{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:TFXJMZOYKSWUZHGJV3JTGTRKX7","short_pith_number":"pith:TFXJMZOY","schema_version":"1.0","canonical_sha256":"996e9665d854ad4c9cc9aed3334e2abfc0e292b14e5f55e8bddca253368a6085","source":{"kind":"arxiv","id":"2606.03381","version":1},"attestation_state":"computed","paper":{"title":"AI Model Extraction Attacks: Bypassing Single-Client Assumptions in Defenses","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Gustavo S\\'anchez, Johannes F. Loevenich, Laurin Holz, Maxime Schwarzer, Roberto Rigolin F. Lopes, Thies M\\\"ohlenhof, Tobias H\\\"urten, Veit Hagenmeyer","submitted_at":"2026-06-02T09:25:29Z","abstract_excerpt":"Ensuring the protection of Artificial Intelligence (AI) models deployed in military Command and Control (C2) systems and critical infrastructure is essential for maintaining information superiority. Model Extraction Attacks (MEAs) pose a significant threat, as they enable adversaries to replicate proprietary models, compromise protected information, and prepare offline adversarial attacks. However, current defense strategies predominantly rely on the Single Client Assumption (SCA), which is the implicit assumption that attacks originate from isolated identities. This work systematically demons"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2606.03381","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T09:25:29Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"02873b45f292880db4888fd8d7107add8ad6e8737f2afd7fe7cfc0d3140ba7b5","abstract_canon_sha256":"828aaabc752dc67bcf2d2f71e0bdb9adcc875dc26b42098796fa1ad5e625a2a9"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-03T01:05:56.433866Z","signature_b64":"PHq0CDu8jyKX4TgIkycqJCiASGasSbtzdXt2nsaE6NT7wyFTpSc/s2+qPArn4om84lMQ2NIA8qMoO3+tiC7KDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"996e9665d854ad4c9cc9aed3334e2abfc0e292b14e5f55e8bddca253368a6085","last_reissued_at":"2026-06-03T01:05:56.433477Z","signature_status":"signed_v1","first_computed_at":"2026-06-03T01:05:56.433477Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"AI Model Extraction Attacks: Bypassing Single-Client Assumptions in Defenses","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Gustavo S\\'anchez, Johannes F. Loevenich, Laurin Holz, Maxime Schwarzer, Roberto Rigolin F. Lopes, Thies M\\\"ohlenhof, Tobias H\\\"urten, Veit Hagenmeyer","submitted_at":"2026-06-02T09:25:29Z","abstract_excerpt":"Ensuring the protection of Artificial Intelligence (AI) models deployed in military Command and Control (C2) systems and critical infrastructure is essential for maintaining information superiority. Model Extraction Attacks (MEAs) pose a significant threat, as they enable adversaries to replicate proprietary models, compromise protected information, and prepare offline adversarial attacks. However, current defense strategies predominantly rely on the Single Client Assumption (SCA), which is the implicit assumption that attacks originate from isolated identities. This work systematically demons"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.03381","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.03381/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2606.03381","created_at":"2026-06-03T01:05:56.433534+00:00"},{"alias_kind":"arxiv_version","alias_value":"2606.03381v1","created_at":"2026-06-03T01:05:56.433534+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.03381","created_at":"2026-06-03T01:05:56.433534+00:00"},{"alias_kind":"pith_short_12","alias_value":"TFXJMZOYKSWU","created_at":"2026-06-03T01:05:56.433534+00:00"},{"alias_kind":"pith_short_16","alias_value":"TFXJMZOYKSWUZHGJ","created_at":"2026-06-03T01:05:56.433534+00:00"},{"alias_kind":"pith_short_8","alias_value":"TFXJMZOY","created_at":"2026-06-03T01:05:56.433534+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/TFXJMZOYKSWUZHGJV3JTGTRKX7","json":"https://pith.science/pith/TFXJMZOYKSWUZHGJV3JTGTRKX7.json","graph_json":"https://pith.science/api/pith-number/TFXJMZOYKSWUZHGJV3JTGTRKX7/graph.json","events_json":"https://pith.science/api/pith-number/TFXJMZOYKSWUZHGJV3JTGTRKX7/events.json","paper":"https://pith.science/paper/TFXJMZOY"},"agent_actions":{"view_html":"https://pith.science/pith/TFXJMZOYKSWUZHGJV3JTGTRKX7","download_json":"https://pith.science/pith/TFXJMZOYKSWUZHGJV3JTGTRKX7.json","view_paper":"https://pith.science/paper/TFXJMZOY","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2606.03381&json=true","fetch_graph":"https://pith.science/api/pith-number/TFXJMZOYKSWUZHGJV3JTGTRKX7/graph.json","fetch_events":"https://pith.science/api/pith-number/TFXJMZOYKSWUZHGJV3JTGTRKX7/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/TFXJMZOYKSWUZHGJV3JTGTRKX7/action/timestamp_anchor","attest_storage":"https://pith.science/pith/TFXJMZOYKSWUZHGJV3JTGTRKX7/action/storage_attestation","attest_author":"https://pith.science/pith/TFXJMZOYKSWUZHGJV3JTGTRKX7/action/author_attestation","sign_citation":"https://pith.science/pith/TFXJMZOYKSWUZHGJV3JTGTRKX7/action/citation_signature","submit_replication":"https://pith.science/pith/TFXJMZOYKSWUZHGJV3JTGTRKX7/action/replication_record"}},"created_at":"2026-06-03T01:05:56.433534+00:00","updated_at":"2026-06-03T01:05:56.433534+00:00"}