{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2021:QU2KTVJPPSOEMYQCEY4UXJ52JD","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"f754ee297b3cb5735027b0959419493c7a5c37fce4372a522790b5113e8db9d2","cross_cats_sorted":["cs.CL","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2021-05-23T10:38:23Z","title_canon_sha256":"a9fa0abe65a994943173ac3e6ea3e985702abf6efe61b29dcffdb51765aa123f"},"schema_version":"1.0","source":{"id":"2105.10909","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2105.10909","created_at":"2026-07-05T03:43:41Z"},{"alias_kind":"arxiv_version","alias_value":"2105.10909v2","created_at":"2026-07-05T03:43:41Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2105.10909","created_at":"2026-07-05T03:43:41Z"},{"alias_kind":"pith_short_12","alias_value":"QU2KTVJPPSOE","created_at":"2026-07-05T03:43:41Z"},{"alias_kind":"pith_short_16","alias_value":"QU2KTVJPPSOEMYQC","created_at":"2026-07-05T03:43:41Z"},{"alias_kind":"pith_short_8","alias_value":"QU2KTVJP","created_at":"2026-07-05T03:43:41Z"}],"graph_snapshots":[{"event_id":"sha256:b9974a06204c1d1c145b95c67ad282725e48500a18d8b40b8ba08dda693d5cb4","target":"graph","created_at":"2026-07-05T03:43:41Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2105.10909/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"The collection and availability of big data, combined with advances in pre-trained models (e.g., BERT, XLNET, etc), have revolutionized the predictive performance of modern natural language processing tasks, ranging from text classification to text generation. This allows corporations to provide machine learning as a service (MLaaS) by encapsulating fine-tuned BERT-based models as APIs. However, BERT-based APIs have exhibited a series of security and privacy vulnerabilities. For example, prior work has exploited the security issues of the BERT-based APIs through the adversarial examples crafte","authors_text":"Chen Chen, Fangzhao Wu, Lingjuan Lyu, Xuanli He","cross_cats":["cs.CL","cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2021-05-23T10:38:23Z","title":"Killing One Bird with Two Stones: Model Extraction and Attribute Inference Attacks against BERT-based APIs"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2105.10909","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:9f3ecdbad3b82e1a2c5fe22acc6a0f2e153bd14fbf410811f256edcbdd6c3de9","target":"record","created_at":"2026-07-05T03:43:41Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"f754ee297b3cb5735027b0959419493c7a5c37fce4372a522790b5113e8db9d2","cross_cats_sorted":["cs.CL","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2021-05-23T10:38:23Z","title_canon_sha256":"a9fa0abe65a994943173ac3e6ea3e985702abf6efe61b29dcffdb51765aa123f"},"schema_version":"1.0","source":{"id":"2105.10909","kind":"arxiv","version":2}},"canonical_sha256":"8534a9d52f7c9c46620226394ba7ba48f769495f5ac073ff5402c846e43e4d1d","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"8534a9d52f7c9c46620226394ba7ba48f769495f5ac073ff5402c846e43e4d1d","first_computed_at":"2026-07-05T03:43:41.196170Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T03:43:41.196170Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"NnQRyRKn9u9aQwFYplNsgFqxpHcw+TJwD8n92HKJROn8lHEmdWc9bhmf0jAVR2GliaRjL4KrYQ4MpANFG50IAg==","signature_status":"signed_v1","signed_at":"2026-07-05T03:43:41.196656Z","signed_message":"canonical_sha256_bytes"},"source_id":"2105.10909","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:9f3ecdbad3b82e1a2c5fe22acc6a0f2e153bd14fbf410811f256edcbdd6c3de9","sha256:b9974a06204c1d1c145b95c67ad282725e48500a18d8b40b8ba08dda693d5cb4"],"state_sha256":"62a9abddd250a3a269b4af29f9290d052cb55fcfc2ac949eee723a794bb2f6ad"}