{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:P24YTHCOA6BY5IBEMAAO33X5XO","short_pith_number":"pith:P24YTHCO","canonical_record":{"source":{"id":"2606.11592","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T02:36:26Z","cross_cats_sorted":[],"title_canon_sha256":"8b0861453ba781a3398bac8b23c4801e1bc1dc8794569390077ba5997372bdbd","abstract_canon_sha256":"51fd58c993a3a9061f5fa1fcfdfa469f569a900d01fbee95792d94bf33b27275"},"schema_version":"1.0"},"canonical_sha256":"7eb9899c4e07838ea0246000edeefdbba73ec3fc98057ae1f6f13baa059c144d","source":{"kind":"arxiv","id":"2606.11592","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.11592","created_at":"2026-06-11T01:09:57Z"},{"alias_kind":"arxiv_version","alias_value":"2606.11592v1","created_at":"2026-06-11T01:09:57Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.11592","created_at":"2026-06-11T01:09:57Z"},{"alias_kind":"pith_short_12","alias_value":"P24YTHCOA6BY","created_at":"2026-06-11T01:09:57Z"},{"alias_kind":"pith_short_16","alias_value":"P24YTHCOA6BY5IBE","created_at":"2026-06-11T01:09:57Z"},{"alias_kind":"pith_short_8","alias_value":"P24YTHCO","created_at":"2026-06-11T01:09:57Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:P24YTHCOA6BY5IBEMAAO33X5XO","target":"record","payload":{"canonical_record":{"source":{"id":"2606.11592","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T02:36:26Z","cross_cats_sorted":[],"title_canon_sha256":"8b0861453ba781a3398bac8b23c4801e1bc1dc8794569390077ba5997372bdbd","abstract_canon_sha256":"51fd58c993a3a9061f5fa1fcfdfa469f569a900d01fbee95792d94bf33b27275"},"schema_version":"1.0"},"canonical_sha256":"7eb9899c4e07838ea0246000edeefdbba73ec3fc98057ae1f6f13baa059c144d","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-11T01:09:57.965464Z","signature_b64":"cFiJ9jCn5gZqhokJgif7IsFqbRRG7egwwobIyLChU/FM5r4Pork3TLPyfBAE9FfzS6Vg9obn7i7YF2+/hWfWCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"7eb9899c4e07838ea0246000edeefdbba73ec3fc98057ae1f6f13baa059c144d","last_reissued_at":"2026-06-11T01:09:57.964618Z","signature_status":"signed_v1","first_computed_at":"2026-06-11T01:09:57.964618Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.11592","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-11T01:09:57Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"N6k4RHlh4oF3FV9JAQqgv768dkX18HemxgQmkhds7+RvSLYZnxjXsDpS9IadJQWfpPwhGvoSTTQ6IeVPZPEEBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-23T08:02:59.410449Z"},"content_sha256":"55bc2573b1f5ac53a326dd882f36c9969485d7bd5fd51f1928983b6ff9720e2e","schema_version":"1.0","event_id":"sha256:55bc2573b1f5ac53a326dd882f36c9969485d7bd5fd51f1928983b6ff9720e2e"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:P24YTHCOA6BY5IBEMAAO33X5XO","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Defense Against Prompt Inversion Attacks: An Information-Theoretic Approach for LLM Collaborative Inference","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Hossein Khalili, Nader Sehatbakhsh, Sayedeh Leila Noorbakhsh","submitted_at":"2026-06-10T02:36:26Z","abstract_excerpt":"Collaborative edge-cloud inference enables resource-constrained devices to leverage large language models (LLMs) by offloading partial computation to cloud servers. However, transmitting intermediate activations exposes sensitive user prompts to prompt inversion attacks, where an adversary reconstructs the original input from shared representations. Existing defenses rely largely on heuristic perturbations or empirical tuning, offering limited theoretical understanding of privacy leakage and its interaction with utility and latency constraints. We propose an information-theoretic defense frame"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.11592","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.11592/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-11T01:09:57Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"l/Y/ZWaIwomL0bUrf/CG7lB0ru3ip9rWqFxQ4XLAav9JFubqRCbC/uELnjcQh40CtRXcuI392xviqV1ilHwCDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-23T08:02:59.410825Z"},"content_sha256":"c01a08d8d0c323b6a27f45da0d104ff4d379e7e017650129596b7cbebac929c9","schema_version":"1.0","event_id":"sha256:c01a08d8d0c323b6a27f45da0d104ff4d379e7e017650129596b7cbebac929c9"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/P24YTHCOA6BY5IBEMAAO33X5XO/bundle.json","state_url":"https://pith.science/pith/P24YTHCOA6BY5IBEMAAO33X5XO/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/P24YTHCOA6BY5IBEMAAO33X5XO/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-23T08:02:59Z","links":{"resolver":"https://pith.science/pith/P24YTHCOA6BY5IBEMAAO33X5XO","bundle":"https://pith.science/pith/P24YTHCOA6BY5IBEMAAO33X5XO/bundle.json","state":"https://pith.science/pith/P24YTHCOA6BY5IBEMAAO33X5XO/state.json","well_known_bundle":"https://pith.science/.well-known/pith/P24YTHCOA6BY5IBEMAAO33X5XO/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:P24YTHCOA6BY5IBEMAAO33X5XO","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"51fd58c993a3a9061f5fa1fcfdfa469f569a900d01fbee95792d94bf33b27275","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T02:36:26Z","title_canon_sha256":"8b0861453ba781a3398bac8b23c4801e1bc1dc8794569390077ba5997372bdbd"},"schema_version":"1.0","source":{"id":"2606.11592","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.11592","created_at":"2026-06-11T01:09:57Z"},{"alias_kind":"arxiv_version","alias_value":"2606.11592v1","created_at":"2026-06-11T01:09:57Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.11592","created_at":"2026-06-11T01:09:57Z"},{"alias_kind":"pith_short_12","alias_value":"P24YTHCOA6BY","created_at":"2026-06-11T01:09:57Z"},{"alias_kind":"pith_short_16","alias_value":"P24YTHCOA6BY5IBE","created_at":"2026-06-11T01:09:57Z"},{"alias_kind":"pith_short_8","alias_value":"P24YTHCO","created_at":"2026-06-11T01:09:57Z"}],"graph_snapshots":[{"event_id":"sha256:c01a08d8d0c323b6a27f45da0d104ff4d379e7e017650129596b7cbebac929c9","target":"graph","created_at":"2026-06-11T01:09:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.11592/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Collaborative edge-cloud inference enables resource-constrained devices to leverage large language models (LLMs) by offloading partial computation to cloud servers. However, transmitting intermediate activations exposes sensitive user prompts to prompt inversion attacks, where an adversary reconstructs the original input from shared representations. Existing defenses rely largely on heuristic perturbations or empirical tuning, offering limited theoretical understanding of privacy leakage and its interaction with utility and latency constraints. We propose an information-theoretic defense frame","authors_text":"Hossein Khalili, Nader Sehatbakhsh, Sayedeh Leila Noorbakhsh","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T02:36:26Z","title":"Defense Against Prompt Inversion Attacks: An Information-Theoretic Approach for LLM Collaborative Inference"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.11592","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:55bc2573b1f5ac53a326dd882f36c9969485d7bd5fd51f1928983b6ff9720e2e","target":"record","created_at":"2026-06-11T01:09:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"51fd58c993a3a9061f5fa1fcfdfa469f569a900d01fbee95792d94bf33b27275","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T02:36:26Z","title_canon_sha256":"8b0861453ba781a3398bac8b23c4801e1bc1dc8794569390077ba5997372bdbd"},"schema_version":"1.0","source":{"id":"2606.11592","kind":"arxiv","version":1}},"canonical_sha256":"7eb9899c4e07838ea0246000edeefdbba73ec3fc98057ae1f6f13baa059c144d","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"7eb9899c4e07838ea0246000edeefdbba73ec3fc98057ae1f6f13baa059c144d","first_computed_at":"2026-06-11T01:09:57.964618Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-11T01:09:57.964618Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"cFiJ9jCn5gZqhokJgif7IsFqbRRG7egwwobIyLChU/FM5r4Pork3TLPyfBAE9FfzS6Vg9obn7i7YF2+/hWfWCg==","signature_status":"signed_v1","signed_at":"2026-06-11T01:09:57.965464Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.11592","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:55bc2573b1f5ac53a326dd882f36c9969485d7bd5fd51f1928983b6ff9720e2e","sha256:c01a08d8d0c323b6a27f45da0d104ff4d379e7e017650129596b7cbebac929c9"],"state_sha256":"232eb64b501221e779644a4b16d94c3c04935eab236e967ae0b0e8b49bd756ef"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"YV4E+hA1VYtoH68V+vYGd1VhhXGNh8YbP1CGMwjC0gAY5omhF+whaqwd2ZP6Hci9sphvyHYmovEpQ35wv8K1AA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-23T08:02:59.412986Z","bundle_sha256":"df81c8ed65e7994327af908f97b875ed520a29a55f8bed12a2c42799e23d03ee"}}