{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:TBJ2ZCRNXXSJF6W5FP7J6LCVFL","short_pith_number":"pith:TBJ2ZCRN","canonical_record":{"source":{"id":"1904.00344","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.MM","submitted_at":"2019-03-31T06:04:50Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"f989eed8a95db381d162502576f7796fe871096e7f69e7b916380fb48bef1ced","abstract_canon_sha256":"a9512c541e175b79256bcd2792084f3c77842327cc0842e907d433824139aa41"},"schema_version":"1.0"},"canonical_sha256":"9853ac8a2dbde492fadd2bfe9f2c552ad74c32b7731bcb2f1e5f099315b08bcd","source":{"kind":"arxiv","id":"1904.00344","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1904.00344","created_at":"2026-05-17T23:49:48Z"},{"alias_kind":"arxiv_version","alias_value":"1904.00344v1","created_at":"2026-05-17T23:49:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1904.00344","created_at":"2026-05-17T23:49:48Z"},{"alias_kind":"pith_short_12","alias_value":"TBJ2ZCRNXXSJ","created_at":"2026-05-18T12:33:27Z"},{"alias_kind":"pith_short_16","alias_value":"TBJ2ZCRNXXSJF6W5","created_at":"2026-05-18T12:33:27Z"},{"alias_kind":"pith_short_8","alias_value":"TBJ2ZCRN","created_at":"2026-05-18T12:33:27Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:TBJ2ZCRNXXSJF6W5FP7J6LCVFL","target":"record","payload":{"canonical_record":{"source":{"id":"1904.00344","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.MM","submitted_at":"2019-03-31T06:04:50Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"f989eed8a95db381d162502576f7796fe871096e7f69e7b916380fb48bef1ced","abstract_canon_sha256":"a9512c541e175b79256bcd2792084f3c77842327cc0842e907d433824139aa41"},"schema_version":"1.0"},"canonical_sha256":"9853ac8a2dbde492fadd2bfe9f2c552ad74c32b7731bcb2f1e5f099315b08bcd","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:49:48.671139Z","signature_b64":"v01oLU/Eba1ljQvchrcsfjEXPijXYxJn3YqPQ3dVl5gMIlbwaEzbF7qyUQN309vtrRz8oFzEhKiEm2E9crhLCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9853ac8a2dbde492fadd2bfe9f2c552ad74c32b7731bcb2f1e5f099315b08bcd","last_reissued_at":"2026-05-17T23:49:48.670657Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:49:48.670657Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1904.00344","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:49:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"WoiBpKGrdAHz2AXvyN21ScKTM9QtIA3DohHS7a5lBfwVX6w8VVeCgequDYIp9bwMZJfKVnHTTXFa64M5HN/NDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T04:50:48.198173Z"},"content_sha256":"e1f5d8491dc47b833a44f0b876f21fda2aa476a10f169321aa4aff64afeab0f2","schema_version":"1.0","event_id":"sha256:e1f5d8491dc47b833a44f0b876f21fda2aa476a10f169321aa4aff64afeab0f2"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:TBJ2ZCRNXXSJF6W5FP7J6LCVFL","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"BlackMarks: Blackbox Multibit Watermarking for Deep Neural Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.MM","authors_text":"Bita Darvish Rouhani, Farinaz Koushanfar, Huili Chen","submitted_at":"2019-03-31T06:04:50Z","abstract_excerpt":"Deep Neural Networks have created a paradigm shift in our ability to comprehend raw data in various important fields ranging from computer vision and natural language processing to intelligence warfare and healthcare. While DNNs are increasingly deployed either in a white-box setting where the model internal is publicly known, or a black-box setting where only the model outputs are known, a practical concern is protecting the models against Intellectual Property (IP) infringement. We propose BlackMarks, the first end-to-end multi-bit watermarking framework that is applicable in the black-box s"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1904.00344","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:49:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"3ogGwK459hrTFCJkMrtG5/TWcSMXKHKXS6+EhSGZeJp3jeLeJsLmIGV0ibJol5p3RwNJyEOA3KW68fwd4DQEBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T04:50:48.198536Z"},"content_sha256":"fe0273979e3e1cc2cae2d976be6c4feee3831f4b4359e5190adb4ee78de8a262","schema_version":"1.0","event_id":"sha256:fe0273979e3e1cc2cae2d976be6c4feee3831f4b4359e5190adb4ee78de8a262"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/TBJ2ZCRNXXSJF6W5FP7J6LCVFL/bundle.json","state_url":"https://pith.science/pith/TBJ2ZCRNXXSJF6W5FP7J6LCVFL/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/TBJ2ZCRNXXSJF6W5FP7J6LCVFL/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-30T04:50:48Z","links":{"resolver":"https://pith.science/pith/TBJ2ZCRNXXSJF6W5FP7J6LCVFL","bundle":"https://pith.science/pith/TBJ2ZCRNXXSJF6W5FP7J6LCVFL/bundle.json","state":"https://pith.science/pith/TBJ2ZCRNXXSJF6W5FP7J6LCVFL/state.json","well_known_bundle":"https://pith.science/.well-known/pith/TBJ2ZCRNXXSJF6W5FP7J6LCVFL/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:TBJ2ZCRNXXSJF6W5FP7J6LCVFL","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"a9512c541e175b79256bcd2792084f3c77842327cc0842e907d433824139aa41","cross_cats_sorted":["cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.MM","submitted_at":"2019-03-31T06:04:50Z","title_canon_sha256":"f989eed8a95db381d162502576f7796fe871096e7f69e7b916380fb48bef1ced"},"schema_version":"1.0","source":{"id":"1904.00344","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1904.00344","created_at":"2026-05-17T23:49:48Z"},{"alias_kind":"arxiv_version","alias_value":"1904.00344v1","created_at":"2026-05-17T23:49:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1904.00344","created_at":"2026-05-17T23:49:48Z"},{"alias_kind":"pith_short_12","alias_value":"TBJ2ZCRNXXSJ","created_at":"2026-05-18T12:33:27Z"},{"alias_kind":"pith_short_16","alias_value":"TBJ2ZCRNXXSJF6W5","created_at":"2026-05-18T12:33:27Z"},{"alias_kind":"pith_short_8","alias_value":"TBJ2ZCRN","created_at":"2026-05-18T12:33:27Z"}],"graph_snapshots":[{"event_id":"sha256:fe0273979e3e1cc2cae2d976be6c4feee3831f4b4359e5190adb4ee78de8a262","target":"graph","created_at":"2026-05-17T23:49:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Deep Neural Networks have created a paradigm shift in our ability to comprehend raw data in various important fields ranging from computer vision and natural language processing to intelligence warfare and healthcare. While DNNs are increasingly deployed either in a white-box setting where the model internal is publicly known, or a black-box setting where only the model outputs are known, a practical concern is protecting the models against Intellectual Property (IP) infringement. We propose BlackMarks, the first end-to-end multi-bit watermarking framework that is applicable in the black-box s","authors_text":"Bita Darvish Rouhani, Farinaz Koushanfar, Huili Chen","cross_cats":["cs.CR"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.MM","submitted_at":"2019-03-31T06:04:50Z","title":"BlackMarks: Blackbox Multibit Watermarking for Deep Neural Networks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1904.00344","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:e1f5d8491dc47b833a44f0b876f21fda2aa476a10f169321aa4aff64afeab0f2","target":"record","created_at":"2026-05-17T23:49:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"a9512c541e175b79256bcd2792084f3c77842327cc0842e907d433824139aa41","cross_cats_sorted":["cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.MM","submitted_at":"2019-03-31T06:04:50Z","title_canon_sha256":"f989eed8a95db381d162502576f7796fe871096e7f69e7b916380fb48bef1ced"},"schema_version":"1.0","source":{"id":"1904.00344","kind":"arxiv","version":1}},"canonical_sha256":"9853ac8a2dbde492fadd2bfe9f2c552ad74c32b7731bcb2f1e5f099315b08bcd","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"9853ac8a2dbde492fadd2bfe9f2c552ad74c32b7731bcb2f1e5f099315b08bcd","first_computed_at":"2026-05-17T23:49:48.670657Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:49:48.670657Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"v01oLU/Eba1ljQvchrcsfjEXPijXYxJn3YqPQ3dVl5gMIlbwaEzbF7qyUQN309vtrRz8oFzEhKiEm2E9crhLCA==","signature_status":"signed_v1","signed_at":"2026-05-17T23:49:48.671139Z","signed_message":"canonical_sha256_bytes"},"source_id":"1904.00344","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:e1f5d8491dc47b833a44f0b876f21fda2aa476a10f169321aa4aff64afeab0f2","sha256:fe0273979e3e1cc2cae2d976be6c4feee3831f4b4359e5190adb4ee78de8a262"],"state_sha256":"877789fb08a4b1eb138525ec7e65dfb8aaf28310067b7fc62f83afeb2ae9b3c8"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"xWR+p6zEycvZpzHj7K1omZFoMAAFbAyPWaoJVPBRskiZsfLn9ib3rtilvzJYOxlpXB2D/Fs5OEAo/LLsbOZ4DQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-30T04:50:48.200327Z","bundle_sha256":"6c5fe0efacbbc13f755bebef3052185986402891c4df01de2fc009cd9070185f"}}