{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:YEBJHSTMEGVUJPH32PX2VEVRNW","short_pith_number":"pith:YEBJHSTM","canonical_record":{"source":{"id":"1906.01444","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-06-02T18:20:36Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"d17e623250d7d68d4f3ef27f44b7b383505f33fd0c061e16e2906e8d2b390146","abstract_canon_sha256":"507ac88030379692dde039f461bab13b163e6b996e95f7f5bdf62ac06218637a"},"schema_version":"1.0"},"canonical_sha256":"c10293ca6c21ab44bcfbd3efaa92b16db199c7ca7561300089b6110bc14605b5","source":{"kind":"arxiv","id":"1906.01444","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1906.01444","created_at":"2026-05-17T23:44:16Z"},{"alias_kind":"arxiv_version","alias_value":"1906.01444v1","created_at":"2026-05-17T23:44:16Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1906.01444","created_at":"2026-05-17T23:44:16Z"},{"alias_kind":"pith_short_12","alias_value":"YEBJHSTMEGVU","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_16","alias_value":"YEBJHSTMEGVUJPH3","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_8","alias_value":"YEBJHSTM","created_at":"2026-05-18T12:33:33Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:YEBJHSTMEGVUJPH32PX2VEVRNW","target":"record","payload":{"canonical_record":{"source":{"id":"1906.01444","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-06-02T18:20:36Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"d17e623250d7d68d4f3ef27f44b7b383505f33fd0c061e16e2906e8d2b390146","abstract_canon_sha256":"507ac88030379692dde039f461bab13b163e6b996e95f7f5bdf62ac06218637a"},"schema_version":"1.0"},"canonical_sha256":"c10293ca6c21ab44bcfbd3efaa92b16db199c7ca7561300089b6110bc14605b5","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:44:16.586244Z","signature_b64":"9l4zyqEXHKpzZ/aDHFUaZAELw03lt00rMeO/r4+vgVe8bxvm5BpnCZ442lkdFkBtqaYST0LbDz/tzxNp2uXmBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c10293ca6c21ab44bcfbd3efaa92b16db199c7ca7561300089b6110bc14605b5","last_reissued_at":"2026-05-17T23:44:16.585670Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:44:16.585670Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1906.01444","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:44:16Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Z6QloAl80MhjVeZIbhi2lis2CFbmwY6Ynk0NqnKxntvdAUeLxEKud719qbMvFo8r4caDFE6uZkd97112c6YNDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-29T15:10:54.798128Z"},"content_sha256":"574181b5c40c898ba3bd704cdbe177838b62d79a1849ffbf0d0ffcb9388e2805","schema_version":"1.0","event_id":"sha256:574181b5c40c898ba3bd704cdbe177838b62d79a1849ffbf0d0ffcb9388e2805"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:YEBJHSTMEGVUJPH32PX2VEVRNW","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Heterogeneous Gaussian Mechanism: Preserving Differential Privacy in Deep Learning with Provable Robustness","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Dejing Dou, Minh Vu, My T. Thai, NHatHai Phan, Ruoming Jin, Xintao Wu, Yang Liu","submitted_at":"2019-06-02T18:20:36Z","abstract_excerpt":"In this paper, we propose a novel Heterogeneous Gaussian Mechanism (HGM) to preserve differential privacy in deep neural networks, with provable robustness against adversarial examples. We first relax the constraint of the privacy budget in the traditional Gaussian Mechanism from (0, 1] to (0, \\infty), with a new bound of the noise scale to preserve differential privacy. The noise in our mechanism can be arbitrarily redistributed, offering a distinctive ability to address the trade-off between model utility and privacy loss. To derive provable robustness, our HGM is applied to inject Gaussian "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1906.01444","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:44:16Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"7cbKL2yrw/4YPIz2+0Z6H6hqaYMngpP4sbMI3pVJIcexsZGbSNxh72dlqV/x1YCok2Qz+oPrOqY+o9b2ZvQQBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-29T15:10:54.798538Z"},"content_sha256":"024573473a80f5c5b1451168a10f3bbb865c4a55c841c9ca54926aebc79c0c4a","schema_version":"1.0","event_id":"sha256:024573473a80f5c5b1451168a10f3bbb865c4a55c841c9ca54926aebc79c0c4a"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/YEBJHSTMEGVUJPH32PX2VEVRNW/bundle.json","state_url":"https://pith.science/pith/YEBJHSTMEGVUJPH32PX2VEVRNW/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/YEBJHSTMEGVUJPH32PX2VEVRNW/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-29T15:10:54Z","links":{"resolver":"https://pith.science/pith/YEBJHSTMEGVUJPH32PX2VEVRNW","bundle":"https://pith.science/pith/YEBJHSTMEGVUJPH32PX2VEVRNW/bundle.json","state":"https://pith.science/pith/YEBJHSTMEGVUJPH32PX2VEVRNW/state.json","well_known_bundle":"https://pith.science/.well-known/pith/YEBJHSTMEGVUJPH32PX2VEVRNW/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:YEBJHSTMEGVUJPH32PX2VEVRNW","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"507ac88030379692dde039f461bab13b163e6b996e95f7f5bdf62ac06218637a","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-06-02T18:20:36Z","title_canon_sha256":"d17e623250d7d68d4f3ef27f44b7b383505f33fd0c061e16e2906e8d2b390146"},"schema_version":"1.0","source":{"id":"1906.01444","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1906.01444","created_at":"2026-05-17T23:44:16Z"},{"alias_kind":"arxiv_version","alias_value":"1906.01444v1","created_at":"2026-05-17T23:44:16Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1906.01444","created_at":"2026-05-17T23:44:16Z"},{"alias_kind":"pith_short_12","alias_value":"YEBJHSTMEGVU","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_16","alias_value":"YEBJHSTMEGVUJPH3","created_at":"2026-05-18T12:33:33Z"},{"alias_kind":"pith_short_8","alias_value":"YEBJHSTM","created_at":"2026-05-18T12:33:33Z"}],"graph_snapshots":[{"event_id":"sha256:024573473a80f5c5b1451168a10f3bbb865c4a55c841c9ca54926aebc79c0c4a","target":"graph","created_at":"2026-05-17T23:44:16Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"In this paper, we propose a novel Heterogeneous Gaussian Mechanism (HGM) to preserve differential privacy in deep neural networks, with provable robustness against adversarial examples. We first relax the constraint of the privacy budget in the traditional Gaussian Mechanism from (0, 1] to (0, \\infty), with a new bound of the noise scale to preserve differential privacy. The noise in our mechanism can be arbitrarily redistributed, offering a distinctive ability to address the trade-off between model utility and privacy loss. To derive provable robustness, our HGM is applied to inject Gaussian ","authors_text":"Dejing Dou, Minh Vu, My T. Thai, NHatHai Phan, Ruoming Jin, Xintao Wu, Yang Liu","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-06-02T18:20:36Z","title":"Heterogeneous Gaussian Mechanism: Preserving Differential Privacy in Deep Learning with Provable Robustness"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1906.01444","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:574181b5c40c898ba3bd704cdbe177838b62d79a1849ffbf0d0ffcb9388e2805","target":"record","created_at":"2026-05-17T23:44:16Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"507ac88030379692dde039f461bab13b163e6b996e95f7f5bdf62ac06218637a","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-06-02T18:20:36Z","title_canon_sha256":"d17e623250d7d68d4f3ef27f44b7b383505f33fd0c061e16e2906e8d2b390146"},"schema_version":"1.0","source":{"id":"1906.01444","kind":"arxiv","version":1}},"canonical_sha256":"c10293ca6c21ab44bcfbd3efaa92b16db199c7ca7561300089b6110bc14605b5","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"c10293ca6c21ab44bcfbd3efaa92b16db199c7ca7561300089b6110bc14605b5","first_computed_at":"2026-05-17T23:44:16.585670Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:44:16.585670Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"9l4zyqEXHKpzZ/aDHFUaZAELw03lt00rMeO/r4+vgVe8bxvm5BpnCZ442lkdFkBtqaYST0LbDz/tzxNp2uXmBw==","signature_status":"signed_v1","signed_at":"2026-05-17T23:44:16.586244Z","signed_message":"canonical_sha256_bytes"},"source_id":"1906.01444","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:574181b5c40c898ba3bd704cdbe177838b62d79a1849ffbf0d0ffcb9388e2805","sha256:024573473a80f5c5b1451168a10f3bbb865c4a55c841c9ca54926aebc79c0c4a"],"state_sha256":"43676aa1dcb0b6b4493d9073066d2bf31f2db8b12260acc277cf357e872dba45"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"NPFQ+BEVvXdH1ni/CFMzCrcUZXCtPnHxC5/SkFwZ4FTUSEnRrdGXAe/Y1uyO6XRMuovv0YIB1XK/oKOzYLqaCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-29T15:10:54.801873Z","bundle_sha256":"338a2b82b44ea153e09f7a6e6bf038186d3708c506f7aaa2d22bf571f8aaf0ad"}}