{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2016:YQGAVUNE5P4WQJJUQ3ADIFVG5A","short_pith_number":"pith:YQGAVUNE","canonical_record":{"source":{"id":"1612.00155","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.NE","submitted_at":"2016-12-01T05:59:57Z","cross_cats_sorted":["cs.CV","cs.LG"],"title_canon_sha256":"60d25ea85780f7a93da2ef62c3450b5918d44e45dc3d99bce7933f203f47ed24","abstract_canon_sha256":"fb4138974da39df785bf915988acc365f131d64981e755b1f68d2b2207a5d8e4"},"schema_version":"1.0"},"canonical_sha256":"c40c0ad1a4ebf968253486c03416a6e81edd451e703d58e315ceba60efe09d9d","source":{"kind":"arxiv","id":"1612.00155","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1612.00155","created_at":"2026-05-18T00:56:05Z"},{"alias_kind":"arxiv_version","alias_value":"1612.00155v1","created_at":"2026-05-18T00:56:05Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1612.00155","created_at":"2026-05-18T00:56:05Z"},{"alias_kind":"pith_short_12","alias_value":"YQGAVUNE5P4W","created_at":"2026-05-18T12:30:53Z"},{"alias_kind":"pith_short_16","alias_value":"YQGAVUNE5P4WQJJU","created_at":"2026-05-18T12:30:53Z"},{"alias_kind":"pith_short_8","alias_value":"YQGAVUNE","created_at":"2026-05-18T12:30:53Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2016:YQGAVUNE5P4WQJJUQ3ADIFVG5A","target":"record","payload":{"canonical_record":{"source":{"id":"1612.00155","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.NE","submitted_at":"2016-12-01T05:59:57Z","cross_cats_sorted":["cs.CV","cs.LG"],"title_canon_sha256":"60d25ea85780f7a93da2ef62c3450b5918d44e45dc3d99bce7933f203f47ed24","abstract_canon_sha256":"fb4138974da39df785bf915988acc365f131d64981e755b1f68d2b2207a5d8e4"},"schema_version":"1.0"},"canonical_sha256":"c40c0ad1a4ebf968253486c03416a6e81edd451e703d58e315ceba60efe09d9d","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:56:05.894065Z","signature_b64":"bQqg2fVqcqnmMDj3sxgvTjmZyj3wxPNfZFg6Doxh1IbpPvi8nzehEAoAKf011LhZNWOmKqb1lA9I7IjU6XrgAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c40c0ad1a4ebf968253486c03416a6e81edd451e703d58e315ceba60efe09d9d","last_reissued_at":"2026-05-18T00:56:05.893435Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:56:05.893435Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1612.00155","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:56:05Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"lWxf19ee5K8hw1slHxUTWEs74LrAHxiv5oDAngFG8GeMsBBCwKA2oPYAZ6q8P1zXSradFJAZ24z1puWyXSz8DA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T16:39:53.647019Z"},"content_sha256":"341adabea366a2eb244b363425b778691e1b58a39d3f600164b3496ac7bdb9f2","schema_version":"1.0","event_id":"sha256:341adabea366a2eb244b363425b778691e1b58a39d3f600164b3496ac7bdb9f2"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2016:YQGAVUNE5P4WQJJUQ3ADIFVG5A","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Adversarial Images for Variational Autoencoders","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV","cs.LG"],"primary_cat":"cs.NE","authors_text":"Eduardo Valle, Julia Tavares, Pedro Tabacof","submitted_at":"2016-12-01T05:59:57Z","abstract_excerpt":"We investigate adversarial attacks for autoencoders. We propose a procedure that distorts the input image to mislead the autoencoder in reconstructing a completely different target image. We attack the internal latent representations, attempting to make the adversarial input produce an internal representation as similar as possible as the target's. We find that autoencoders are much more robust to the attack than classifiers: while some examples have tolerably small input distortion, and reasonable similarity to the target image, there is a quasi-linear trade-off between those aims. We report "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1612.00155","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:56:05Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"YY6JOS9mP/ZIbPWIE4gQXjirZ48h2De6gKWuIER6DzPQxGz9gQWDRrfNdvmGgSKJYpI7EqvEZI89q2YEdKsWBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T16:39:53.647388Z"},"content_sha256":"7add2a158f0cc8845a3d1f9271fc041f23b2fb87494e5f58bfb40ba2554d4543","schema_version":"1.0","event_id":"sha256:7add2a158f0cc8845a3d1f9271fc041f23b2fb87494e5f58bfb40ba2554d4543"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/YQGAVUNE5P4WQJJUQ3ADIFVG5A/bundle.json","state_url":"https://pith.science/pith/YQGAVUNE5P4WQJJUQ3ADIFVG5A/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/YQGAVUNE5P4WQJJUQ3ADIFVG5A/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-03T16:39:53Z","links":{"resolver":"https://pith.science/pith/YQGAVUNE5P4WQJJUQ3ADIFVG5A","bundle":"https://pith.science/pith/YQGAVUNE5P4WQJJUQ3ADIFVG5A/bundle.json","state":"https://pith.science/pith/YQGAVUNE5P4WQJJUQ3ADIFVG5A/state.json","well_known_bundle":"https://pith.science/.well-known/pith/YQGAVUNE5P4WQJJUQ3ADIFVG5A/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2016:YQGAVUNE5P4WQJJUQ3ADIFVG5A","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"fb4138974da39df785bf915988acc365f131d64981e755b1f68d2b2207a5d8e4","cross_cats_sorted":["cs.CV","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.NE","submitted_at":"2016-12-01T05:59:57Z","title_canon_sha256":"60d25ea85780f7a93da2ef62c3450b5918d44e45dc3d99bce7933f203f47ed24"},"schema_version":"1.0","source":{"id":"1612.00155","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1612.00155","created_at":"2026-05-18T00:56:05Z"},{"alias_kind":"arxiv_version","alias_value":"1612.00155v1","created_at":"2026-05-18T00:56:05Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1612.00155","created_at":"2026-05-18T00:56:05Z"},{"alias_kind":"pith_short_12","alias_value":"YQGAVUNE5P4W","created_at":"2026-05-18T12:30:53Z"},{"alias_kind":"pith_short_16","alias_value":"YQGAVUNE5P4WQJJU","created_at":"2026-05-18T12:30:53Z"},{"alias_kind":"pith_short_8","alias_value":"YQGAVUNE","created_at":"2026-05-18T12:30:53Z"}],"graph_snapshots":[{"event_id":"sha256:7add2a158f0cc8845a3d1f9271fc041f23b2fb87494e5f58bfb40ba2554d4543","target":"graph","created_at":"2026-05-18T00:56:05Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We investigate adversarial attacks for autoencoders. We propose a procedure that distorts the input image to mislead the autoencoder in reconstructing a completely different target image. We attack the internal latent representations, attempting to make the adversarial input produce an internal representation as similar as possible as the target's. We find that autoencoders are much more robust to the attack than classifiers: while some examples have tolerably small input distortion, and reasonable similarity to the target image, there is a quasi-linear trade-off between those aims. We report ","authors_text":"Eduardo Valle, Julia Tavares, Pedro Tabacof","cross_cats":["cs.CV","cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.NE","submitted_at":"2016-12-01T05:59:57Z","title":"Adversarial Images for Variational Autoencoders"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1612.00155","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:341adabea366a2eb244b363425b778691e1b58a39d3f600164b3496ac7bdb9f2","target":"record","created_at":"2026-05-18T00:56:05Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"fb4138974da39df785bf915988acc365f131d64981e755b1f68d2b2207a5d8e4","cross_cats_sorted":["cs.CV","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.NE","submitted_at":"2016-12-01T05:59:57Z","title_canon_sha256":"60d25ea85780f7a93da2ef62c3450b5918d44e45dc3d99bce7933f203f47ed24"},"schema_version":"1.0","source":{"id":"1612.00155","kind":"arxiv","version":1}},"canonical_sha256":"c40c0ad1a4ebf968253486c03416a6e81edd451e703d58e315ceba60efe09d9d","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"c40c0ad1a4ebf968253486c03416a6e81edd451e703d58e315ceba60efe09d9d","first_computed_at":"2026-05-18T00:56:05.893435Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:56:05.893435Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"bQqg2fVqcqnmMDj3sxgvTjmZyj3wxPNfZFg6Doxh1IbpPvi8nzehEAoAKf011LhZNWOmKqb1lA9I7IjU6XrgAQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:56:05.894065Z","signed_message":"canonical_sha256_bytes"},"source_id":"1612.00155","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:341adabea366a2eb244b363425b778691e1b58a39d3f600164b3496ac7bdb9f2","sha256:7add2a158f0cc8845a3d1f9271fc041f23b2fb87494e5f58bfb40ba2554d4543"],"state_sha256":"cc58de0f20fa7b88623ce107718d6145192d60adcd64c4cd0a396dbdccf386aa"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"YflJVgwq7LYogsuM/wbV5lSrY6koD20iTYyCFxo4dUYQHpSwS/1MZ2jsUflyWxjoyZ8ZAxkb51T9iH0aRkLLDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-03T16:39:53.649370Z","bundle_sha256":"fa94343b4b0ac7c9e2bacf5ac977b4e6d10c3460bb1d5eb1de94c8c847e06cef"}}