{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:KEQIK4KERHG4OHQZVHYWNPVZAN","short_pith_number":"pith:KEQIK4KE","canonical_record":{"source":{"id":"2606.18312","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-16T10:24:40Z","cross_cats_sorted":["cs.DC","cs.LG"],"title_canon_sha256":"ccad9b670f4a60b425029be4acabd9a02c21721097f5fe4315ed716ec98e5245","abstract_canon_sha256":"433ed75b2fca99bf9136377c31ebf3c69ef007ba3edd73226a7599676ccdf7f7"},"schema_version":"1.0"},"canonical_sha256":"512085714489cdc71e19a9f166beb903599d8f97bf3bb24e7f2396fa6efe20f7","source":{"kind":"arxiv","id":"2606.18312","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.18312","created_at":"2026-06-19T16:10:57Z"},{"alias_kind":"arxiv_version","alias_value":"2606.18312v1","created_at":"2026-06-19T16:10:57Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.18312","created_at":"2026-06-19T16:10:57Z"},{"alias_kind":"pith_short_12","alias_value":"KEQIK4KERHG4","created_at":"2026-06-19T16:10:57Z"},{"alias_kind":"pith_short_16","alias_value":"KEQIK4KERHG4OHQZ","created_at":"2026-06-19T16:10:57Z"},{"alias_kind":"pith_short_8","alias_value":"KEQIK4KE","created_at":"2026-06-19T16:10:57Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:KEQIK4KERHG4OHQZVHYWNPVZAN","target":"record","payload":{"canonical_record":{"source":{"id":"2606.18312","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-16T10:24:40Z","cross_cats_sorted":["cs.DC","cs.LG"],"title_canon_sha256":"ccad9b670f4a60b425029be4acabd9a02c21721097f5fe4315ed716ec98e5245","abstract_canon_sha256":"433ed75b2fca99bf9136377c31ebf3c69ef007ba3edd73226a7599676ccdf7f7"},"schema_version":"1.0"},"canonical_sha256":"512085714489cdc71e19a9f166beb903599d8f97bf3bb24e7f2396fa6efe20f7","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-19T16:10:57.654334Z","signature_b64":"xirvWeTA3XgomD01YwGQeSA2lh+I3NkX+ZXbyLdMHJiHJ3aRrDreWmUPBp1elQJrLu44v4wHhPnBBoaWSxuCCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"512085714489cdc71e19a9f166beb903599d8f97bf3bb24e7f2396fa6efe20f7","last_reissued_at":"2026-06-19T16:10:57.653970Z","signature_status":"signed_v1","first_computed_at":"2026-06-19T16:10:57.653970Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.18312","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-19T16:10:57Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"hmLlMTT+74PiO3nHCCvnrqHhBkV1iN5BptoBj8Hdv44YEljWoHxJ8MNZpZMOjzyS0zrlXCKvprglAR7nxszEDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T22:28:46.987076Z"},"content_sha256":"195c1d83b4f9c130408d3583bda0c4a6aac1cc5fa99236cc38ecce5a887aefaf","schema_version":"1.0","event_id":"sha256:195c1d83b4f9c130408d3583bda0c4a6aac1cc5fa99236cc38ecce5a887aefaf"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:KEQIK4KERHG4OHQZVHYWNPVZAN","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"TIGER: Inverting Transformer Gradients via Embedding-Subspace Distance Optimization","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.DC","cs.LG"],"primary_cat":"cs.CR","authors_text":"Dimitar I. Dimitrov, Ivo Petrov, Martin Vechev, William Kalikman","submitted_at":"2026-06-16T10:24:40Z","abstract_excerpt":"Federated learning allows multiple clients to jointly train a shared model by sending gradient updates to a central server while keeping raw inputs local. However, prior gradient inversion attacks show that these updates can reveal enough information to reconstruct client inputs. Existing attacks on transformers either optimize dummy inputs to match the true client updates, which is costly and unstable for modern models, or exploit the low rank of attention gradients to identify a subspace containing the true layer embeddings, followed by a discrete membership test for candidate tokens. Howeve"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.18312","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.18312/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-19T16:10:57Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8MQyF6kVwZXC+PO/fibHAdCYK4iJsfvjvTC7JMbtcKwDyt6WlIJovWiqYICNK+swynGA+UdFxNTvWJd2yO25DA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T22:28:46.987477Z"},"content_sha256":"94a266afb35e8c9b4ad9d6006a8241c80b2a7a7016ea52723caab9f797332f6f","schema_version":"1.0","event_id":"sha256:94a266afb35e8c9b4ad9d6006a8241c80b2a7a7016ea52723caab9f797332f6f"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/KEQIK4KERHG4OHQZVHYWNPVZAN/bundle.json","state_url":"https://pith.science/pith/KEQIK4KERHG4OHQZVHYWNPVZAN/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/KEQIK4KERHG4OHQZVHYWNPVZAN/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-30T22:28:46Z","links":{"resolver":"https://pith.science/pith/KEQIK4KERHG4OHQZVHYWNPVZAN","bundle":"https://pith.science/pith/KEQIK4KERHG4OHQZVHYWNPVZAN/bundle.json","state":"https://pith.science/pith/KEQIK4KERHG4OHQZVHYWNPVZAN/state.json","well_known_bundle":"https://pith.science/.well-known/pith/KEQIK4KERHG4OHQZVHYWNPVZAN/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:KEQIK4KERHG4OHQZVHYWNPVZAN","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"433ed75b2fca99bf9136377c31ebf3c69ef007ba3edd73226a7599676ccdf7f7","cross_cats_sorted":["cs.DC","cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-16T10:24:40Z","title_canon_sha256":"ccad9b670f4a60b425029be4acabd9a02c21721097f5fe4315ed716ec98e5245"},"schema_version":"1.0","source":{"id":"2606.18312","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.18312","created_at":"2026-06-19T16:10:57Z"},{"alias_kind":"arxiv_version","alias_value":"2606.18312v1","created_at":"2026-06-19T16:10:57Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.18312","created_at":"2026-06-19T16:10:57Z"},{"alias_kind":"pith_short_12","alias_value":"KEQIK4KERHG4","created_at":"2026-06-19T16:10:57Z"},{"alias_kind":"pith_short_16","alias_value":"KEQIK4KERHG4OHQZ","created_at":"2026-06-19T16:10:57Z"},{"alias_kind":"pith_short_8","alias_value":"KEQIK4KE","created_at":"2026-06-19T16:10:57Z"}],"graph_snapshots":[{"event_id":"sha256:94a266afb35e8c9b4ad9d6006a8241c80b2a7a7016ea52723caab9f797332f6f","target":"graph","created_at":"2026-06-19T16:10:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.18312/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Federated learning allows multiple clients to jointly train a shared model by sending gradient updates to a central server while keeping raw inputs local. However, prior gradient inversion attacks show that these updates can reveal enough information to reconstruct client inputs. Existing attacks on transformers either optimize dummy inputs to match the true client updates, which is costly and unstable for modern models, or exploit the low rank of attention gradients to identify a subspace containing the true layer embeddings, followed by a discrete membership test for candidate tokens. Howeve","authors_text":"Dimitar I. Dimitrov, Ivo Petrov, Martin Vechev, William Kalikman","cross_cats":["cs.DC","cs.LG"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-16T10:24:40Z","title":"TIGER: Inverting Transformer Gradients via Embedding-Subspace Distance Optimization"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.18312","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:195c1d83b4f9c130408d3583bda0c4a6aac1cc5fa99236cc38ecce5a887aefaf","target":"record","created_at":"2026-06-19T16:10:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"433ed75b2fca99bf9136377c31ebf3c69ef007ba3edd73226a7599676ccdf7f7","cross_cats_sorted":["cs.DC","cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-16T10:24:40Z","title_canon_sha256":"ccad9b670f4a60b425029be4acabd9a02c21721097f5fe4315ed716ec98e5245"},"schema_version":"1.0","source":{"id":"2606.18312","kind":"arxiv","version":1}},"canonical_sha256":"512085714489cdc71e19a9f166beb903599d8f97bf3bb24e7f2396fa6efe20f7","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"512085714489cdc71e19a9f166beb903599d8f97bf3bb24e7f2396fa6efe20f7","first_computed_at":"2026-06-19T16:10:57.653970Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-19T16:10:57.653970Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"xirvWeTA3XgomD01YwGQeSA2lh+I3NkX+ZXbyLdMHJiHJ3aRrDreWmUPBp1elQJrLu44v4wHhPnBBoaWSxuCCw==","signature_status":"signed_v1","signed_at":"2026-06-19T16:10:57.654334Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.18312","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:195c1d83b4f9c130408d3583bda0c4a6aac1cc5fa99236cc38ecce5a887aefaf","sha256:94a266afb35e8c9b4ad9d6006a8241c80b2a7a7016ea52723caab9f797332f6f"],"state_sha256":"9b0340066b52e79822d13140f9b39cd0f3064ee518642a822cbc8be043ede430"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"bO6q8zeQfBH9j3elqHYofil4QYptimz/cL934r5ECC4zpXmgYW+yszLF6Xl6wd8vs3hY1OyktB9uC2PzuKTZCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-30T22:28:46.989627Z","bundle_sha256":"81af288c3020a66229931b67fb44e53e592c6b8b25f68f0beee2087e40de29c2"}}