{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:KUDWUASOGU3HSQIM3OTAZ4GLYP","short_pith_number":"pith:KUDWUASO","canonical_record":{"source":{"id":"1807.05852","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-07-16T13:35:30Z","cross_cats_sorted":["cs.CR","cs.LG"],"title_canon_sha256":"a14a74714804f7469485d7907342d5f91b844aed7243eda9992f57c16d68fbef","abstract_canon_sha256":"a546f1eab7a526605f7a452ba8d43df709a9a72e78d9c51f734b8341a1b2269f"},"schema_version":"1.0"},"canonical_sha256":"55076a024e353679410cdba60cf0cbc3ee9d36170c8017220c26984bc1b6e5b5","source":{"kind":"arxiv","id":"1807.05852","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1807.05852","created_at":"2026-05-18T00:10:42Z"},{"alias_kind":"arxiv_version","alias_value":"1807.05852v1","created_at":"2026-05-18T00:10:42Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1807.05852","created_at":"2026-05-18T00:10:42Z"},{"alias_kind":"pith_short_12","alias_value":"KUDWUASOGU3H","created_at":"2026-05-18T12:32:33Z"},{"alias_kind":"pith_short_16","alias_value":"KUDWUASOGU3HSQIM","created_at":"2026-05-18T12:32:33Z"},{"alias_kind":"pith_short_8","alias_value":"KUDWUASO","created_at":"2026-05-18T12:32:33Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:KUDWUASOGU3HSQIM3OTAZ4GLYP","target":"record","payload":{"canonical_record":{"source":{"id":"1807.05852","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-07-16T13:35:30Z","cross_cats_sorted":["cs.CR","cs.LG"],"title_canon_sha256":"a14a74714804f7469485d7907342d5f91b844aed7243eda9992f57c16d68fbef","abstract_canon_sha256":"a546f1eab7a526605f7a452ba8d43df709a9a72e78d9c51f734b8341a1b2269f"},"schema_version":"1.0"},"canonical_sha256":"55076a024e353679410cdba60cf0cbc3ee9d36170c8017220c26984bc1b6e5b5","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:10:42.407734Z","signature_b64":"q0UQXR8uCx1n3z0EIeBwkItDZzf9uGIMMzygWVK3QMtd41Ff50jkAean3fNBtUCq2FNQTF5cRSX3lLQfji2OAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"55076a024e353679410cdba60cf0cbc3ee9d36170c8017220c26984bc1b6e5b5","last_reissued_at":"2026-05-18T00:10:42.407094Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:10:42.407094Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1807.05852","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:10:42Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"J0pBAd0vEK7lF09CyZdq3SHtyaQteiHe1Crsf/68XzwcZxLpZd4KoKrriWneo6MHd1P1gNU0FUqJWe+udJM7Cw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-05T12:10:44.340229Z"},"content_sha256":"7547f14bf9f6452855ed4ba836a7d4deae29bbc0b05e417fc6b5403a94b78d0c","schema_version":"1.0","event_id":"sha256:7547f14bf9f6452855ed4ba836a7d4deae29bbc0b05e417fc6b5403a94b78d0c"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:KUDWUASOGU3HSQIM3OTAZ4GLYP","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Machine Learning with Membership Privacy using Adversarial Regularization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.LG"],"primary_cat":"stat.ML","authors_text":"Amir Houmansadr, Milad Nasr, Reza Shokri","submitted_at":"2018-07-16T13:35:30Z","abstract_excerpt":"Machine learning models leak information about the datasets on which they are trained. An adversary can build an algorithm to trace the individual members of a model's training dataset. As a fundamental inference attack, he aims to distinguish between data points that were part of the model's training set and any other data points from the same distribution. This is known as the tracing (and also membership inference) attack. In this paper, we focus on such attacks against black-box models, where the adversary can only observe the output of the model, but not its parameters. This is the curren"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1807.05852","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:10:42Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"uVsCAHNl4/4ZqFGWNHc2I4efe+yZxJLt9da1c9jcn7QOsQJ0MPpL1m4K4OD5AzaToQsjNdONSdg7ENAOpRCqAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-05T12:10:44.340599Z"},"content_sha256":"d3df6114c72381e2b37df29a3314a79084b65c8ace782ac39c6651ebe9fc22b9","schema_version":"1.0","event_id":"sha256:d3df6114c72381e2b37df29a3314a79084b65c8ace782ac39c6651ebe9fc22b9"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/KUDWUASOGU3HSQIM3OTAZ4GLYP/bundle.json","state_url":"https://pith.science/pith/KUDWUASOGU3HSQIM3OTAZ4GLYP/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/KUDWUASOGU3HSQIM3OTAZ4GLYP/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-05T12:10:44Z","links":{"resolver":"https://pith.science/pith/KUDWUASOGU3HSQIM3OTAZ4GLYP","bundle":"https://pith.science/pith/KUDWUASOGU3HSQIM3OTAZ4GLYP/bundle.json","state":"https://pith.science/pith/KUDWUASOGU3HSQIM3OTAZ4GLYP/state.json","well_known_bundle":"https://pith.science/.well-known/pith/KUDWUASOGU3HSQIM3OTAZ4GLYP/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:KUDWUASOGU3HSQIM3OTAZ4GLYP","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"a546f1eab7a526605f7a452ba8d43df709a9a72e78d9c51f734b8341a1b2269f","cross_cats_sorted":["cs.CR","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-07-16T13:35:30Z","title_canon_sha256":"a14a74714804f7469485d7907342d5f91b844aed7243eda9992f57c16d68fbef"},"schema_version":"1.0","source":{"id":"1807.05852","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1807.05852","created_at":"2026-05-18T00:10:42Z"},{"alias_kind":"arxiv_version","alias_value":"1807.05852v1","created_at":"2026-05-18T00:10:42Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1807.05852","created_at":"2026-05-18T00:10:42Z"},{"alias_kind":"pith_short_12","alias_value":"KUDWUASOGU3H","created_at":"2026-05-18T12:32:33Z"},{"alias_kind":"pith_short_16","alias_value":"KUDWUASOGU3HSQIM","created_at":"2026-05-18T12:32:33Z"},{"alias_kind":"pith_short_8","alias_value":"KUDWUASO","created_at":"2026-05-18T12:32:33Z"}],"graph_snapshots":[{"event_id":"sha256:d3df6114c72381e2b37df29a3314a79084b65c8ace782ac39c6651ebe9fc22b9","target":"graph","created_at":"2026-05-18T00:10:42Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Machine learning models leak information about the datasets on which they are trained. An adversary can build an algorithm to trace the individual members of a model's training dataset. As a fundamental inference attack, he aims to distinguish between data points that were part of the model's training set and any other data points from the same distribution. This is known as the tracing (and also membership inference) attack. In this paper, we focus on such attacks against black-box models, where the adversary can only observe the output of the model, but not its parameters. This is the curren","authors_text":"Amir Houmansadr, Milad Nasr, Reza Shokri","cross_cats":["cs.CR","cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-07-16T13:35:30Z","title":"Machine Learning with Membership Privacy using Adversarial Regularization"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1807.05852","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:7547f14bf9f6452855ed4ba836a7d4deae29bbc0b05e417fc6b5403a94b78d0c","target":"record","created_at":"2026-05-18T00:10:42Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"a546f1eab7a526605f7a452ba8d43df709a9a72e78d9c51f734b8341a1b2269f","cross_cats_sorted":["cs.CR","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-07-16T13:35:30Z","title_canon_sha256":"a14a74714804f7469485d7907342d5f91b844aed7243eda9992f57c16d68fbef"},"schema_version":"1.0","source":{"id":"1807.05852","kind":"arxiv","version":1}},"canonical_sha256":"55076a024e353679410cdba60cf0cbc3ee9d36170c8017220c26984bc1b6e5b5","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"55076a024e353679410cdba60cf0cbc3ee9d36170c8017220c26984bc1b6e5b5","first_computed_at":"2026-05-18T00:10:42.407094Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:10:42.407094Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"q0UQXR8uCx1n3z0EIeBwkItDZzf9uGIMMzygWVK3QMtd41Ff50jkAean3fNBtUCq2FNQTF5cRSX3lLQfji2OAA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:10:42.407734Z","signed_message":"canonical_sha256_bytes"},"source_id":"1807.05852","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:7547f14bf9f6452855ed4ba836a7d4deae29bbc0b05e417fc6b5403a94b78d0c","sha256:d3df6114c72381e2b37df29a3314a79084b65c8ace782ac39c6651ebe9fc22b9"],"state_sha256":"7925ad34d81a64308ccf98ef51165de3c30859b8d451833d2dd12471a2ddf9d4"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"38JQ0cqQAen5mo/4Uq+SZsUE4jZxPPhA8o4kV6roqbMmeCzwqwFW8+x54ixDjDb0KmVl62IlHP4u25ZoA02+Dw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-05T12:10:44.342602Z","bundle_sha256":"0ddbd5d2482b4001a9b718ac2b5ef9836740ea4ac0233d094257386bcb27e1dd"}}