_canon_sha256":"193bf6b4f5bce675ad5301415e89ac35f376b8d8886172322235a7e8d994b98a"},"schema_version":"1.0","source":{"id":"1901.03583","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1901.03583","created_at":"2026-05-17T23:55:38Z"},{"alias_kind":"arxiv_version","alias_value":"1901.03583v2","created_at":"2026-05-17T23:55:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1901.03583","created_at":"2026-05-17T23:55:38Z"},{"alias_kind":"pith_short_12","alias_value":"T3IVZMKK6OEH","created_at":"2026-05-18T12:33:27Z"},{"alias_kind":"pith_short_16","alias_value":"T3IVZMKK6OEHYAWZ","created_at":"2026-05-18T12:33:27Z"},{"alias_kind":"pith_short_8","alias_value":"T3IVZMKK","created_at":"2026-05-18T12:33:27Z"}],"graph_snapshots":[{"event_id":"sha256:d9c6089e376d988a38631042842598f783617afd998716079b10828ef80d579f","target":"graph","created_at":"2026-05-17T23:55:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Recent work has shown that deep-learning algorithms for malware detection are also susceptible to adversarial examples, i.e., carefully-crafted perturbations to input malware that enable misleading classification. Although this has questioned their suitability for this task, it is not yet clear why such algorithms are easily fooled also in this particular application domain. In this work, we take a first step to tackle this issue by leveraging explainable machine-learning algorithms developed to interpret the black-box decisions of deep neural networks. In particular, we use an explainable tec","authors_text":"Alessandro Armando, Battista Biggio, Fabio Roli, Giovanni Lagorio, Luca Demetrio","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-01-11T14:02:51Z","title":"Explaining Vulnerabilities of Deep Learning to Adversarial Malware Binaries"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1901.03583","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:2e4ceebb8d981e2674f564cbdc4c450ab8148ecfde785e39686ddb36e625941f","target":"record","created_at":"2026-05-17T23:55:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"6d83b7969f19ee1faed0ac4b87a11fa6ca62375817a098269b0c1c6265fd80bd","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-01-11T14:02:51Z","title_canon_sha256":"193bf6b4f5bce675ad5301415e89ac35f376b8d8886172322235a7e8d994b98a"},"schema_version":"1.0","source":{"id":"1901.03583","kind":"arxiv","version":2}},"canonical_sha256":"9ed15cb14af3887c02d9fda4a27c7807ee071ef4b7ca27c89b22bf119f5dab36","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"9ed15cb14af3887c02d9fda4a27c7807ee071ef4b7ca27c89b22bf119f5dab36","first_computed_at":"2026-05-17T23:55:38.111711Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:55:38.111711Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Kw8nO3mLXj22IQMwbSPCGj9kFZOwZi32F4aWo1YV4Z8hEvFxRMJoNMoPsosjpwPRsTYW5bJpodfQrfVsyYkCCw==","signature_status":"signed_v1","signed_at":"2026-05-17T23:55:38.112093Z","signed_message":"canonical_sha256_bytes"},"source_id":"1901.03583","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:2e4ceebb8d981e2674f564cbdc4c450ab8148ecfde785e39686ddb36e625941f","sha256:d9c6089e376d988a38631042842598f783617afd998716079b10828ef80d579f"],"state_sha256":"c571343eddd8ec5674c3d478692ce3184f76a793681147c2c28a28530b07aacc"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"WqCO7GRrv2LykBgF1P5qwDcRvOB/mwRUlfCyFQCPy713zAkLqeQ/ifOwcyPspzkkm+7YknzCYVXndMvJdNsAAw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-22T00:50:47.379336Z","bundle_sha256":"afc52daee666392a99e2dc6e9bf513a7839485fd6812a7e58326b9d49676d708"}}