{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2016:6RJAHTB4QLEOLFF7UXCVQ2XBTI","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"6f90debb2027f9b771b0d00bc3e77172bbeb7c4bc97691478f727bafa6864817","cross_cats_sorted":["cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-09-09T20:39:20Z","title_canon_sha256":"22e7fb22e559f9fac634821de77bbfb20fcb5482adc28d1b93b54aedc6fde20b"},"schema_version":"1.0","source":{"id":"1609.02943","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1609.02943","created_at":"2026-05-18T01:03:26Z"},{"alias_kind":"arxiv_version","alias_value":"1609.02943v2","created_at":"2026-05-18T01:03:26Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1609.02943","created_at":"2026-05-18T01:03:26Z"},{"alias_kind":"pith_short_12","alias_value":"6RJAHTB4QLEO","created_at":"2026-05-18T12:30:01Z"},{"alias_kind":"pith_short_16","alias_value":"6RJAHTB4QLEOLFF7","created_at":"2026-05-18T12:30:01Z"},{"alias_kind":"pith_short_8","alias_value":"6RJAHTB4","created_at":"2026-05-18T12:30:01Z"}],"graph_snapshots":[{"event_id":"sha256:fbb907d4fcd32589cdac8533c5e4ef280542e524639c31b03854e3bc2b653b5d","target":"graph","created_at":"2026-05-18T01:03:26Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Machine learning (ML) models may be deemed confidential due to their sensitive training data, commercial value, or use in security applications. Increasingly often, confidential ML models are being deployed with publicly accessible query interfaces. ML-as-a-service (\"predictive analytics\") systems are an example: Some allow users to train models on potentially sensitive data and charge others for access on a pay-per-query basis.\n  The tension between model confidentiality and public access motivates our investigation of model extraction attacks. In such attacks, an adversary with black-box acc","authors_text":"Ari Juels, Fan Zhang, Florian Tram\\`er, Michael K. Reiter, Thomas Ristenpart","cross_cats":["cs.LG","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-09-09T20:39:20Z","title":"Stealing Machine Learning Models via Prediction APIs"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1609.02943","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:047131d8a6c8d034b4159d5b92918a8939cafacd8835db0656b57ba77015b541","target":"record","created_at":"2026-05-18T01:03:26Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"6f90debb2027f9b771b0d00bc3e77172bbeb7c4bc97691478f727bafa6864817","cross_cats_sorted":["cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-09-09T20:39:20Z","title_canon_sha256":"22e7fb22e559f9fac634821de77bbfb20fcb5482adc28d1b93b54aedc6fde20b"},"schema_version":"1.0","source":{"id":"1609.02943","kind":"arxiv","version":2}},"canonical_sha256":"f45203cc3c82c8e594bfa5c5586ae19a362e9b1b845c274032b7a0aa50a0dbbc","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"f45203cc3c82c8e594bfa5c5586ae19a362e9b1b845c274032b7a0aa50a0dbbc","first_computed_at":"2026-05-18T01:03:26.048902Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T01:03:26.048902Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"QnvTmphHnWGxtKca5vX37alBNgsMnI8liikroiLpyR0kHUOaXfGXB3Vak9uZJAcFfqar+pDSM1IwM0AIMknMDg==","signature_status":"signed_v1","signed_at":"2026-05-18T01:03:26.049446Z","signed_message":"canonical_sha256_bytes"},"source_id":"1609.02943","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:047131d8a6c8d034b4159d5b92918a8939cafacd8835db0656b57ba77015b541","sha256:fbb907d4fcd32589cdac8533c5e4ef280542e524639c31b03854e3bc2b653b5d"],"state_sha256":"bca8e0906a3c04c348ad62f82be2f29851740c33df90fc19abcf0852a74b8c9b"}