{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:K6UIH52O5ZUZ64YOFYPQXSLE55","short_pith_number":"pith:K6UIH52O","canonical_record":{"source":{"id":"2606.17464","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-06-16T03:26:15Z","cross_cats_sorted":[],"title_canon_sha256":"5cdf5b83197cd00fea52c2da65055bf9a351b85a01ce6939d7653a0bbc121a1a","abstract_canon_sha256":"d3f47a556204fa050f532f8ae5a1fdf5824addb38e4952bc1674e1d6f5dd79b2"},"schema_version":"1.0"},"canonical_sha256":"57a883f74eee699f730e2e1f0bc964ef58dd9c303634e152d4d7549a5e4e8526","source":{"kind":"arxiv","id":"2606.17464","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.17464","created_at":"2026-06-19T16:10:13Z"},{"alias_kind":"arxiv_version","alias_value":"2606.17464v1","created_at":"2026-06-19T16:10:13Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.17464","created_at":"2026-06-19T16:10:13Z"},{"alias_kind":"pith_short_12","alias_value":"K6UIH52O5ZUZ","created_at":"2026-06-19T16:10:13Z"},{"alias_kind":"pith_short_16","alias_value":"K6UIH52O5ZUZ64YO","created_at":"2026-06-19T16:10:13Z"},{"alias_kind":"pith_short_8","alias_value":"K6UIH52O","created_at":"2026-06-19T16:10:13Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:K6UIH52O5ZUZ64YOFYPQXSLE55","target":"record","payload":{"canonical_record":{"source":{"id":"2606.17464","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-06-16T03:26:15Z","cross_cats_sorted":[],"title_canon_sha256":"5cdf5b83197cd00fea52c2da65055bf9a351b85a01ce6939d7653a0bbc121a1a","abstract_canon_sha256":"d3f47a556204fa050f532f8ae5a1fdf5824addb38e4952bc1674e1d6f5dd79b2"},"schema_version":"1.0"},"canonical_sha256":"57a883f74eee699f730e2e1f0bc964ef58dd9c303634e152d4d7549a5e4e8526","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-19T16:10:13.705646Z","signature_b64":"OhtvtHNKqUfQ9y0g1o8Zokt8wwKyQYxicjgHXwiw+3Uz3XT1KLKLMCLvIFvCBp9LSC6mODGyg/xABAfTr6COAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"57a883f74eee699f730e2e1f0bc964ef58dd9c303634e152d4d7549a5e4e8526","last_reissued_at":"2026-06-19T16:10:13.705243Z","signature_status":"signed_v1","first_computed_at":"2026-06-19T16:10:13.705243Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.17464","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-19T16:10:13Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"4d0ZlbWMvjg6/9ugwChfeV7XKDzymFLH0FDUMyKvi4U4v3S6Z5trQPvWisK3CzVAazRz3twrLW+UnYdNHZP7Cg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-27T12:53:16.645361Z"},"content_sha256":"fcc459108bcf8a8836221c04cfb5188ad52d0539b193e8479d8e0f44f571cc3f","schema_version":"1.0","event_id":"sha256:fcc459108bcf8a8836221c04cfb5188ad52d0539b193e8479d8e0f44f571cc3f"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:K6UIH52O5ZUZ64YOFYPQXSLE55","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"CheckMIABench: Firm Foundations For Membership Inference Attacks on Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Jason Wang, Jeffrey G. Wang, Marvin Li, Seth Neel","submitted_at":"2026-06-16T03:26:15Z","abstract_excerpt":"Membership inference attacks (MIAs) are a canonical way to assess a machine learning model's privacy properties. Although several attempts have been made to evaluate MIAs on language models, the extant literature has suffered numerous difficulties in constructing clean evaluations to test new techniques. In particular, subtle distribution shifts between member and non-member sets can undermine the statistical validity of MIAs; recent work has underscored this by showing that \"blind\" methods with no access to the underlying model can perform far better than published methods on the same benchma"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.17464","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.17464/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-19T16:10:13Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"7N5oOzVbrQYQnmaziX4ayjSvtSHK3UAnnRDEMfvjrUnHl/hxw35OR4Koc82/12YhwFPbiBD35HSjrK5btzUvBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-27T12:53:16.645791Z"},"content_sha256":"682b64072c6b7498fcf72d670d41f4a99161513801f93bf16101753430842861","schema_version":"1.0","event_id":"sha256:682b64072c6b7498fcf72d670d41f4a99161513801f93bf16101753430842861"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/K6UIH52O5ZUZ64YOFYPQXSLE55/bundle.json","state_url":"https://pith.science/pith/K6UIH52O5ZUZ64YOFYPQXSLE55/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/K6UIH52O5ZUZ64YOFYPQXSLE55/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-27T12:53:16Z","links":{"resolver":"https://pith.science/pith/K6UIH52O5ZUZ64YOFYPQXSLE55","bundle":"https://pith.science/pith/K6UIH52O5ZUZ64YOFYPQXSLE55/bundle.json","state":"https://pith.science/pith/K6UIH52O5ZUZ64YOFYPQXSLE55/state.json","well_known_bundle":"https://pith.science/.well-known/pith/K6UIH52O5ZUZ64YOFYPQXSLE55/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:K6UIH52O5ZUZ64YOFYPQXSLE55","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"d3f47a556204fa050f532f8ae5a1fdf5824addb38e4952bc1674e1d6f5dd79b2","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-06-16T03:26:15Z","title_canon_sha256":"5cdf5b83197cd00fea52c2da65055bf9a351b85a01ce6939d7653a0bbc121a1a"},"schema_version":"1.0","source":{"id":"2606.17464","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.17464","created_at":"2026-06-19T16:10:13Z"},{"alias_kind":"arxiv_version","alias_value":"2606.17464v1","created_at":"2026-06-19T16:10:13Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.17464","created_at":"2026-06-19T16:10:13Z"},{"alias_kind":"pith_short_12","alias_value":"K6UIH52O5ZUZ","created_at":"2026-06-19T16:10:13Z"},{"alias_kind":"pith_short_16","alias_value":"K6UIH52O5ZUZ64YO","created_at":"2026-06-19T16:10:13Z"},{"alias_kind":"pith_short_8","alias_value":"K6UIH52O","created_at":"2026-06-19T16:10:13Z"}],"graph_snapshots":[{"event_id":"sha256:682b64072c6b7498fcf72d670d41f4a99161513801f93bf16101753430842861","target":"graph","created_at":"2026-06-19T16:10:13Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.17464/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Membership inference attacks (MIAs) are a canonical way to assess a machine learning model's privacy properties. Although several attempts have been made to evaluate MIAs on language models, the extant literature has suffered numerous difficulties in constructing clean evaluations to test new techniques. In particular, subtle distribution shifts between member and non-member sets can undermine the statistical validity of MIAs; recent work has underscored this by showing that \"blind\" methods with no access to the underlying model can perform far better than published methods on the same benchma","authors_text":"Jason Wang, Jeffrey G. Wang, Marvin Li, Seth Neel","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-06-16T03:26:15Z","title":"CheckMIABench: Firm Foundations For Membership Inference Attacks on Language Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.17464","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:fcc459108bcf8a8836221c04cfb5188ad52d0539b193e8479d8e0f44f571cc3f","target":"record","created_at":"2026-06-19T16:10:13Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"d3f47a556204fa050f532f8ae5a1fdf5824addb38e4952bc1674e1d6f5dd79b2","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-06-16T03:26:15Z","title_canon_sha256":"5cdf5b83197cd00fea52c2da65055bf9a351b85a01ce6939d7653a0bbc121a1a"},"schema_version":"1.0","source":{"id":"2606.17464","kind":"arxiv","version":1}},"canonical_sha256":"57a883f74eee699f730e2e1f0bc964ef58dd9c303634e152d4d7549a5e4e8526","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"57a883f74eee699f730e2e1f0bc964ef58dd9c303634e152d4d7549a5e4e8526","first_computed_at":"2026-06-19T16:10:13.705243Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-19T16:10:13.705243Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"OhtvtHNKqUfQ9y0g1o8Zokt8wwKyQYxicjgHXwiw+3Uz3XT1KLKLMCLvIFvCBp9LSC6mODGyg/xABAfTr6COAg==","signature_status":"signed_v1","signed_at":"2026-06-19T16:10:13.705646Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.17464","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:fcc459108bcf8a8836221c04cfb5188ad52d0539b193e8479d8e0f44f571cc3f","sha256:682b64072c6b7498fcf72d670d41f4a99161513801f93bf16101753430842861"],"state_sha256":"9822312e442535b105fafbcb34009210dbeffc1258f606cea09d5d30107242b9"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"aP1dU4kiy0TVyK4A7KZEDwjeksqlK12UO1HqeREv9TGpTgBxkC57Ju1dvid4l7/y4sEX6wHi7hNJFORwimxkDg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-27T12:53:16.647696Z","bundle_sha256":"580d3431351a208dbbec12ce0efe3c5e460599d0edb41ae736ad072b6995370d"}}