Pith. sign in

Paper Citation Record · LEDGER

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs

As of 16 August 2026, this Paper Citation Record lists 23 of 23 outbound references and 2 inbound Pith citation observations for arXiv:2505.18332.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2505.18332 v1

Coverage vector

measured 23 of 23 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T14:38:40.274729Z

measured 25 of 25 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-16T06:30:59.297886+00:00

measured 2 of 2 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-15T19:01:48.793889Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-06T19:45:53.232647Z

Reference resolution

23 of 23 outbound references displayed

  • verified exact0
  • verified fuzzy3
  • unresolved19
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 405bb342-b6ab-4809-b747-ea0c4bdf1960 · outbound

This paper cites Dominic Edelmann, Tamás F Móri, and Gábor J Székely.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs Dominic Edelmann, Tamás F Móri, and Gábor J Székely

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:37.803451Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:37.803451Z digest=sha256:568370acb7eea27c15e5f65c5cce3c87c24014edcb1c9d11f48708c66f726faf

Observation f90b11d6-7100-411b-96f5-46551fe6ad64 · outbound

This paper cites Kai Kugler, Simon Münker, Johannes Höhmann, and Achim Rettinger.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs Kai Kugler, Simon Münker, Johannes Höhmann, and Achim Rettinger

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:38.184531Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:38.184531Z digest=sha256:89a19ffbd27b7780ee58d02d54190968e91eead8c3a80b6a38b5a3d363ff3445

Observation e1b153f3-dcfb-4886-a998-338e1fd4d020 · outbound

This paper cites Sentence Embedding Leaks More Information than You Expect: Generative Embedding Inversion Attack to Recover the Whole Sentence.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs Sentence Embedding Leaks More Information than You Expect: Generative Embedding Inversion Attack to Recover the Whole Sentence

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:38.358259Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:38.358259Z digest=sha256:82a414b738e860d3511101f660f9d57d57aff4bcf031d49ce426035496a60d9a

Observation f3e2e271-3360-47be-86b0-cda2b71c51cc · outbound

This paper cites Nimbus: Secure and Efficient Two-Party Inference for Transformers.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs Nimbus: Secure and Efficient Two-Party Inference for Transformers

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:38.487443Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:38.487443Z digest=sha256:f2e22368d223041cf5f5268e7bfb7f27d0fc821bb85ecb4bbf47a183c3087630

Observation 5452b8ae-69ed-42d8-88b7-90ece172ad6c · outbound

This paper cites CENTAUR: Bridging the Impossible Trinity of Privacy, Efficiency, and Performance in Privacy-Preserving Transformer Inference.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs CENTAUR: Bridging the Impossible Trinity of Privacy, Efficiency, and Performance in Privacy-Preserving Transformer Inference

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:38.596035Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:38.596035Z digest=sha256:d552a18e2e7607d69c378aca46b01a38bd5eada39ee0087f905807a8d5f38221

Observation 25b075a5-ca98-4f95-a209-9c46046671a6 · outbound

This paper cites Guilherme Penedo, Hynek Kydlíˇcek, Loubna Ben allal, Anton Lozhkov, Margaret Mitchell, Colin Raffel, Leandro V on Werra, and Thomas Wolf.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs Guilherme Penedo, Hynek Kydlíˇcek, Loubna Ben allal, Anton Lozhkov, Margaret Mitchell, Colin Raffel, Leandro V on Werra, and Thomas Wolf

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T14:38:41.947472Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=pdf_text observed=2026-08-07T14:38:38.730685Z digest=sha256:189b9a2d59f379c21b3230c9de59bc7ff7ebb45cd7a802be0be3a252b66017f9

Observation a97d5fb2-cecf-4536-ae27-1ce8453ca5c6 · outbound

This paper cites The FineWeb Datasets: Decanting the Web for the Finest Text Data at Scale.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs The FineWeb Datasets: Decanting the Web for the Finest Text Data at Scale

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:38.867121Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:38.867121Z digest=sha256:73701a544b21dbcd76938041f85cf1ad3cac779fcd805c41bd09c8ab61845c98

Observation 929a1d1c-b476-4d16-a7e9-1d1afb04d445 · outbound

This paper cites Impacts of floating-point non-associativity on reproducibility for HPC and deep learning applications.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs Impacts of floating-point non-associativity on reproducibility for HPC and deep learning applications

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:38.943566Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:38.943566Z digest=sha256:3e0d92d15b7c31527d28c5d3a409d66e49d379b6a4bfefb53d76c53c01013690

Observation 050b391d-a856-4244-afc2-0ba3363dbee4 · outbound

This paper cites Gemma 2: Improving Open Language Models at a Practical Size.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs Gemma 2: Improving Open Language Models at a Practical Size

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:39.213094Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:39.213094Z digest=sha256:34233be599dd24f0a3d4268f7056dbf2097a71c9a6602b1d734faec9df5d8c98

Observation 9a5408b3-a5ba-4a16-880f-4a59dd712917 · outbound

This paper cites URLhttps://www.nature.com/articles/ s41591-023-02459-w.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs URLhttps://www.nature.com/articles/ s41591-023-02459-w

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:39.308441Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:39.308441Z digest=sha256:59915242b752ae59a5d039e13d7cbd5f877c8b17851c0962bcebdd01ee8f417c

Observation b318fd1f-c2be-4027-986a-080307085676 · outbound

This paper cites Information Leakage from Embedding in Large Language Models.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs Information Leakage from Embedding in Large Language Models

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:39.430162Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:39.430162Z digest=sha256:daf81db1a0cf5b011ba308044e1ee96a2bf9f396df312c8520e453474ccb8d3c

Observation 6cf0fa41-4653-4cd8-972e-bb45c3fbf5fa · outbound

This paper cites LiveBench: A Challenging, Contamination-Limited LLM Benchmark.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs LiveBench: A Challenging, Contamination-Limited LLM Benchmark

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:39.534397Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:39.534397Z digest=sha256:fb806ae4cbdb26fbbffce20476d8388248d1c0460622ca29bf231a92250fb519

Observation 6e0adb27-92b2-4168-becf-b61cb126c5b8 · outbound

This paper cites an unresolved cited work.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs Unresolved cited work

Reference 18

Resolution
unresolved
raw_fallback, observed 2026-08-07T14:38:41.694067Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=pdf_text observed=2026-08-07T14:38:39.653671Z digest=sha256:05489c3c9f7e291dfc1223f62528f47ab3b0854b64183d67bc204b93b7e81aff

Observation 330888a8-3dba-4f7f-892f-579af943c615 · outbound

This paper cites Secure Transformer Inference Protocol.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs Secure Transformer Inference Protocol

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:39.900830Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:39.900830Z digest=sha256:eaf7750190a22ddfd7490d86bf0c79f0907cbfd0901ea70616005401990a58e5

Observation 1dabbc83-2d3e-4d86-b13e-b26bf1efe134 · outbound

This paper cites Multilingual Machine Translation with Large Language Models: Empirical Results and Analysis.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs Multilingual Machine Translation with Large Language Models: Empirical Results and Analysis

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:40.028865Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:40.028865Z digest=sha256:45f3b9e15ddea335b473197d62e4b22615800ca80c40d6695cd1de1c976651f0

Observation eff3107f-0396-4048-af88-450eddb49230 · outbound

This paper cites Theorem 2.F or any δ >0, there exist random variables W, X, Y, Zsuch that Discorr(W, X)> Discorr(Y, Z), the pair(W, X)is notδ-reconstructible, and the pair(Y, Z)isδ-reconstructible.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs Theorem 2.F or any δ >0, there exist random variables W, X, Y, Zsuch that Discorr(W, X)> Discorr(Y, Z), the pair(W, X)is notδ-reconstructible, and the pair(Y, Z)isδ-reconstructible

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T14:38:41.376947Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=pdf_text observed=2026-08-07T14:38:40.140195Z digest=sha256:57a0061b12e27992d56d6ab314d7328942b0f6c96fe705ee3cff2234a7c4a759

Observation c63babae-7383-4e11-ab10-fb8c2e85a9cc · outbound

This paper cites an unresolved cited work.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs Unresolved cited work

Reference 23

Resolution
malformed identifier
raw_fallback, observed 2026-08-07T14:38:41.174748Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=pdf_text observed=2026-08-07T14:38:40.274729Z digest=sha256:112d04b74d37213eee0c4b358b23eb568a6fc67bb98b6f5bda538fb3d768239f

Observation 217ae278-409a-4d07-8c3e-89c7f9dc1258 · outbound

This paper cites Mu Yuan, Lan Zhang, and Xiang-Yang Li.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs Mu Yuan, Lan Zhang, and Xiang-Yang Li

Reference 1982

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:39.788862Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:39.788862Z digest=sha256:a83767fb59fa1ac14f9bfbd775c84f0f8be6425abe0e46805c30f426838832a3

Observation 024fa13c-e315-4233-bde3-47fe306704ee · outbound

This paper cites ISBN 0897912217.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs ISBN 0897912217

Reference 1987

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:37.953011Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:37.953011Z digest=sha256:df8589a9cb5ccbeb0b3d6944ec043d5362b3519b4916e173b00957dbd8a15247

Observation 4091a69d-26ae-4ade-8ac2-cfdbf4d6f9d3 · outbound

This paper cites ISBN 9781450370899.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs ISBN 9781450370899

Reference 2020

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:39.081987Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:39.081987Z digest=sha256:9bde9b84fc127b9e876140c8d11ac8a04037b64b0871c619af02802812007796

Observation bc9668f2-dcb5-465a-9d20-52d2ab5d015f · outbound

This paper cites Theodore W Anderson.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs Theodore W Anderson

Reference 2023

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:37.643481Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:37.643481Z digest=sha256:213c700dafcbbf9073cfc39637bfe17ad15efffed42570f563279eb7a6967b21

Observation 5b5acde4-26de-487e-a48c-f2c938fb5c45 · outbound

This paper cites The Llama 3 Herd of Models.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs The Llama 3 Herd of Models

Reference 2024

Resolution
unresolved
no resolver link, observed 2026-08-07T14:38:38.067869Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T14:38:38.067869Z digest=sha256:5d887ebf99c9b47f70e9e761bba98d26965430193bc057e507ac21a692c3b0a1

Observation d81059e1-18c2-4a00-89b7-394f4a7964f4 · outbound

This paper cites Ye Dong, Wen jie Lu, Yancheng Zheng, Haoqi Wu, Derun Zhao, Jin Tan, Zhicong Huang, Cheng Hong, Tao Wei, and Wenguang Chen.

An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs Ye Dong, Wen jie Lu, Yancheng Zheng, Haoqi Wu, Derun Zhao, Jin Tan, Zhicong Huang, Cheng Hong, Tao Wei, and Wenguang Chen

Reference 2025

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T14:38:42.175429Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=pdf_text observed=2026-08-07T14:38:37.714278Z digest=sha256:1b2e2933d4954807c30de0cfabd26f6b6dd4849729c8edcafe4cdb8f05c2032c

Pith citing papers

Observation 5e077ced-1f74-482f-bd16-4e8ec8fa5553 · inbound

Mechanistic Interpretability in the Presence of Architectural Obfuscation cites this paper.

Mechanistic Interpretability in the Presence of Architectural Obfuscation An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-15T19:01:48.793889Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T19:01:48.793889Z digest=sha256:e07656bfd78d44555d58c21ca203eb79c4ead7964d6c0258f1395b9decccf212

Observation 8025759c-1d9d-4b83-9e27-0aa6c46d9597 · inbound

Cascade: Token-Sharded Private LLM Inference cites this paper.

Cascade: Token-Sharded Private LLM Inference An Attack to Break Permutation-Based Private Third-Party Inference Schemes for LLMs

Reference 21

Resolution
verified exact
local_arxiv, observed 2026-08-06T19:45:53.239409Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-06T19:45:52.933522Z digest=sha256:bc98a178e3cf807f5138e5ef61ad86d61656acbc799db873896cb6b79b94e96e