{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:UKYZRPY7HDWQQCN3LUW3223O7I","short_pith_number":"pith:UKYZRPY7","canonical_record":{"source":{"id":"1902.01148","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-02-04T12:25:05Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"fa798eb656b1d79f2e3dab0763e7c3bf354b65fca0bf3df9ce9686540c4e7f5e","abstract_canon_sha256":"2d2d1c5621bd4869d478f63e294333cd713d1233b6ea2c0f91c8de0cf073fa09"},"schema_version":"1.0"},"canonical_sha256":"a2b198bf1f38ed0809bb5d2dbd6b6efa03b4a12a8443942aedd1c855bd79a8f3","source":{"kind":"arxiv","id":"1902.01148","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1902.01148","created_at":"2026-05-17T23:43:37Z"},{"alias_kind":"arxiv_version","alias_value":"1902.01148v2","created_at":"2026-05-17T23:43:37Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1902.01148","created_at":"2026-05-17T23:43:37Z"},{"alias_kind":"pith_short_12","alias_value":"UKYZRPY7HDWQ","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_16","alias_value":"UKYZRPY7HDWQQCN3","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_8","alias_value":"UKYZRPY7","created_at":"2026-05-18T12:33:30Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:UKYZRPY7HDWQQCN3LUW3223O7I","target":"record","payload":{"canonical_record":{"source":{"id":"1902.01148","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-02-04T12:25:05Z","cross_cats_sorted":["cs.CR","stat.ML"],"title_canon_sha256":"fa798eb656b1d79f2e3dab0763e7c3bf354b65fca0bf3df9ce9686540c4e7f5e","abstract_canon_sha256":"2d2d1c5621bd4869d478f63e294333cd713d1233b6ea2c0f91c8de0cf073fa09"},"schema_version":"1.0"},"canonical_sha256":"a2b198bf1f38ed0809bb5d2dbd6b6efa03b4a12a8443942aedd1c855bd79a8f3","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:43:37.119650Z","signature_b64":"xFxp8ZPKCXOVuuZy0FhKmcBIXuZ0W1iYy+lbPNuQgcMpuRUZej/XuhymkdHSBhYO5jtU+oTYao/fQemBHd2qCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a2b198bf1f38ed0809bb5d2dbd6b6efa03b4a12a8443942aedd1c855bd79a8f3","last_reissued_at":"2026-05-17T23:43:37.119138Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:43:37.119138Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1902.01148","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:43:37Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"gRmkwyT0bLqkEki16wLboHnBVuIbr0dY0XXy/uxRWgHancybLQoHBtp9j7Mzwu4GTn9E/cvzgVnzd9cXKsMcCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-19T23:24:58.830754Z"},"content_sha256":"e33d8c4b357852ff4aa1a3acc713cea56a1610d097f29b8f5662d9130e649ce1","schema_version":"1.0","event_id":"sha256:e33d8c4b357852ff4aa1a3acc713cea56a1610d097f29b8f5662d9130e649ce1"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:UKYZRPY7HDWQQCN3LUW3223O7I","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Theoretical evidence for adversarial robustness through randomization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","stat.ML"],"primary_cat":"cs.LG","authors_text":"Alexandre Araujo, C\\'edric Gouy-Pailler, Florian Yger, Hisashi Kashima, Jamal Atif, Laurent Meunier, Rafael Pinot","submitted_at":"2019-02-04T12:25:05Z","abstract_excerpt":"This paper investigates the theory of robustness against adversarial attacks. It focuses on the family of randomization techniques that consist in injecting noise in the network at inference time. These techniques have proven effective in many contexts, but lack theoretical arguments. We close this gap by presenting a theoretical analysis of these approaches, hence explaining why they perform well in practice. More precisely, we make two new contributions. The first one relates the randomization rate to robustness to adversarial attacks. This result applies for the general family of exponentia"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1902.01148","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:43:37Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8uX7JNVmL3pcgoXj2kSbmkSg30Z1Y59UoyXGMV3Do4Y65uuLMyMyv8OrlcmgBFxjVkYbLROtlIeOQRS4xeaWCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-19T23:24:58.831105Z"},"content_sha256":"c618f3e6fff5aba801d483e94e4f98bdebf9b673d218b926419613b525ad3cfa","schema_version":"1.0","event_id":"sha256:c618f3e6fff5aba801d483e94e4f98bdebf9b673d218b926419613b525ad3cfa"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/UKYZRPY7HDWQQCN3LUW3223O7I/bundle.json","state_url":"https://pith.science/pith/UKYZRPY7HDWQQCN3LUW3223O7I/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/UKYZRPY7HDWQQCN3LUW3223O7I/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-19T23:24:58Z","links":{"resolver":"https://pith.science/pith/UKYZRPY7HDWQQCN3LUW3223O7I","bundle":"https://pith.science/pith/UKYZRPY7HDWQQCN3LUW3223O7I/bundle.json","state":"https://pith.science/pith/UKYZRPY7HDWQQCN3LUW3223O7I/state.json","well_known_bundle":"https://pith.science/.well-known/pith/UKYZRPY7HDWQQCN3LUW3223O7I/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:UKYZRPY7HDWQQCN3LUW3223O7I","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"2d2d1c5621bd4869d478f63e294333cd713d1233b6ea2c0f91c8de0cf073fa09","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-02-04T12:25:05Z","title_canon_sha256":"fa798eb656b1d79f2e3dab0763e7c3bf354b65fca0bf3df9ce9686540c4e7f5e"},"schema_version":"1.0","source":{"id":"1902.01148","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1902.01148","created_at":"2026-05-17T23:43:37Z"},{"alias_kind":"arxiv_version","alias_value":"1902.01148v2","created_at":"2026-05-17T23:43:37Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1902.01148","created_at":"2026-05-17T23:43:37Z"},{"alias_kind":"pith_short_12","alias_value":"UKYZRPY7HDWQ","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_16","alias_value":"UKYZRPY7HDWQQCN3","created_at":"2026-05-18T12:33:30Z"},{"alias_kind":"pith_short_8","alias_value":"UKYZRPY7","created_at":"2026-05-18T12:33:30Z"}],"graph_snapshots":[{"event_id":"sha256:c618f3e6fff5aba801d483e94e4f98bdebf9b673d218b926419613b525ad3cfa","target":"graph","created_at":"2026-05-17T23:43:37Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"This paper investigates the theory of robustness against adversarial attacks. It focuses on the family of randomization techniques that consist in injecting noise in the network at inference time. These techniques have proven effective in many contexts, but lack theoretical arguments. We close this gap by presenting a theoretical analysis of these approaches, hence explaining why they perform well in practice. More precisely, we make two new contributions. The first one relates the randomization rate to robustness to adversarial attacks. This result applies for the general family of exponentia","authors_text":"Alexandre Araujo, C\\'edric Gouy-Pailler, Florian Yger, Hisashi Kashima, Jamal Atif, Laurent Meunier, Rafael Pinot","cross_cats":["cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-02-04T12:25:05Z","title":"Theoretical evidence for adversarial robustness through randomization"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1902.01148","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:e33d8c4b357852ff4aa1a3acc713cea56a1610d097f29b8f5662d9130e649ce1","target":"record","created_at":"2026-05-17T23:43:37Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"2d2d1c5621bd4869d478f63e294333cd713d1233b6ea2c0f91c8de0cf073fa09","cross_cats_sorted":["cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-02-04T12:25:05Z","title_canon_sha256":"fa798eb656b1d79f2e3dab0763e7c3bf354b65fca0bf3df9ce9686540c4e7f5e"},"schema_version":"1.0","source":{"id":"1902.01148","kind":"arxiv","version":2}},"canonical_sha256":"a2b198bf1f38ed0809bb5d2dbd6b6efa03b4a12a8443942aedd1c855bd79a8f3","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a2b198bf1f38ed0809bb5d2dbd6b6efa03b4a12a8443942aedd1c855bd79a8f3","first_computed_at":"2026-05-17T23:43:37.119138Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:43:37.119138Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"xFxp8ZPKCXOVuuZy0FhKmcBIXuZ0W1iYy+lbPNuQgcMpuRUZej/XuhymkdHSBhYO5jtU+oTYao/fQemBHd2qCA==","signature_status":"signed_v1","signed_at":"2026-05-17T23:43:37.119650Z","signed_message":"canonical_sha256_bytes"},"source_id":"1902.01148","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:e33d8c4b357852ff4aa1a3acc713cea56a1610d097f29b8f5662d9130e649ce1","sha256:c618f3e6fff5aba801d483e94e4f98bdebf9b673d218b926419613b525ad3cfa"],"state_sha256":"baa361f486b8dbf3ceba0df3f60720ce1f4acf77b63dcbe4a9e85a7bfa3ee99f"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"lzumkAQYVofgaL8+SX+39PGVWhxoP+YZeWDqMs830mhSfEN44LxRv58wcy33ZJfHJIPwnQqFiuuxnUayqvVwBg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-19T23:24:58.833047Z","bundle_sha256":"39d20a9ee74e4800f30fff7773b6e7fd4f9f6f11759aade4a88d4ebca5e562a2"}}