{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:VAOKE5KYRTMTFBMDNF7GUIRHJS","short_pith_number":"pith:VAOKE5KY","canonical_record":{"source":{"id":"2607.01194","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-07-01T17:26:24Z","cross_cats_sorted":[],"title_canon_sha256":"b86648386689313bbd74bc777bcc7c150a25757b10be0f8c8402fa4201f71fa1","abstract_canon_sha256":"ace22462c38eb969384d5520001e08979818040ab61a40f7e71f4a5b295202d8"},"schema_version":"1.0"},"canonical_sha256":"a81ca275588cd9328583697e6a22274c97aaaaa382c2780a5efb1538b770b449","source":{"kind":"arxiv","id":"2607.01194","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2607.01194","created_at":"2026-07-02T01:18:32Z"},{"alias_kind":"arxiv_version","alias_value":"2607.01194v1","created_at":"2026-07-02T01:18:32Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2607.01194","created_at":"2026-07-02T01:18:32Z"},{"alias_kind":"pith_short_12","alias_value":"VAOKE5KYRTMT","created_at":"2026-07-02T01:18:32Z"},{"alias_kind":"pith_short_16","alias_value":"VAOKE5KYRTMTFBMD","created_at":"2026-07-02T01:18:32Z"},{"alias_kind":"pith_short_8","alias_value":"VAOKE5KY","created_at":"2026-07-02T01:18:32Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:VAOKE5KYRTMTFBMDNF7GUIRHJS","target":"record","payload":{"canonical_record":{"source":{"id":"2607.01194","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-07-01T17:26:24Z","cross_cats_sorted":[],"title_canon_sha256":"b86648386689313bbd74bc777bcc7c150a25757b10be0f8c8402fa4201f71fa1","abstract_canon_sha256":"ace22462c38eb969384d5520001e08979818040ab61a40f7e71f4a5b295202d8"},"schema_version":"1.0"},"canonical_sha256":"a81ca275588cd9328583697e6a22274c97aaaaa382c2780a5efb1538b770b449","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-02T01:18:32.274255Z","signature_b64":"eF8OGoHIjMxK1aRt4V92JvjA78J/rntH6VA/p9BWATAARuzuV0T8I3O3xm8/PBP3SRcMWwfxIB+5Mmo1zG9MDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a81ca275588cd9328583697e6a22274c97aaaaa382c2780a5efb1538b770b449","last_reissued_at":"2026-07-02T01:18:32.273867Z","signature_status":"signed_v1","first_computed_at":"2026-07-02T01:18:32.273867Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2607.01194","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-02T01:18:32Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"WHUGFxekak34fusVcfFvX59LETG177g87EOLwZIyE9/JiMv1IBjWo7AsScudxFW1cVMQLFyS8A2aVzLie6hIDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-02T22:51:06.947880Z"},"content_sha256":"52e74be3481bd395955abc92de250b612063eee4881caf31f07329370782f5f0","schema_version":"1.0","event_id":"sha256:52e74be3481bd395955abc92de250b612063eee4881caf31f07329370782f5f0"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:VAOKE5KYRTMTFBMDNF7GUIRHJS","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Detecting Adversarial Evasion Attacks Against Autoencoder-Based Network Intrusion Detection Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Ashim Siwakoti, Niklas Bunzel","submitted_at":"2026-07-01T17:26:24Z","abstract_excerpt":"Evasion attacks deliberately manipulate input to an ML-based system to produce an incorrect prediction while the manipulated input still appears benign. The PANDA framework has demonstrated that adversarial examples developed for the vision domain can be transferred to the network domain by converting packet sequences into invertible grayscale images, enabling gradient-based attacks such as masked FGSM against autoencoder-based network intrusion detection systems (NIDS). These attacks manipulate the NIDS anomaly score without altering the underlying attack semantics, leaving defenders without "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2607.01194","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2607.01194/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-02T01:18:32Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"icTSborqqduXe8nUaOY1Awv67dy1fXXBLPjWUGWsYTt0JTgnx0RWH/UaemZDe/ZPUSFMIWEr7BbVAVieltrTBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-02T22:51:06.948261Z"},"content_sha256":"8ac8e7146d17b2c57c991dd55e8832cbf1b26fae1d63c0ff0f1b598c5a65ff0d","schema_version":"1.0","event_id":"sha256:8ac8e7146d17b2c57c991dd55e8832cbf1b26fae1d63c0ff0f1b598c5a65ff0d"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/VAOKE5KYRTMTFBMDNF7GUIRHJS/bundle.json","state_url":"https://pith.science/pith/VAOKE5KYRTMTFBMDNF7GUIRHJS/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/VAOKE5KYRTMTFBMDNF7GUIRHJS/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-02T22:51:06Z","links":{"resolver":"https://pith.science/pith/VAOKE5KYRTMTFBMDNF7GUIRHJS","bundle":"https://pith.science/pith/VAOKE5KYRTMTFBMDNF7GUIRHJS/bundle.json","state":"https://pith.science/pith/VAOKE5KYRTMTFBMDNF7GUIRHJS/state.json","well_known_bundle":"https://pith.science/.well-known/pith/VAOKE5KYRTMTFBMDNF7GUIRHJS/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:VAOKE5KYRTMTFBMDNF7GUIRHJS","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"ace22462c38eb969384d5520001e08979818040ab61a40f7e71f4a5b295202d8","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-07-01T17:26:24Z","title_canon_sha256":"b86648386689313bbd74bc777bcc7c150a25757b10be0f8c8402fa4201f71fa1"},"schema_version":"1.0","source":{"id":"2607.01194","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2607.01194","created_at":"2026-07-02T01:18:32Z"},{"alias_kind":"arxiv_version","alias_value":"2607.01194v1","created_at":"2026-07-02T01:18:32Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2607.01194","created_at":"2026-07-02T01:18:32Z"},{"alias_kind":"pith_short_12","alias_value":"VAOKE5KYRTMT","created_at":"2026-07-02T01:18:32Z"},{"alias_kind":"pith_short_16","alias_value":"VAOKE5KYRTMTFBMD","created_at":"2026-07-02T01:18:32Z"},{"alias_kind":"pith_short_8","alias_value":"VAOKE5KY","created_at":"2026-07-02T01:18:32Z"}],"graph_snapshots":[{"event_id":"sha256:8ac8e7146d17b2c57c991dd55e8832cbf1b26fae1d63c0ff0f1b598c5a65ff0d","target":"graph","created_at":"2026-07-02T01:18:32Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2607.01194/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Evasion attacks deliberately manipulate input to an ML-based system to produce an incorrect prediction while the manipulated input still appears benign. The PANDA framework has demonstrated that adversarial examples developed for the vision domain can be transferred to the network domain by converting packet sequences into invertible grayscale images, enabling gradient-based attacks such as masked FGSM against autoencoder-based network intrusion detection systems (NIDS). These attacks manipulate the NIDS anomaly score without altering the underlying attack semantics, leaving defenders without ","authors_text":"Ashim Siwakoti, Niklas Bunzel","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-07-01T17:26:24Z","title":"Detecting Adversarial Evasion Attacks Against Autoencoder-Based Network Intrusion Detection Systems"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2607.01194","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:52e74be3481bd395955abc92de250b612063eee4881caf31f07329370782f5f0","target":"record","created_at":"2026-07-02T01:18:32Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"ace22462c38eb969384d5520001e08979818040ab61a40f7e71f4a5b295202d8","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-07-01T17:26:24Z","title_canon_sha256":"b86648386689313bbd74bc777bcc7c150a25757b10be0f8c8402fa4201f71fa1"},"schema_version":"1.0","source":{"id":"2607.01194","kind":"arxiv","version":1}},"canonical_sha256":"a81ca275588cd9328583697e6a22274c97aaaaa382c2780a5efb1538b770b449","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a81ca275588cd9328583697e6a22274c97aaaaa382c2780a5efb1538b770b449","first_computed_at":"2026-07-02T01:18:32.273867Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-02T01:18:32.273867Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"eF8OGoHIjMxK1aRt4V92JvjA78J/rntH6VA/p9BWATAARuzuV0T8I3O3xm8/PBP3SRcMWwfxIB+5Mmo1zG9MDw==","signature_status":"signed_v1","signed_at":"2026-07-02T01:18:32.274255Z","signed_message":"canonical_sha256_bytes"},"source_id":"2607.01194","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:52e74be3481bd395955abc92de250b612063eee4881caf31f07329370782f5f0","sha256:8ac8e7146d17b2c57c991dd55e8832cbf1b26fae1d63c0ff0f1b598c5a65ff0d"],"state_sha256":"7e522aa31f9bb78ffe31f9c10935602a96f182c66a2b03d44bfde5ea8006aab4"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"/Sa18Uq6CQ4fj6TxA7S+EcuQnr39CMHONargLTbhSC7Wfp3e7PUYkkl5B/KBm8v85p7Qr1hNrVdbPqUofAC8DA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-02T22:51:06.950362Z","bundle_sha256":"d7e4ec6875eac88111d22fa5b2c1e1f2e001f3be84a2792191f3c2b3cfd4e342"}}